Privacy Policy
- Data controller
- What data we collect
- What we use your data for
- Legal basis for each processing activity
- How long we keep it
- Who we share it with
- International transfers
- Connecting social networks (third-party data)
- Automated decisions and artificial intelligence
- Your rights
- Security measures
- Minors
- Changes to this policy
1. Data controller
The controller of your personal data is:
- Owner: Mónica Lorenzo González (sole trader)
- Tax ID (NIF): 38131132F
- D-U-N-S Number: 374082016
- Registered address: C/ Garcilaso 26, 3º 1ª, 08027 Barcelona, Spain
- Contact email: orbita@orbitasolutions.org
- Website: www.orbitasolutions.org
2. What data we collect
2.1 User account
When you create an ōrbita account and use the service we may collect:
- Identification data: full name, email, postal address, phone number.
- Company data: trading name, tax details, contact details, industry, website.
- Information provided to draft your marketing plan: company description, products, services, value proposition, target audience and any other information you choose to share.
- Payment data: processed directly by Stripe (ōrbita does not store full card numbers).
- Product usage data: when you sign in, which features you use, errors and performance metrics.
- Content you upload or generate: text, images (including access to your device's photo library if you grant it) and microphone audio when you enable dictation.
2.2 Connected social network data
When a user connects their social network accounts (Meta, TikTok, X, Pinterest, LinkedIn, YouTube, Google Business Profile and others), ōrbita stores the identifiers and tokens needed to publish and to retrieve metrics, as well as public and performance data (followers, interactions, reach). We do not store passwords: authentication is performed via OAuth, in the same way as tools such as Metricool or Loomly. On the networks where ōrbita shows you the comments on your posts, the commenter's public data is held only in a temporary cache and for a limited time; the detail for LinkedIn is in section 8.9.
2.3 Waiting list (pre-launch sign-ups)
Before opening registration we ran a waiting list. If you signed up, we keep your name, email, company name, industry and the date and time of sign-up until you ask to be removed. This channel is no longer active: you can now create your account and start using ōrbita directly.
2.4 Location (marketplace search)
If you use the marketplace provider search and grant your device's location permission, we process your approximate coordinates (latitude and longitude) for a single purpose: sorting agency and freelancer results by proximity. Location is used only at the moment of the search, we do not keep a location history, and we neither share it with third parties nor use it for advertising. The permission is optional: you can deny it and search by city or postcode instead.
2.5 Newsletter
If you subscribe to our newsletter from the website, we process your email (and your preferred language, if you tell us). We use double opt-in: you are only subscribed if you confirm through the link we email you. You can unsubscribe at any time from the link included in every send, and choose which types of communication you want to receive when we offer several. The newsletter is managed by our processor Brevo (see section 6).
2.6 Information stored on your device
ōrbita stores and accesses information directly on your device or browser, and allows certain third parties to do so. Specifically:
- On the website (orbitasolutions.org): first-party and third-party cookies, local storage (localStorage and sessionStorage) and similar identifiers. Details of each cookie, its purpose, its duration and the responsible third party are set out in our Cookie Policy. Cookies that are not strictly necessary are only set if you accept them in the consent banner, and you can change your choice at any time.
- In the application (app.orbitasolutions.org and the iOS and Android apps): local device storage to keep you signed in, save your interface preferences and hold drafts while you work. This data is deleted when you sign out or uninstall the application.
- Third parties that may store or read information on your device from our website: Google (Google Analytics 4 and Google Tag Manager), Meta Platforms, TikTok, LinkedIn and OpenAI (OpenAI Ads measurement pixel), for measurement and, where you consent, advertising purposes. See our Cookie Policy.
Inside the application we do not display advertising and we do not allow third parties to serve advertising content, and data obtained from the APIs of connected social networks is never used for advertising purposes (see section 8.7).
2.7 How you found us
When you create an account we store, linked to it, the minimum information that tells us how you reached ōrbita. Specifically:
- The campaign parameters carried by the web address you arrived with (the usual utm_source, utm_medium, utm_campaign, utm_content and utm_term).
