# Data processing addendum

> How Orbit processes the personal data your apps handle: roles, security measures, sub-processors, transfers, breach notice and deletion.

Last updated 4 October 2026. Draft: the company details in this document, and some of its terms, are placeholders until launch. Deleting data for good is not built yet. Today a deleted app is taken off the servers, but its records, and those of a deleted team, stay in our database. The times given here for deletion do not apply yet.

## In short

- You are the controller of the personal data your apps handle, and we process it for you only to provide the service.
- We do not look into the data inside your apps as part of normal operation, and every staff sign-in to a customer account is recorded.
- Each app runs in the region you chose, while the records the dashboard keeps about it are stored in the United States.
- Other companies process data for us, and we tell you at least 30 days before we add or replace one.
- We tell you about a breach that affects the personal data in your apps within 72 hours of becoming aware of it.
- We hold no third-party certification today, so there is no audit report to hand over.

The full text below is what counts.

Your apps may handle personal data of other people. This addendum says what we do with that data while we host your apps, and what each side answers for.

"We", "us" and "our" mean Example Hosting, Inc., the company that runs Orbit. "You" means the person or organization that uses the service.

## When this addendum applies

This addendum is part of the agreement between you and us that the [terms of service](https://arrangic.com/terms) set out. It applies when you use the service to process personal data of other people and a data protection law requires a contract between you and us. Examples are the GDPR, the UK GDPR and the privacy laws of US states such as California. Below, "the agreement" means that agreement, and "the data" means that personal data.

If this addendum and the terms of service say different things about data protection, this addendum comes first.

## Roles

You decide why and how the data is processed. That makes you its controller, or its processor if you handle it for a customer of your own.

We process the data for you. That makes us your processor, or your sub-processor in the second case, and your "service provider" under the privacy law of California.

For the personal data we hold about you, such as your account, billing and contact details, we are a controller ourselves. The [privacy policy](https://arrangic.com/privacy) covers that, not this addendum.

## The processing

| Item | Details |
| --- | --- |
| Subject | Hosting your apps. |
| Duration | As long as the agreement lasts, and after it until the data is deleted (see [Deletion](#deletion)). |
| Nature | Storing, running, transmitting and logging. |
| Purpose | Providing the service to you. |
| Kinds of data and of people | Whatever your apps handle. Typically the people who use your apps or are named in them, such as your users, customers and staff, and their names, contact details, sign-in details and network addresses. You decide that, and we do not know what it is. |
| Special categories of data | Only if you put them there. The service is not designed for them. |

Runtime logs are part of the processing. They hold whatever your app prints, unfiltered. We do not store them in our database: the infrastructure provider that runs the app keeps them for about a week, and every member of your team can read them.

## Your instructions

We process the data only on your documented instructions. Those are the agreement, the settings you choose in the dashboard, and what your apps do. By choosing a region for an app and by using the dashboard, you instruct us to process the data in those places.

We do not use the data for purposes of our own. Keeping the service running and secure, and looking into a fault or into abuse as the [acceptable use policy](https://arrangic.com/acceptable-use) describes, are part of providing the service.

If a law requires us to process the data in another way, we tell you first, unless that law forbids it. If we believe an instruction of yours breaks data protection law, we tell you at once.

## What we commit to

### Confidentiality and staff access

Everyone we allow to reach the data is bound to keep it confidential.

We do not look into the data inside your apps as part of normal operation. A small number of authorized staff can see your account, your team, your apps, the names of your repositories, your deployments and the activity trail. To give support, or to investigate a fault or abuse, they can sign in to your account through a link that works for two minutes. They then see what you see in the dashboard, and that includes your logs. Every such sign-in is recorded, with the staff member and their IP address.

### Security measures

We take the technical and organizational measures that the risk to the data calls for. Today these are the following. The [security page](https://arrangic.com/security) describes them further.

- **Isolation.** Each replica of an app runs in its own virtual machine. A team's apps share a private network that other teams cannot reach. Every app has its own build environment and build cache.
- **Network.** From the internet an app can be reached on ports 80 and 443 only. Plain HTTP is redirected to HTTPS, and certificates are issued and renewed automatically.
- **Variables.** Environment variables are encrypted at rest in our database with AES-256, and every reveal of a value is recorded in the activity trail.
- **Sign-in.** There are no passwords. We email a code that is valid for ten minutes and five tries, and requests for codes are rate limited.
- **The dashboard.** It tells browsers to use HTTPS only, and its pages cannot be shown inside a frame on another site. The cookies that sign you in are sent over HTTPS only and cannot be read by scripts on the page.
- **Roles.** A team has an owner, admins and members. Members cannot see the values of existing variables and cannot delete apps.
- **Activity trail.** The dashboard records who did what in your team, and when.
- **GitHub.** Access tokens for GitHub are created when needed, live for less than an hour and are not stored in our database.

We may change these measures as the service changes, as long as the protection of the data as a whole does not become weaker.

### Help with requests and assessments

The people whose data your apps handle have rights under the law, such as seeing, correcting or deleting it. Answering them is your part, because we do not know what is in your apps. We help as far as we can. If such a person writes to us and we can tell which app is meant, we pass the request to you and do not answer it ourselves.

