Data Processing Addendum

REORBIT – DATA PROCESSING ADDENDUM (DPA)

Effective Date: March 26, 2026
Company: Reorbit Labs OÜ (“Reorbit”, “Processor”)
Merchant: (“Controller”)


1. Purpose & Scope

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Reorbit and the Merchant.

This DPA applies where Reorbit processes personal data on behalf of the Merchant in connection with the Services.


2. Roles of the Parties

For the purposes of applicable data protection laws:

  • The Merchant acts as the Data Controller
  • Reorbit acts as the Data Processor

Reorbit shall process personal data solely on documented instructions from the Merchant, unless required to do otherwise by applicable law.


3. Nature and Purpose of Processing

Reorbit processes personal data to:

  • Provide and operate the Services
  • Enable reviews, loyalty programs, and lifecycle messaging
  • Sync, organize, and analyze customer and order data
  • Provide reporting and analytics

Processing may include collection, storage, organization, analysis, and transmission of data.


4. Types of Personal Data

Personal data processed may include:

  • Names
  • Email addresses
  • Shipping and billing addresses
  • Order and transaction data
  • Loyalty data (including points, rewards, and redemptions)
  • Behavioral and engagement data

5. Categories of Data Subjects

Data subjects may include:

  • Customers of the Merchant
  • Website visitors
  • Subscribers to communications

6. Processor Obligations

Reorbit shall:

  • Process personal data only in accordance with the Merchant’s instructions
  • Ensure that personnel authorized to process data are bound by confidentiality obligations
  • Implement appropriate technical and organizational security measures
  • Assist the Merchant, where reasonably possible, in responding to data subject requests
  • Assist with compliance related to data protection obligations
  • Notify the Merchant of personal data breaches without undue delay

7. Subprocessors

Reorbit may engage third-party subprocessors to support the Services.

Reorbit shall:

  • Ensure subprocessors are bound by data protection obligations equivalent to those set out in this DPA
  • Maintain an up-to-date list of subprocessors

8. International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), Reorbit shall ensure appropriate safeguards are in place, including:

  • Standard Contractual Clauses (SCCs)
  • Or other legally recognized transfer mechanisms

9. Security Measures

Reorbit implements reasonable technical and organizational measures, including:

  • Encryption in transit
  • Access controls and authentication measures
  • Monitoring and logging systems
  • Internal policies for data protection and security

10. Data Breach Notification

In the event of a personal data breach affecting Merchant data, Reorbit shall notify the Merchant without undue delay and provide reasonable assistance in addressing the breach.


11. Data Retention & Deletion

Upon termination of the Services:

  • Personal data will be deleted or returned to the Merchant within a reasonable timeframe
  • Backup copies may be retained for a limited period for security and legal compliance purposes

12. Audit & Information Rights

Reorbit shall make available to the Merchant reasonable information necessary to demonstrate compliance with this DPA.


13. Liability

Each party’s liability under this DPA shall be subject to the limitations of liability set out in the Terms of Service.


14. Governing Law

This DPA shall be governed by the laws of Estonia, unless otherwise required by applicable data protection laws.


15. Contact

For any data protection inquiries:

Email: support@reorbit.app