Legal
Data Processing Addendum
Processor terms for personal data Orcastrator handles on behalf of customer organisations.
Last updated: 12 July 2026
Purpose
This Data Processing Addendum (“DPA”) forms part of the agreement between Orcastrator and the customer organisation (“Customer”) that uses the Orcastrator product. It applies when Orcastrator processes personal data on Customer’s behalf in providing the Service.
It is intended to help Customers meet Article 28 GDPR / UK GDPR obligations for processors. Where a signed enterprise DPA exists, that signed document controls if there is a conflict.
Roles of the parties
Customer is the controller (or a processor instructing Orcastrator on behalf of a controller) for Customer Content that includes personal data.
Orcastrator is the processor for that data, and will process it only on documented instructions from Customer — including configuration in the product and this DPA — unless required to do otherwise by law.
For marketing-site inquiries from individuals, Orcastrator acts as a controller; that processing is described in the Privacy Policy, not this DPA.
Details of processing
Subject matter: hosting and processing Customer Content to provide Blueprints, test management, Sonar AI assistance, orchestration, live execution, Pulse, billing administration, and related support.
Duration: for the term of the Service and any post-termination retention required to wind down or meet legal duties, then deletion or return as described below.
Nature and purpose: storage, transmission, display, analysis, backup, and support access as needed to operate the Service.
Types of personal data: may include names, emails, identifiers, role/membership data, and any personal data Customer elects to place in specs, tests, evidence, or other workspace content.
Data subjects: Customer’s personnel, contractors, and any individuals whose data Customer submits to the Service.
Customer instructions
Customer instructs Orcastrator to process personal data to provide the Service, secure it, prevent abuse, and comply with law. Customer is responsible for the lawfulness of its instructions and for the accuracy of personal data it submits.
Confidentiality and personnel
Orcastrator ensures that persons authorised to process personal data are bound by confidentiality obligations and receive appropriate training relative to their role.
Security measures
Orcastrator implements appropriate technical and organisational measures as summarised on the Security page, including encryption in transit for public endpoints, access control, and environment separation appropriate to the Service. Customer is responsible for securing credentials, agent environments it operates, and content it chooses to upload.
Subprocessors
Customer authorises Orcastrator to engage subprocessors to deliver the Service (for example cloud hosting, email, identity, analytics, and payment infrastructure). Orcastrator will impose data-protection obligations on subprocessors that are no less protective than those in this DPA, as applicable to their services.
Enterprise Customers may request the current subprocessor list and notification mechanics as part of their agreement. Material changes to core subprocessors will be handled as described in that agreement or via reasonable notice where no alternate process exists.
Assistance with data-subject rights
Taking into account the nature of processing, Orcastrator will assist Customer by appropriate technical and organisational measures, insofar as possible, for Customer to respond to requests from data subjects. Where a request is sent directly to Orcastrator, we will redirect the individual to Customer when feasible.
Personal data breaches
Orcastrator will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer personal data we process, and will provide information reasonably available to help Customer meet its notification obligations.
Return or deletion
Upon termination of the Service, Orcastrator will delete or return Customer personal data in accordance with product capabilities and Customer’s instructions, except where retention is required by law or needed for secure wind-down, dispute resolution, or financial records. Plan retention windows may delete older run evidence earlier during the subscription.
Audits and information
Upon written request, and no more than once per year (unless a supervisory authority or documented incident requires more), Orcastrator will make available information reasonably necessary to demonstrate compliance with this DPA, which may include security summaries, questionnaire responses, or attestations under NDA. On-site audits, if agreed, will be scheduled to minimise disruption and may be subject to reasonable conditions.
International transfers
Where Orcastrator transfers personal data from the UK/EEA to a country not recognised as providing adequate protection, Orcastrator will use a valid transfer mechanism (such as standard contractual clauses) as required. Customers with residency or sovereignty requirements should discuss deployment options with sales before onboarding.
Liability
Liability arising under this DPA is subject to the limitations and exclusions in the Terms of Service or the governing enterprise agreement, except where prohibited by applicable data-protection law.
Questions about this document? Contact support (support@orcastrator.qa) or privacy (privacy@orcastrator.qa).