Legal
Data processing
Last updated 25 September 2026
When you bring contact data into Orbitmate, you are the controller and [Orbitmate legal entity name] is your processor. This page summarises our data processing terms. A signed data processing agreement (DPA) is available to every customer.
Processing details
| Subject matter | Providing the Orbitmate service to the customer |
|---|---|
| Duration | The subscription term, plus the deletion period after it ends |
| Nature and purpose | Storing, enriching and scoring contact data; generating draft connection notes, messages and comments; running approved campaign actions and managing replies through the customer’s connected LinkedIn senders |
| Data subjects | The customer’s prospects and contacts, and the customer’s own users |
| Categories of data | Names, professional details, public LinkedIn profile and activity, company information, messages and derived scores |
| Special-category data | Not intended; customers must not upload it |
Our commitments
- Process personal data only on the customer’s documented instructions.
- Ensure everyone with access is bound by confidentiality.
- Apply appropriate technical and organisational security measures.
- Engage sub-processors only under written terms at least as protective, and tell customers before adding or replacing one.
- Help the customer answer data subject requests and meet its own obligations.
- Notify the customer without undue delay after becoming aware of a personal data breach.
- Delete or return personal data at the end of the service, at the customer’s choice.
- Make the information needed to demonstrate compliance available.
Sub-processors
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Amazon Web Services | Hosts the product application, database, backups, file storage and LinkedIn session storage | All customer data stored in the product | United States (us-east-1) |
| Cloudflare | Hosts this website and stores its demo and contact requests; runs the default AI models (Workers AI) that write drafts and score audience fit | Website requests and form submissions; contact context used for a draft or a fit score | Global network |
| Langfuse | Monitors the quality, reliability and cost of AI requests | Full AI prompts and responses, which can include contact profile data, plus request metadata | European Union |
| Resend | Sends account and approval notification email | Account email addresses and notification content | United States |
Each LinkedIn sender also connects through a dedicated proxy: [proxy provider: supplied by the customer, or Bright Data if Orbitmate provisions it].
Services you connect with your own key
Enrichment runs on Apify and Tavily accounts that the customer creates and connects under Settings → Integrations; drafting can optionally use the customer’s own OpenRouter key. The customer holds the contract with these providers, and they process data under that contract. Orbitmate sends requests to them only when the customer asks it to, and does not use these accounts for anything else.
| Service | Purpose | Data involved |
|---|---|---|
| Apify | Collects public LinkedIn profile, post, comment and company data for enrichment | LinkedIn profile and company URLs, and the public data returned for them |
| Tavily | Searches recent third-party news about a contact’s company | Company and person names used as search queries, and the news returned |
| OpenRouter | Optional: routes drafting and scoring to the model the customer picks, instead of the default | Contact context used for a draft or a fit score, and the draft text |
[To be confirmed by counsel: final sub-processor list and the transfer mechanism in place with each provider]
Security measures
- Each customer’s data is kept in its own workspace, separated in every query.
- Hosting on AWS (us-east-1) on encrypted disks; daily snapshots and nightly encrypted backups to S3, kept for 30 days; secrets held in AWS SSM Parameter Store.
- Application-level AES-256-GCM encryption of inbox message content (a separate key per record), provider API keys, LinkedIn passwords, two-step verification secrets and proxy passwords.
- LinkedIn session data on storage encrypted with a dedicated KMS key, with one proxy and one browser profile per sender; deleting a sender purges its profile.
- Role-based access with custom roles, optional TOTP two-factor sign-in, session revocation, and an audit log of actions with CSV export.
- Every outbound LinkedIn action is approved by a person at the customer before it is sent.
- Inbox message content is deleted 365 days after it is received.
[Confirm and add: access reviews, incident response, penetration testing] We do not hold security certifications today.
International transfers
Where personal data leaves the UK or European Economic Area, the DPA incorporates [the EU Standard Contractual Clauses (module 2 and 3) and the UK International Data Transfer Addendum].
Getting a signed DPA
Email privacy@orbitmate.ai or use our contact form with your company’s legal name and address, and we will send the DPA for signature.