Orbidex ("we", "us", "our") operates the Orbidex IT Help Desk Portal, accessible at orbidex.app and related subdomains (the "Service").
For the purposes of applicable data protection law (including the GDPR where it applies), we act as the data processor on behalf of our customers (who are the data controllers for their employees' data) and as the data controller for data relating to our own customers and their administrators.
We collect data in two contexts:
A. Customer account data — data about the companies and administrators who purchase the Service:
B. End-user data — data uploaded or generated by our customers and their employees through use of the Service:
C. Usage data — automatically collected technical information:
| Purpose | Legal basis |
|---|---|
| Providing and operating the Service | Contract performance |
| Sending transactional emails (ticket notifications, alerts) | Contract performance |
| Customer support and troubleshooting | Legitimate interests |
| Security monitoring and fraud prevention | Legitimate interests |
| Improving the Service (aggregated, anonymised) | Legitimate interests |
| Billing and invoicing | Contract performance / legal obligation |
| Compliance with legal obligations | Legal obligation |
We do not sell personal data. We do not use personal data for advertising or profiling.
We share data only with sub-processors necessary to operate the Service:
| Sub-processor | Purpose | Location | Privacy policy |
|---|---|---|---|
| Supabase Inc. | Database hosting & authentication | United States | supabase.com/privacy |
| Render Services Inc. | Application hosting | United States | render.com/privacy |
| Resend Inc. | Transactional email delivery | United States | resend.com/legal/privacy-policy |
We may disclose data if required by law or court order, or to protect the rights and safety of our users. We will notify affected customers where legally permitted to do so.
We retain customer data for as long as the account is active. Upon termination:
You may request immediate deletion at any time by contacting us at the address below.
We implement appropriate technical and organisational measures to protect personal data, including:
For a detailed overview, see our Security Overview.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and in any event within 72 hours of becoming aware of it.
Depending on your location, you may have the following rights regarding your personal data:
End users should direct requests to their employer (our customer), who is the data controller. Customers may exercise their rights by contacting us at the address in Section 11.
You also have the right to lodge a complaint with your local data protection supervisory authority.
We use minimal cookies necessary to operate the Service:
localStorage to keep you logged in (session-scoped)localStorage)We do not use advertising cookies, third-party tracking cookies, or analytics cookies that identify individuals.
The Service is designed for use by businesses and their employees. It is not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.
We may update this Privacy Policy from time to time. We will notify customers of material changes by email at least 14 days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
For privacy-related questions, data subject requests, or to exercise your rights: