Data Processing Addendum (DPA)

Standard agreement outlining our processing obligations under GDPR Article 28.

Last Updated: June 21, 2026

1. Scope and Applicability

This Data Processing Addendum ("DPA") applies to the processing of personal data by OrionHQ as a data processor on behalf of our customer (the "Data Controller"). This agreement is integrated into and forms part of the Terms of Service.

2. Processing of Personal Data

OrionHQ shall process personal data only in accordance with the Controller's documented instructions, including transferring personal data outside the EEA or UK only upon controller request or explicit compliance mechanisms.

3. Technical & Organizational Measures

We implement industry-standard technical security configurations to protect data, including:

  • End-to-end TLS encryption for all API traffic.
  • Firebase security isolation rules preventing browser write access to critical collections.
  • Role-Based Access Control (RBAC) scopes.
  • Progressive log rate-limiting.

4. Subprocessors

The Controller authorizes OrionHQ to engage subprocessors to support platform capabilities. A complete list of active subprocessors is available on our Subprocessors page. We execute written compliance DPAs with all subprocessors.

5. Audits and Erasure

OrionHQ shall make available to the Controller information necessary to demonstrate compliance with Article 28. Upon request, we will export and permanently delete controller personal data, unless legally required to retain it.

Data Processing Addendum (DPA) | OrionHQ