Legal
Data processing addendum
Effective date:
This Data Processing Addendum (“DPA”) forms part of the Terms of Service and applies whenever OrbiCrawl AI processes personal data on your behalf — chiefly, the data your crawls collect. In GDPR terms: you are the controller, we are the processor. It is designed to satisfy Article 28 GDPR and equivalent obligations under the UK GDPR and other data-protection laws.
1. Scope of processing
- Subject matter: business-contact data extracted from websites you designate — names, business emails and phone numbers, social profiles, company details and related signals.
- Duration: while your account is active, plus the deletion windows in the Privacy Policy.
- Nature and purpose: crawling, extraction, validation, enrichment, AI scoring, storage, export and delivery to integrations you configure — solely to provide the Service.
- Data subjects: personnel and representatives of the businesses whose public websites you crawl.
2. Processing on your instructions
We process customer personal data only on your documented instructions — your crawl configurations, workflow rules, exports and API calls are those instructions — and never for our own marketing or model training. If we believe an instruction violates data-protection law we will tell you before proceeding.
3. Confidentiality and security
- Personnel with access are bound by confidentiality obligations.
- Technical measures include TLS in transit, encryption at rest, hashed credentials, role-based access, audit logging and network isolation — as described in the Privacy Policy.
- We notify you of a personal-data breach affecting your workspace without undue delay and no later than 72 hours after confirmation, with the information you need for your own notifications.
4. Subprocessors
You authorize the subprocessors listed in the Privacy Policy (infrastructure, storage, payment, AI inference). We remain responsible for their performance. We will give at least 14 days’ notice before adding a subprocessor that touches customer personal data; if you reasonably object on data-protection grounds and we cannot accommodate you, you may terminate affected services and receive a pro-rata refund of prepaid fees.
5. Assistance and data-subject requests
- We forward data-subject requests we receive about your crawled data to you and, taking into account the nature of processing, assist you in fulfilling them — the dashboard’s search, export and delete tools are the primary mechanism.
- We assist with your DPIAs and supervisory-authority consultations to the extent the information is in our control.
6. Transfers and audits
- International transfers rely on adequacy decisions or Standard Contractual Clauses, which are incorporated by reference where required.
- Once per year, on 30 days’ notice, you may audit our compliance with this DPA — first through our documentation and security summaries, and where those are genuinely insufficient, through a mutually agreed independent audit at your cost.
7. Return and deletion
You can export your data at any time (CSV, Excel, JSON, API). On termination we delete customer personal data within 30 days (backups within 35), except where law requires retention. On written request we confirm deletion.
8. Need a signed copy?
Enterprise customers who need a countersigned DPA or wish to attach their own SCC annexes can email legal@orbicrawl.com — we’ll return a signature-ready copy.