On request we help you with impact assessments and with questions from a data protection authority.

### Personal data breaches

If we become aware of a breach of security that affects your apps, their records or their logs, and so may affect the data, we tell the owner of the team by email. We do so without undue delay, and no later than 72 hours after we become aware of it.

As far as we know it, we tell you what happened, which data and which people are affected and what we have done about it. We tell you more as we learn it, and we help you with the notices you have to make.

### Deletion

When an app is deleted, by you or by us under the terms of service, we stop it and remove its running copies and its address at once. We delete its records (settings, variables, deployments and build logs) within 30 days.

When the agreement ends, we delete the data within 30 days, unless the law requires us to keep it. Copy what you need before the agreement ends. If you ask at [privacy@arrangic.com](mailto:privacy@arrangic.com) before the data is deleted, we send you a copy of the records we still hold.

## Your commitments

- You have a lawful ground for processing the data, and for having us process it.
- If you handle the data for a customer of your own, you have that customer's permission to use us and our sub-processors, and your instructions to us are that customer's instructions.
- You set up your apps securely. Your code, your dependencies and your secrets are yours to look after.
- You keep your own backups: an app's disk and memory are temporary, and we do not back up what it writes.
- You do not put data into the service that the law does not allow to be there.

## Sub-processors

You give us general permission to use other companies for parts of the service. We use these kinds:

| Kind of provider | What it receives |
| --- | --- |
| Infrastructure providers that build and run your apps | Source code during a build, built images, variables, hostnames, runtime logs and the traffic of your apps |
| A cloud provider that hosts the dashboard and its database | All account data, including the records of your apps |
| A payment provider | The team owner's name and email address, the plan and the payment details |
| An email delivery provider | The recipient's address and the message |
| A mailbox provider | The messages you send us |
| A DNS provider | The addresses of apps, no personal data |

The first two are our sub-processors for the data: only they come into contact with it as part of the service. The others receive data about you as our customer, or what you choose to send us by email, and are listed to complete the picture. What follows is about the first two. GitHub is not a sub-processor: you connect it yourself, under GitHub's own terms.

The list of the companies is available on request at [privacy@arrangic.com](mailto:privacy@arrangic.com). The list as it stands on the day you accept this addendum is the agreed list.

We tell the owner of the team by email at least 30 days before we add or replace a sub-processor. If we have to replace one at short notice to keep the service running or secure, we tell you as soon as we can, and your right to object stays. You can object on reasonable data protection grounds before the change takes effect. If we cannot find a way to meet your objection, you may end the agreement, and we refund the part of a plan fee that you paid for the time after the end.

We bind each one by contract to duties no weaker than those in this addendum, and we stay responsible to you for what it does.

## Data location and transfers

You choose a region for each app. The app runs in that region. Requests to the app enter the network of the infrastructure provider near the visitor and are carried to that region, and the runtime logs are kept by that provider. When a member of your team opens the runtime log, its lines pass through the dashboard. The records the dashboard keeps about an app (settings, variables and build logs) are stored with your account data, in the United States.

If the data comes from the European Economic Area, the United Kingdom or Switzerland and goes to a country without an adequacy decision, the standard contractual clauses of the European Commission apply between you and us, in modules two and three, for transfers to a processor. For data from the United Kingdom, the UK addendum to those clauses applies as well. Both are made part of this addendum by this reference, with you as the exporter and us as the importer.

The details the clauses ask for are in this addendum: the processing, the measures, the sub-processors and the locations. The clauses also ask for choices that this page cannot make for every customer, such as the country whose law governs them. Those are set out in the signed copy. If the clauses and this addendum or the terms of service say different things, the clauses come first.

## Audits

On request we give you the information you need to show that we keep to this addendum. You can ask once a year, with reasonable notice. You can ask more often after a breach of the data, when a data protection authority requires it, or when there are signs that we do not keep to this addendum.

You, or an independent auditor you appoint who is bound to confidentiality, may audit how we keep to this addendum, including by inspection. We agree the time, the scope and the way beforehand, so that the data of other customers is not put at risk.

We hold no third-party certification today and have had no independent audit, so there is no report to hand over.

## California

Where the privacy law of California applies to the data, we do not sell or share it, in the meaning that law gives those words. We do not keep, use or disclose it for anything other than providing the service to you, and we do not combine it with personal data from other sources. We tell you if we can no longer meet these duties. You may take reasonable steps to stop a use of the data that this addendum does not allow.

## Liability

**The limits and exclusions of liability in the [terms of service](https://arrangic.com/terms) apply to this addendum as well. Nothing here limits liability that the law does not allow to be limited, or what either side owes to the people whose data it is.**

## Contact and a signed copy

For anything under this addendum, including an objection to a sub-processor, write to [privacy@arrangic.com](mailto:privacy@arrangic.com).

This addendum applies without a signature. If you need a signed copy, ask at the same address.

---

This document on the site: https://arrangic.com/dpa  
All legal documents: https://arrangic.com/legal
