1.1. Purpose of This Policy
This Privacy Policy explains how Orbas (“we,” “us,” or “our”) collects, uses, discloses, and protects your personal data when you access or use our platform, websites, mobile applications, and related services. Our commitment is to safeguard your data in line with applicable privacy and data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy ensures transparency in our practices and empowers Users to exercise their rights effectively.
1.2. Scope and Applicability
This policy applies to all users of Orbas, including but not limited to clients, service providers, partners, contractors, and visitors to our digital platforms. It governs:
This policy does not cover activities of external websites, service providers, or platforms linked from Orbas but not controlled by us.
1.3. Definitions
For clarity, the following terms are used consistently throughout this Privacy Policy:
“Third-Party Processor”: An external organisation engaged by Orbas to assist in processing personal data, subject to contractual safeguards.
Orbas collects personal data to enable the delivery of platform services, enhance user experience, and meet legal obligations. This section explains the categories of data we collect, how we collect it, and from where.
We aim to be transparent in how personal information is handled and to give users meaningful control over their data. The data collected varies depending on the user’s role (e.g., client, provider, partner) and activity on the platform.
2.1. Categories of Data Collected
We may collect the following types of personal data:
These categories enable Orbas to provide personalised services, ensure platform safety, fulfil contractual obligations, and comply with legal requirements.
2.2. Data You Provide to Us
We collect personal data that you actively provide during your interactions with the platform. This includes actions such as:
We treat all user-provided data with confidentiality and process it only for legitimate purposes in line with user expectations and consent.
Users are responsible for ensuring all submitted data is accurate and up to date. Inaccurate data may hinder access to platform features or lead to regulatory compliance issues.
2.3. Data We Collect Automatically
When you use Orbas, we automatically collect certain types of data through built-in analytics and third-party tools. This data includes:
Automatically collected data allows us to optimise the platform experience, detect unusual activity, and improve services through aggregate analysis.
2.4. Data from Third Parties
We may also obtain personal data from external sources in accordance with this Privacy Policy and relevant legal bases. These sources include:
This data helps us confirm eligibility, improve onboarding efficiency, and strengthen user identity assurance.
2.5. Cookies and Tracking Technologies
Orbas uses cookies and related technologies for several reasons:
Users have the right to adjust cookie preferences at any time via browser settings or the in-app cookie control panel. Please see our dedicated Cookie Policy for more detail on managing consent and setting retention periods.
Orbas processes personal data only where it has a valid legal basis under applicable data protection legislation, including the UK GDPR. The specific basis we rely on may vary depending on the type of data collected, the nature of the interaction, and the purpose of processing. This section outlines the main legal grounds upon which Orbas relies.
3.1. Consent
We may process your personal data where you have explicitly given your informed, specific, and unambiguous consent. This typically applies to:
You may withdraw your consent at any time by updating your preferences in your account dashboard or by contacting us directly. Withdrawal of consent does not affect the lawfulness of processing carried out before such withdrawal.
3.2. Contractual Necessity
We process data when it is necessary to perform or enter into a contract with you. This includes:
Without this data, Orbas would be unable to provide its core platform services effectively.
3.3. Legitimate Interests
We process certain data under our legitimate business interests, provided these are not overridden by your rights or freedoms. This includes:
Where required, we conduct legitimate interest assessments to ensure the balance of interests is fair and lawful.
3.4. Legal Obligation
Orbas may process or retain certain data to comply with legal and regulatory requirements. Examples include:
In such cases, the processing is necessary to meet our legal duties and may override objections or deletion requests.
3.5. Vital Interests and Public Task
Although rare, we may process personal data to protect someone’s life or in the public interest. Scenarios might include:
Such processing is strictly limited to exceptional cases and follows regulatory guidelines to safeguard user rights.
Orbas uses the personal data it collects to provide, maintain, and enhance the platform, ensuring a safe and optimised experience for all users. This section outlines the key purposes for which data is processed.
4.1. Service Provision and User Account Management
We use your personal data to operate the platform and deliver core functionalities. This includes:
Without this data, we would not be able to maintain your account or deliver essential platform services.
