Scope
This policy applies to information collected through the Orbitra public website, demo requests, email conversations, event follow-ups, related business communications, product support, automatic application reports, and Microsoft Teams connection, setup and help interactions. Orbitra Security is a Canadian company and handles personal information in accordance with applicable Canadian privacy requirements.
Customer use of an Orbitra product, pilot, proof of concept, or paid service may also be governed by a separate agreement, order form, data processing addendum, or security schedule.
Information We Collect
We may collect information you provide directly, including name, work email, company, team size, message content, and any details you choose to include in a demo request or email.
We may also collect limited technical information from website visits, such as browser type, device type, approximate region, referring page, and pages viewed, when needed to operate, secure, or improve the site. If you accept optional visitor analytics, our analytics and visitor-identification providers may also associate a visit with business or company information available to them.
If you participate in a demo, pilot, or evaluation, we may receive business contact information, implementation context, and security or identity environment details that you authorize us to review.
Microsoft Teams Interactions
When enabled for your organization, Orbitra Response uses Microsoft Teams for setup guidance and selected workspace notifications. Setup and help interactions can occur before you sign in to or connect an Orbitra workspace.
Microsoft may supply organization, user, team, channel, conversation and message identifiers, display names, message content, installation or removal events, and technical authentication and delivery information. Orbitra uses this information to authenticate requests, process supported setup steps, choose a fixed guidance reply, check authorized connections and prevent duplicate messages.
Guidance replies contain fixed instructions. They do not use a model to interpret your message, grant workspace access, confirm a successful connection or authorize a response. A reply may show a cleaned and shortened Microsoft-provided display name to identify who added the app or requested help. This display name is not proof of workspace administrator authority.
Orbitra saves the minimum reply destination and any displayed sender name in encrypted guidance records. The original callback body, authentication token, message text and setup code are not saved in those records. Hashes, timestamps, processing status and available provider message references support duplicate prevention and reconciliation. See guidance retention for the cleanup thresholds.
The public Teams callback and setup/help processing use US services, including for India workspaces. Connection and alert records use the workspace's home region; shared ownership and authorization metadata use US services. Selected notifications may contain identity or incident context visible to people with access to the destination channel. Microsoft Teams and Azure Bot Service also process information under their own terms and your organization's arrangements.
See Teams data use and connection support for setup, disconnect and data-request guidance.
How We Use Information
- Respond to demo requests, questions, and business inquiries.
- Schedule meetings and provide product information.
- Operate, maintain, secure, and improve the website.
- Understand customer needs and evaluate product fit.
- Understand website engagement and follow up with potential business customers when optional visitor analytics are accepted.
- Detect, prevent, and investigate misuse, security issues, or fraud.
- Comply with legal, accounting, contractual, and compliance obligations.
Cookies and Local Storage
The public website uses local storage to remember whether you accepted or declined the cookie and trust notice. We may use essential cookies or similar technologies for site reliability, security, and basic preference storage.
If you accept, Orbitra loads optional visitor analytics and identification technology provided through Instantly and Leadsy. Their technology and supporting service providers may process technical, engagement, approximate location, and business-identity signals associated with the visit. If you decline or have not made a choice, Orbitra does not load this visitor tag.
You can clear local storage or cookies through your browser settings to reset your choice. Some site preferences may reset when you do this.
Automatic Application Reports
Orbitra automatically reports selected application failures to its internal support service in the United States, including failures during sign-in and account recovery. This reliability reporting operates independently of optional analytics choices and Do Not Track settings.
Reports use a restricted set of technical fields: application version, error category, a page category without record identifiers or query strings, time, and, when available, an application file reference, source position, HTTP status and request reference. They do not include arbitrary error messages, console contents, passwords, access tokens, setup codes, webhook signatures, form entries or chat content. Authenticated reports may be linked to your verified Orbitra user and workspace. Public recovery reports are sent without account credentials.
Automatic reports expire 14 days after they are first recorded; additional occurrences do not extend that expiry. Duplicate-detection receipts expire after one day, and temporary rate-limit records use hashed source-address keys. Expired records are removed by scheduled cleanup. Access to the report inbox requires Orbitra platform administration permission. See Data use for processing locations and the scope of these retention periods.
A separate issue report you choose to submit can include your description and an attachment you explicitly provide.
Retention and Security
We keep information for as long as needed for the purposes described in this policy, including responding to requests, maintaining business records, meeting legal obligations, and protecting our rights.
We use reasonable administrative, technical, and organizational safeguards designed to protect information. No internet service or email communication can be guaranteed to be completely secure.
Your Choices and Rights
You may ask us to access, correct, update, delete, or limit use of personal information you have provided to us, subject to legal, security, and contractual limits.
You can also ask us to stop sending non-transactional messages. We may still send administrative, security, or relationship-related communications when appropriate.
For a request about a Teams setup or help interaction, including one without an Orbitra account, contact hello@orbitrasecurity.com. Include the approximate time with time zone and enough context to identify the interaction. Do not send passwords, setup codes, access tokens or unredacted chat content. Additional information may be needed to verify the request and locate the records.
Disconnecting a Teams connection stops Orbitra from using that connection. Removing the app in Teams is a separate action. Neither action recalls provider-held messages or automatically deletes every historical record. Public guidance records can exist without a linked Orbitra account, so deleting a workspace alone does not identify every such interaction.
Contact
For privacy questions or requests, contact Orbitra Security at hello@orbitrasecurity.com.
Last updated: September 7, 2026