Legal

Data Processing Agreement

Last updated: June 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between you (“Operator” / “Controller”) and Palladium Innovations (“Company” / “Processor”) and satisfies the requirements of GDPR Article 28. It applies when Palladium Innovations processes personal data on behalf of the Operator under the Orbilex cloud-hosted service. For self-hosted deployments, the Operator is the sole controller and processor of end-client data. Questions? Email legal@orbilex.app.

1. Definitions

“Controller” means the natural or legal person who determines the purposes and means of processing personal data — in this context, the Operator.

“Processor” means the natural or legal person who processes personal data on behalf of the Controller — in this context, Palladium Innovations.

“Personal Data” has the meaning given in Article 4(1) GDPR: any information relating to an identified or identifiable natural person.

“Processing” has the meaning given in Article 4(2) GDPR.

“Sub-processor” means any third party engaged by Palladium Innovations to carry out processing activities on the Controller's behalf.

“Supervisory Authority” means the competent data protection authority in the relevant jurisdiction (e.g., the ICO in the UK, or the lead supervisory authority under GDPR).

2. Subject matter and duration

Palladium Innovations processes personal data on behalf of the Operator solely to provide the Orbilex cloud-hosted platform as described in the Terms of Service. The processing begins when the Operator activates a cloud-hosted subscription and ends on the date that the Operator's subscription is terminated, at which point the provisions of §12 (Data return and deletion) apply.

3. Nature and purpose of processing

The processing is necessary to provide the Orbilex SaaS platform, which includes:

  • Authenticating and managing operator and end-client accounts
  • Storing and processing billing records, invoices, and payment metadata
  • Maintaining audit logs and provisioning records
  • Delivering transactional emails (ticket notifications, invoice receipts, license alerts)
  • Providing the client portal and knowledge base to the Operator's end-clients

Palladium Innovations does not use the Operator's data for any other purpose and will not process it for its own commercial interests.

4. Types of personal data

The personal data processed may include:

  • Identity data (name, company name)
  • Contact data (email address, phone number)
  • Account credentials (hashed passwords, session tokens)
  • Financial data (invoice amounts, payment status; card numbers are never stored)
  • Technical data (IP addresses, browser type, access timestamps)
  • Support data (ticket content, message history)
  • Usage data (provisioning events, audit log entries)

5. Categories of data subjects

The data subjects whose personal data is processed include:

  • Operator personnel — the Operator's staff members who access the Orbilex dashboard (owners, admins, billing contacts, support staff)
  • End-clients — the Operator's customers who use the client portal, receive invoices, and submit support tickets

6. Controller obligations

The Operator, as Controller, warrants and undertakes that:

  • It has a lawful basis under GDPR Article 6 for all personal data provided to or generated through the platform;
  • It has provided data subjects with appropriate privacy notices covering the processing described in this DPA;
  • It will not instruct Palladium Innovations to process personal data in a manner that would violate applicable data protection law;
  • It is responsible for the accuracy, quality, and legality of the personal data it submits to the platform;
  • It will promptly inform Palladium Innovations if any instruction given would, in the Operator's opinion, infringe applicable data protection law.

7. Processor obligations

Palladium Innovations, as Processor, undertakes the following in accordance with GDPR Article 28(3):

  • (a) Instructions only. Process personal data only on documented instructions from the Controller, unless required to do so by applicable law (in which case, notify the Controller in advance unless prohibited by law).
  • (b) Confidentiality. Ensure that all persons authorised to process personal data are bound by appropriate confidentiality obligations.
  • (c) Security. Implement the technical and organisational measures described in §10 of this DPA in accordance with GDPR Article 32.
  • (d) Sub-processors. Not engage a new sub-processor without prior notice to the Controller as described in §8 below.
  • (e) Data subject rights. Assist the Controller in fulfilling its obligations to respond to data subject rights requests as described in §9.
  • (f) Security and breach assistance. Assist the Controller with its obligations under GDPR Articles 32–36 (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of the processing and information available.
  • (g) Return and deletion. At the Controller's choice, delete or return all personal data to the Controller at the end of service provision, and delete existing copies unless storage is required by applicable law (§12).
  • (h) Audit cooperation. Make available all information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits as described in §13.

8. Sub-processors

The Operator grants Palladium Innovations general authorisation to engage the sub-processors listed in the Privacy Policy §2b. Palladium Innovations will notify the Operator by email and by updating the Privacy Policy at least 14 days before engaging any new sub-processor or materially changing an existing sub-processor's role.

