Legal
Last updated: June 2026
“Controller” means the natural or legal person who determines the purposes and means of processing personal data — in this context, the Operator.
“Processor” means the natural or legal person who processes personal data on behalf of the Controller — in this context, Palladium Innovations.
“Personal Data” has the meaning given in Article 4(1) GDPR: any information relating to an identified or identifiable natural person.
“Processing” has the meaning given in Article 4(2) GDPR.
“Sub-processor” means any third party engaged by Palladium Innovations to carry out processing activities on the Controller's behalf.
“Supervisory Authority” means the competent data protection authority in the relevant jurisdiction (e.g., the ICO in the UK, or the lead supervisory authority under GDPR).
Palladium Innovations processes personal data on behalf of the Operator solely to provide the Orbilex cloud-hosted platform as described in the Terms of Service. The processing begins when the Operator activates a cloud-hosted subscription and ends on the date that the Operator's subscription is terminated, at which point the provisions of §12 (Data return and deletion) apply.
The processing is necessary to provide the Orbilex SaaS platform, which includes:
Palladium Innovations does not use the Operator's data for any other purpose and will not process it for its own commercial interests.
The personal data processed may include:
The data subjects whose personal data is processed include:
The Operator, as Controller, warrants and undertakes that:
Palladium Innovations, as Processor, undertakes the following in accordance with GDPR Article 28(3):
The Operator grants Palladium Innovations general authorisation to engage the sub-processors listed in the Privacy Policy §2b. Palladium Innovations will notify the Operator by email and by updating the Privacy Policy at least 14 days before engaging any new sub-processor or materially changing an existing sub-processor's role.
If the Operator objects to a new sub-processor on reasonable data protection grounds, it must notify Palladium Innovations at legal@orbilex.app within 14 days of the notification. The parties will work in good faith to resolve the objection. If resolution is not possible within 30 days, the Operator may terminate its subscription without penalty.
Palladium Innovations remains fully liable to the Controller for the acts and omissions of its sub-processors as if they were its own acts and omissions.
Palladium Innovations will provide reasonable technical and organisational assistance to help the Operator respond to data subject rights requests (access, rectification, erasure, restriction, portability, and objection) within the timeframes required by applicable data protection law.
The Operator is responsible for responding to data subject requests as the Controller. Palladium Innovations will not respond directly to data subjects except on the Controller's express written instruction. Requests received by Palladium Innovations directly from data subjects will be forwarded to the Operator within 3 business days.
Palladium Innovations implements the following technical and organisational measures to ensure a level of security appropriate to the risk, in accordance with GDPR Article 32:
Access control
Role-based access control (Admin, Staff, Client) with principle of least privilege. Multi-factor authentication enforced for all operator accounts. Session tokens are short-lived and rotated on privilege change.
Encryption
TLS 1.2+ for all data in transit. AES-256 for data at rest. Payment gateway credentials, SMTP credentials, registrar credentials, and server credentials are stored as encrypted ciphertext using envelope encryption with a per-tenant key version.
Audit logging
All platform actions are written to an immutable, append-only audit log recording actor, action, resource, IP address, and timestamp. Logs cannot be modified or deleted by operators.
Availability and resilience
Infrastructure deployed across multiple availability zones. Automated health checks with alerting. Daily backups retained for 30 days. Incident response runbook maintained and reviewed quarterly.
Vulnerability management
Automated dependency vulnerability scanning on every build. Critical CVEs patched within 14 days. Penetration testing conducted annually. SOC 2 Type II audit in progress (expected Q4 2026).
Sub-processor oversight
All sub-processors are assessed for GDPR compliance before engagement. Data processing agreements in place with each sub-processor. Annual review of sub-processor compliance posture.
In the event of a personal data breach affecting data processed under this DPA, Palladium Innovations will:
Breach notifications must be sent to the Controller's registered email address. The Operator is responsible for notifying its data subjects and supervisory authority as required by applicable law.
On termination or expiry of the cloud-hosted subscription, Palladium Innovations will:
To initiate an early export or deletion before the 30-day window expires, email legal@orbilex.app.
Palladium Innovations will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA and will permit audits conducted by the Controller or an independent auditor appointed by the Controller, subject to the following conditions:
Where the Controller requests audit information that is already covered by an existing third-party certification (e.g., SOC 2 report), Palladium Innovations may provide that certification in lieu of a bespoke audit.
Palladium Innovations will not transfer personal data outside the EEA, UK, or a country with an adequate level of protection (as determined by the European Commission or the UK Secretary of State) without an appropriate transfer mechanism in place, such as the Standard Contractual Clauses (SCCs) approved by the European Commission or the UK International Data Transfer Agreement (IDTA).
The sub-processors listed in the Privacy Policy have been assessed, and appropriate transfer mechanisms are in place for each.
This DPA is governed by the laws of England and Wales. Any dispute arising from or in connection with this DPA shall be subject to the jurisdiction of the courts of England and Wales, without prejudice to any mandatory rights the Operator may have under applicable data protection law in its own jurisdiction.
Palladium Innovations
Data protection matters: legal@orbilex.app
A signed copy of this DPA suitable for countersignature is available on request.