Data Processing Agreement
Last updated: June 11, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the customer using Orloi ("Controller") and Otimo Earth s.r.o ("Processor", "Otimo Earth", "we", "us"), a company registered in the Czech Republic under business ID 19558635 at Varšavská 715/36, Vinohrady (Praha 2), 120 00 Praha.
This DPA applies where Otimo Earth processes personal data on behalf of Controller in connection with Orloi. Capitalized terms not defined in this DPA have the meaning given in the applicable Terms of Service, order form, pilot agreement, or other written agreement between the parties.
1. Acceptance of this DPA
If you use Orloi as a controller and Otimo Earth processes personal data on your behalf as a processor, this DPA forms part of the Terms of Service or other written agreement governing your use of Orloi.
By creating an account, accepting the Terms of Service, signing an order form, or using Orloi in a way that causes Otimo Earth to process personal data on your behalf, you agree to this DPA on behalf of the Customer.
This DPA applies automatically where Otimo Earth processes personal data on behalf of the Customer as a processor.
2. Definitions
"Customer" means the legal entity or person that accepts the Terms of Service, order form, pilot agreement, or other written agreement for Orloi.
"Controller" means Customer to the extent Customer determines the purposes and means of processing Controller Personal Data through Orloi.
"Controller Personal Data" means personal data processed by Otimo Earth as processor on behalf of Controller under this DPA.
"Account Data" means personal data processed by Otimo Earth as an independent controller for account administration, billing, support, security, abuse prevention, legal compliance, service communications, and similar business purposes. Account Data is governed by the Privacy Policy and is not governed by this DPA except where applicable law requires otherwise.
"Customer Postgres" means the Postgres database, compatible database, or hosted Postgres service configured by Controller as the destination for Orloi outputs.
"Changelog Data" means changelog, event, metric, report, alert, profile, process-map, operational-memory, and AI-derived output generated by Orloi from Controller-configured Airtable activity or related integration data.
"Documented Instructions" means the Terms of Service, this DPA, Controller's configuration and use of Orloi, selected Airtable bases, tables, fields, webhook scopes, AI settings, Customer Postgres destination, and any other written instructions agreed by the parties.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Controller Personal Data.
"Active Controller Personal Data" means Controller Personal Data held in Processor-managed production systems, excluding backup copies, security logs, legal or compliance records, and data written to Customer Postgres.
3. Scope Clarification
This DPA applies only to Otimo Earth's processing of Controller Personal Data as processor on behalf of Controller. Otimo Earth may process Account Data as an independent controller as described in the Privacy Policy.
4. Subject Matter & Duration
Subject Matter: Processing of personal data by Processor on behalf of Controller to observe configured Airtable activity, process webhook and integration data, and write changelog, metric, report, alert, and operational-memory outputs to Controller's configured Postgres database.
Duration: From the effective date of the applicable agreement until cessation of the relevant Service and deletion or return of Controller Personal Data as described in this DPA, unless longer retention is required by law or backup expiry.
5. Roles & Responsibilities
Controller is the data controller for Controller Personal Data processed through Orloi. Processor is the data processor for the processing activities covered by this DPA.
Processor will:
- process Controller Personal Data only on Documented Instructions from Controller, including with regard to international transfers, unless required by applicable law;
- promptly inform Controller if, in Processor's opinion, an instruction infringes applicable data protection law;
- ensure personnel authorized to process Controller Personal Data are subject to appropriate confidentiality obligations;
- implement and maintain appropriate technical and organizational measures as described in Annex B;
- assist Controller, taking into account the nature of processing, with data subject requests where Controller cannot reasonably fulfill the request without Processor assistance;
- assist Controller with GDPR Articles 32-36 obligations, including security, breach notification, DPIAs, and prior consultation, where applicable and taking into account the nature of processing and information available to Processor;
- notify Controller without undue delay after becoming aware of a personal data breach affecting Controller Personal Data;
- return or delete Controller Personal Data upon termination or Controller instruction, subject to legal retention requirements, backup expiry, and the Customer Postgres boundary described in Annex A;
- maintain records of processing activities as required by GDPR Article 30(2);
- make available information reasonably necessary to demonstrate compliance with this DPA.
Controller is responsible for:
- the lawfulness of Controller Personal Data and processing instructions;
- selecting Airtable bases, tables, fields, webhook scopes, AI features, and destination databases appropriately;
- providing required notices and obtaining required rights, permissions, or consents;
- establishing an appropriate lawful basis, completing any required DPIA or similar assessment, and meeting applicable workplace, employment, data protection, and AI-law requirements where Controller Personal Data includes personal data relating to employees, contractors, collaborators, candidates, or other workers;
- securing and backing up Controller's configured Postgres database;
- responding to data subject requests where Controller can do so through its own systems, Airtable, or Customer Postgres access.
6. Documented Instructions
Processor will process Controller Personal Data only on Documented Instructions from Controller, including with regard to international transfers, unless required by EU or Member State law applicable to Processor. Processor will inform Controller of that legal requirement before processing unless the law prohibits such notice on important grounds of public interest.
