Data Processing Agreement
Effective: 2026-08-04. Applies to all Orbyt customers subject to GDPR (EU/EEA/UK), CCPA (California), or similar data-protection laws.
The honest version. Orbyt is a solo-founder product and this page describes current practice, not a countersigned contract. There is no executed DPA on file for self-serve customers, no signed Standard Contractual Clauses, and no contractual breach-notification clock with remedies attached. Nothing here has been through outside counsel yet. If you need an executed DPA or SCCs for a procurement review, write to legal@orbytjobs.ai and we will handle it case by case. This page updates when that changes.
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Orbyt (a product of Purecraft LLC, “Orbyt”) and its customer (“Customer”). It governs the processing of personal data by Orbyt as a data processor acting on behalf of Customer as data controller.
1. Definitions
“GDPR” means the EU General Data Protection Regulation 2016/679. “CCPA” means the California Consumer Privacy Act. “Personal Data” has the meaning given in applicable law. “Sub-processor” means any third party engaged by Orbyt to process Personal Data on Customer’s behalf.
2. Scope and roles
Customer is the data controller and Orbyt is the data processor. Orbyt processes Personal Data solely to provide the Orbyt service, to comply with legal obligations, and on Customer’s documented instructions. Orbyt will not sell Personal Data or use it to train general-purpose AI models.
3. Categories of Personal Data
Personal Data processed by Orbyt typically includes: user account data (name, email, authentication tokens), job-search data entered by the user (applications, contacts, resumes, notes), device and usage telemetry (IP, browser, page views), and billing data processed via Stripe. Orbyt also keeps a server-side audit log of authentication, billing, team-administration, and data-export events, purged automatically on a 90-day retention window and deleted with the account it belongs to.
4. Sub-processors
Orbyt uses the following sub-processors: Vercel (hosting, U.S.), Supabase (database and auth, U.S.), Stripe (payments, U.S.), Resend (transactional email, U.S.), Upstash (Redis rate limits, U.S.), Sentry (error monitoring and sampled session replay with all text masked, U.S.), PostHog (product analytics inside the signed-in app, U.S.), Cloudflare (Turnstile bot protection on auth forms and public free tools, global edge), Anthropic / OpenAI (on-request AI features, U.S.). xAI is reachable only when a user supplies their own xAI key on the Unlimited plan, so it processes data on that user’s instruction rather than as an Orbyt sub-processor. Orbyt relies on each provider’s published data-processing terms and has not countersigned bespoke sub-processor agreements.
5. International transfers
Personal Data is stored in the United States. For Customers in the EU/EEA/UK, Orbyt has not executed Standard Contractual Clauses and will discuss them case by case on request at legal@orbytjobs.ai. Orbyt does not currently self-certify under the EU-US Data Privacy Framework.
6. Security
Orbyt implements appropriate technical and organizational measures including: TLS 1.2+ in transit, AES-256 at rest (via Supabase), Row Level Security on every database table, least-privilege access, and security.txt at /.well-known/security.txt for vulnerability disclosure. Orbyt is not SOC 2 certified and does not currently have a scheduled audit; see the Trust Center for current security practices.
7. Data subject rights
Customer and its end users may at any time: export all data via the app, delete their account (which removes Personal Data from production systems immediately, by cascade delete, with backups aging out within 30 days), and request copies or corrections of Personal Data by emailing legal@orbytjobs.ai.
8. Breach notification
Orbyt aims to notify Customer without undue delay, and in practice targets 72 hours, on becoming aware of a Personal Data breach affecting Customer data, along with information necessary to meet Customer’s own notification obligations.
9. Audits
Customer may request written confirmation of sub-processor obligations once per year by emailing legal@orbytjobs.ai. Orbyt does not currently hold a SOC 2 report. On-site audits are permitted with 30 days’ notice and at Customer’s expense.
10. Deletion and return
On termination of the service, Customer may export data via the app. Deleting the account removes Personal Data from production systems immediately; where an account is not deleted, Orbyt will delete Personal Data from production systems within 30 days of termination. Backups are purged within 30 days on their normal rotation.
11. Contact
For DPA questions or to request a signed copy, email legal@orbytjobs.ai. See also Privacy Policy and Terms of Service.