- The click identifier the advert itself adds to the address, if you came from one of our advertising campaigns.
- The domain of the site you came from (for example chatgpt.com or google.com). We store the domain only, never the full address of the referring page, and we discard ōrbita's own domains.
- The page of our website you landed on, without the parameters of the address.
- The platform you signed up from (web, iOS, Android or macOS) and the time of that first visit.
This data is collected in your own browser or device, kept for at most 7 days before the sign-up and discarded if you never create the account. No third party takes part in collecting it, it is not used to profile you or to show you advertising inside ōrbita, and it feeds no automated decision.
3. What we use your data for
- Waiting list (pre-launch sign-ups): sending product news to those who signed up before launch, until they ask to be removed.
- User account: providing the contracted service, managing your account, offering support and issuing invoices.
- Marketing plan and content: drafting your plan, generating content and publishing to your networks when you authorise it.
- Product improvement: aggregate usage analysis, error detection, performance metrics.
- Commercial communications: sending you information about new features, offers or relevant content (you can object at any time).
- Newsletter: sending the newsletters you subscribed to, with basic delivery, open and click metrics to improve the content (until you unsubscribe).
- Measuring how you found us: knowing which channel brought you to ōrbita (campaign, advert, search engine, social network or direct visit) so we can focus our outreach and measure the results of our campaigns.
- Legal compliance: accounting, tax and consumer protection obligations.
4. Legal basis for each processing activity
- Waiting list (pre-launch sign-ups), newsletter and commercial communications: your consent (art. 6.1.a GDPR).
- User account and service provision: performance of a contract (art. 6.1.b GDPR).
- Invoicing and accounting obligations: compliance with a legal obligation (art. 6.1.c GDPR).
- Product improvement, fraud prevention and security: legitimate interest (art. 6.1.f GDPR).
- Measuring how you found us: legitimate interest (art. 6.1.f GDPR): understanding how well our own outreach channels work, with minimal data and no profiling.
- Analytics and marketing cookies: your consent (art. 22 LSSI-CE).
5. How long we keep it
- Waiting list (pre-launch sign-ups): until you ask to be removed.
- Newsletter: until you unsubscribe or withdraw your consent.
- User account: for as long as your account is active. After closure, identification and billing-related data is kept for the legally required periods (up to 6 years for accounting and tax obligations, art. 30 of the Spanish Commercial Code and tax legislation).
- Technical logs: the maximum period legally permitted, with the minimum necessary for security, audit and compliance purposes (Spanish Law 25/2007 where applicable).
- Connected social network data: for as long as the connection remains active, revalidating it periodically against each platform's API. When you disconnect the account, revoke the permission or request its deletion, the associated identity data is deleted on the spot and residual copies within a maximum of 7 calendar days. Data obtained from the YouTube API Services and from Google APIs is additionally subject to the specific rules in section 8.7.
- How you found us: for as long as the account exists. It is deleted together with the rest of the account data when you close it, subject to the legal retention periods stated above.
- Cookies and information stored on your device: as detailed in section 2.6 and in our Cookie Policy.
