Terms for processing contact data on your behalf.
Version: 2 October 2026
This Data Processing Agreement (DPA) forms part of the Orvo Terms between the business or organisational customer identified by its account and Sorin Constantin Ciornei, NIP PL6793214413, ul. Szlak 77/222, 31-153 Kraków, Poland (Orvo). It applies where Orvo processes personal data on the customer's behalf under the GDPR. If the customer is itself a processor, it must have its controller's authority to appoint Orvo. This DPA prevails over conflicting Terms concerning that processing.
The customer determines the purposes and lawful basis of its contact-data processing. Orvo processes that data only on documented instructions, including this agreement and the customer's use of account features, sharing, integrations, export and deletion controls. Orvo will inform the customer if an instruction appears to infringe applicable data-protection law. Where law requires other processing, Orvo will inform the customer beforehand unless legally prohibited.
Orvo acts as a separate controller for its own account administration, payment, security, legal compliance and limited trial-abuse prevention, as explained in the Privacy Policy. This does not permit reuse of customer contact content for unrelated purposes.
Orvo ensures that people authorised to process customer data are bound by confidentiality obligations. Orvo implements technical and organisational measures appropriate to the risk under Article 32 GDPR and reviews them as the service changes.
Current measures include HTTPS for the hosted website and API, Render infrastructure encryption at rest for managed PostgreSQL and persistent disks, authenticated account access, application access controls, restricted production access, opt-in controls for built-in AI, invalidation of local access credentials at closure, scheduled cleanup, and infrastructure backup/recovery facilities. Production infrastructure is in Virginia, USA. These measures are not a certification or a guarantee against every incident. Customers must protect credentials and choose lawful content and sharing settings.
The customer gives general written authorisation for the subprocessors in the maintained provider list for their stated processing: Render for infrastructure, Groq for enabled built-in AI, and Resend where delivered email contains customer data. Customer-selected integrations act under their own applicable terms and instructions; they are not automatically Orvo subprocessors. Providers acting solely on Orvo's controller data are outside this DPA.
Before a new or replacement subprocessor receives customer data, Orvo will provide at least 30 days' notice by email or a prominent account notice, identify its purpose and processing location, and allow objections on reasonable data-protection grounds. Orvo will work to resolve an objection. If it cannot, the customer may discontinue the affected feature or terminate the affected service with a pro-rata refund of unused prepaid fees. New AI uses requiring consent will not start without it.
Orvo imposes data-protection obligations providing the protection required by Article 28 on subprocessors and remains responsible for their performance of those obligations. Transfers outside the EEA must have a valid Chapter V GDPR mechanism, such as an applicable adequacy decision or European Commission Standard Contractual Clauses with required supplementary measures. Listing a provider does not itself establish a transfer mechanism. Copies of safeguards are available on request, with necessary redactions.
Taking account of the processing and information available, Orvo assists with data-subject requests, security obligations, breach notification, impact assessments and supervisory-authority consultation. Orvo forwards requests concerning customer-controlled data to the customer and does not independently decide the response unless legally required.
Orvo notifies the customer without undue delay after becoming aware of a personal-data breach affecting its data. The notice gives the known nature and scope, likely consequences, mitigation and a contact point, with updates as information becomes available. Customers remain responsible for their own regulator and individual notifications.
Customers may export information before closure and request assistance with return or deletion. At the customer's choice on termination, Orvo returns or deletes personal data and deletes existing copies unless law requires retention. Closure disables access; routine core-data erasure is scheduled after a 30-day closure period. Registered uploads and referenced account photos are removed through hourly cleanup after that period. Temporary inputs, logs and backups follow the retention schedule.
Backups remain isolated from ordinary use until rotation. Any recovery must reapply completed erasure requests before restored personal data returns to ordinary service use. Ordinary scheduled cleanup needs no extra request. Legally retained data stays protected and limited to its required purpose. Trial-prevention retention covers the account email/history, not CRM content.
Orvo makes available information necessary to demonstrate compliance and allows and contributes to audits, including inspections, by the customer or its mandated independent auditor. The parties coordinate reasonable notice, confidentiality and protection of other customers' information. These arrangements do not prevent necessary audits, urgent incident-related checks or supervisory-authority access, and do not remove rights required by Article 28.
The Terms' liability provisions apply only to the extent permitted by law. Nothing limits data subjects' rights, supervisory-authority powers or liability and remedies that cannot lawfully be limited. Polish law governs without displacing mandatory applicable data-protection law.
Instructions, incident contacts, objections and assistance: office@getorvo.com. The customer must keep its account contact address current.