Privacy Policy
- Data controller
- What data we collect
- What we use your data for
- Legal basis for each processing activity
- How long we keep it
- Who we share it with
- International transfers
- Connecting social networks (third-party data)
- Automated decisions and artificial intelligence
- Your rights
- Security measures
- Minors
- Changes to this policy
1. Data controller
The controller of your personal data is:
- Owner: Mónica Lorenzo González (sole trader)
- Tax ID (NIF): 38131132F
- D-U-N-S Number: 374082016
- Registered address: C/ Garcilaso 26, 3º 1ª, 08027 Barcelona, Spain
- Contact email: orbita@orbitasolutions.org
- Website: www.orbitasolutions.org
2. What data we collect
2.1 User account
When you create an ōrbita account and use the service we may collect:
- Identification data: full name, email, postal address, phone number.
- Company data: trading name, tax details, contact details, industry, website.
- Information provided to draft your marketing plan: company description, products, services, value proposition, target audience and any other information you choose to share.
- Payment data: processed directly by Stripe (ōrbita does not store full card numbers).
- Product usage data: when you sign in, which features you use, errors and performance metrics.
- Content you upload or generate: text, images (including access to your device's photo library if you grant it) and microphone audio when you enable dictation.
2.2 Connected social network data
When a user connects their social network accounts (Meta, TikTok, X, Pinterest, LinkedIn, YouTube, Google Business Profile and others), ōrbita stores the identifiers and tokens needed to publish and to retrieve metrics, as well as public and performance data (followers, interactions, reach). We do not store passwords: authentication is performed via OAuth, in the same way as tools such as Metricool or Loomly.
2.3 Waiting list (pre-launch sign-ups)
Before opening registration we ran a waiting list. If you signed up, we keep your name, email, company name, industry and the date and time of sign-up until you ask to be removed. This channel is no longer active: you can now create your account and start using ōrbita directly.
2.4 Location (marketplace search)
If you use the marketplace provider search and grant your device's location permission, we process your approximate coordinates (latitude and longitude) for a single purpose: sorting agency and freelancer results by proximity. Location is used only at the moment of the search, we do not keep a location history, and we neither share it with third parties nor use it for advertising. The permission is optional: you can deny it and search by city or postcode instead.
2.5 Newsletter
If you subscribe to our newsletter from the website, we process your email (and your preferred language, if you tell us). We use double opt-in: you are only subscribed if you confirm through the link we email you. You can unsubscribe at any time from the link included in every send, and choose which types of communication you want to receive when we offer several. The newsletter is managed by our processor Brevo (see section 6).
2.6 Information stored on your device
ōrbita stores and accesses information directly on your device or browser, and allows certain third parties to do so. Specifically:
- On the website (orbitasolutions.org): first-party and third-party cookies, local storage (localStorage and sessionStorage) and similar identifiers. Details of each cookie, its purpose, its duration and the responsible third party are set out in our Cookie Policy. Cookies that are not strictly necessary are only set if you accept them in the consent banner, and you can change your choice at any time.
- In the application (app.orbitasolutions.org and the iOS and Android apps): local device storage to keep you signed in, save your interface preferences and hold drafts while you work. This data is deleted when you sign out or uninstall the application.
- Third parties that may store or read information on your device from our website: Google (Google Analytics 4 and Google Tag Manager), Meta Platforms, TikTok and LinkedIn, for measurement and, where you consent, advertising purposes. See our Cookie Policy.
Inside the application we do not display advertising and we do not allow third parties to serve advertising content, and data obtained from the APIs of connected social networks is never used for advertising purposes (see section 8.7).
3. What we use your data for
- Waiting list (pre-launch sign-ups): sending product news to those who signed up before launch, until they ask to be removed.
- User account: providing the contracted service, managing your account, offering support and issuing invoices.
- Marketing plan and content: drafting your plan, generating content and publishing to your networks when you authorise it.
- Product improvement: aggregate usage analysis, error detection, performance metrics.
- Commercial communications: sending you information about new features, offers or relevant content (you can object at any time).
- Newsletter: sending the newsletters you subscribed to, with basic delivery, open and click metrics to improve the content (until you unsubscribe).
- Legal compliance: accounting, tax and consumer protection obligations.
4. Legal basis for each processing activity
- Waiting list (pre-launch sign-ups), newsletter and commercial communications: your consent (art. 6.1.a GDPR).
- User account and service provision: performance of a contract (art. 6.1.b GDPR).
- Invoicing and accounting obligations: compliance with a legal obligation (art. 6.1.c GDPR).
- Product improvement, fraud prevention and security: legitimate interest (art. 6.1.f GDPR).
- Analytics and marketing cookies: your consent (art. 22 LSSI-CE).
5. How long we keep it
- Waiting list (pre-launch sign-ups): until you ask to be removed.
- Newsletter: until you unsubscribe or withdraw your consent.
- User account: for as long as your account is active. After closure, identification and billing-related data is kept for the legally required periods (up to 6 years for accounting and tax obligations, art. 30 of the Spanish Commercial Code and tax legislation).
- Technical logs: the maximum period legally permitted, with the minimum necessary for security, audit and compliance purposes (Spanish Law 25/2007 where applicable).
- Connected social network data: for as long as the connection remains active, revalidating it periodically against each platform's API. When you disconnect the account, revoke the permission or request its deletion, the associated data is deleted within a maximum of 30 calendar days. Data obtained from the YouTube API Services and from Google APIs is additionally subject to the specific rules in section 8.7.
- Cookies and information stored on your device: as detailed in section 2.6 and in our Cookie Policy.
6. Who we share it with
To provide the service we work with suppliers acting as data processors. They only access the data strictly necessary and under a processing agreement (art. 28 GDPR). These are:
| Supplier | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | EU (eu-west-1) |
| Netlify | Hosting and application delivery | USA (with SCCs and EU-U.S. DPF) |
| Google Cloud | Cloud infrastructure | EU |
| Stripe | Payment processing | USA (with SCCs) |
| Resend, Loops | Transactional email | EU / USA (with SCCs) |
| Brevo (Sendinblue SAS) | Email marketing and newsletter (sending, segmentation and open and click metrics) | EU (France) |
| Google Analytics 4 | Usage analytics | USA (with SCCs) |
| Mixpanel | Usage analytics and session replay for error diagnosis, with masking of sensitive fields | USA (with SCCs) |
| OneSignal | Application push notifications (alerts about activity in your account) | USA (with SCCs) |
| Meta Platforms Ireland Ltd. (Facebook, Instagram, Threads) | Publishing to connected social networks via OAuth (Graph API, Threads API) and, where applicable, advertising pixels | Ireland / USA (with SCCs and EU-U.S. DPF) |
| LinkedIn Ireland Unlimited Company | Publishing to personal profiles and/or company pages via OAuth (Posts API, Community Management API) and, where applicable, conversion tracking | Ireland / USA (with SCCs and EU-U.S. DPF) |
| TikTok Technology Limited (Ireland) and TikTok Information Technologies UK Limited | Content publishing via OAuth (Content Posting API) and, where applicable, advertising pixels | Ireland / United Kingdom / Singapore / USA (with SCCs) |
| Google LLC (YouTube, Google Business Profile) | Publishing to connected Google services via OAuth (YouTube Data API v3, Google Business Profile APIs) | USA / International (with SCCs) |
| X Corp., Pinterest | Publishing to connected social networks and/or advertising pixels once integrated | USA / International (with SCCs) |
| Canva Pty Ltd | Importing the user's designs and creating new designs via OAuth (Connect API), when the user connects their own Canva account | Australia / USA (with SCCs) |
| HubSpot | CRM and support | EU / USA (with SCCs) |
| Intercom, Crisp | Customer service and chat | EU / USA (with SCCs) |
| OpenAI, Anthropic, Google Vertex AI | AI content generation | USA / EU depending on the model (with SCCs) |
Where there is a legal obligation, we may also share data with competent public authorities (the Spanish tax agency, courts, law enforcement).
