Legal document

Privacy Policy

This is the English translation of ōrbita's Privacy Policy. The Spanish version is the legally binding one; in case of discrepancy, the Spanish text prevails.
At ōrbita we care about your privacy and about the privacy of the people whose data you entrust to us. This document explains clearly what data we process, for what purpose, for how long, who we share it with and how you can exercise your rights. It is drafted in accordance with Regulation (EU) 2016/679 (GDPR), Spanish Organic Law 3/2018 (LOPDGDD) and Spanish Law 34/2002 (LSSI-CE).

1. Data controller

The controller of your personal data is:

Note: ōrbita is currently an early-stage startup operated under a sole trader regime. When the corresponding company is incorporated, this document will be updated with the new registration details and users will be notified through the website and by email.

2. What data we collect

2.1 User account

When you create an ōrbita account and use the service we may collect:

2.2 Connected social network data

When a user connects their social network accounts (Meta, TikTok, X, Pinterest, LinkedIn, YouTube, Google Business Profile and others), ōrbita stores the identifiers and tokens needed to publish and to retrieve metrics, as well as public and performance data (followers, interactions, reach). We do not store passwords: authentication is performed via OAuth, in the same way as tools such as Metricool or Loomly.

2.3 Waiting list (pre-launch sign-ups)

Before opening registration we ran a waiting list. If you signed up, we keep your name, email, company name, industry and the date and time of sign-up until you ask to be removed. This channel is no longer active: you can now create your account and start using ōrbita directly.

2.4 Location (marketplace search)

If you use the marketplace provider search and grant your device's location permission, we process your approximate coordinates (latitude and longitude) for a single purpose: sorting agency and freelancer results by proximity. Location is used only at the moment of the search, we do not keep a location history, and we neither share it with third parties nor use it for advertising. The permission is optional: you can deny it and search by city or postcode instead.

2.5 Newsletter

If you subscribe to our newsletter from the website, we process your email (and your preferred language, if you tell us). We use double opt-in: you are only subscribed if you confirm through the link we email you. You can unsubscribe at any time from the link included in every send, and choose which types of communication you want to receive when we offer several. The newsletter is managed by our processor Brevo (see section 6).

2.6 Information stored on your device

ōrbita stores and accesses information directly on your device or browser, and allows certain third parties to do so. Specifically:

Inside the application we do not display advertising and we do not allow third parties to serve advertising content, and data obtained from the APIs of connected social networks is never used for advertising purposes (see section 8.7).

3. What we use your data for

5. How long we keep it

6. Who we share it with

To provide the service we work with suppliers acting as data processors. They only access the data strictly necessary and under a processing agreement (art. 28 GDPR). These are:

Where there is a legal obligation, we may also share data with competent public authorities (the Spanish tax agency, courts, law enforcement).

Session replay. To diagnose errors and improve usability we use Mixpanel's session replay feature, which records your interaction with the interface (clicks, navigation and scrolling) in anonymised form. We apply masking of sensitive fields (such as passwords and data entered into forms), so their content is not recorded. This data is processed on the legal basis of our legitimate interest in ensuring the security and correct operation of the service, and is enabled according to your consent to analytics cookies.

We do not sell or transfer your data to third parties for commercial purposes.

7. International transfers

Some of our suppliers are based, or have servers, outside the European Economic Area, mainly in the United States. In all cases we guarantee an adequate level of protection through:

8. Connecting social networks (third-party data)

8.1 How the connection is established

When you connect your business social network accounts to ōrbita, authentication is performed using the standard OAuth 2.0 protocol. ōrbita never receives or stores your password: the social network identifies you directly and returns an access token to us. That token is stored encrypted in our database and is used only for the actions you authorise (publishing content, reading metrics, refreshing permissions). You can revoke the connection at any time from ōrbita or from the social network itself, which invalidates the token immediately.

8.2 ōrbita's dual legal role

With respect to your own account data (public name, profile picture, identifiers the network returns when authenticating you), ōrbita acts as data controller, on the legal basis of performance of the contract (art. 6.1.b GDPR).

With respect to the personal data of your followers, contacts or people who interact with your posts (public names, comments, aggregate metrics), you are the data controller and ōrbita acts as data processor on your behalf. When you activate the connection and accept our Terms and Conditions, a Data Processing Agreement (DPA) governing this relationship under art. 28 GDPR is automatically entered into.

8.3 Data we receive from each platform

The exact data ōrbita receives depends on the scopes (permissions) you authorise when connecting and on each network's features. The main ones for each supported platform are summarised below.

8.4 What we use that data for

We do not use this data for third-party advertising, we do not sell it and we do not share it with other ōrbita users.

8.5 How long we keep social network data

While the connection is active, we keep the data described above. When you disconnect a network (from ōrbita or from the platform itself) or delete your account, we delete the associated tokens, identifiers and metrics within a maximum of 30 days, as described in our Data deletion instructions.

8.6 Data deletion initiated from the social network (Meta)

If you remove ōrbita from Facebook, Instagram or Threads (Settings → Apps and websites → ōrbita → Remove), Meta automatically sends us a Data Deletion Callback. We process that notification and delete the data associated with that connection, returning a confirmation code you can check from Meta's own platform. This integration meets Meta's requirements for third-party apps and forms part of our data deletion protocol.

8.7 YouTube API Services and Google data

ōrbita uses the YouTube API Services. By using ōrbita and connecting your channel you agree to be bound by the YouTube Terms of Service (https://www.youtube.com/t/terms). Google's processing of the data we access is additionally governed by the Google Privacy Policy (https://policies.google.com/privacy).

