This is a scaffold. Every section flagged TODO[lawyer] is a placeholder. Orbitex makes no representations under this document until counsel replaces them.
1. What we collect
- Operational metrics for the AI agents you operate, uploaded by CSV or imported from supported integrations. HubSpot is live; Jobber is sandbox-only; Vapi is not yet available. The KPI registry that defines acceptable metrics is published in the platform itself.
- Outcome events tied to those agents, closed-won deals, completed jobs, defect-detection counts, etc.
- Account information, email, name, company, vertical, provided at signup via our auth provider.
2. What we do not collect
- No customer-of-customer PII appears in our application logs. Logs reference IDs, never names / emails / phone numbers / transcripts.
- OAuth refresh tokens are encrypted at rest using a key managed in our deploy environment.
- TODO[lawyer], anything additional we need to commit to here.
3. How the data is used
Operational metrics and outcome events are used to compute your AgentScore and ImplementationScore in the dashboard. Aggregated and anonymized metrics may be used to train Orbitex's predictive deployment model, this is the "data-rights" checkbox at signup.
TODO[lawyer], exact scope of the data-rights grant; opt-out mechanics; anonymization standard reference.
4. Uploaded source data
Raw upload files are retained and are not automatically anonymized. Use only data you are authorized to provide and remove unnecessary personal information before uploading.
TODO[lawyer], confirm processing purposes, retention terms, and any future anonymization commitments before publication.
5. Subprocessors
TODO[lawyer], Neon, Vercel, Railway, Cloudflare R2, Anthropic, Clerk, Sentry, PostHog. List with purposes and current data-handling agreements.
6. Data retention
TODO[lawyer], retention windows for KPI events, outcome events, score records, OAuth tokens, audit logs.
7. Your rights
TODO[lawyer], access, deletion, portability, opt-out, contact path.
8. Security
- OAuth refresh tokens encrypted at rest (Fernet KEK held in a secrets manager).
- Append-only / immutable database tables for KPI events, outcome events, and score records.
- No production access from local development environments.
- TODO[lawyer], incident notification commitments, audit posture.
9. Changes
TODO[lawyer].
Questions? TODO[lawyer], privacy@orbitex...