6. Who we share it with
To provide the service we work with suppliers acting as data processors. They only access the data strictly necessary and under a processing agreement (art. 28 GDPR). These are:
| Supplier | Purpose | Location |
|---|---|---|
| Supabase | Database and authentication | EU (eu-west-1) |
| Netlify | Hosting and application delivery | USA (with SCCs and EU-U.S. DPF) |
| Google Cloud | Cloud infrastructure | EU |
| Stripe | Payment processing | USA (with SCCs) |
| Resend, Loops | Transactional email | EU / USA (with SCCs) |
| Brevo (Sendinblue SAS) | Email marketing and newsletter (sending, segmentation and open and click metrics) | EU (France) |
| Google Analytics 4 | Usage analytics | USA (with SCCs) |
| Mixpanel | Usage analytics and session replay for error diagnosis, with masking of sensitive fields | USA (with SCCs) |
| OneSignal | Application push notifications (alerts about activity in your account) | USA (with SCCs) |
| Meta Platforms Ireland Ltd. (Facebook, Instagram, Threads) | Publishing to connected social networks via OAuth (Graph API, Threads API) and, where applicable, advertising pixels | Ireland / USA (with SCCs and EU-U.S. DPF) |
| LinkedIn Ireland Unlimited Company | Publishing to personal profiles and/or company pages via OAuth (Posts API, Community Management API) and, where applicable, conversion tracking | Ireland / USA (with SCCs and EU-U.S. DPF) |
| TikTok Technology Limited (Ireland) and TikTok Information Technologies UK Limited | Content publishing (Content Posting API) and reading the statistics of your account and your public videos (Display API) via OAuth and, where applicable, advertising pixels | Ireland / United Kingdom / Singapore / USA (with SCCs) |
| Google LLC (YouTube, Google Business Profile) | Publishing to connected Google services via OAuth (YouTube Data API v3, Google Business Profile APIs) | USA / International (with SCCs) |
| X Corp., Pinterest | Publishing to connected social networks and/or advertising pixels once integrated | USA / International (with SCCs) |
| Canva Pty Ltd | Importing the user's designs and creating new designs via OAuth (Connect API), when the user connects their own Canva account | Australia / USA (with SCCs) |
| HubSpot | CRM and support | EU / USA (with SCCs) |
| Intercom, Crisp | Customer service and chat | EU / USA (with SCCs) |
| OpenAI, Anthropic, Google Vertex AI | AI content generation | USA / EU depending on the model (with SCCs) |
| OpenAI (OpenAI Ads) | Measurement pixel and Conversions API for ōrbita's ChatGPT ad campaigns, only with your marketing consent | USA (with SCCs) |
Where there is a legal obligation, we may also share data with competent public authorities (the Spanish tax agency, courts, law enforcement).
Session replay. To diagnose errors and improve usability we use Mixpanel's session replay feature, which records your interaction with the interface (clicks, navigation and scrolling) in anonymised form. We apply masking of sensitive fields (such as passwords and data entered into forms), so their content is not recorded. This data is processed on the legal basis of our legitimate interest in ensuring the security and correct operation of the service, and is enabled according to your consent to analytics cookies.
We do not sell or transfer your data to third parties for commercial purposes.
7. International transfers
Some of our suppliers are based, or have servers, outside the European Economic Area, mainly in the United States. In all cases we guarantee an adequate level of protection through:
- The supplier's adherence to the EU-U.S. Data Privacy Framework where available.
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- A preference for European regions wherever the supplier allows it.
- Additional technical measures such as encryption and data minimisation.
8. Connecting social networks (third-party data)
8.1 How the connection is established
When you connect your business social network accounts to ōrbita, authentication is performed using the standard OAuth 2.0 protocol. ōrbita never receives or stores your password: the social network identifies you directly and returns an access token to us. That token is stored encrypted in our database and is used only for the actions you authorise (publishing content, reading metrics, refreshing permissions). You can revoke the connection at any time from ōrbita or from the social network itself, which invalidates the token immediately.
8.2 ōrbita's dual legal role
With respect to your own account data (public name, profile picture, identifiers the network returns when authenticating you), ōrbita acts as data controller, on the legal basis of performance of the contract (art. 6.1.b GDPR).
With respect to the personal data of your followers, contacts or people who interact with your posts (public names, comments, aggregate metrics), you are the data controller and ōrbita acts as data processor on your behalf. When you activate the connection and accept our Terms and Conditions, a Data Processing Agreement (DPA) governing this relationship under art. 28 GDPR is automatically entered into.
8.3 Data we receive from each platform
The exact data ōrbita receives depends on the scopes (permissions) you authorise when connecting and on each network's features. The main ones for each supported platform are summarised below.
