OrbitCRM Privacy Policy

Last Updated: April 9, 2026

1. Purpose and Scope

OrbitCRM ("we," "us," or "our") respects your privacy. This policy explains how we collect, use, and safeguard the information we receive via our website (the "Site") and our business productivity platform (the "Services").

As a UK-based entity, we process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

Important Note: This policy applies to the information we collect about our users (e.g., account holders). It does not apply to the data our customers upload into OrbitCRM (e.g., their leads and contact lists), which is governed by our Data Processing Agreement (DPA) and the customer's own privacy policy.

2. Information We Collect

We collect information you provide directly to us:

  • Account Information: Name, email address, company name, and password.
  • Billing Data: For paid plans, we use a PCI-DSS compliant third-party processor. We do not store full credit card details on our servers.
  • CRM Integration: If you choose to import Google Contacts or sync your email, we collect metadata (subject lines, timestamps) and content necessary to display your communications within the CRM.
  • Orbit AI Assistant: We collect prompts and feedback you provide to the AI. This is used to generate insights and automate tasks. Note: Orbit AI is not HIPAA-compliant; do not input sensitive health data.

3. How We Use Your Information

We process your data under the following legal bases:

  • Performance of a Contract: To provide the CRM services you signed up for.
  • Legitimate Interests: To improve our platform, ensure security, and conduct internal analytics.
  • Consent: For marketing communications (which you can opt-out of at any time).

4. How We Share Your Information

We do not sell your personal data. We share information only with:

  • Service Providers: Such as Nylas (for email integration) or cloud hosting providers, under strict confidentiality agreements.
  • Legal Requirements: If required by UK law enforcement or regulatory bodies.
  • Business Transfers: In the event of a merger or sale of OrbitCRM.

5. Data Retention & Security

  • Retention: We keep your data for as long as your account is active or as required by UK tax and legal obligations.
  • Security: We are SOC 2 compliant and use industry-standard encryption (TLS for data in transit and AES-256 at rest).
  • AI Data: Your data is never used to train publicly available third-party AI models.

6. Your Rights (UK & EEA Users)

Under the UK GDPR, you have the following rights:

  • Access: Request a copy of the data we hold about you.
  • Correction: Ask us to fix inaccurate information.
  • Erasure: Request that we delete your data (the "right to be forgotten").
  • Portability: Request a transfer of your data to another service.
  • Objection: Object to processing based on legitimate interests.

To exercise these rights, please contact [email protected]. We will respond within 30 days.

7. Cookies and Tracking

We use cookies to analyze trends and remember your settings.

  • Essential Cookies: Required for the site to function.
  • Analytics: We use Google Analytics (you can opt-out via browser extensions).
  • Do Not Track: Like most platforms, we do not currently respond to "Do Not Track" signals.

8. International Transfers

As a UK company, if we transfer data outside the UK/EEA (for example, to a US-based server), we ensure a similar degree of protection by using Standard Contractual Clauses (SCCs) or relying on the UK Extension to the EU-U.S. Data Privacy Framework.

9. Supervisory Authority

If you feel we have not addressed your privacy concerns adequately, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection regulator (www.ico.org.uk).

10. Contact Us

For questions regarding this policy or our data practices: