OrbitAlert
Sign in →

Legal

Privacy Policy

Effective date: 27 June 2026

This Privacy Policy explains how OrbitAlert collects, uses, stores, and shares your personal data when you use our platform. It also describes your rights and how to exercise them. Please read it carefully.

1. Data Controller

OrbitAlert (“we”, “us”, “our”) is the data controller responsible for personal data processed in connection with the OrbitAlert service available at orbitalert.net.

For all privacy enquiries, data subject requests, or complaints, contact us at: legal@orbitalert.net.

2. Scope & Applicability

This Privacy Policy applies to:

  • Visitors to our marketing website at orbitalert.net.
  • Registered users of the OrbitAlert dashboard.
  • Customers accessing the OrbitAlert API.
  • Individuals who contact us for support, sales, or other enquiries.

This policy does not apply to third-party websites, services, or applications that may be linked from our platform. We are not responsible for the privacy practices of those third parties.

This policy covers personal data as defined under the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA), as applicable.

3. Data We Collect

3.1 Account & identity data

Name, email address, and any other information provided when creating an account. Authentication (including password hashing and session management) is handled by Clerk, Inc. We receive identity and session tokens from Clerk but do not store raw passwords. OrbitAlert also stores your user ID, account creation date, and account status.

3.2 Billing & payment data

Subscription plan, billing cycle, invoice history, and payment status. Payment card details (card number, CVC, expiry) are collected and stored exclusively by our payment processor; OrbitAlert never receives or stores full card numbers. We retain transaction records, including amounts and timestamps, for tax and accounting purposes.

3.3 Configuration & operational data

Ground station coordinates (latitude, longitude, elevation mask), satellite identifiers, alert lead times, Webhook endpoint URLs, API Key identifiers (hashed), and notification preferences. This data is submitted by you to configure the Service.

3.4 API & usage logs

Timestamps and endpoints of API requests, HTTP response codes, API Key identifiers used per request, and Webhook delivery attempts (target URL, HTTP status code, response time, retry count, pass details). These logs are used for billing verification, debugging, and security monitoring.

3.5 Technical & device data

IP address, browser type and version, operating system, referring URL, pages visited within the dashboard, and session duration. This data is collected automatically via server logs and analytics tools when you access the platform.

3.6 Communications

Content of emails, support tickets, or other messages you send to us, including your name, email address, and any personal information you choose to include.

3.7 Data we do NOT collect

We do not collect: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning sexual orientation. We do not intentionally collect data about individuals under 18.

4. How We Use Your Data

PurposeData used
Providing and operating the ServiceAccount, configuration, API/usage logs
Authentication and account securityAccount, technical/device data
Processing payments and issuing invoicesBilling, account data
Delivering Webhook notificationsConfiguration data, API logs
Sending transactional emails (invoices, alerts, security notices)Account data
Responding to support requestsCommunications, account data
Monitoring service health and debuggingAPI/usage logs, technical data
Detecting and preventing fraud or abuseAll categories, including IP address
Complying with legal obligations (tax, accounting, law enforcement)Billing, account data
Improving the Service through aggregated, anonymised analyticsUsage logs (anonymised)
Sending product updates and feature announcementsAccount data (opt-out available)

6. Data Sharing & Sub-Processors

We do not sell, rent, or trade your personal data. We share data only as described below.

Our current sub-processors:

Sub-processorPurposeLocation
Clerk, Inc.User authentication, session managementUSA (SCCs)
Payment processorSubscription billing, payment card processingEU / USA
Vercel, Inc.Frontend hosting and CDNUSA (SCCs)
Cloud infrastructure providerDatabase, compute, and storageEU / USA
Transactional email providerInvoice and notification deliveryEU / USA

We may update our sub-processors list. Material changes will be communicated in accordance with Section 18. Customers who have signed a Data Processing Agreement may object to new sub-processors as set out in that agreement.

We may also share data with professional advisers (lawyers, accountants, auditors) under appropriate confidentiality obligations, and with successors in interest in the event of a merger, acquisition, or asset sale.

7. International Data Transfers

Some of our sub-processors operate in countries outside the European Economic Area (EEA) or the United Kingdom. Where we transfer personal data to such countries, we ensure an adequate level of protection by relying on one or more of the following mechanisms:

  • European Commission adequacy decisions;
  • Standard Contractual Clauses (SCCs) approved by the European Commission;
  • UK International Data Transfer Agreements (IDTAs) or addenda to SCCs, as applicable.