-
Meta (Facebook Pages, Instagram Business/Creator, Threads): identifier and public name of your page or account, profile picture, access token with limited permissions (typically
pages_show_list,pages_manage_posts,instagram_basic,instagram_content_publish,threads_basic,threads_content_publishand equivalents), aggregate post metrics and public comment data where applicable. Meta identifies us as a verified application and sends us automatic notifications if you remove the app, in accordance with its Data Deletion Callback procedure. -
LinkedIn (personal profile and company pages): identifier and public name, public profile picture, access token with the ten permissions LinkedIn shows when you connect:
r_basicprofile(identity and picture),w_member_socialandw_member_social_feed(post and comment as a person),rw_organization_admin(read the pages you administer),r_organization_socialandr_organization_social_feed(read the comments on your pages' posts),w_organization_socialandw_organization_social_feed(post and comment on your company pages),r_organization_followers(suggest followers of your page when mentioning people; the lookup is live and we do not store the follower list) andr_member_postAnalytics(read the statistics of the posts on your profile made from ōrbita). Your company page statistics are read withrw_organization_admin. We do not request your contact network size, and we do not access your contact network or private messages. The detail of what we do on your behalf, what we read, what we store and for how long is in section 8.9. -
TikTok: identifier, public name and avatar, access token with limited permissions:
user.info.basic(account identity),video.publish(post to your account) and, when you grant them on connecting,user.info.statsandvideo.list(read the statistics of your account and of your public videos for the Metrics section). We do not access your private messages, your bio or the list of accounts you follow. The detail of what we do on your behalf, what we read, what we store and for how long is in section 8.10. -
Google (YouTube, Google Business Profile): channel or listing identifier, public name, handle, profile image and access token with the minimum permissions required (
youtube.uploadandyoutube.readonlyfor YouTube;business.managefor Google Business Profile). We do not access private messages, reviews or statistics. Full details, including update and deletion periods, are in section 8.7. - X (Twitter), Pinterest: identifier, public name and access token with the minimum permissions required for the features enabled, once these networks are integrated into ōrbita.
8.4 What we use that data for
- Publishing content on your behalf, when you schedule or authorise it.
- Managing the interactions on the posts you have made from ōrbita: reading their comments when you open the interactions inbox, replying to them, adding or removing a reaction, and mentioning companies or page followers in the text. Each of these actions is initiated by a person in your workspace from inside ōrbita; none of them runs automatically.
- Displaying your aggregate metrics inside ōrbita (reach, interactions, audience).
- Automatically renewing access tokens so you do not have to reconnect continuously.
- Detecting technical errors in the integration and logging them internally with minimal retention.
We do not use this data for third-party advertising, we do not sell it and we do not share it with other ōrbita users.
8.5 How long we keep social network data
While the connection is active, we keep the data described above. When you disconnect a network (from ōrbita or from the platform itself) or delete your account, we delete the access tokens and that account's identity data (public name, handle, profile picture and granted permissions) on the spot and, on the platforms that offer an endpoint for it (Google and LinkedIn), we also revoke the grant on the platform itself. All that remains is one technical identifier, the one linking the posts you already published to the account they went out through, plus residual copies in our technical logs: both are deleted within a maximum of 7 days, as described in our Data deletion instructions. The comment cache and the internal management state associated with that connection are deleted within that same maximum period of 7 days.
8.6 Data deletion initiated from the social network (Meta)
If you remove ōrbita from Facebook, Instagram or Threads (Settings → Apps and websites → ōrbita → Remove), Meta automatically sends us a Data Deletion Callback. We process that notification and delete the data associated with that connection, returning a confirmation code you can check from Meta's own platform. This integration meets Meta's requirements for third-party apps and forms part of our data deletion protocol.
8.7 YouTube API Services and Google data
What data we obtain. Through the YouTube API Services, ōrbita accesses only the data needed for the features you enable. Specifically, using the youtube.upload and youtube.readonly scopes, we store:
- Your channel identifier and its public name, the handle and the profile image URL, so we can show you which channel is connected and prevent you from publishing to the wrong channel.
