GDPR-ready. By design.
How Adzone Orbit complies with the EU General Data Protection Regulation and protects data subject rights.
Our GDPR Commitment
Adzone Orbit is fully committed to GDPR compliance. We have implemented privacy-by-design principles throughout our platform, ensuring that data protection is built into every feature from the ground up. We process personal data lawfully, fairly, and transparently.
Lawful Basis for Processing
We process personal data under the following lawful bases: (1) Contract — processing necessary to provide the service you requested. (2) Legal obligation — compliance with applicable laws. (3) Legitimate interest — improving our service and ensuring security. (4) Consent — for optional marketing communications and analytics.
Data Subject Rights
Under GDPR, data subjects have the following rights, all of which Orbit supports: Right of access — request a copy of your data. Right to rectification — correct inaccurate data. Right to erasure — request deletion ("right to be forgotten"). Right to restrict processing. Right to data portability — receive your data in a machine-readable format. Right to object — to certain types of processing. Right to withdraw consent at any time.
How to Exercise Your Rights
You can exercise most data rights directly from your account settings (export data, delete account, manage consent). For other requests, contact our Data Protection Officer at privacy@adzoneorbit.com. We respond to all requests within 30 days, free of charge.
Data Processing Agreement (DPA)
Adzone Orbit acts as a Data Processor for customer data. We offer a standard DPA to all customers subject to GDPR, detailing our obligations as a processor. Enterprise customers can request a customized DPA. Our DPA covers processing purposes, data security measures, sub-processor management, and breach notification procedures.
International Data Transfers
For transfers of personal data outside the EU/EEA, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. We do not transfer data to countries without adequate data protection unless appropriate safeguards are in place. Our sub-processors are all bound by SCCs or equivalent safeguards.
Sub-Processors
We use vetted sub-processors for hosting, email delivery, payment processing, and analytics. A current list of sub-processors is available on request. We provide 30 days notice before adding or changing sub-processors. All sub-processors are GDPR-compliant and bound by strict data processing agreements.
Data Breach Notification
In the event of a personal data breach, we notify affected customers and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by Article 33 of the GDPR. Our incident response plan includes breach detection, containment, assessment, notification, and remediation procedures.
Data Protection Officer
Our Data Protection Officer (DPO) oversees GDPR compliance and serves as a point of contact for data subjects and supervisory authorities. Contact our DPO at dpo@adzoneorbit.com for any GDPR-related questions or requests.
Questions about this policy?
Our legal and security teams are happy to clarify any aspect of our policies.