You may request a copy of the relevant transfer safeguards by contacting us at legal@orbitalert.net.

8. Data Retention

CategoryRetention period
Account & identity dataDuration of account + 2 years after closure
Billing & invoice records7 years (legal / tax obligation)
Configuration data (alert definitions)Duration of account + 30 days after closure
API usage logs90 days rolling
Webhook delivery logs90 days rolling
Technical / device logs (IP, browser)30 days rolling
Support communications3 years after resolution
Anonymised, aggregated analyticsIndefinitely (no personal data)

We may retain data for longer periods where required by applicable law or where necessary to establish, exercise, or defend legal claims.

9. Cookies & Tracking Technologies

We use cookies and similar technologies to operate and improve the Service. Below is a description of the cookies we use:

CategoryPurposeBasisCan opt out?
Strictly necessaryAuthentication session tokens, CSRF protection, security cookies required for the Service to function.Contract / legitimate interestNo — required for Service operation
FunctionalRemembers dashboard preferences (satellite selection, time zone, language).Legitimate interestYes — via browser settings
AnalyticsAggregate, anonymised page view counts and session data used to identify performance issues and prioritise improvements. No cross-site tracking.ConsentYes — opt out via cookie banner

We do not use advertising, retargeting, or cross-site tracking cookies. We do not share cookie data with advertising networks.

Do Not Track. Some browsers transmit a “Do Not Track” signal. Because there is no universally accepted standard for responding to such signals, we do not currently alter our data collection practices in response to them.

Email tracking. Transactional emails (invoices, alerts, security notices) do not contain tracking pixels. Marketing or product update emails may contain a single tracking pixel that records whether the email was opened and, if so, the approximate time and device type. This is used solely to measure the effectiveness of our communications and to suppress further emails to addresses that are undeliverable. You can prevent pixel tracking by configuring your email client to block remote images. Opting out of marketing emails (see Section 13) also stops email tracking.

10. Automated Decision-Making & Profiling

OrbitAlert does not make decisions about you that produce legal or similarly significant effects using fully automated processing (i.e., without any meaningful human review).

We do use automated rules to detect potentially abusive API usage patterns (e.g., excessive request rates or anomalous access patterns) and may automatically apply rate limiting or temporary throttling. These automated actions affect Service access but do not constitute profiling under GDPR Article 22 in a way that produces legal effects.

If your account is suspended following an automated detection event, you have the right to request human review by contacting legal@orbitalert.net.

11. Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, loss, and destruction. These measures include:

  • Encryption in transit (TLS 1.2 or higher) for all data transmitted between your browser or API client and our servers.
  • Encryption at rest for databases containing personal data.
  • API Key hashing — we store only a hashed representation of your API Keys, not the plaintext value.
  • Role-based access controls limiting OrbitAlert personnel access to personal data to those with a legitimate operational need.
  • Regular security reviews and vulnerability assessments.
  • Infrastructure-level logging and anomaly detection.

No method of transmission over the internet or method of electronic storage is completely secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

12. Data Breach Notification

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, OrbitAlert will:

  • Notify the competent supervisory authority (the Hellenic Data Protection Authority, or the authority in the affected jurisdiction) within 72 hours of becoming aware of the breach, where feasible, in accordance with GDPR Article 33.
  • Notify affected individuals without undue delay if the breach is likely to result in a high risk to their rights and freedoms, in accordance with GDPR Article 34.
  • Document all breaches internally, including those not meeting the threshold for external notification.

Breach notifications to individuals will be sent to the registered email address on the account and will describe the nature of the breach, the data affected, likely consequences, and the measures we have taken or propose to take.

13. Your Rights Under GDPR (EEA & UK)

If you are located in the European Economic Area or the United Kingdom, you have the following rights regarding your personal data:

RightWhat it means
Right of access (Art. 15)Request a copy of the personal data we hold about you and information about how it is processed.
Right to rectification (Art. 16)Request correction of inaccurate or incomplete personal data.
Right to erasure (Art. 17)Request deletion of your personal data where there is no overriding legal basis for us to continue processing it. Note: this right is not absolute — see the exceptions below.
Right to restriction (Art. 18)Request that we restrict processing of your data in certain circumstances (e.g., while you contest accuracy).
Right to data portability (Art. 20)Request a copy of data you provided to us in a structured, commonly used, machine-readable format.
Right to object (Art. 21)Object to processing based on legitimate interests, including direct marketing. We must stop unless we have compelling legitimate grounds.
Right to withdraw consent (Art. 7(3))Withdraw consent for processing based on consent (e.g., analytics cookies, marketing emails) at any time, without affecting prior processing.
Rights related to automated decision-making (Art. 22)Not be subject to solely automated decisions that produce significant effects. Request human review of automated decisions.