- The authorisation token that lets us upload videos on your behalf, stored encrypted, together with the list of permissions you granted.
- The identifier and URL of the videos you publish from ōrbita, so we can show you the status of your posts and link you to them.
ōrbita does not store YouTube statistics (views, subscribers, interactions) and does not read messages or private data from other channels or third parties.
What we use it for. Exclusively to publish the content you schedule and to show you the status of your posts within ōrbita. ōrbita's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use this data for advertising, we do not sell it, we do not transfer it to third parties and we do not use it to train artificial intelligence models.
How long we keep it and how often we refresh it. The YouTube data listed above (your channel identity and the references to the videos you publish from ōrbita) and your Google Business Profile listing data are revalidated against the Google APIs at least every 30 calendar days while the connection is active, so that what you see in ōrbita always matches the current data on the source platform. If the connection stops being active (because you disconnect it, because you revoke the permission or because it expires), that data is deleted within a maximum of 7 calendar days, well inside the 30 calendar day ceiling the YouTube policies require. Authorisation tokens are kept while the connection remains active and are deleted immediately upon disconnection.
How to revoke access and how to delete the data. You can revoke ōrbita's access to your YouTube, Google Business Profile and general Google data at any time:
- From ōrbita itself, under Account → Connections → Disconnect. When you disconnect, we revoke the token with Google and delete the data associated with that connection.
- From your Google account security settings page: https://myaccount.google.com/connections?filters=3,4.
- By requesting deletion in writing at orbita@orbitasolutions.org. We handle these requests within a maximum of 7 calendar days, and usually within 24 to 48 hours.
The full procedure is set out in our Data deletion instructions.
Google Business Profile. When you connect your Google Business Profile listing, ōrbita accesses your account and listing identifiers and an authorisation token to publish, on your behalf and with your consent, the posts you schedule. We do not access reviews or any other data in your Google account beyond what is necessary for that feature. The same retention, refresh and deletion rules described above apply, and this processing is likewise governed by the Google Privacy Policy and by the Google API Services User Data Policy.
8.8 Canva (importing and creating designs)
If you connect your own Canva account, ōrbita integrates with the Canva Connect API via OAuth so you can bring your designs into your posts and create new designs without leaving ōrbita. By connecting you agree to be bound by the Canva Terms of Use, and Canva's processing of the data it provides to us is additionally governed by the Canva Privacy Policy.
ōrbita accesses only the data needed for those features, with minimum permissions (typically profile:read, design:meta:read, design:content:read and design:content:write): your public name, to show you which account is connected; your designs' metadata (title, thumbnail, page count, date), so we can list and search them; the content of the designs you choose, which we export to attach as images to your post; and the creation of a blank design sized for the chosen network when you use "Create with Canva". We store access tokens encrypted; imported designs become files belonging to your own post. ōrbita does not modify your existing designs, does not access designs you do not select, and exported files are processed in our backend without being exposed to the browser.
You can revoke ōrbita's access at any time from the Connections section of the application. On disconnection we revoke the token with Canva and delete it; tokens and identifiers are erased in accordance with section 8.5 and our Data deletion instructions.
8.9 LinkedIn: publishing, interactions and metrics
This section sets out, for the LinkedIn API integration, what ōrbita does on your behalf, what data it reads, what it stores and for how long. The specific permissions requested when you connect are listed in section 8.3.
What we do on your behalf. Every action ōrbita performs on LinkedIn is initiated by a person in your workspace from inside ōrbita; none of them runs automatically. Specifically: publishing to your personal profile and/or to the company page you choose (scheduled posts are reviewed and approved by you before they go out), publishing a first comment of your own under that post, replying to the comments on your posts, adding or removing a reaction to those comments, and mentioning companies or page followers in the text.
What we read and when. From ōrbita's Interactions inbox we read the comments on the posts made from ōrbita, not those on your whole account. Reading happens on demand, when you open the inbox or press refresh, against the LinkedIn API. There is also a per-post panel showing the name and professional headline of each commenter.