Session replay. To diagnose errors and improve usability we use Mixpanel's session replay feature, which records your interaction with the interface (clicks, navigation and scrolling) in anonymised form. We apply masking of sensitive fields (such as passwords and data entered into forms), so their content is not recorded. This data is processed on the legal basis of our legitimate interest in ensuring the security and correct operation of the service, and is enabled according to your consent to analytics cookies.
We do not sell or transfer your data to third parties for commercial purposes.
7. International transfers
Some of our suppliers are based, or have servers, outside the European Economic Area, mainly in the United States. In all cases we guarantee an adequate level of protection through:
- The supplier's adherence to the EU-U.S. Data Privacy Framework where available.
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- A preference for European regions wherever the supplier allows it.
- Additional technical measures such as encryption and data minimisation.
8. Connecting social networks (third-party data)
8.1 How the connection is established
When you connect your business social network accounts to ōrbita, authentication is performed using the standard OAuth 2.0 protocol. ōrbita never receives or stores your password: the social network identifies you directly and returns an access token to us. That token is stored encrypted in our database and is used only for the actions you authorise (publishing content, reading metrics, refreshing permissions). You can revoke the connection at any time from ōrbita or from the social network itself, which invalidates the token immediately.
8.2 ōrbita's dual legal role
With respect to your own account data (public name, profile picture, identifiers the network returns when authenticating you), ōrbita acts as data controller, on the legal basis of performance of the contract (art. 6.1.b GDPR).
With respect to the personal data of your followers, contacts or people who interact with your posts (public names, comments, aggregate metrics), you are the data controller and ōrbita acts as data processor on your behalf. When you activate the connection and accept our Terms and Conditions, a Data Processing Agreement (DPA) governing this relationship under art. 28 GDPR is automatically entered into.
8.3 Data we receive from each platform
The exact data ōrbita receives depends on the scopes (permissions) you authorise when connecting and on each network's features. The main ones for each supported platform are summarised below.
-
Meta (Facebook Pages, Instagram Business/Creator, Threads): identifier and public name of your page or account, profile picture, access token with limited permissions (typically
pages_show_list,pages_manage_posts,instagram_basic,instagram_content_publish,threads_basic,threads_content_publishand equivalents), aggregate post metrics and public comment data where applicable. Meta identifies us as a verified application and sends us automatic notifications if you remove the app, in accordance with its Data Deletion Callback procedure. -
LinkedIn (personal profile and company pages): identifier and public name, public profile picture, access token with limited permissions (typically
openid,profile,email,w_member_socialto post as a person, andw_organization_social/r_organization_socialto manage company pages where applicable). We do not access your contact network or private messages. -
TikTok: identifier, public name and avatar, access token with limited permissions (typically
user.info.basic,video.publishand/orvideo.upload). We do not access your private messages or the list of accounts you follow. -
Google (YouTube, Google Business Profile): channel or listing identifier, public name, handle, profile image and access token with the minimum permissions required (
youtube.uploadandyoutube.readonlyfor YouTube;business.managefor Google Business Profile). We do not access private messages, reviews or statistics. Full details, including update and deletion periods, are in section 8.7. - X (Twitter), Pinterest: identifier, public name and access token with the minimum permissions required for the features enabled, once these networks are integrated into ōrbita.
8.4 What we use that data for
- Publishing content on your behalf, when you schedule or authorise it.
- Displaying your aggregate metrics inside ōrbita (reach, interactions, audience).
- Automatically renewing access tokens so you do not have to reconnect continuously.
- Detecting technical errors in the integration and logging them internally with minimal retention.
We do not use this data for third-party advertising, we do not sell it and we do not share it with other ōrbita users.
8.5 How long we keep social network data
While the connection is active, we keep the data described above. When you disconnect a network (from ōrbita or from the platform itself) or delete your account, we delete the associated tokens, identifiers and metrics within a maximum of 30 days, as described in our Data deletion instructions.
