Bright Mind Agency Logo
Bright Mind Agency Logo
How it worksPricingSupport
Sign inGet Started
Legal

Data Processing Agreement

Last updated: 2026-08-16

These terms apply where you use the oriiion service to process personal data for which you are the controller. They form part of the agreement between you and Get Orion AI AB and satisfy Article 28(3) of the General Data Protection Regulation. They take effect when you accept our terms of service and continue for as long as we process personal data on your behalf.

Published in English and Swedish. In the event of any discrepancy, the English version governs.

1. Roles and definitions

Terms used in these provisions have the meaning given to them in the General Data Protection Regulation. In particular:

  • Controller: You, where you determine the purposes and means of processing personal data relating to your customers, contacts, audience or staff.
  • Processor: Get Orion AI AB, where it processes that personal data on your behalf.
  • Sub-processor: A third party engaged by us to carry out processing activities on your behalf.
  • Customer personal data: Personal data for which you are the controller and which is processed through the service.

We act as a controller in our own right, and not as your processor, in respect of the personal data of the individual who holds the account, our billing records, our security logs and our own product analytics. That processing is governed by our privacy policy rather than by these provisions.

2. Subject matter and details of the processing

The particulars required by Article 28(3) are as follows.

Subject matterProvision of the oriiion service, being the generation, scheduling and publication of marketing content, the operation of an assistant across chat, messaging and telephone channels, and the retrieval and presentation of engagement data from connected accounts.
DurationFor as long as your account is active, and thereafter for the period stated in section 10.
Nature and purposeCollection, storage, organisation, retrieval, transmission to third party systems for generation and publication, and erasure, in each case for the purpose of providing the service to you.
Categories of personal dataIdentifiers and contact details, business information, message and conversation content, images, video, audio and documents you or your contacts submit, engagement and audience statistics, and any other personal data you choose to submit through the service.
Categories of data subjectsYour customers and prospective customers, the people who contact you through the channels connected to the service, your audience on connected social accounts, your staff and any person depicted or described in material you submit.

You must not submit special categories of personal data as defined in Article 9, or personal data relating to criminal convictions and offences, through the service. The service is not designed for that data and the measures described in section 4 are not calibrated for it.

3. Processing on documented instructions

We process customer personal data only on your documented instructions, including with regard to transfers to a third country, unless required to do otherwise by Union or Member State law. Where we are so required, we will inform you of that legal requirement before processing, unless the law prohibits us from doing so on important grounds of public interest.

Your instructions are constituted by these provisions, by our terms of service, and by your use of the features of the service, including the settings you choose and the accounts you connect. Configuring a feature is an instruction to carry out the processing that feature performs.

We will inform you if, in our opinion, an instruction infringes the General Data Protection Regulation or other Union or Member State data protection provisions.

4. Security of processing

We implement technical and organisational measures appropriate to the risk, taking account of the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing. The measures in place are:

  • Encryption of all data in transit using TLS, both between you and the service and between the service and its sub-processors.
  • Encryption of the database and of object storage at rest by the providers operating them.
  • Authentication of every request to the application, with each request scoped to the account it belongs to, and restriction of access to production systems to the personnel who require it.
  • Logical separation of each customer's data by account, so that data belonging to one account is not returned to another.
  • Logging of requests and errors, retained for a limited period, to allow faults and suspicious activity to be identified and investigated.
  • Daily backup of the database with point-in-time recovery, operated by the database provider.
  • A commitment to confidentiality from every person authorised to process customer personal data.

Get Orion AI AB does not hold SOC 2 attestation or ISO 27001 certification and has not undergone an independent security audit. Several of our sub-processors hold such certifications; we can confirm the position for a named sub-processor on request. We state this because a customer's own assessment under Article 28(1) should rest on what is actually in place.

Files submitted through the service are stored with our storage provider and served from addresses that are not published or indexed but are not individually access-controlled. A person who obtains or correctly constructs the address of a file can retrieve it. You should take this into account when deciding what material to submit.

5. Sub-processors

You give general written authorisation for us to engage sub-processors. We impose on each sub-processor, by contract, data protection obligations offering at least the same level of protection as these provisions, and we remain fully liable to you for the performance of that sub-processor's obligations.