What we store and for how long. For the inbox to work we keep a cache with the comment text, its date, the public name of the commenter and, if you reply, the text of your reply, for a maximum of 24 hours; a daily purge deletes it and, if you open the inbox again, the comments are read afresh from LinkedIn. The per-post panel data (name and professional headline) is likewise cached for a maximum of 24 hours. We neither obtain nor store the commenter's profile picture. In no case do we keep third-party profiles for more than 24 hours, nor the text of their comments for more than 48 hours, in line with LinkedIn's Data Storage Requirements; in practice everything expires after 24 hours.
What is kept with no time limit. Only technical identifiers (the LinkedIn URNs of the post, of the comment and of its author) and the internal management state of each comment within ōrbita (read, archived, assigned to a team member, reply date and the date on which ōrbita first saw the comment; the comment's publication date as given by LinkedIn is not kept for more than 48 hours). This is what allows your team's work not to be lost when the cache is reloaded. The identity of your own authenticated account (name, handle and picture) is kept for as long as the connection is active; the identity of your page (name, handle and logo) is additionally revalidated against LinkedIn at least every 45 days.
What we measure. In ōrbita's Metrics section we read, for your company page, the follower count, page views and the impressions, clicks, reactions, comments and reshares of its posts (Community Management API: Follower, Page and Share Statistics); and, for your personal profile, the impressions, reach, reactions, comments and reshares only of the posts made from ōrbita (Member Post Analytics), because LinkedIn does not let any application list a profile's other posts or read its follower count. These are aggregate figures: they contain no data about the people who view, react or comment. They are read once a day and when you press refresh, and we keep a daily snapshot of those totals while the connection is active so we can show you how they evolve, for a maximum of 12 months (a nightly purge deletes data older than one year, in line with LinkedIn's Data Storage Requirements); on disconnection they are deleted within the period set out in section 8.5.
Follower suggestions when mentioning. When you type a mention, your page's followers are looked up live against LinkedIn and we do not store that list.
Who can see it and what it is used for. LinkedIn data is only shown to people with access to that company's workspace in ōrbita. It is never exported, never combined with other sources and never used for sales, lead generation or advertising: it is used exclusively to manage the profile or page you have connected.
On disconnection or account deletion. What section 8.5 describes applies: we delete the access tokens and that account's identity data on the spot, we revoke the grant with LinkedIn, and residual copies are deleted within a maximum of 7 days. The comment cache and the internal management state of that connection are deleted within that same maximum period of 7 days.
8.10 TikTok: publishing and metrics
What we do on your behalf. Publish to your TikTok account the videos or photos you create and schedule in ōrbita (Content Posting API, video.publish permission). Every post goes out only after your explicit action; privacy level, commercial content disclosure and the comment, duet and stitch settings are chosen by you for each post and are never pre-selected.
What we measure. In the Metrics section of ōrbita, with the user.info.stats and video.list permissions (Display API), we read your account's follower count, total likes and number of videos and, for each of your public videos, its identifier, date, title, thumbnail, link and its views, likes, comments and shares. These are aggregate figures of your own account: they contain no data about the people who watch, react or comment. They are read once a day and when you tap refresh; we keep a daily snapshot of the account totals and the latest figure for each video while the connection is active, so we can show you their evolution.
Who can see it and what it is used for. TikTok data is shown only to the people with access to that company's workspace in ōrbita. It is never exported, never combined with other sources and never used for sales, prospecting or advertising: it serves only so you can see how the account you connected is performing.
On disconnecting or deleting your account. Section 8.5 applies: we immediately delete the access tokens and the identity data of that account, and the stored statistics of that connection are deleted within a maximum of 7 days.
9. Automated decisions and artificial intelligence
ōrbita uses artificial intelligence models (providers: OpenAI, Anthropic, Google Vertex AI, among others) to generate content, suggestions and marketing plans. This generation always takes place at the user's request or with the user's authorisation: you decide what is drafted, what is published and when.