What data we obtain. Through the YouTube API Services, ōrbita accesses only the data needed for the features you enable. Specifically, using the youtube.upload and youtube.readonly scopes, we store:

ōrbita does not store YouTube statistics (views, subscribers, interactions) and does not read messages or private data from other channels or third parties.

What we use it for. Exclusively to publish the content you schedule and to show you the status of your posts within ōrbita. ōrbita's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use this data for advertising, we do not sell it, we do not transfer it to third parties and we do not use it to train artificial intelligence models.

How long we keep it and how often we refresh it. Your YouTube channel data and your Google Business Profile listing data are revalidated against the Google APIs at least every 30 calendar days while the connection is active, so that what you see in ōrbita always matches the current data on the source platform. If the connection stops being active (because you disconnect it, because you revoke the permission or because it expires), that data is deleted within a maximum of 30 calendar days. Authorisation tokens are kept while the connection remains active and are deleted immediately upon disconnection.

How to revoke access and how to delete the data. You can revoke ōrbita's access to your YouTube, Google Business Profile and general Google data at any time:

The full procedure is set out in our Data deletion instructions.

Google Business Profile. When you connect your Google Business Profile listing, ōrbita accesses your account and listing identifiers and an authorisation token to publish, on your behalf and with your consent, the posts you schedule. We do not access reviews or any other data in your Google account beyond what is necessary for that feature. The same retention, refresh and deletion rules described above apply, and this processing is likewise governed by the Google Privacy Policy and by the Google API Services User Data Policy.

Contact for matters relating to the YouTube API Services. If you have questions or complaints, or wish to exercise your rights over the data ōrbita obtains from the YouTube API Services or from Google APIs, write to orbita@orbitasolutions.org or by post to Mónica Lorenzo González, C/ Garcilaso 26, 3º 1ª, 08027 Barcelona, Spain. We will reply within a maximum of one month (art. 12.3 GDPR).

8.8 Canva (importing and creating designs)

If you connect your own Canva account, ōrbita integrates with the Canva Connect API via OAuth so you can bring your designs into your posts and create new designs without leaving ōrbita. By connecting you agree to be bound by the Canva Terms of Use, and Canva's processing of the data it provides to us is additionally governed by the Canva Privacy Policy.

ōrbita accesses only the data needed for those features, with minimum permissions (typically profile:read, design:meta:read, design:content:read and design:content:write): your public name, to show you which account is connected; your designs' metadata (title, thumbnail, page count, date), so we can list and search them; the content of the designs you choose, which we export to attach as images to your post; and the creation of a blank design sized for the chosen network when you use "Create with Canva". We store access tokens encrypted; imported designs become files belonging to your own post. ōrbita does not modify your existing designs, does not access designs you do not select, and exported files are processed in our backend without being exposed to the browser.

You can revoke ōrbita's access at any time from the Connections section of the application. On disconnection we revoke the token with Canva and delete it; tokens and identifiers are erased in accordance with section 8.5 and our Data deletion instructions.

9. Automated decisions and artificial intelligence

ōrbita uses artificial intelligence models (providers: OpenAI, Anthropic, Google Vertex AI, among others) to generate content, suggestions and marketing plans. This generation always takes place at the user's request or with the user's authorisation: you decide what is drafted, what is published and when.

Individual automated decisions that could produce significant legal effects are subject to human oversight (review and approval by the user before publishing). If we ever implemented processing falling within the scope of art. 22 GDPR, we would inform you beforehand and request your explicit consent.

Important: the data you send to these models may be processed by providers outside the EEA (mainly the USA). We apply the safeguards described in section 7 and, wherever possible, configure the services so that your data is not used to train models ("no training" modes or equivalent).

Processing of your company's URL. When you enter your company's web address during onboarding, you authorise ōrbita to access the public content of that URL and process it (including sending it to AI providers under the conditions described above) for the sole purpose of pre-loading your marketing plan, product catalogue, customer FAQs and brand elements into your account. This content is not used for other customers, is not published, and is not kept beyond what is necessary to build those elements. Our access to your website identifies itself with the User-Agent Orbita-Bot/1.0 so you can recognise it in your logs.

9.1 Compliance with Regulation (EU) 2024/1689 (AI Act)

ōrbita acts as a deployer of general-purpose AI systems under Regulation (EU) 2024/1689 (AI Act). We are not a provider of foundation models; we integrate models from recognised providers.

The user is informed at all times which parts of the product use AI and retains the right not to use them. The user's own obligations regarding transparency towards their audience (when publishing AI-assisted content) are set out in the Terms and Conditions.

10. Your rights

As a data subject you may exercise the following rights at any time:

To exercise any of these rights, write to us at orbita@orbitasolutions.org stating the right you wish to exercise. We will only request proof of identity if there are reasonable doubts about who is making the request, in accordance with art. 12.6 GDPR.

If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD): C/ Jorge Juan, 6, 28001 Madrid · www.aepd.es.

11. Security measures

We apply technical and organisational measures appropriate to the risk: encryption in transit (HTTPS/TLS) and at rest, role-based access control, backups, activity logging, two-factor authentication for staff with access to data, and periodic security reviews. All our suppliers meet equivalent standards (ISO 27001, SOC 2 or similar).

12. Minors

ōrbita is not directed at children under 16. We do not knowingly collect data from children under that age. If we detect that data from a minor has been collected without parental consent, we delete it as soon as possible. If you believe a minor has provided us with data, write to us at orbita@orbitasolutions.org.

13. Changes to this policy

We may update this policy to reflect legal, technical or product changes. Where changes are substantial, we will notify you by email or through a prominent notice on the website at least 15 days in advance. The date of the last update appears at the top of this document.

Any questions? Write to us at orbita@orbitasolutions.org and we will reply within 5 business days.