Legal
Privacy Policy
Effective: TODO[lawyer] — effective date
This is a scaffold. Every section flagged TODO[lawyer] is a placeholder. Orbitex makes no representations under this document until counsel replaces them.
1. What we collect
- Operational metrics for the AI agents you operate — uploaded by CSV or pulled via OAuth integrations (HubSpot, Jobber, Vapi, etc.). The KPI registry that defines acceptable metrics is published in the platform itself.
- Outcome events tied to those agents — closed-won deals, completed jobs, defect-detection counts, etc.
- Account information — email, name, company, vertical — provided at signup via our auth provider.
2. What we do not collect
- No customer-of-customer PII appears in our application logs. Logs reference IDs, never names / emails / phone numbers / transcripts.
- OAuth refresh tokens are encrypted at rest using a key managed in our deploy environment.
- TODO[lawyer] — anything additional we need to commit to here.
3. How the data is used
Operational metrics and outcome events are used to compute your AgentScore and ImplementationScore in the dashboard. Aggregated and anonymized metrics may be used to train Orbitex's predictive deployment model — this is the "data-rights" checkbox at signup.
TODO[lawyer] — exact scope of the data-rights grant; opt-out mechanics; anonymization standard reference.
4. Anonymization at ingest
When data flows into any analytics warehouse used to train Orbitex's predictive models, identifiers (company name, agent name, customer-of-customer identifiers if present) are stripped at the ingestion boundary. We do not aggregate identified data and anonymize later — that pattern is dangerous and we don't use it.
5. Subprocessors
TODO[lawyer] — Neon, Vercel, Railway, Cloudflare R2, Anthropic, Clerk, Sentry, PostHog. List with purposes and current data-handling agreements.
6. Data retention
TODO[lawyer] — retention windows for KPI events, outcome events, score records, OAuth tokens, audit logs.
7. Your rights
TODO[lawyer] — access, deletion, portability, opt-out, contact path.
8. Security
- OAuth refresh tokens encrypted at rest (Fernet KEK held in a secrets manager).
- Append-only / immutable database tables for KPI events, outcome events, and score records.
- No production access from local development environments.
- TODO[lawyer] — incident notification commitments, audit posture.
9. Changes
TODO[lawyer].
Questions? TODO[lawyer] — privacy@orbitex...