Skip to content
ORBITRAONE

Legal

Data Processing Addendum

Version 1.0 · Last updated

Summary

This addendum applies where ORBITRA ONE™ processes personal data on behalf of an institutional client in providing ORBITRA ONE™ services. It sets out the parties’ roles, the safeguards that govern the processing, the rules for sub-processors and international transfers, our assistance with data-subject requests and breaches, and what happens to the data when the services end.

01Application

This data processing addendum (the “Addendum”) forms part of the agreement (the “Agreement”) between ORBITRA ONE™ (the “Processor”) and the institutional client named in it (the “Client”) for ORBITRA ONE™ services, and it applies to all Client Personal Data.

02Definitions

  • Data Protection Law means all laws on the protection of personal data and privacy that apply to processing under the Agreement.
  • Client Personal Data means personal data processed by the Processor on behalf of the Client under the Agreement.
  • Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Client Personal Data.
  • Sub-processor means a third party engaged by the Processor to process Client Personal Data.
  • Transfer Mechanism means a mechanism recognized by Data Protection Law for transferring personal data across borders, such as an adequacy decision or standard contractual clauses.

Terms such as controller, processor, data subject, personal data, processing and supervisory authority have the meanings given in Data Protection Law, or the nearest equivalent where that law uses other terms. Capitalized terms not defined here have the meanings given in the Agreement.

03Roles of the parties

The Client is the controller and the Processor is the processor of Client Personal Data. Where the Client itself acts as a processor for a third-party controller, the Processor acts as its sub-processor, and the Client confirms that its controller has authorized the Client’s instructions and the Processor’s appointment.

The Client is responsible for the lawfulness of the processing it instructs, including having a lawful basis and giving data subjects any required information.

This Addendum does not cover personal data that ORBITRA ONE™ processes as an independent controller — for example, for customer due diligence, sanctions screening, market surveillance, fraud prevention, security or its own legal and regulatory obligations. That processing is described in the privacy policy and the applicable product privacy notice.

04Subject matter, duration, nature and purpose

  • Subject matter — the provision of ORBITRA ONE™ services under the Agreement, such as institutional access to Orbitra Prime, subaccount and permission management, execution and reporting interfaces, and related support.
  • Duration — the term of the Agreement, together with any period after it during which Client Personal Data is returned or deleted under this Addendum.
  • Nature — collection, storage, retrieval, use, transmission, deletion and other operations needed to provide the services.
  • Purpose — solely to provide, secure, support and maintain the services in accordance with the Client’s documented instructions.

05Categories of data and data subjects

Data subjects may include the Client’s employees, traders, authorized users, officers, contractors and agents and, where the Client uses the services for them, its own customers or end users.

Client Personal Data may include identification and contact details, roles and permissions, login and access records, device and network identifiers, communications, and account, order, transaction and wallet-address data linked to identified users.

Special categories of personal data are not intended to be processed. The Client will not provide such data unless the parties have agreed additional safeguards in writing.

06Processor obligations

The Processor will:

  • process Client Personal Data only on the Client’s documented instructions, including with regard to international transfers, unless the law requires otherwise — in which case it will inform the Client first, unless the law prohibits that;
  • inform the Client if, in its opinion, an instruction infringes Data Protection Law;
  • not sell or share Client Personal Data, or retain, use or disclose it for any purpose other than providing the services;
  • apply the security measures described in this Addendum;
  • assist the Client, taking into account the nature of the processing and the information available to it, with data-protection impact assessments and prior consultations with supervisory authorities;
  • make available the information needed to demonstrate compliance with this Addendum.

07Confidentiality

The Processor ensures that everyone authorized to process Client Personal Data is bound by an appropriate duty of confidentiality, receives suitable data-protection training and has access only to the data needed for their role.

