REORBIT – DATA PROCESSING ADDENDUM (DPA)
Effective Date: March 26, 2026
Company: Reorbit Labs OÜ (“Reorbit”, “Processor”)
Merchant: (“Controller”)
1. Purpose & Scope
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Reorbit and the Merchant.
This DPA applies where Reorbit processes personal data on behalf of the Merchant in connection with the Services.
2. Roles of the Parties
For the purposes of applicable data protection laws:
- The Merchant acts as the Data Controller
- Reorbit acts as the Data Processor
Reorbit shall process personal data solely on documented instructions from the Merchant, unless required to do otherwise by applicable law.
3. Nature and Purpose of Processing
Reorbit processes personal data to:
- Provide and operate the Services
- Enable reviews, loyalty programs, and lifecycle messaging
- Sync, organize, and analyze customer and order data
- Provide reporting and analytics
Processing may include collection, storage, organization, analysis, and transmission of data.
4. Types of Personal Data
Personal data processed may include:
- Names
- Email addresses
- Shipping and billing addresses
- Order and transaction data
- Loyalty data (including points, rewards, and redemptions)
- Behavioral and engagement data
5. Categories of Data Subjects
Data subjects may include:
- Customers of the Merchant
- Website visitors
- Subscribers to communications
6. Processor Obligations
Reorbit shall:
- Process personal data only in accordance with the Merchant’s instructions
- Ensure that personnel authorized to process data are bound by confidentiality obligations
- Implement appropriate technical and organizational security measures
- Assist the Merchant, where reasonably possible, in responding to data subject requests
- Assist with compliance related to data protection obligations
- Notify the Merchant of personal data breaches without undue delay
7. Subprocessors
Reorbit may engage third-party subprocessors to support the Services.
Reorbit shall:
- Ensure subprocessors are bound by data protection obligations equivalent to those set out in this DPA
- Maintain an up-to-date list of subprocessors
8. International Data Transfers
Where personal data is transferred outside the European Economic Area (EEA), Reorbit shall ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs)
- Or other legally recognized transfer mechanisms
9. Security Measures
Reorbit implements reasonable technical and organizational measures, including:
- Encryption in transit
- Access controls and authentication measures
- Monitoring and logging systems
- Internal policies for data protection and security
10. Data Breach Notification
In the event of a personal data breach affecting Merchant data, Reorbit shall notify the Merchant without undue delay and provide reasonable assistance in addressing the breach.
11. Data Retention & Deletion
Upon termination of the Services:
- Personal data will be deleted or returned to the Merchant within a reasonable timeframe
- Backup copies may be retained for a limited period for security and legal compliance purposes
12. Audit & Information Rights
Reorbit shall make available to the Merchant reasonable information necessary to demonstrate compliance with this DPA.
13. Liability
Each party’s liability under this DPA shall be subject to the limitations of liability set out in the Terms of Service.
14. Governing Law
This DPA shall be governed by the laws of Estonia, unless otherwise required by applicable data protection laws.
15. Contact
For any data protection inquiries:
Email: support@reorbit.app
