At a glance
- You control the dataYou are the controller. We process analytics and form data only to run the service, on your instructions.
- Minimal by designThe tracker stores no cookies and no raw IP addresses, so most analytics data is not personal data at all.
- Breaches reported promptlyIf a breach affects your data, we tell you without undue delay with what you need to meet your own duties.
- Deleted when you leaveDelete a site or close your account and its data is permanently removed from the live system.
This summary is for convenience only. The full text below is what applies.
#1. Scope and how this applies
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (the “Customer”) and DA Orbit (“we”, “us”), which operates Quantalog. It applies whenever we process personal data on your behalf while providing the Service, and it takes effect automatically when you accept the Terms. If this DPA and the Terms conflict on the processing of personal data, this DPA prevails.
If your organisation needs a countersigned copy for its records, email daorbit2k25@gmail.com and we will send one.
#2. Definitions
“Personal data”, “controller”, “processor”, “data subject”, “processing” and “personal data breach” have the meanings given in the applicable data protection law, including the EU and UK GDPR and India's Digital Personal Data Protection Act, 2023 (“Data Protection Law”). Where a law uses different terms, such as “data fiduciary” and “data processor”, the equivalent meaning applies.
#3. Roles of the parties
For data collected by the tracker on your websites and apps, for responses submitted to your forms, and for content you upload to your workspaces (“Customer Data”), you are the controller and we are your processor. For your own account, billing and support information, we act as an independent controller, as described in our Privacy Policy.
You are responsible for having a lawful basis for the data you collect through the Service and for any notices your visitors and respondents need. Our Terms forbid sending directly identifying personal data through custom event properties.
#4. Details of the processing
#Subject matter, nature and purpose
Collecting, storing, aggregating and displaying analytics; storing form responses; generating reports, audits and AI answers you request; and providing the related support — solely to provide the Service to you.
#Duration
For as long as you use the Service, and until Customer Data is deleted under section 11.
#Categories of data subjects
- visitors to websites and users of apps on which you install the tracker or SDK;
- people who submit your forms; and
- members of your workspaces whose activity appears in the Service.
#Categories of personal data
- pseudonymous analytics: page addresses, referrers, campaign parameters, screen size, device type, browser, operating system, country, and a daily-rotating visitor hash;
- app user identifiers, if you choose to send them through the Platform API or mobile SDK;
- form responses, which contain whatever your form asks for; and
- custom events and properties you choose to send.
The Service is not designed for special categories of personal data, such as health or biometric data. Do not collect them through the tracker or forms unless your own legal basis and safeguards allow it.
#5. Processing on your instructions
We process Customer Data only on your documented instructions. The Terms, this DPA and the settings you choose in the Service are your complete instructions. If we believe an instruction breaks Data Protection Law, we will tell you. If the law requires us to process Customer Data in another way, we will tell you first unless the law forbids it.
#6. Confidentiality
Everyone we authorise to process Customer Data is bound by a duty of confidentiality, and access is limited to the people who need it to run and support the Service.
#7. Security measures
We maintain technical and organisational measures appropriate to the risk, including:
- TLS encryption for all data in transit;
- passwords stored only as one-way bcrypt hashes;
- access tokens for connected accounts encrypted at rest;
- workspace-level access control enforced on every request, with role-based permissions;
- session revocation, optional two-factor authentication and an idle screen lock;
- production access limited to the people who need it; and
- data minimisation in the tracker itself, as described in section 4.
We review these measures as the Service and the risks change, and will not reduce the overall level of protection during your use of the Service.
#8. Sub-processors
You authorise us to use the following sub-processors to provide the Service. Each one is bound by written terms that protect Customer Data at least as well as this DPA, and we remain responsible for their performance.
- MongoDB Atlas — database hosting.
- Vercel — application hosting.
- Cloudflare — content delivery and network security, and Workers AI, which runs Orbit.
- Cloudinary — storage for images and files you upload.
- Razorpay and Cashfree — payment processing.
- Email and WhatsApp delivery providers — sending reports and notifications you set up.
- Google, LinkedIn and Meta — only when you connect an account with them.
We will update this list before a new sub-processor starts processing Customer Data. If you have a reasonable data protection objection to a new sub-processor, tell us within 30 days. We will try to resolve it; if we cannot, you may stop using the affected part of the Service or close your account.
#9. Helping you meet your obligations
Most data subject requests can be handled directly in the dashboard, where you can export or permanently delete a site's data. Where you need more, we will reasonably help you respond to requests to exercise data subject rights, and with data protection impact assessments and consultations with authorities, taking into account the nature of the processing.
If a data subject contacts us directly about Customer Data, we will refer them to you. Because the tracker does not store identifying data, we usually cannot link records to a specific visitor.
#10. Personal data breaches
If we become aware of a personal data breach affecting Customer Data, we will notify you without undue delay. The notice will describe the nature of the breach, the data and data subjects likely affected, the likely consequences, and the steps we have taken or propose, and we will update it as more becomes known. Notifying you is not an admission of fault.
#11. Deletion and return
You can export or delete Customer Data at any time from the dashboard. When you delete a site or close your account, we permanently delete the related Customer Data from the live system. Copies held in backups are overwritten as backups expire. We keep data longer only where the law requires it.
#12. Information and audits
We will make available the information reasonably needed to show that we comply with this DPA. Where that information is not enough, you may audit our compliance, at your own cost, no more than once a year, with at least 30 days' written notice, during normal business hours and subject to reasonable confidentiality terms. Audits must not compromise the security of the Service or of other customers' data.
#13. International transfers
Customer Data may be processed in countries other than your own, including India and the United States. Where Data Protection Law restricts a transfer, we rely on an appropriate safeguard, such as the standard contractual clauses offered by our sub-processors.
#14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
#15. Changes to this DPA
We may update this DPA when the Service or the law changes. The date at the top shows the latest version. We will not make a change that materially reduces the protection of Customer Data without notifying account holders by email before it takes effect.
#16. Contact
For questions about this DPA or to request a signed copy, email daorbit2k25@gmail.com. See also our Privacy Policy.