Orbiio

Privacy Policy

Last updated: 2 October 2026

Orbiio respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, store and protect information when you use the Orbiio application, website and associated services.

For the purposes of applicable data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller is:

Trading as Orbiio

1. Information we collect

Depending on how Orbiio is used, we may process the following categories of information:

Account information

  • Name
  • Email address
  • Organisation name
  • User account details
  • Authentication and account configuration information

Support and communications data

  • Emails connected to Orbiio
  • Email subject lines
  • Sender and recipient information
  • Message content
  • Attachments
  • Support enquiries
  • Incident reports
  • Ticket history
  • Notes and correspondence associated with support cases

Integration data

Where you connect third-party services such as Google Gmail, we may receive information necessary to provide the integration, including authorised account identifiers and access permissions.

Technical information

  • IP address
  • Browser and device information
  • Application logs
  • Error logs
  • Date and time of access
  • Usage information
  • Security and authentication events

We only collect information that is reasonably necessary to provide and improve the Orbiio service.

2. Google and Gmail data

Orbiio may connect to Google services, including Gmail, where authorised by the user or organisation.

Where Gmail access is enabled, Orbiio may access email information for the purpose of:

  • identifying support or problem-report emails;
  • creating and updating support tickets;
  • categorising or prioritising incidents;
  • associating communications with existing support cases;
  • sending, modifying or managing messages where authorised;
  • providing automated support workflows; and
  • generating summaries or structured support information.

Orbiio only accesses Google account information that has been expressly authorised through Google's OAuth consent process.

Orbiio's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We do not sell Google user data or use Gmail content for advertising purposes.

3. How we use personal information

We may use information to:

  • provide and operate Orbiio;
  • authenticate users;
  • monitor connected support inboxes;
  • create and manage support tickets;
  • identify technical issues and incidents;
  • automate support workflows;
  • classify, summarise or analyse support communications;
  • notify users of relevant incidents;
  • maintain security;
  • prevent misuse or unauthorised access;
  • investigate faults;
  • improve the performance and reliability of Orbiio;
  • provide customer support; and
  • comply with legal and regulatory obligations.

We do not use personal information for purposes that are incompatible with the purposes for which it was collected.

4. Artificial intelligence and automated processing

Orbiio may use artificial intelligence and automated processing to assist with functions such as:

  • categorising emails;
  • identifying potential incidents;
  • summarising messages;
  • extracting technical information;
  • suggesting ticket priorities;
  • identifying duplicate or related reports; and
  • assisting support teams with responses or investigations.

Automated systems may occasionally produce inaccurate results. Where appropriate, users should review automatically generated information before relying upon it for significant decisions.

Orbiio does not use customer communications to train general-purpose artificial intelligence models unless this has been separately and explicitly agreed.

5. Legal basis for processing

Where UK GDPR applies, we may rely on one or more of the following legal bases:

  • Contract: processing necessary to provide services requested by a customer.
  • Legitimate interests: operating, securing and improving Orbiio and providing efficient technical support services.
  • Consent: where you have specifically consented to particular processing, such as connecting a third-party account.
  • Legal obligation: where processing is required by law.

Where Orbiio processes information on behalf of an organisation using the service, that organisation may be the data controller and Orbiio may act as a data processor.

6. Sharing information

We may share information with trusted third-party service providers where necessary to operate Orbiio.

These may include providers of:

  • cloud hosting;
  • database infrastructure;
  • email services;
  • authentication services;
  • artificial intelligence services;
  • monitoring and analytics;
  • security infrastructure; and
  • technical support services.

These providers are only permitted to process information for authorised purposes and are subject to appropriate contractual and security requirements.

We may also disclose information where required by law, regulation, court order or lawful request from a competent authority.

We do not sell personal information.

7. International data transfers

Some service providers used by Orbiio may process data outside the United Kingdom.

Where personal information is transferred internationally, we take reasonable steps to ensure appropriate safeguards are in place in accordance with applicable data protection laws.

These safeguards may include recognised adequacy arrangements, contractual protections or approved international data transfer mechanisms.

8. Data retention

We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy.

Retention periods may vary depending on:

  • the type of information;
  • contractual requirements;
  • customer configuration;
  • support and incident history;
  • security requirements; and
  • legal obligations.

Customers may be able to delete certain information through Orbiio or request deletion by contacting us.

9. Security

We use reasonable technical and organisational measures designed to protect information against:

  • unauthorised access;
  • accidental loss;
  • destruction;
  • alteration;
  • misuse; and
  • unauthorised disclosure.

These measures may include encryption, authentication controls, access restrictions, monitoring and secure infrastructure.

No internet-based system can be guaranteed to be completely secure, but we continually review our security practices.

10. OAuth credentials and authentication tokens

Where Orbiio connects to third-party services using OAuth, authentication credentials and access tokens are handled securely and are used only for providing the authorised integration.

Users may revoke Orbiio's access to third-party services at any time through the relevant third-party account settings or by disconnecting the integration within Orbiio where that functionality is available.

11. Your rights

Depending on applicable law, you may have rights including the right to:

  • access your personal information;
  • correct inaccurate information;
  • request deletion of your information;
  • restrict processing;
  • object to certain processing;
  • request portability of your information;
  • withdraw consent where processing is based on consent; and
  • complain to a data protection authority.

In the United Kingdom, you may raise concerns with the Information Commissioner's Office (ICO).

Requests relating to personal data can be sent to: privacy@orbiio.co.uk

12. Organisation-managed accounts

Where Orbiio is provided to you through your employer or another organisation, that organisation may control your account and determine how information is processed within Orbiio.

Questions relating to information controlled by your organisation should normally be directed to that organisation.

13. Children's privacy

Orbiio is intended for business and professional use and is not designed for children.

We do not knowingly collect personal information from children through the service.

14. Third-party services

Orbiio may contain integrations with or links to third-party services.

Those services operate under their own terms and privacy policies, and Orbiio is not responsible for the privacy practices of third-party providers.

15. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to Orbiio, legal requirements or our data-processing practices.

The latest version will be made available through the Orbiio website or application.

Where material changes are made, we may provide additional notice where appropriate.

16. Contact

If you have questions about this Privacy Policy or how Orbiio processes personal information, contact:

Orbiio
Email: privacy@orbiio.co.uk

© 2026 OrbiioReturn to app