Privacy Policy (GDPR)
How Orbit handles account data, conversations, prompts, files, model requests, automated actions, billing records, support messages, and website preferences.
001 / Controller
Orbit Systems B.V. is the controller for the public website, direct customer accounts, billing metadata, support, and product administration. For business customer content, Orbit may act as processor under a signed DPA. Contact: support@orbitdev.org.
002 / Data We Process
Orbit may process your name, email address, account identifiers, password hashes and authentication events, plan and entitlement data, device and log information, support messages, cookie choices, prompts, conversations, files, voice transcripts when used, generated output, tool calls, agent or automation state, browser context you choose to send, and developer API activity.
003 / Purposes
Orbit uses data to create and protect accounts, provide requested AI and tool features, maintain conversation and workspace state, enforce plan limits, process billing, prevent abuse, investigate errors, provide support, comply with law, and improve reliability. Orbit does not sell personal data for advertising.
004 / Legal Bases
Contract performance generally supports account, workspace, AI-request, and billing processing. Legitimate interests may support security, fraud prevention, service diagnostics, and product administration where those interests are not overridden by your rights. Consent supports optional cookies and any feature that specifically asks for it. Legal obligations may require tax, accounting, fraud, or lawful-request records.
005 / AI Content
Prompts, conversation history, uploaded files, code, browser context, and tool instructions may be stored as part of the workspace and sent to the model or tool provider selected or routed for your request. The repository does not establish exact file, conversation, backup, or deletion periods; these require the retention decision listed above. Product controls for deleting conversations, files, and accounts must be confirmed before publication.
006 / AI providers and training
Orbit supports routing to Orbit models and third-party providers displayed in the product, including OpenAI, Anthropic/Claude, and Google/Gemini. Those providers may receive the content necessary to answer a request. Orbit’s exact provider contracts, retention controls, and training opt-outs are not contained in this website repository, so [MODEL TRAINING POLICY CONFIRMATION REQUIRED] must be resolved before making a definitive no-training promise.
007 / Service providers and payment
Stripe is used for the billing flow documented by the current app and receives payment and transaction information; Orbit should not receive full card details through support channels. Orbit may also use providers for hosting, authentication, email, AI infrastructure, security, and operations. The definitive public subprocessor list is still required.
008 / Transfers and retention
Some providers may process data outside the EEA. Orbit must document the applicable adequacy decision, standard contractual clauses, or other transfer safeguard for each provider. Data is kept only for a defined operational or legal purpose, but exact production periods are unresolved: [DATA RETENTION PERIOD REQUIRED].
009 / Your rights
Where GDPR applies, you may request information, access, correction, deletion, restriction, portability, or objection, and may withdraw consent without affecting earlier lawful processing. You may also complain to the Dutch Autoriteit Persoonsgegevens or another competent supervisory authority.
010 / Requests and account deletion
Send a request from your account email to support@orbitdev.org. Orbit may verify identity and must normally respond within the period required by applicable law. Account deletion behavior and backup removal timing must be confirmed in the product before this policy is final.
011 / Security and children
Orbit uses access controls, authentication, transport encryption, and operational safeguards described on the Security page. No internet service is risk-free. Orbit is not directed to children under 16 unless a lawful school or parental arrangement and appropriate notices apply.
012 / Cookies and changes
The public website currently uses local storage for consent and interface preferences and has no detected analytics or advertising trackers. See the Cookie Policy. Orbit will update this notice when data practices change and provide additional notice where law requires it.