This Data Processing Agreement ("DPA") is part of the agreement between you ("Customer", "you") and Orchly AI ("Orchly", "we", "us") for use of the Orchly AI platform (the "Service"), made up of our Terms of Use and any order form. It applies whenever we process personal data on your behalf. By using the Service, you agree to this DPA. If you need a countersigned copy, email hello@orchly.ai.
1. Scope and roles
For personal data you put into the Service or that the Service collects for you, such as your website's visit logs, contacts you add for outreach, or content you ask our agents to write, you are the controller and we are the processor. We process that data only to provide the Service to you.
For your account, billing and product usage data, we act as an independent controller, as described in our Privacy Policy. This DPA does not cover that data.
If you use the Service on behalf of your own clients, as an agency does, you are the processor for them and we are your subprocessor. You are responsible for having the right agreements with your clients.
2. Definitions
"Data Protection Laws" means all laws that apply to the processing of personal data under the agreement, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended ("CCPA"). "Personal data", "controller", "processor", "data subject", "processing" and "personal data breach" have the meanings given in the GDPR. "Customer Personal Data" means personal data we process on your behalf under this DPA. "Subprocessor" means a third party we engage to process Customer Personal Data.
3. Details of processing
- Subject matter
- Providing the Service: AI search and SEO visibility tracking, website and traffic analytics, content creation and optimization, outreach and reporting.
- Duration
- For as long as you use the Service, plus the deletion period in section 11.
- Nature and purpose
- Collecting, storing, analysing, generating and displaying data so you can see and improve how your brand appears in Google and AI search.
- Data subjects
- Your team members who use the Service; visitors to your websites; contacts and prospects you add or find for outreach; people named in content or documents you upload.
- Types of personal data
- Names, business email addresses and job titles; IP addresses, user agents and pages visited from your website logs; any personal data contained in content, documents or prompts you provide.
- Special categories
- None. You agree not to send us special category data (such as health, religious or biometric data) through the Service.
4. Our obligations
We will:
- process Customer Personal Data only on your documented instructions, which are the agreement, this DPA and your use and configuration of the Service, unless the law requires otherwise. If the law requires otherwise, we will tell you first unless the law forbids it;
- tell you if we believe an instruction breaks Data Protection Laws;
- make sure everyone who can access Customer Personal Data is bound by confidentiality;
- not sell or share Customer Personal Data, or use it for any purpose other than providing the Service, as those terms are defined in the CCPA;
- not use Customer Personal Data to train our own AI models;
- keep the security measures in section 5 in place.
You are responsible for having a lawful basis for the personal data you give us, and for the instructions you give.
5. Security measures
We keep technical and organisational measures appropriate to the risk, including:
- Encryption: data is encrypted in transit with TLS and at rest by our hosting providers. Credentials you connect, such as mailbox passwords for outreach, are also encrypted in our database with AES-256-GCM.
- Separation: each workspace's data is kept apart with database row-level security, so one customer can't read another's data.
- Access control: staff access to production systems is limited to people who need it, uses individual accounts, and is removed when no longer needed.
- Least data: connected services such as Google Search Console and Google Analytics use OAuth with read access where that is enough, and you can disconnect them at any time.
- Resilience: our database provider keeps backups, and our infrastructure runs on providers with SOC 2 or equivalent certifications.
- Abuse protection: our APIs are rate-limited, and API keys you create can be revoked at any time.
We may update these measures over time, as long as the overall level of protection does not go down.