The sub-processors currently engaged, with the purpose and place of processing of each, are listed and kept current on our sub-processor page.

We will update that page before a new sub-processor begins processing customer personal data. You may object, on reasonable grounds relating to data protection, within 30 days of the page being updated. Where you object, we will use reasonable efforts to make the affected functionality available without that sub-processor. Where that is not possible, you may terminate the affected part of the service and receive a refund of any fees paid in advance for the period after termination.

Where you connect an account with a social, commerce or payment platform, that platform receives customer personal data as an independent controller and not as our sub-processor. We are not responsible for its processing. Those recipients are identified separately on the same page.

6. Transfers to third countries

Providing the service involves transferring customer personal data outside the European Economic Area, principally to the United States.

The database in which customer personal data is stored is operated by our database provider in regions located in the United States. Customer personal data is therefore stored in the United States for the duration of the processing, and not only transmitted there for individual operations. If your own assessment requires storage within the European Economic Area, tell us before you begin using the service so that we can tell you whether that is available.

For each transfer we rely on one of the following, and will identify which applies to a given sub-processor on request:

  • The Standard Contractual Clauses adopted by the European Commission, incorporated into the sub-processor's data processing terms.
  • The EU-US Data Privacy Framework, where the recipient is certified under it.
  • An adequacy decision of the European Commission covering the country concerned.

7. Assistance to the controller

Taking into account the nature of the processing, we assist you by appropriate technical and organisational measures, insofar as possible, in fulfilling your obligation to respond to requests to exercise data subject rights. The service provides an export of the personal data held in an account in a machine-readable format, and provides account deletion, both without our involvement.

Where a data subject makes a request to us that concerns customer personal data, we will not respond to it ourselves unless you instruct us to. We will inform you of the request without undue delay.

We assist you in ensuring compliance with Articles 32 to 36, taking into account the nature of the processing and the information available to us. This includes providing the information reasonably required for a data protection impact assessment concerning the service.

8. Audit

We make available to you the information necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by you or by an auditor you mandate. An audit may be carried out once in any twelve month period, on 30 days' written notice, during business hours, and subject to confidentiality undertakings.

We may satisfy an audit request by providing documentation of our measures, answers to a security questionnaire, and any third party reports held by our sub-processors that we are permitted to share. Where you require an on-site inspection, you bear the reasonable costs. An audit may not unreasonably disrupt our business or compromise the confidentiality or security of other customers' data.

9. Personal data breaches

We notify you without undue delay after becoming aware of a personal data breach affecting customer personal data, and in any event within 48 hours, so that you can meet your own notification obligations. The notification describes the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where the information is not all available at once, it is provided in phases without further undue delay.

Our procedure, including how to report a suspected incident to us, is set out in our incident response policy.

10. Return and deletion

You may export customer personal data at any time during the term through the export function in the service. On termination, and at your choice, we delete or return customer personal data and delete existing copies, unless Union or Member State law requires storage of the data.

Where an account is deleted, associated customer personal data is erased 30 days after deletion. That interval exists so that a deletion made in error can be reversed. Data held in backups is removed as those backups expire in the ordinary backup cycle. If you require deletion sooner than 30 days, write to the contact in section 11 and we will carry it out.

11. Contact and precedence

Notices under these provisions, including objections to a sub-processor and audit requests, should be sent to:

Processor: Get Orion AI AB

Registration number: 559391-9961

Registered address: Huskvarnavägen 82, 554 66 Jönköping, Sweden

Contact for data protection: data@oriiion.ai

In the event of a conflict between these provisions and our terms of service, these provisions prevail in relation to the processing of customer personal data. In the event of a conflict between these provisions and the Standard Contractual Clauses where those clauses apply, the Standard Contractual Clauses prevail.

Bright Mind Agency Logo

Social media, done for you. Built for small business owners.

Product

  • How it works
  • Pricing

Help

  • Support
  • Contact

Company

  • About
  • Careers

Legal

  • Privacy
  • Terms
  • Cookies
  • Data processing
  • Sub-processors
  • AI transparency
  • EU AI Act
  • Incident response

© 2026 oriiion AB

🛡️ GDPR compliant