Controller's configuration choices in Orloi, including selected Airtable bases, tables, fields, webhook scopes, AI features, retention choices, and Customer Postgres destination, constitute Documented Instructions.
7. Subprocessors
Controller gives general written authorization for Processor to use subprocessors listed in the applicable subprocessor register.
The subprocessor register will identify material subprocessors by name, service or processing purpose, relevant processing location or hosting region where available, and applicable transfer safeguard where relevant.
Processor will provide at least 30 days' prior notice of intended material additions or replacements where practicable. Shorter notice may be given where a change is required for security, reliability, legal compliance, provider discontinuation, or urgent operational reasons.
Controller may object to a new or replacement subprocessor on reasonable data-protection grounds. The parties will work in good faith to resolve the objection. If the objection cannot reasonably be resolved, Controller may disable the affected feature or terminate the affected Service to the extent the new subprocessor is necessary for that Service.
Processor will impose data-protection obligations on subprocessors substantially equivalent to this DPA and remains responsible for their performance. Customer Postgres is selected and controlled by Controller and is not an Otimo Earth subprocessor unless separately agreed in writing.
The current subprocessor register is available at Subprocessors. The register distinguishes subprocessors used for core Orloi processing, optional or feature-dependent processing such as AI, and commercial/account processing such as billing or support.
8. International Transfers
Where Controller Personal Data is transferred outside the EU/EEA, Processor will rely on Standard Contractual Clauses approved by the European Commission or other applicable transfer safeguards, unless an adequacy decision or other lawful transfer mechanism applies.
Processor will make applicable transfer information reasonably available through the subprocessor register, Trust Center materials, or on request where required.
9. Data Subject Rights
Processor will promptly forward any data subject request it receives in relation to Controller Personal Data to Controller and will not respond directly unless instructed by Controller or required by law.
Processor will provide reasonable assistance to Controller for access, rectification, erasure, portability, objection, and restriction requests where Controller cannot reasonably fulfill the request using Airtable, Customer Postgres, or other Controller-controlled systems.
10. Personal Data Breach Notification
Processor will notify Controller without undue delay and, where reasonably practicable, within 48 hours after becoming aware of a Personal Data Breach affecting Controller Personal Data.
An initial notice may be incomplete and based on information then available. Processor will provide further updates as reasonably available, including information to help Controller assess the nature of the breach, affected categories of data subjects and records where known, likely consequences, and measures taken or proposed to address the breach.
Breach notices will be sent to Controller's account contact, security contact, or other contact point designated by Controller.
11. Audit & Information Rights
Processor will make available information reasonably necessary to demonstrate compliance with this DPA and will allow and contribute to audits, including inspections, as required by applicable data protection law.
Controller should first use available Trust Center materials, security documentation, subprocessors information, retention materials, and written responses. Any additional audit will normally be conducted as a remote documentation review unless applicable law, a supervisory authority, or a Personal Data Breach affecting Controller Personal Data requires otherwise. Any audit or inspection must be reasonable, proportionate, subject to confidentiality, scheduled in advance, limited to systems and records relevant to Controller Personal Data, and conducted in a way that does not compromise security, confidentiality, or other customers' data.
Unless required by a supervisory authority, applicable law, or a Personal Data Breach affecting Controller Personal Data, audits are limited to once per 12-month period.
12. Liability
Each party is liable for its own breach of this DPA. Processor's aggregate liability under this DPA is limited to the extent permitted by applicable law and the applicable master terms, order form, pilot agreement, or other written agreement between the parties.
13. Termination & Deletion
Upon termination of the Service or Controller's written request, Processor will delete or return Active Controller Personal Data, at Controller's choice, unless EU or Member State law requires continued retention.
If Controller does not provide deletion or return instructions within 30 days after termination, Controller instructs Processor to delete Active Controller Personal Data, subject to legal retention requirements and backup expiry.
Processor will confirm deletion of Active Controller Personal Data upon written request where reasonably practicable. Backup copies are purged according to the applicable backup lifecycle, currently up to 90 days where Processor-managed backups apply.
Deletion or termination of an Orloi account or connection stops future ingestion and removes or disables relevant Processor-managed records. It does not automatically delete Changelog Data already written to Customer Postgres, which Controller controls directly.
14. Governing Law & Jurisdiction
This DPA is governed by the laws of the Czech Republic, unless applicable data protection law requires otherwise. Exclusive venue for disputes is the courts of Prague, Czech Republic, unless mandatory law provides otherwise.
Annex A: Processing Description - Orloi
A1. Nature of Processing
Collection, receipt, transformation, enrichment, classification, summarization, storage, transmission, deletion, and security processing of Airtable webhook payloads, integration metadata, operational logs, schema information, collaborator metadata, and derived changelog outputs.
A2. Purpose of Processing
To provide an operational changelog and related visibility features for Controller's configured Airtable bases, including event capture, schema change tracking, metrics, summaries, reports, alerts, profiles, and optional AI-assisted analysis.
The Service is not intended to be used for employee performance evaluation, automated HR decision-making, or decisions producing legal or similarly significant effects concerning individuals.
A3. Categories of Data Subjects
Data subjects may include:
- Controller's users, workspace members, collaborators, employees, contractors, candidates, or other workers whose activity or metadata appears in Airtable or related operational data;
- Controller's customers, leads, suppliers, partners, applicants, or other individuals whose personal data is contained in configured Airtable records;
- other individuals whose personal data is included by Controller in Airtable fields, webhook payloads, comments, metadata, or derived changelog outputs.
A4. Categories of Personal Data
Personal Data Processed may include:
- Airtable record data selected or made available by Controller, including field values that may contain names, email addresses, phone numbers, notes, statuses, free-text fields, identifiers, customer metadata, and other Controller-defined data;
- Airtable metadata, including base IDs, table IDs, field IDs, record IDs, schema changes, webhook payloads, collaborator metadata, automation metadata, and timestamps;
- Changelog Data, including raw events, compacted events, metrics, summaries, reports, alerts, profiles, process maps, and AI-derived operational artifacts;
- collaborator identifiers and activity metadata, where such data is present in Controller-configured sources or generated by configured Service features;
- technical and operational data required to provide, secure, monitor, troubleshoot, and maintain the Service, including logs, diagnostics, queue state, cache entries, and credential metadata.
A5. Restricted Data
Orloi is not designed for protected health information or electronic protected health information subject to HIPAA, GDPR special-category data, criminal-offense data, children's data, payment card data, government identification numbers, or other data subject to sector-specific legal or contractual restrictions beyond ordinary business personal data ("Restricted Data").
Controller must not intentionally configure Orloi to process Airtable bases, tables, fields, webhook scopes, AI features, or destination databases known to contain Restricted Data unless Processor has agreed to that use in a separate written agreement.
If Processor becomes aware that Orloi is processing Restricted Data without such written agreement, Processor may suspend affected processing, request remediation, exclude affected data from processing where technically feasible, or delete relevant Processor-managed copies, without affecting Controller's responsibility for the original data in Airtable, Customer Postgres, or other Controller-controlled systems.
A6. Processor-Persisted Data
Persisted by Processor may include account metadata, configuration metadata, integration identifiers, encrypted credentials or credential references, Airtable base/table/field/webhook identifiers, Customer Postgres connection configuration, processing status, logs, diagnostics, and other operational metadata required to provide and secure the Service.
Changelog Data is designed to be written to Controller's configured Customer Postgres as the durable destination. Processor does not use its own infrastructure as the primary system of record for Changelog Data, but limited operational copies, logs, cache entries, queue state, diagnostics, and backups may exist according to the applicable retention policy and infrastructure-provider backup lifecycle.
A7. Optional AI Processing
AI-assisted processing is optional and configuration-dependent. Where enabled or required for a configured feature, AI providers may process limited operational context solely to provide configured Orloi features such as summarization, pattern detection, reporting, alerting, profiles, and related operational analysis.
AI providers that process Controller Personal Data are treated as subprocessors and are listed in the applicable subprocessor register.
Redaction and pseudonymization controls may reduce exposure of obvious high-risk values in supported AI paths, but they do not guarantee that AI inputs contain no personal data.
Processor will not permit AI providers to use Controller Personal Data to train general-purpose AI models unless expressly agreed by Controller.
AI-assisted features are not intended to be used as the sole basis for legal, compliance, employment, credit, insurance, healthcare, eligibility, disciplinary, or other high-impact decisions affecting individuals.
Annex B: Technical and Organizational Measures
Processor maintains technical and organizational measures appropriate to the nature of the Service, including:
- HTTPS/TLS for web traffic and database connections;
- encryption at rest where supported by relevant infrastructure providers;
- encryption of sensitive credentials using AES-256-GCM or dedicated credential infrastructure;
- access controls and least-privilege practices for production systems;
- administrative access protected by two-factor authentication where available;
- restricted logging and limited access to operational logs;
- webhook verification using HMAC-SHA256 where supported by the integration;
- CI/CD, linting, and code review practices;
- vendor and subprocessor review for material processing activities;
- incident response and breach assessment procedures.
Further security and privacy materials are available in the Trust Center, including Security, Retention Policy, and Subprocessors.
Annex C: Subprocessors
The current public subprocessor register is available at Subprocessors.
The register may include:
- core Orloi subprocessors for hosting, authentication, application data, integration authorization, queue/cache state, email delivery, and observability;
- optional or configuration-dependent subprocessors, including AI providers where AI-assisted features are enabled;
- commercial/account subprocessors, such as billing or support providers, where those providers process account, support, or billing data.
Controller's configured Customer Postgres provider is selected and controlled by Controller unless otherwise agreed in writing.
Incorporation
This DPA is incorporated into the Terms of Service and applies automatically where Otimo Earth processes personal data on behalf of the Customer as a processor.
Last updated: June 11, 2026