Privacy Policy
Last updated: September 18, 2026
1. Introduction & scope
This Privacy Policy explains how Muhammad Umair, an individual trading as “OrbisApp” (“OrbisApp,” “we,” “us”), handles personal data in connection with the orbisapp.net website, our demo-access and contact features, and our billing and automation platform (the “Service”). It applies to visitors to our website, people who request demo access or contact us, and holders of admin-panel and client-portal accounts. It does not govern how our business customers handle their own end-customers’ data (see the next section).
2. Our roles: controller vs. processor
OrbisApp acts in two distinct roles:
- As a controller for personal data we decide how to use — for example, data from website visitors, demo requests, contact-form messages, and our own account holders.
- As a processor for the end-customer data that our business customers (hosting providers and SaaS sellers) enter into the platform. In that role we process such data only on the business customer’s instructions under a data processing agreement available on request, and that business customer is the controller.
3. Personal data we collect
- Demo-access requests: the email address you submit to receive demo credentials.
- Contact messages: your name, email address, and the content of your message.
- Account data: credentials and profile details for admin-panel and client-portal accounts.
- Technical & usage data: IP address and request metadata used for security, rate limiting, and spam prevention, and basic pageview information — page path, referrer, and device/browser information (your user-agent), together with a randomly generated per-visit identifier — collected to understand site usage. We do not set tracking cookies or track you across sites.
- Billing data: payments and account top-ups are handled by our merchant of record, Paddle.com Market Limited (“Paddle”), which collects your billing details directly to process the transaction; we do not collect or store your full payment-card details. We do maintain your account balance and a record of funds you add and amounts applied to subscriptions, renewals, and other charges, so we can operate your account and process renewals from your available funds.
4. How we use personal data
We use personal data to: provide demo access and respond to inquiries; operate, secure, and improve the Service; prevent abuse through rate limiting and captcha; send transactional communications; and, where permitted, send marketing you can opt out of. Where the GDPR or UK GDPR applies, our legal bases include performance of a contract, our legitimate interests (such as security and service improvement), consent where required, and compliance with legal obligations.
7. International data transfers
Our servers are located in Canada. Where personal data of individuals in the EEA or UK is transferred outside those regions, we rely on an appropriate transfer mechanism such as an adequacy decision or Standard Contractual Clauses.
8. Data retention
We keep personal data only as long as necessary for the purposes described above or as required by law. Indicative periods: demo requests 1 month; contact messages 1 month; security and rate-limit logs 90 days; analytics and pageview data 90 days. When data is no longer needed, we delete or anonymize it.
9. Security
We use technical and organizational measures appropriate to the risk, such as encryption in transit (HTTPS), HMAC-signed captcha tokens, access controls on the admin panel, and protecting stored credentials. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Your privacy rights (GDPR/UK GDPR)
Subject to applicable law, you may have the right to access, rectify, erase, restrict, or object to our processing of your personal data, to data portability, and to withdraw consent where processing is based on consent. You also have the right to lodge a complaint with a supervisory authority. To exercise these rights, contact us using the details below.
11. US state privacy rights
Depending on your state of residence (for example, California under the CCPA/CPRA), you may have rights to know, delete, and correct personal data, and to opt out of certain sharing. We do not sell or share personal data as those terms are defined by such laws.
12. Children’s privacy
The Service is not directed to children, and we do not knowingly collect personal data from anyone under the age of 16. If you believe a child has provided us personal data, contact us and we will delete it.
13. Automated & AI processing
Our client-portal “Ask AI” feature lets an end-user submit a natural-language question and returns an answer grounded in the business customer’s own knowledgebase content. When a question is submitted, it is transmitted through our servers to the AI provider that the business customer has configured for their account, and a response is returned, sometimes after further processing. The question and the response are stored in the business customer’s own account so that customer can review them; in this capacity the business customer is the controller and OrbisApp acts only as a processor on that customer’s instructions, consistent with our controller and processor roles described above. OrbisApp does not use these questions or responses for its own purposes or to train AI models; the AI provider’s own handling of the data is governed by the terms of the provider the business customer selects. This feature is not used to make decisions that produce legal or similarly significant effects about anyone.
14. Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify affected users by email or a prominent notice on our website, and, where required, give advance notice before the changes take effect.
15. Contact
For privacy questions or to exercise your rights, contact us at info@orbisapp.net, or through the Contact form.