08Security measures

The Processor implements technical and organizational measures appropriate to the risk, taking into account the state of the art, the costs of implementation, the nature, scope, context and purposes of the processing, and the risks to data subjects. They include:

  • encryption of data in transit and at rest, with key management under MPC or HSM-based controls where appropriate;
  • role-based access, least privilege, multi-factor authentication and four-eyes approval for sensitive operations;
  • segregation of environments, duties and client data within a zero-trust network architecture;
  • logging, monitoring and alerting for anomalous access;
  • secure development practices, dependency and secret scanning, and signed releases;
  • backup and recovery procedures that are tested periodically;
  • regular testing and evaluation of the effectiveness of these measures.

The Processor may update its measures, provided that the overall level of protection is not reduced.

09Sub-processors

The Client gives general authorization for the Processor to engage sub-processors. The Processor keeps a list of current sub-processors and makes it available to the Client on request.

The Processor will notify the Client before adding or replacing a sub-processor. The Client may object on reasonable data-protection grounds within the period stated in the notice. The parties will discuss any objection in good faith; if it cannot be resolved, the Client may terminate the affected services, without penalty, as its sole remedy.

Each sub-processor is bound by a written contract imposing data-protection obligations no less protective than those in this Addendum. The Processor remains responsible to the Client for each sub-processor’s performance of those obligations.

10International transfers

The Processor and its sub-processors transfer Client Personal Data across borders only in compliance with Data Protection Law. Where a transfer requires a Transfer Mechanism, the appropriate mechanism — including any standard contractual clauses in the form required by the competent authority — is incorporated into this Addendum by reference, together with any supplementary measures needed to protect the data.

The Processor will inform the Client if it can no longer meet the requirements of an applicable Transfer Mechanism.

11Assistance with data-subject requests

Taking into account the nature of the processing, the Processor assists the Client through appropriate technical and organizational measures, as far as possible, in responding to requests from data subjects to exercise their rights.

If the Processor receives such a request directly, it will promptly forward it to the Client and will not respond to it, other than to refer the data subject to the Client, unless the Client instructs it to or the law requires otherwise.

12Personal-data breach notification

The Processor will notify the Client without undue delay after becoming aware of a Personal Data Breach.

The notification will describe, as far as the information is available, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Information that is not available at once will be provided in phases as it becomes available.

The Processor will take reasonable steps to contain and investigate the breach and will cooperate with the Client in meeting its obligations to notify supervisory authorities and data subjects. Notification is not an acknowledgment of fault or liability.

13Audits and information

The Processor makes available the information reasonably necessary to demonstrate compliance with this Addendum, which may include summaries of independent assessments or certifications where they exist.

Where that information is insufficient, or where a supervisory authority requires it, the Client may carry out an audit or inspection itself or through an independent auditor bound by confidentiality. Audits take place on reasonable prior notice, with a scope and timing agreed in advance, and without disrupting the services or compromising the security or confidentiality of other clients. Each party bears its own audit costs, unless the audit reveals a material breach by the Processor.

14Deletion or return of data

When the services end, the Processor will, at the Client’s choice, delete or return Client Personal Data and delete existing copies, unless the law requires it to retain them. The Client may make its choice by written instruction or by using available export tools before the services end.

Data that the law requires the Processor to retain remains protected by this Addendum and is processed only for the purpose that requires its retention. Backup copies are deleted as backups expire in their normal cycle.

15Liability

Each party’s liability arising out of or in connection with this Addendum is subject to the limitations and exclusions of liability in the Agreement, except where Data Protection Law does not permit them. Nothing in this Addendum limits either party’s liability to data subjects under Data Protection Law.

16Governing law

This Addendum is governed by the law that governs the Agreement, except where Data Protection Law or a Transfer Mechanism requires particular obligations to be governed by another law. Disputes are resolved under the dispute-resolution provisions of the Agreement.

17Order of precedence

If the documents conflict, they apply in this order:

  • any Transfer Mechanism incorporated into this Addendum;
  • this Addendum;
  • the Agreement.

Nothing in this Addendum reduces either party’s obligations under Data Protection Law. Questions about this Addendum, and requests for a copy to sign, can be sent to hello@orbitraone.com or hello@orbitraone.com.