OrbitCRM and the General Data Protection Regulation (GDPR)

The General Data Protection Regulation (GDPR) and its UK equivalent (UK GDPR) represent the highest standards of data protection globally. These regulations ensure transparency, fairness, and accountability in how personal data—any information relating to an identifiable individual—is handled.

As a UK-based company, OrbitCRM has been designed with "Privacy by Design" at its core. We are fully committed to helping our users maintain compliance with both UK and EU data protection standards.

1. Does the GDPR apply to my organization?

The GDPR applies to you if:

  • Your organization is based in the UK or the EU.
  • You process the personal data of individuals located in the UK or the EU (regardless of where your company is based).

2. Controllers vs. Processors: What is our relationship?

Under the GDPR, organizations are classified based on their relationship to the data:

  • You are the Controller: Because you decide which contacts, leads, and accounts to enter into OrbitCRM and how that data is used for your business, you are the Data Controller.
  • OrbitCRM is the Processor: We process personal data only on your behalf and according to your instructions (e.g., when you create a task, send an email through the CRM, or generate an AI summary).

3. OrbitCRM's Role as a Processor

We act as the custodian of your data. To ensure a compliant relationship:

  • Subprocessors: We maintain a list of trusted third-party services (such as our hosting providers and email integration partners like Nylas) that help us deliver our services.
  • Data Processing Addendum (DPA): We provide a standard DPA that outlines our commitment to security, data breach notification, and your audit rights. This DPA is incorporated into our Terms of Service for all customers.
  • Orbit AI: While our AI assistant helps automate tasks, we ensure that your CRM data is not used to train publicly available machine learning models, maintaining strict boundaries for your proprietary information.

4. How OrbitCRM helps you stay compliant

OrbitCRM includes features specifically designed to help you fulfill your obligations as a Controller:

  • Right to Access/Erasure: You can easily export or delete specific contact records or account data if a customer exercises their "Right to be Forgotten."
  • Data Portability: Our export tools allow you to provide customers with their data in a structured, machine-readable format.
  • Security: With SOC 2 compliance and UK-based data protection standards, we ensure your business information is guarded against unauthorized access.

5. Next Steps for Your Compliance

  • Review our Terms and Privacy Policy: Our latest updates reflect current UK and EU data protection laws. See our Terms of Service and Privacy Policy.
  • Sign our DPA: If your organization requires a signed Data Processing Addendum for your records, you can request our standard UK/EU DPA by emailing [email protected].
  • Audit Your Data: Ensure you have a legal basis (such as consent or legitimate interest) for the contacts you manage within the platform.