8.6 Data deletion initiated from the social network (Meta)
If you remove ōrbita from Facebook, Instagram or Threads (Settings → Apps and websites → ōrbita → Remove), Meta automatically sends us a Data Deletion Callback. We process that notification and delete the data associated with that connection, returning a confirmation code you can check from Meta's own platform. This integration meets Meta's requirements for third-party apps and forms part of our data deletion protocol.
8.7 YouTube API Services and Google data
What data we obtain. Through the YouTube API Services, ōrbita accesses only the data needed for the features you enable. Specifically, using the youtube.upload and youtube.readonly scopes, we store:
- Your channel identifier and its public name, the handle and the profile image URL, so we can show you which channel is connected and prevent you from publishing to the wrong channel.
- The authorisation token that lets us upload videos on your behalf, stored encrypted, together with the list of permissions you granted.
- The identifier and URL of the videos you publish from ōrbita, so we can show you the status of your posts and link you to them.
ōrbita does not store YouTube statistics (views, subscribers, interactions) and does not read messages or private data from other channels or third parties.
What we use it for. Exclusively to publish the content you schedule and to show you the status of your posts within ōrbita. ōrbita's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use this data for advertising, we do not sell it, we do not transfer it to third parties and we do not use it to train artificial intelligence models.
How long we keep it and how often we refresh it. Your YouTube channel data and your Google Business Profile listing data are revalidated against the Google APIs at least every 30 calendar days while the connection is active, so that what you see in ōrbita always matches the current data on the source platform. If the connection stops being active (because you disconnect it, because you revoke the permission or because it expires), that data is deleted within a maximum of 30 calendar days. Authorisation tokens are kept while the connection remains active and are deleted immediately upon disconnection.
How to revoke access and how to delete the data. You can revoke ōrbita's access to your YouTube, Google Business Profile and general Google data at any time:
- From ōrbita itself, under Account → Connections → Disconnect. When you disconnect, we revoke the token with Google and delete the data associated with that connection.
- From your Google account security settings page: https://myaccount.google.com/connections?filters=3,4 (also reachable as myaccount.google.com/permissions).
- By requesting deletion in writing at orbita@orbitasolutions.org. We handle these requests within a maximum of 7 calendar days, and usually within 24 to 48 hours.
The full procedure is set out in our Data deletion instructions.
Google Business Profile. When you connect your Google Business Profile listing, ōrbita accesses your account and listing identifiers and an authorisation token to publish, on your behalf and with your consent, the posts you schedule. We do not access reviews or any other data in your Google account beyond what is necessary for that feature. The same retention, refresh and deletion rules described above apply, and this processing is likewise governed by the Google Privacy Policy and by the Google API Services User Data Policy.
8.8 Canva (importing and creating designs)
If you connect your own Canva account, ōrbita integrates with the Canva Connect API via OAuth so you can bring your designs into your posts and create new designs without leaving ōrbita. By connecting you agree to be bound by the Canva Terms of Use, and Canva's processing of the data it provides to us is additionally governed by the Canva Privacy Policy.
ōrbita accesses only the data needed for those features, with minimum permissions (typically profile:read, design:meta:read, design:content:read and design:content:write): your public name, to show you which account is connected; your designs' metadata (title, thumbnail, page count, date), so we can list and search them; the content of the designs you choose, which we export to attach as images to your post; and the creation of a blank design sized for the chosen network when you use "Create with Canva". We store access tokens encrypted; imported designs become files belonging to your own post. ōrbita does not modify your existing designs, does not access designs you do not select, and exported files are processed in our backend without being exposed to the browser.
You can revoke ōrbita's access at any time from the Connections section of the application. On disconnection we revoke the token with Canva and delete it; tokens and identifiers are erased in accordance with section 8.5 and our Data deletion instructions.
9. Automated decisions and artificial intelligence
ōrbita uses artificial intelligence models (providers: OpenAI, Anthropic, Google Vertex AI, among others) to generate content, suggestions and marketing plans. This generation always takes place at the user's request or with the user's authorisation: you decide what is drafted, what is published and when.
