Legal
Privacy policy
Last updated 25 September 2026
This policy explains what personal data [Orbitmate legal entity name] (“Orbitmate”, “we”) handles when you visit orbitmate.ai, when you use the Orbitmate product, and when your details appear in a customer’s outreach. It covers what we collect, why, who we share it with, how long we keep it and the rights you have.
Who is responsible for your data
We play two different roles, depending on whose data it is.
- Controller for data about our own visitors, prospects and customers’ account users: for example your name and email when you book a demo, create an account or contact us.
- Processor for the contact data our customers bring into Orbitmate: the people they import, enrich and message. The customer decides whom to contact and why, and is the controller of that data. We process it only on their instructions, under our data processing terms.
If you received a message sent through Orbitmate and want to know what is held about you, contact the sender first. You can also write to us at privacy@orbitmate.ai and we will pass your request to the right customer and help them answer it.
What we collect
From this website
- Demo and contact requests: name, work email, company, role, the number of LinkedIn senders you run, your message and the page you sent it from.
- Basic request data our hosting provider handles to serve and protect the site, such as IP address and browser type. We do not run analytics or advertising trackers on this site.
From account users
- Account details: name, email address, organization and role.
- Connected LinkedIn senders: the LinkedIn email and password, the two-step verification secret if you add one, proxy details, and the session data needed to act for that sender. Passwords and secrets are encrypted; session data is kept on encrypted storage.
- Billing details, once paid plans launch: plan, sender count and billing period. Card details will be held by our payment provider, [payment provider], not by us.
- Product usage and support conversations.
About the people our customers contact
- Public LinkedIn profile information: name, headline, about, location, profile URL, experience, education, skills and similar profile sections, and an email address if the customer imports one.
- Public activity used as context: up to 50 recent posts with their reactions and comments, and up to 20 comments the person wrote.
- Public information about the person’s company, including its LinkedIn page and recent third-party news.
- Messages exchanged through a connected sender, and scores and classifications the product derives from the above (audience fit, reply intent).
How we use it, and our legal bases
| Purpose | Legal basis (GDPR / UK GDPR) |
|---|---|
| Providing the product and the features a customer turns on | Performance of our contract with the customer |
| Answering demo and contact requests | Our legitimate interest in responding to people who ask us to |
| Account, security and service email | Performance of contract; legitimate interest in keeping accounts secure |
| Improving the reliability, quality and cost of the product | Legitimate interest, limited to what is needed |
| Billing, tax and legal obligations | Legal obligation |
| Processing contact data on a customer’s behalf | Determined by the customer as controller; we act on their instructions |
AI features
Orbitmate uses AI models to write draft connection notes, messages and comments, and to score how well a contact fits a customer’s audience. To do that, we send the relevant context, such as a contact’s profile and recent public posts, to the model provider: Cloudflare Workers AI by default, or OpenRouter if the customer connects its own key. Reply intent labels in the inbox are set by fixed rules, not by an AI model.
We monitor AI requests with Langfuse. It receives the full prompt and response of each request, which can include contact profile data.
[To be confirmed with each provider’s terms: whether providers may retain or train on inputs, and the retention period]
Drafts are suggestions. Every connection request, message, comment and reaction waits for a person at the customer to approve, edit or reject it before it is sent.
International transfers
Our main hosting is in the United States, and some providers process data in other countries. Where data leaves the UK or the European Economic Area, we rely on [transfer mechanism: EU Standard Contractual Clauses, the UK Addendum and/or an adequacy decision].
How long we keep it
- Account and customer data: for as long as the account is active. Account and organization deletion is handled on request today; we then delete the data within [number] days, unless we must keep it longer by law.
- LinkedIn message content in the inbox: deleted 365 days after it is received.
- Uploaded contact import files: deleted after 365 days.
- Raw data returned by enrichment providers: cleared after its retention window; the profile data derived from it stays with the contact.
- Other contact data a customer brought in: until the customer deletes it or asks us to delete their account.
- Database backups: nightly backups expire after 30 days.
- Demo and contact requests: [retention period], then deleted.
- Billing records: as long as tax law requires.
Your rights
Under the GDPR and UK GDPR you can ask to access, correct or delete your data, to restrict or object to its processing, and to receive it in a portable format. Where we rely on consent, you can withdraw it at any time. You can also complain to your local data protection authority.
If you live in California, the CCPA/CPRA gives you the right to know what we collect, to delete or correct it, and not to be discriminated against for using these rights. We do not sell or share personal information as those laws define it.
To use any of these rights, write to privacy@orbitmate.ai. We answer within one month, or the period your law sets. If your data is in Orbitmate because a customer contacted you, we will work with that customer to answer you.
Security
The product runs on AWS in the United States (us-east-1) on encrypted disks, with encrypted backups. Inbox message content, provider API keys, LinkedIn passwords, two-step verification secrets and proxy passwords are additionally encrypted in the application with AES-256-GCM, and LinkedIn session data is kept on storage encrypted with a dedicated key. Customer workspaces are separated, access is controlled by roles, and an audit log records actions. We do not hold security certifications today. More on our security page.
Children
Orbitmate is a business tool. It is not directed at children, and we do not knowingly collect data from anyone under 16.
Changes to this policy
We will update this page when our practices change and change the date at the top. If a change is significant, we will tell account holders by email before it takes effect.
Contact
[Orbitmate legal entity name], [registered address]. Email privacy@orbitmate.ai. [Data protection officer or EU/UK representative, if required]