Overview
Orbit PSA uses the third-party services listed below to operate the Service. Together these are our "sub-processors." Each one has been reviewed against our vendor-risk criteria and signed a Data Processing Addendum (DPA) where applicable.
This list is reviewed quarterly and on every material vendor change. Customers receive at least 30 days' notice before a new sub-processor that processes Customer Data is added. Notice is sent via email to the customer's billing contact and posted as a banner on this page.
For privacy practices generally, see our Privacy Policy. For security posture, see Security. A Data Processing Addendum (DPA) is available on request via [email protected].
Current sub-processors
| Sub-processor | Purpose | Data category | Region | Certifications |
|---|---|---|---|---|
| Vercel Inc. Privacy policy | Application hosting, edge delivery, serverless compute | All Customer Data stored in the Orbit application; HTTP request logs | United States (multi-region) | SOC 2 Type II, ISO 27001, GDPR-compliant DPA |
| Stripe, Inc. Privacy policy | Payment processing, subscription billing, payment-method storage | Billing contact, payment instrument tokens, transaction history | United States, Ireland (EU customer data) | PCI-DSS Level 1, SOC 1, SOC 2, ISO 27001, GDPR-compliant DPA |
| Resend (Drie Labs Inc.) Privacy policy | Transactional email delivery (account, invoice, notification) | Recipient email addresses, email contents, delivery metadata | United States | SOC 2 Type II, GDPR-compliant DPA |
| Cal.com, Inc. Privacy policy | Demo scheduling, calendar booking embed | Prospect name, email, requested meeting time, optional notes | United States | SOC 2 Type II, GDPR-compliant DPA, ISO 27001 |
| Tawk.to (tawk.to ltd) Privacy policy | Live chat widget on orbitpsa.com | Chat messages, IP, visitor session identifier | United States, EU | GDPR-compliant DPA, CCPA-compliant |
| Google LLC (Google Analytics 4) Privacy policy | Anonymized website analytics, traffic-source attribution, performance metrics | IP (anonymized at collection), browser type, device type, page URLs, referrer | United States, EU | ISO 27001, SOC 2/3, GDPR-compliant DPA, EU-US Data Privacy Framework |
| Cloudflare, Inc. Privacy policy | DNS, edge security, DDoS protection, WAF | IP, HTTP request metadata, transient logs | Global edge network | SOC 2 Type II, ISO 27001, PCI-DSS, GDPR-compliant DPA, FedRAMP Moderate |
| Anthropic, PBC Privacy policy | AI inference for Tuesday AI risk briefings and natural-language features (Scale tier) | Aggregated client metadata sent for inference; no training on customer prompts | United States | SOC 2 Type II, GDPR-compliant DPA |
| GitHub, Inc. (Microsoft) Privacy policy | Source code hosting, CI/CD; not used for Customer Data storage | Employee identities, internal source code (no Customer Data) | United States | SOC 2 Type II, ISO 27001, GDPR-compliant DPA |
| Sentry (Functional Software, Inc.) Privacy policy | Application error tracking and performance monitoring | Error stack traces, browser/runtime metadata, sanitized request context | United States | SOC 2 Type II, ISO 27001, GDPR-compliant DPA |
International data transfers
Most sub-processors operate from the United States. Where Customer Data is transferred from the EU, UK, or other GDPR-equivalent jurisdictions to the US or other countries, we rely on:
- Standard Contractual Clauses (SCCs) as adopted by the European Commission
- EU-US Data Privacy Framework for participating sub-processors (e.g., Google)
- UK Addendum to SCCs for transfers under the UK GDPR
Internal access
Beyond the sub-processors above, Orbit employees with named roles (engineering, customer success, support) may access Customer Data when strictly necessary to provide the Service. All such access is logged, gated by SSO + MFA, and restricted by role. See Access controls for detail.
Right to object
If you object to a new sub-processor for legitimate reasons within 30 days of notice, you may terminate your subscription with respect to services that cannot be provided without the new sub-processor and receive a pro-rata refund of any prepaid fees. To object, email [email protected].
Change log
- May 21, 2026: Initial publication.
Contact
Questions about a specific sub-processor or our vendor-risk process? Email [email protected]. DPA requests: [email protected].
