Sign in Sign up Sign in

Data processing commitments

A one-page summary of how OrbiVigil handles the personal data behind an institutional account, for a procurement file. This is not a substitute for a signed Data Processing Agreement and is not legal advice — see the last section for how to get one.

Scope

This page covers the personal data OrbiVigil handles for an account holder — the named individual(s) at a commune, SDIS, préfecture or similar body who hold an OrbiVigil account — and the territory data they configure. It does not cover the wildfire detections themselves, which are derived from public satellite and weather sources, not from personal data.

Roles, kept simple

We deliberately avoid asserting a legal controller/processor characterisation on this page — that determination depends on your organisation's own use of the service and is properly made with your counsel, not assumed by ours. What we can state plainly: for the account holder's own professional email and the territories they configure, OrbiVigil performs processor-like duties — we store and act on the data to run the service (send alerts, render the dashboard), we do not sell it, and we do not use it to train models or for any purpose the account holder did not ask for.

These are our standard commitments, not a legal opinion on your organisation's obligations under GDPR Article 28. A formal DPA naming the parties and roles precisely is available on request (see §6).

What we process, and why

Our standard commitments

Sub-processors

Requesting a signed DPA

If your procurement process requires a countersigned Data Processing Agreement rather than this summary page, use the contact form with your organisation's name and the account holder's email. We will send a document naming the parties, the categories of data above, and the commitments above in contractual language.

See also /trust/ for our data-protection practices in full.