Skip to main content
rbisApp
Features Pricing FAQ
Terms of Service Privacy Policy Refund Policy
Contact
Legal

Privacy Policy

Last updated: September 18, 2026

On this page

  1. Introduction & scope
  2. Our roles: controller vs. processor
  3. Personal data we collect
  4. How we use personal data
  5. Cookies & tracking
  6. How we share data & subprocessors
  7. International data transfers
  8. Data retention
  9. Security
  10. Your privacy rights (GDPR/UK GDPR)
  11. US state privacy rights
  12. Children’s privacy
  13. Automated & AI processing
  14. Changes to this policy
  15. Contact

1. Introduction & scope

This Privacy Policy explains how Muhammad Umair, an individual trading as “OrbisApp” (“OrbisApp,” “we,” “us”), handles personal data in connection with the orbisapp.net website, our demo-access and contact features, and our billing and automation platform (the “Service”). It applies to visitors to our website, people who request demo access or contact us, and holders of admin-panel and client-portal accounts. It does not govern how our business customers handle their own end-customers’ data (see the next section).

2. Our roles: controller vs. processor

OrbisApp acts in two distinct roles:

  • As a controller for personal data we decide how to use — for example, data from website visitors, demo requests, contact-form messages, and our own account holders.
  • As a processor for the end-customer data that our business customers (hosting providers and SaaS sellers) enter into the platform. In that role we process such data only on the business customer’s instructions under a data processing agreement available on request, and that business customer is the controller.

3. Personal data we collect

  • Demo-access requests: the email address you submit to receive demo credentials.
  • Contact messages: your name, email address, and the content of your message.
  • Account data: credentials and profile details for admin-panel and client-portal accounts.
  • Technical & usage data: IP address and request metadata used for security, rate limiting, and spam prevention, and basic pageview information — page path, referrer, and device/browser information (your user-agent), together with a randomly generated per-visit identifier — collected to understand site usage. We do not set tracking cookies or track you across sites.
  • Billing data: payments and account top-ups are handled by our merchant of record, Paddle.com Market Limited (“Paddle”), which collects your billing details directly to process the transaction; we do not collect or store your full payment-card details. We do maintain your account balance and a record of funds you add and amounts applied to subscriptions, renewals, and other charges, so we can operate your account and process renewals from your available funds.

4. How we use personal data

We use personal data to: provide demo access and respond to inquiries; operate, secure, and improve the Service; prevent abuse through rate limiting and captcha; send transactional communications; and, where permitted, send marketing you can opt out of. Where the GDPR or UK GDPR applies, our legal bases include performance of a contract, our legitimate interests (such as security and service improvement), consent where required, and compliance with legal obligations.

5. Cookies & tracking

OrbisApp is designed to be light on tracking. Our captcha is session-free, so we do not set session cookies for it. We do not use third-party advertising or cross-site tracking cookies.

6. How we share data & subprocessors

We do not sell personal data. We share personal data only with service providers who help us operate the Service, under contracts that limit their use of the data. Our current subprocessors include:

  • Email delivery: MXRoute
  • Hosting/infrastructure: OVH
  • Merchant of record & payment processing: Paddle.com Market Limited (Paddle handles payment, invoicing, and sales tax/VAT as an independent controller of the billing data it collects)
  • Analytics: none (self-hosted analytics only)

We may also disclose data where required by law or to protect our rights, users, or the public.

7. International data transfers

Our servers are located in Canada. Where personal data of individuals in the EEA or UK is transferred outside those regions, we rely on an appropriate transfer mechanism such as an adequacy decision or Standard Contractual Clauses.

8. Data retention

We keep personal data only as long as necessary for the purposes described above or as required by law. Indicative periods: demo requests 1 month; contact messages 1 month; security and rate-limit logs 90 days; analytics and pageview data 90 days. When data is no longer needed, we delete or anonymize it.

9. Security

We use technical and organizational measures appropriate to the risk, such as encryption in transit (HTTPS), HMAC-signed captcha tokens, access controls on the admin panel, and protecting stored credentials. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Your privacy rights (GDPR/UK GDPR)

Subject to applicable law, you may have the right to access, rectify, erase, restrict, or object to our processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with a supervisory authority. To exercise these rights, contact us using the details below.

11. US state privacy rights

Depending on your state of residence (for example, California under the CCPA/CPRA), you may have rights to know, delete, and correct personal data, and to opt out of certain sharing. We do not sell or share personal data as those terms are defined by such laws.

12. Children’s privacy

The Service is not directed to children, and we do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us personal data, contact us and we will delete it.

13. Automated & AI processing

Our client-portal “Ask AI” feature lets an end-user submit a natural-language question and returns an answer grounded in the business customer’s own knowledgebase content. When a question is submitted, it is transmitted through our servers to the AI provider that the business customer has configured for their account, and a response is returned, sometimes after further processing. The question and the response are stored in the business customer’s own account so that customer can review them; in this capacity the business customer is the controller and OrbisApp acts only as a processor on that customer’s instructions, consistent with our controller and processor roles described above. OrbisApp does not use these questions or responses for its own purposes or to train AI models; the AI provider’s own handling of the data is governed by the terms of the provider the business customer selects. This feature is not used to make decisions that produce legal or similarly significant effects about anyone.

14. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify affected users by email or a prominent notice on our website, and, where required, give advance notice before the changes take effect.

15. Contact

For privacy questions or to exercise your rights, contact us at info@orbisapp.net, or through the Contact form.

rbisApp

Billing & automation for the modern era.

Product

Features How It Works FAQ

Company

Get Demo Access Contact Us

Legal

Terms of Service Privacy Policy Refund Policy

© 2026 OrbisApp. All rights reserved.

Contact Us

Have a question? Send us a message and we'll get back to you.