Commercial services
Data Processing Agreement (DPA)
Roles, instructions and security arrangements when processing personal data on behalf of a customer.
Roles and instructions
Unless the work order provides otherwise, the customer is the controller and Orvixa is a processor acting only under documented instructions. If Orvixa considers an instruction unlawful, it informs the customer and may suspend the relevant processing until the risk is resolved.
Processing details
- Subject and duration: the processing subject and duration specified in the DPA annex or work order
- Purpose and processing activities: the purposes and processing operations specified in the DPA annex or work order
- Data and data subject categories: the data and data subject categories specified in the DPA annex or work order
- Controller's rights and obligations: the controller’s instructions and obligations specified in the DPA annex or work order
Security, incidents and audits
Orvixa applies technical and organisational measures proportionate to risk and binds authorised personnel to confidentiality. Upon learning of an incident, it promptly provides verified information to the customer and keeps records. Reasonable audit information is supplied; access that would endanger production security or other customers' confidentiality is not granted.
Subprocessors and international transfers
The subprocessor list, functions and locations are provided to the customer. Agreed notice and objection procedures apply to changes. International transfers do not begin until adequacy, a standard agreement, binding corporate rules or another applicable mechanism has been verified.
Return, deletion and data subject requests
At the end of the service, data enters a return or deletion cycle according to the customer's choice and legal requirements. Reasonable assistance is provided to the controller with data subject requests, regulatory reviews and impact assessments.