Individual automated decisions that could produce significant legal effects are subject to human oversight (review and approval by the user before publishing). If we ever implemented processing falling within the scope of art. 22 GDPR, we would inform you beforehand and request your explicit consent.
Important: the data you send to these models may be processed by providers outside the EEA (mainly the USA). We apply the safeguards described in section 7 and, wherever possible, configure the services so that your data is not used to train models ("no training" modes or equivalent).
Processing of your company's URL. When you enter your company's web address during onboarding, you authorise ōrbita to access the public content of that URL and process it (including sending it to AI providers under the conditions described above) for the sole purpose of pre-loading your marketing plan, product catalogue, customer FAQs and brand elements into your account. This content is not used for other customers, is not published, and is not kept beyond what is necessary to build those elements. Our access to your website identifies itself with the User-Agent Orbita-Bot/1.0 so you can recognise it in your logs.
9.1 Compliance with Regulation (EU) 2024/1689 (AI Act)
ōrbita acts as a deployer of general-purpose AI systems under Regulation (EU) 2024/1689 (AI Act). We are not a provider of foundation models; we integrate models from recognised providers.
- Risk classification: the uses we make of AI in ōrbita (generating marketing plans and content under human supervision) are classified as limited risk. We do not use AI for high-risk systems (Annex III) or for prohibited practices (art. 5 AI Act): subliminal manipulation, social scoring, emotion recognition in the workplace, and so on.
- Transparency (art. 50 AI Act): within the product interface, all AI-generated or AI-assisted content is clearly identified as such before the user reviews it.
- Marking of generated content: where the model provider supports it, outputs are delivered with technical markers (metadata or watermarks) that allow their artificial origin to be identified, in accordance with art. 50.2 AI Act.
- Human oversight: the user reviews and approves all content before it is published. ōrbita does not publish in a fully automated way without human intervention.
- No deepfakes or biometrics: ōrbita does not generate synthetic audio, video or images realistically depicting real people (deepfakes, art. 50.4 AI Act). The images used are those the user provides or selects from lawful catalogues.
- No training on your data: we contract these services in modes that prevent the user's inputs and outputs from being used to train models, where the provider allows it.
The user is informed at all times which parts of the product use AI and retains the right not to use them. The user's own obligations regarding transparency towards their audience (when publishing AI-assisted content) are set out in the Terms and Conditions.
10. Your rights
As a data subject you may exercise the following rights at any time:
- Access: to know what data of yours we process.
- Rectification: to correct inaccurate or incomplete data.
- Erasure ("right to be forgotten"): to delete your data when it is no longer necessary.
- Objection: to object to certain processing based on legitimate interest or marketing.
- Restriction: to restrict processing while a claim is verified.
- Portability: to receive your data in a structured, machine-readable format.
- Withdrawal of consent: at any time, without affecting the lawfulness of prior processing.
- Not to be subject to automated individual decisions with significant legal effects.
To exercise any of these rights, write to us at orbita@orbitasolutions.org stating the right you wish to exercise. We will only request proof of identity if there are reasonable doubts about who is making the request, in accordance with art. 12.6 GDPR.
If you believe we have not handled your request properly, you may lodge a complaint with the Spanish Data Protection Agency (AEPD): C/ Jorge Juan, 6, 28001 Madrid · www.aepd.es.
11. Security measures
We apply technical and organisational measures appropriate to the risk: encryption in transit (HTTPS/TLS) and at rest, role-based access control, backups, activity logging, two-factor authentication for staff with access to data, and periodic security reviews. All our suppliers meet equivalent standards (ISO 27001, SOC 2 or similar).
12. Minors
ōrbita is not directed at children under 16. We do not knowingly collect data from children under that age. If we detect that data from a minor has been collected without parental consent, we delete it as soon as possible. If you believe a minor has provided us with data, write to us at orbita@orbitasolutions.org.
13. Changes to this policy
We may update this policy to reflect legal, technical or product changes. Where changes are substantial, we will notify you by email or through a prominent notice on the website at least 15 days in advance. The date of the last update appears at the top of this document.