Legal

Privacy Policy

Effective: TODO[lawyer] — effective date

This is a scaffold. Every section flagged TODO[lawyer] is a placeholder. Orbitex makes no representations under this document until counsel replaces them.

1. What we collect

  • Operational metrics for the AI agents you operate — uploaded by CSV or pulled via OAuth integrations (HubSpot, Jobber, Vapi, etc.). The KPI registry that defines acceptable metrics is published in the platform itself.
  • Outcome events tied to those agents — closed-won deals, completed jobs, defect-detection counts, etc.
  • Account information — email, name, company, vertical — provided at signup via our auth provider.

2. What we do not collect

  • No customer-of-customer PII appears in our application logs. Logs reference IDs, never names / emails / phone numbers / transcripts.
  • OAuth refresh tokens are encrypted at rest using a key managed in our deploy environment.
  • TODO[lawyer] — anything additional we need to commit to here.

3. How the data is used

Operational metrics and outcome events are used to compute your AgentScore and ImplementationScore in the dashboard. Aggregated and anonymized metrics may be used to train Orbitex's predictive deployment model — this is the "data-rights" checkbox at signup.

TODO[lawyer] — exact scope of the data-rights grant; opt-out mechanics; anonymization standard reference.

4. Anonymization at ingest

When data flows into any analytics warehouse used to train Orbitex's predictive models, identifiers (company name, agent name, customer-of-customer identifiers if present) are stripped at the ingestion boundary. We do not aggregate identified data and anonymize later — that pattern is dangerous and we don't use it.

5. Subprocessors

TODO[lawyer] — Neon, Vercel, Railway, Cloudflare R2, Anthropic, Clerk, Sentry, PostHog. List with purposes and current data-handling agreements.

6. Data retention

TODO[lawyer] — retention windows for KPI events, outcome events, score records, OAuth tokens, audit logs.

7. Your rights

TODO[lawyer] — access, deletion, portability, opt-out, contact path.

8. Security

  • OAuth refresh tokens encrypted at rest (Fernet KEK held in a secrets manager).
  • Append-only / immutable database tables for KPI events, outcome events, and score records.
  • No production access from local development environments.
  • TODO[lawyer] — incident notification commitments, audit posture.

9. Changes

TODO[lawyer].


Questions? TODO[lawyer] — privacy@orbitex...