6. Subprocessors
You give us general authorisation to use subprocessors. We have a written agreement with each one that protects Customer Personal Data at least as well as this DPA, and we remain responsible for their work. These are our current subprocessors:
| Subprocessor | Purpose | Personal data | Location |
|---|---|---|---|
| Supabase | Database, authentication and file storage | Account details, workspace content, settings | United States (AWS us-west-1) |
| Vercel | Application hosting and delivery | All service data in transit, request logs | United States |
| Google Cloud (Cloud Run) | Website crawling workers | URLs and page content of your websites | United States (us-central1) |
| Tinybird | Analytics data store for traffic and visibility data | AI crawler and site visit logs (IP address, user agent, URL), visibility results | United States (AWS us-east) |
| Upstash | Caching and rate limiting | Request metadata, cached results | United States |
| Inngest | Background job scheduling | Job payloads such as workspace and task identifiers | United States |
| OpenAI | AI models for analysis, agents and content | Prompts, brand context, content you ask agents to work on | United States |
| Anthropic | AI models for analysis, agents and content | Prompts, brand context, content you ask agents to work on | United States |
| OpenRouter | Routing requests to AI models | Prompts, brand context, content you ask agents to work on | United States |
| Bright Data | Collecting AI answers and web data through proxies | Tracked prompts, brand and competitor names, target URLs | Israel |
| Firecrawl | Fetching and reading web pages | URLs and public page content | United States |
| DataForSEO | Search ranking and keyword data | Keywords, domains, target locations | Estonia (EU) |
| Ahrefs | Domain and backlink metrics | Domains | Singapore |
| Snov.io | Finding and verifying contacts for link-building outreach | Prospect names, domains and business email addresses | United States |
| Resend | Account and notification emails | Name, email address, email content | United States |
| Polar | Payments and billing | Name, email address, billing details | United States |
| PostHog | Product analytics | Usage events, device and browser data, IP address | United States |
| SourceLoop | Signup and conversion attribution | Email address, conversion events, referral source | United States |
| Featurebase | Support, feedback and changelog | Name, email address, messages you send us | Estonia (EU) |
We will update this page at least 30 days before a new subprocessor starts processing Customer Personal Data. To get notice by email, write to hello@orchly.ai. If you object on reasonable data protection grounds within those 30 days, we will work with you in good faith on a fix. If we can't find one, you may end the affected part of the Service and get a refund of any prepaid fees for it.
Services you connect. Tools you link to Orchly AI yourself, such as Google Search Console, Google Analytics, WordPress, Webflow, Ghost, Sanity, Framer, Slack or your own email inbox, are not our subprocessors. You choose them, and their own terms apply to the data they hold.
7. International transfers
Most of our processing happens in the United States. When Customer Personal Data from the European Economic Area, the United Kingdom or Switzerland is transferred to a country without an adequacy decision, the EU Standard Contractual Clauses (Commission Decision 2021/914) apply and are incorporated into this DPA by reference: Module Two where you are a controller and Module Three where you are a processor. For UK data, the UK International Data Transfer Addendum applies; for Swiss data, the clauses apply with references read as the Swiss FADP. For the clauses, the optional docking clause in clause 7 applies, clause 9 option 2 (general authorisation) applies, the governing law and courts are those of Ireland, and the annexes are completed by section 3, section 5 and section 6 of this DPA.
8. Personal data breaches
If we become aware of a personal data breach affecting Customer Personal Data, we will tell you without undue delay, and within 72 hours at the latest. We will share what we know about the nature of the breach, the data and people affected, likely consequences and the steps we are taking, and keep you updated as we learn more. Telling you is not an admission of fault.
9. Data subject requests and assistance
If someone asks us directly to access, correct, delete or move their personal data held for you, we will pass the request to you and not answer it ourselves unless you ask us to. The Service lets you find, export and delete data yourself, and we will help where it doesn't. We will also give reasonable help with data protection impact assessments and consultations with supervisory authorities that relate to the Service.
10. Audits
We will make available the information you reasonably need to show we meet this DPA, including answers to security questionnaires and our subprocessors' certifications. If that isn't enough, or a supervisory authority requires it, you may run an audit once a year with 30 days' written notice, during business hours, at your cost, and under confidentiality terms.
11. Return and deletion
You can export your data while your account is active. When the agreement ends, we will delete Customer Personal Data within 30 days, unless the law requires us to keep it. Copies in backups are overwritten on the normal backup cycle and stay protected by this DPA until then.
12. General terms
This DPA lasts as long as we process Customer Personal Data for you. If it conflicts with the Terms of Use, this DPA wins for data protection matters, and the Standard Contractual Clauses win over both. Each party's liability under this DPA is subject to the limits in the Terms of Use. Governing law and jurisdiction are as set out in the Terms of Use, except where the Standard Contractual Clauses require otherwise. We may update this DPA to reflect changes in law or in the Service; we will post the new version here, and material changes that reduce your protection will not apply to you without notice.
13. Contact
For questions about this DPA, to request a signed copy, or to exercise any right in it, email hello@orchly.ai.