Privacy Policy

1. Data collection

Depending on the modules you use, we may collect and process:

2. Purpose

We use data to:

3. No data selling

We do not sell personal or company data.

4. Data sharing

Data may be shared with:

4a. Subprocessors and service categories

To operate the Platform we may engage subprocessors or service providers in the following categories (not an exhaustive vendor list; providers may change as the stack evolves):

Such parties process data only as needed to provide their service to us, under contractual confidentiality / data-processing terms where applicable. For a current category confirmation or enterprise diligence request, contact info@orbitasolution.com.

4b. Enterprise data processing terms (DPA)

Enterprise customers that require a formal Data Processing Agreement (DPA) or additional processing schedules may request them in writing. Contact info@orbitasolution.com with your company legal name, country, and required annexes. Until a separate DPA is signed, this Privacy Policy and the Terms & Conditions govern processing for the Service.

5. Security disclaimer

We implement reasonable administrative, technical, and organisational safeguards.

However, no system is completely secure.

5a. Our privacy commitment & your account security

We protect your privacy. We process personal and company data to operate and secure the Platform, with company-scoped isolation, and we do not sell personal data. Details are in this Privacy Policy and applicable law (including PDPA principles where Malaysia applies). See also Sections 4a–4b (subprocessors / DPA) and Section 14 (security incident notification where required by law).

You must protect your account. Keep passwords, verification codes, API/connector secrets, and devices confidential. Do not share logins. Notify us promptly of suspected unauthorised access. Compromise caused by shared or weak credentials remains your responsibility; we apply reasonable safeguards but cannot warrant absolute security. Related terms: Terms §41.

6. Data risk

Users acknowledge that storing data on the Platform carries inherent risk.

7. User rights

Users may request access, correction, or deletion of eligible personal profile data, subject to applicable law and verification requirements.

Depending on your location, you may also have additional rights such as restriction, portability, objection, withdrawal of consent, or complaint to a supervisory authority, subject to legal limits and operational integrity requirements.

8a. Retention

Personal data is retained only for as long as necessary to provide the service, maintain account records, satisfy security requirements, or comply with statutory tax, accounting, audit, and regulatory obligations.

Transactional tracking records, carton movements, picking logs, delivery confirmation records, invoice histories, audit trails, and ledger-linked operational records may be retained where required for audit, tax, accounting, fraud prevention, dispute resolution, security, or regulatory obligations.

8. Cookies

We use cookies for login, session continuity, performance, and security. Details: Cookie Policy.

9. Updates

This policy may be updated. Material changes may be communicated where practicable.