4.2. Transaction Processing and Support
We use personal and financial data to enable secure transactions and support interactions, including:
All financial information is handled in compliance with applicable payment regulations and standards.
4.3. Communication and Marketing
Your contact and interaction data may be used to:
You may opt out of non-essential communications at any time through your account settings or unsubscribe links.
4.4. Security and Fraud Prevention
We process user data to maintain a safe and trustworthy platform environment. This includes:
Security systems are designed to balance risk detection with minimal intrusion on user privacy.
4.5. Analytics and Platform Improvement
We analyse aggregated and anonymised data to:
All analytical processing is governed by data minimisation principles and conducted using secure tools.
Orbas operates in a global digital environment and, as such, your personal data may be stored or processed in countries outside of your country of residence. We are committed to ensuring that all international data transfers are conducted in a manner that safeguards your rights and complies with applicable data protection laws.
6.1. Hosting and Storage Locations
Your personal data may be hosted or processed in secure data centres located in the United Kingdom, the European Economic Area (EEA), or other jurisdictions where Orbas or its third-party service providers maintain operations. These facilities are selected based on their adherence to strict data security standards and regulatory compliance.
We make every effort to ensure that storage providers offer high standards of physical, technical, and organisational security aligned with the UK GDPR.
6.2. Transfers Outside the UK/EU
Where personal data is transferred outside the UK or EEA to a country that has not been deemed to provide an adequate level of data protection by the UK government or European Commission, we implement appropriate safeguards to protect your information. These may include:
Such transfers are limited to what is necessary for platform functionality, support services, fraud monitoring, and data analytics.
6.3. Safeguards and Standard Contractual Clauses
We enter into binding agreements with any third-party data processors located outside of the UK or EEA. These agreements include:
If you would like to receive a copy of the relevant safeguards for international transfers, you may contact us using the details in Section 13 of this Policy.
Orbas retains personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, regulatory, tax, accounting, or reporting requirements. This section outlines the principles we apply to determine appropriate retention periods and our practices for secure deletion or anonymisation.
7.1. Retention Periods by Category
We apply varying retention periods depending on the type of personal data and the purpose of processing. For example:
7.2. Criteria for Retention
Retention periods are determined based on several factors, including:
We conduct periodic reviews of our data processing and retention practices to ensure continued compliance.
7.3. Data Deletion and Anonymisation
Once the applicable retention period expires, we take appropriate steps to:
Users may also request deletion of their personal data by contacting our support team or exercising their rights under Section 8 of this Policy. Please note that some data may be retained where necessary to comply with legal obligations or resolve disputes.
Orbas respects and upholds the data rights of all individuals whose personal data it processes. These rights are granted under the UK General Data Protection Regulation (UK GDPR) and are exercisable in accordance with the law. This section sets out the rights available to you and how you may exercise them.
8.1. Right to Access
You have the right to request confirmation of whether Orbas is processing your personal data, and if so, to access that data. This includes information about the purposes of processing, categories of data held, recipients of the data, and retention periods.
Requests for access should be submitted via the contact details in Section 13. We will respond within the statutory timeframes and provide a copy of the data where applicable.
8.2. Right to Rectification
You have the right to request the correction of any inaccurate or incomplete personal data held by Orbas. We aim to keep your data accurate and up to date. You may also update certain data directly via your account dashboard.
8.3. Right to Erasure (“Right to be Forgotten”)
In certain cases, you may request that we delete your personal data, particularly where:
Please note that erasure may be limited by legal or contractual retention obligations.
8.4. Right to Restriction of Processing
You have the right to restrict the processing of your data in specific situations, such as:
Restricted data will only be processed with your consent or for legal purposes.
8.5. Right to Data Portability
Where processing is based on consent or a contract, and carried out by automated means, you may request that we provide your personal data in a structured, commonly used, and machine-readable format. You may also request that this data be transmitted directly to another controller where feasible.
8.6. Right to Object
You have the right to object to the processing of your personal data where we rely on legitimate interests or public interest as the legal basis. If you object, we will stop processing your data unless we can demonstrate compelling legitimate grounds that override your interests.
You also have the absolute right to object to direct marketing at any time.
