Legal index
Orbit’s legal and trust materials split into two halves: the binding documents Devotel publishes (terms, privacy, the Trust Center) and the tenant-operated controls this docs site describes. Use this page as the map between the two: which document governs which relationship, which obligations land on Devotel versus on your own team, and where each control is documented.This page is a directory, not legal advice. Your obligations depend on
where your end users live and what data you process — confirm with
qualified counsel.
Reading order for a legal review
If you are reviewing Orbit for procurement or vendor risk, read in this order — each document layers on the previous one:- Terms of service — the contract between you and Devotel: acceptable use, service levels, liability, and governing law. Everything else hangs off this agreement.
- Privacy policy — what personal data Orbit collects to run the service, how long we keep it, and the rights you and your end users can exercise. Includes the do-not-sell portal for CCPA/CPRA opt-out of sale or sharing.
- Trust Center — the delivery vehicle for the commitments the ToS names: SOC 2 control mappings, the subprocessor registry with data-residency notes, and downloadable agreements (DPA, BAA).
- Security overview — how the platform enforces the Trust Center claims: encryption and network hardening, tenant isolation, key handling, and incident reporting.
Obligation map: document and owner
Every obligation a reviewer tries to place resolves to either a platform-owned document or a tenant-operated control. The mapping:
The split matters in a review: Devotel-owned rows resolve by document
review alone, while tenant-owned rows also require you to operate the
named control.
Review-closure checklist
Work these steps in order. When every item is checked, your vendor review is closed.- Execute the agreements that need signatures; review the rest. Only the DPA — and the BAA if your workload touches PHI — are executable once. Sign the DPA self-serve and add the BAA in the Trust Center rather than red-lining terms. The terms of service and privacy policy are review-only.
- Route the reading to the right reviewer. Split the remaining
documents per role:
- Counsel — terms of service, DPA, BAA, and the subprocessor registry in the Trust Center.
- Platform engineer — the SOC 2 control split (which controls stay tenant-owned) and API key scopes (least-privilege minting for the traffic you plan to send).
- Tenant reviewer — the controls you operate: consent management, send gates, opt-out suppression, and DSAR fulfillment.
- Check the tenant-owned controls are green. Each advisor row in the obligation map passes only when its control is configured and passing in your organization — not merely documented here.
- Close the review. When the agreements above are executed and the role-specific checks are green, your vendor review is closed. File the executed DPA/BAA and the current checklist state in your vendor-risk record.
Tenant-operated controls
The documents above describe Devotel’s commitments. The guides below describe the controls you operate to back your own obligations — consent, suppression, DSAR intake, and the checks that gate every send. These are the entries a compliance reviewer actually walks through.Compliance posture overview
Per-jurisdiction gates, quiet hours, and the posture check that runs
before every send.
SOC 2 control ownership split
Which controls are platform-owned and which stay with your tenant.
HIPAA on Orbit
The BAA boundary and the controls for PHI workloads.
Consent management
Per-channel consent capture, lawful-basis tracking, and signed receipts.
Opt-out & suppression
Cross-channel suppression of opted-out recipients, with bulk CSV import.
Send gates
BAA, quiet hours, DNC, reassigned-numbers, and preference checks before a send.
Data subject requests (DSAR)
Operator-filed and self-service DSAR intake, and the fulfilment pipeline.
Self-serve DPA execution
Preview, sign, and download the GDPR Art. 28 Data Processing Agreement.
Binding versus advisory
Classify each surface before you rely on it:- Binding on Devotel — the terms of service, the privacy policy, and any executed agreement from the Trust Center (DPA, BAA). These create obligations on Devotel and on you.
- Advisory — the security overview,
the Trust Center reports, and every
guide under
/complianceand/legalon this docs site. These explain the platform and the controls; they do not amend the agreement.