Individual automated decisions that could produce significant legal effects are subject to human oversight (review and approval by the user before publishing). If we ever implemented processing falling within the scope of art. 22 GDPR, we would inform you beforehand and request your explicit consent.
Important: the data you send to these models may be processed by providers outside the EEA (mainly the USA). We apply the safeguards described in section 7 and, wherever possible, configure the services so that your data is not used to train models ("no training" modes or equivalent).
Processing of your company's URL. When you enter your company's web address during onboarding, you authorise ōrbita to access the public content of that URL and process it (including sending it to AI providers under the conditions described above) for the sole purpose of pre-loading your marketing plan, product catalogue, customer FAQs and brand elements into your account. This content is not used for other customers, is not published, and is not kept beyond what is necessary to build those elements. Our access to your website identifies itself with the User-Agent Orbita-Bot/1.0 so you can recognise it in your logs.
9.1 Compliance with Regulation (EU) 2024/1689 (AI Act)
ōrbita acts as a deployer of general-purpose AI systems under Regulation (EU) 2024/1689 (AI Act). We are not a provider of foundation models; we integrate models from recognised providers.
- Risk classification: the uses we make of AI in ōrbita (generating marketing plans and content under human supervision) are classified as limited risk. We do not use AI for high-risk systems (Annex III) or for prohibited practices (art. 5 AI Act): subliminal manipulation, social scoring, emotion recognition in the workplace, and so on.
- Transparency (art. 50 AI Act): within the product interface, all AI-generated or AI-assisted content is clearly identified as such before the user reviews it.
- Marking of generated content: where the model provider supports it, outputs are delivered with technical markers (metadata or watermarks) that allow their artificial origin to be identified, in accordance with art. 50.2 AI Act.
- Human oversight: the user reviews and approves all content before it is published. ōrbita does not publish in a fully automated way without human intervention.
- No deepfakes or biometrics: ōrbita does not generate synthetic audio, video or images realistically depicting real people (deepfakes, art. 50.4 AI Act). The images used are those the user provides or selects from lawful catalogues.
- No training on your data: we contract these services in modes that prevent the user's inputs and outputs from being used to train models, where the provider allows it.
The user is informed at all times which parts of the product use AI and retains the right not to use them. The user's own obligations regarding transparency towards their audience (when publishing AI-assisted content) are set out in the Terms and Conditions.
10. Your rights
As a data subject you may exercise the following rights at any time:
- Access: to know what data of yours we process.
- Rectification: to correct inaccurate or incomplete data.
- Erasure ("right to be forgotten"): to delete your data when it is no longer necessary.
- Objection: to object to certain processing based on legitimate interest or marketing.
- Restriction: to restrict processing while a claim is verified.
- Portability: to receive your data in a structured, machine-readable format.
- Withdrawal of consent: at any time, without affecting the lawfulness of prior processing.
- Not to be subject to automated individual decisions with significant legal effects.
To exercise any of these rights, write to us at orbita@orbitasolutions.org stating the right you wish to exercise. We will only request proof of identity if there are reasonable doubts about who is making the request, in accordance with art. 12.6 GDPR.
If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD): C/ Jorge Juan, 6, 28001 Madrid · www.aepd.es.
11. Security measures
We apply technical and organisational measures appropriate to the risk: encryption in transit (HTTPS/TLS) and at rest, role-based access control, backups, activity logging, two-factor authentication for staff with access to data, and periodic security reviews. All our suppliers meet equivalent standards (ISO 27001, SOC 2 or similar).
12. Minors
ōrbita is not directed at children under 16. We do not knowingly collect data from children under that age. If we detect that data from a minor has been collected without parental consent, we delete it as soon as possible. If you believe a minor has provided us with data, write to us at orbita@orbitasolutions.org.
13. Changes to this policy
We may update this policy to reflect legal, technical or product changes. Where changes are substantial, we will notify you by email or through a prominent notice on the website at least 15 days in advance. The date of the last update appears at the top of this document.