If the Operator objects to a new sub-processor on reasonable data protection grounds, it must notify Palladium Innovations at legal@orbilex.app within 14 days of the notification. The parties will work in good faith to resolve the objection. If resolution is not possible within 30 days, the Operator may terminate its subscription without penalty.

Palladium Innovations remains fully liable to the Controller for the acts and omissions of its sub-processors as if they were its own acts and omissions.

9. Data subject rights assistance

Palladium Innovations will provide reasonable technical and organisational assistance to help the Operator respond to data subject rights requests (access, rectification, erasure, restriction, portability, and objection) within the timeframes required by applicable data protection law.

The Operator is responsible for responding to data subject requests as the Controller. Palladium Innovations will not respond directly to data subjects except on the Controller's express written instruction. Requests received by Palladium Innovations directly from data subjects will be forwarded to the Operator within 3 business days.

10. Technical and organisational measures (TOMs)

Palladium Innovations implements the following technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with GDPR Article 32:

CategoryMeasures

Access control

Role-based access control (Admin, Staff, Client) with principle of least privilege. Multi-factor authentication enforced for all operator accounts. Session tokens are short-lived and rotated on privilege change.

Encryption

TLS 1.2+ for all data in transit. AES-256 for data at rest. Payment gateway credentials, SMTP credentials, registrar credentials, and server credentials are stored as encrypted ciphertext using envelope encryption with a per-tenant key version.

Audit logging

All platform actions are written to an immutable, append-only audit log recording actor, action, resource, IP address, and timestamp. Logs cannot be modified or deleted by operators.

Availability and resilience

Infrastructure deployed across multiple availability zones. Automated health checks with alerting. Daily backups retained for 30 days. Incident response runbook maintained and reviewed quarterly.

Vulnerability management

Automated dependency vulnerability scanning on every build. Critical CVEs patched within 14 days. Penetration testing conducted annually. SOC 2 Type II audit in progress (expected Q4 2026).

Sub-processor oversight

All sub-processors are assessed for GDPR compliance before engagement. Data processing agreements in place with each sub-processor. Annual review of sub-processor compliance posture.

11. Data breach notification

In the event of a personal data breach affecting data processed under this DPA, Palladium Innovations will:

  • Notify the Controller without undue delay and, where feasible, within 72 hours of becoming aware of the breach;
  • Provide a written incident report including: the nature of the breach, categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed to address the breach;
  • Cooperate fully with the Controller's own breach notification obligations to supervisory authorities and data subjects.

Breach notifications must be sent to the Controller's registered email address. The Operator is responsible for notifying its data subjects and supervisory authority as required by applicable law.

12. Data return and deletion

On termination or expiry of the cloud-hosted subscription, Palladium Innovations will:

  • Export window (30 days). Make available a full data export (JSON/CSV) of all Operator and end-client data for 30 days following termination.
  • Secure deletion. Permanently delete all personal data from production systems at the end of the 30-day window, except where retention is required by applicable law (e.g., tax records).
  • Confirmation. Provide written confirmation of deletion within 14 days of completion, on request.

To initiate an early export or deletion before the 30-day window expires, email legal@orbilex.app.

13. Audit rights

Palladium Innovations will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and will permit audits conducted by the Controller or an independent auditor appointed by the Controller, subject to the following conditions:

  • The Controller must give Palladium Innovations at least 30 days' written notice of an intended audit;
  • Audits shall be conducted during normal business hours and in a manner that minimises disruption;
  • The Controller shall bear all costs of such audits unless the audit reveals a material breach of this DPA;
  • Any third-party auditor must sign a confidentiality agreement acceptable to Palladium Innovations before commencing the audit.

Where the Controller requests audit information that is already covered by an existing third-party certification (e.g., SOC 2 report), Palladium Innovations may provide that certification in lieu of a bespoke audit.

14. International data transfers

Palladium Innovations will not transfer personal data outside the EEA, UK, or a country with an adequate level of protection (as determined by the European Commission or the UK Secretary of State) without an appropriate transfer mechanism in place, such as the Standard Contractual Clauses (SCCs) approved by the European Commission or the UK International Data Transfer Agreement (IDTA).

The sub-processors listed in the Privacy Policy have been assessed, and appropriate transfer mechanisms are in place for each.

15. Governing law

This DPA is governed by the laws of England and Wales. Any dispute arising from or in connection with this DPA shall be subject to the jurisdiction of the courts of England and Wales, without prejudice to any mandatory rights the Operator may have under applicable data protection law in its own jurisdiction.

16. Contact

Palladium Innovations
Data protection matters: legal@orbilex.app

A signed copy of this DPA suitable for countersignature is available on request.