8.7. Right to Withdraw Consent
Where you have given consent for specific data processing activities, you have the right to withdraw that consent at any time. This will not affect the lawfulness of processing based on consent before its withdrawal.
You can withdraw consent through your account preferences or by contacting us.
8.8. Right to Lodge a Complaint
If you believe your data rights have been violated or that your data has been misused, you have the right to file a complaint with the UK Information Commissioner’s Office (ICO) or the data protection authority in your jurisdiction.
We encourage you to contact us first so that we can attempt to resolve the issue directly.
Orbas is committed to maintaining the confidentiality, integrity, and availability of your personal data. We implement a range of technical and organisational measures to protect your information against unauthorised access, accidental loss, destruction, or disclosure. This section outlines our approach to data security.
9.1. Technical and Organisational Measures
We adopt industry-standard security protocols and maintain a layered security architecture to safeguard data. Our measures include:
All systems are built with privacy-by-design and follow security best practices in software development.
9.2. Incident Response
Orbas maintains an incident response plan to promptly detect, assess, and address data breaches or security threats. In the event of a breach:
We strive to be transparent and proactive in our response to any security incidents.
9.3. User Responsibility for Account Security
Users are responsible for maintaining the confidentiality of their login credentials and ensuring their devices are protected. To support this:
While we take extensive measures to protect your data, your vigilance as a user is equally important in maintaining platform security.
Orbas may use automated systems, including artificial intelligence (AI), to assist in delivering personalised services, enhance operational efficiency, and improve user outcomes. However, we ensure that such decisions do not adversely affect your rights or freedoms without meaningful human oversight. This section outlines our use of automated decision-making tools and your associated rights.
10.1. AI-Powered Profiling
We may use AI-powered algorithms to:
These profiling systems operate on a logic designed to maximise user relevance, quality, and platform integrity. Where AI is involved, its outputs are monitored and refined to reduce bias and improve transparency.
10.2. User Impact and Right to Human Review
Where an automated decision produces legal effects or significantly affects you (e.g., denial of access, rating downgrades, restricted visibility), you have the right to:
We are committed to ensuring fairness and accountability in all automated processing and will provide accessible means to challenge or override decisions when required.
Orbas may provide links to external websites or integrate with third-party services for enhanced functionality. While we take care to partner with reputable providers, we do not control how third parties operate or handle your data once you leave our platform. This section outlines the scope and limitations of our responsibility for third-party content and services.
11.1. External Sites and Services
Our platform may contain links to external websites, plug-ins, widgets, or services (such as payment processors, identity verification tools, and learning content providers). When you interact with these third-party platforms:
Examples include logging in through social media, watching embedded video content, or making secure payments via trusted gateways.
11.2. Responsibility Disclaimer
Orbas is not responsible for the content, privacy practices, or data processing activities of third-party websites or services not controlled by us. We do not:
Your interactions with such services are at your own risk, and your data will be governed by their respective policies. Where possible, we will provide clear notice when you are leaving our environment.
We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or enhancements to our services. We are committed to keeping users informed of material changes and maintaining transparency in how we use your data.
12.1. Notice of Changes
Whenever we make significant amendments to this Policy:
12.2. Effective Date
Each version of the Privacy Policy will include an effective date, clearly shown at the top of the document. Changes take effect on the date specified, unless otherwise communicated in the notice.
12.3. Continued Use as Acceptance
By continuing to use the Orbas platform after the revised Privacy Policy takes effect, you acknowledge and agree to the terms of the updated Policy. If you do not agree with any aspect of the revised version, you should discontinue use of the platform and may request deletion of your account and data as outlined in Section 8.
If you have any questions, concerns, or requests regarding this Privacy Policy or how your personal data is handled, you may contact us or our appointed Data Protection Officer (DPO) directly. We are committed to responding promptly and transparently to all privacy-related inquiries.
13.1. Contact for Privacy Queries
For general privacy questions, account-related data requests, or to exercise any of your rights under Section 8 of this Policy, please contact:
Email: privacy@orbas.io
Address:61 Bridge Street, Hertfordshire, HR5 3DJ
Please include sufficient details to verify your identity and the nature of your request.