Exceptions to the right of erasure

We may decline a request for erasure, or retain certain data notwithstanding an erasure request, where retention is necessary to:

  • Comply with a legal obligation (e.g., retaining invoices for tax purposes under applicable accounting law).
  • Establish, exercise, or defend legal Claims — including where we reasonably anticipate, or are engaged in, litigation or regulatory proceedings involving the requesting individual or their employer.
  • Prevent, detect, or investigate fraud, security incidents, or abuse of the Service.
  • Complete a transaction the individual has requested or reasonably anticipated.
  • Exercise rights of freedom of expression or information.

Where we decline an erasure request in full or in part, we will notify you of the reason and your right to complain to the supervisory authority.

How to opt out of marketing

You may opt out of marketing emails at any time by: (a) clicking the “unsubscribe” link in any marketing email we send; or (b) sending a request to legal@orbitalert.net with the subject line “Unsubscribe”. Opt-out requests are processed within 10 business days. Opting out of marketing does not affect transactional communications related to your account (invoices, security notices, service updates).

To exercise any of the rights listed above, submit a written request to legal@orbitalert.net. We will respond within 30 days (extendable by a further 60 days for complex requests, with advance notice). We may need to verify your identity — typically by confirming access to your registered email address — before processing your request. We will not charge a fee for reasonable requests.

If you are not satisfied with our response, you have the right to lodge a complaint with your local supervisory authority. In Greece, this is the Hellenic Data Protection Authority (HDPA) dpa.gr. In the UK, this is the Information Commissioner’s Office (ICO) — ico.org.uk.

14. California Residents (CCPA / CPRA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to know. You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties with whom we share it.
  • Right to delete. You may request deletion of personal information we have collected, subject to certain exceptions.
  • Right to correct. You may request correction of inaccurate personal information.
  • Right to opt out of sale or sharing. OrbitAlert does not sell or share your personal information for cross-context behavioural advertising.
  • Right to limit use of sensitive personal information. OrbitAlert does not use sensitive personal information for purposes beyond those necessary to provide the Service.
  • Right to non-discrimination. We will not discriminate against you for exercising your CCPA/CPRA rights.

To submit a California privacy request, contact us at legal@orbitalert.net. We will respond within 45 days (extendable by 45 days with notice). We may need to verify your identity.

In the preceding 12 months, we have collected the categories of personal information described in Section 3 of this Policy. We have not sold any personal information.

15. Data Processing Agreement

If you are a business customer subject to GDPR and you use OrbitAlert to process personal data on behalf of your organisation (for example, ground station coordinates that identify an individual’s location), you are required to enter into a Data Processing Agreement (DPA) with OrbitAlert under GDPR Article 28.

OrbitAlert’s full DPA is published at orbitalert.net/dpa and is incorporated into and accepted as part of the Terms of Service. The DPA includes Standard Contractual Clauses (EU SCCs 2021/914, Module 2), a description of all processing activities, technical and organisational security measures (TOMs), and the list of approved Sub-Processors.

To request a countersigned PDF copy of the DPA, email legal@orbitalert.net with the subject line “DPA — Countersigned Copy Request”. We will respond within 5 business days.

16. Privacy by Design & Data Minimisation

OrbitAlert embeds privacy into the design and operation of the Service from the outset, rather than as an afterthought. Our approach includes:

  • Data minimisation. We collect only the personal data that is strictly necessary for the purposes described in this Policy. Where a purpose can be achieved with less data or with anonymised data, we use that approach.
  • Purpose limitation. Personal data collected for one purpose is not repurposed for an incompatible purpose without your knowledge and, where required, your consent.
  • Pseudonymisation. Where practicable, we pseudonymise or anonymise personal data in analytics, testing, and internal reporting pipelines. Anonymised data is not considered personal data and is not subject to the restrictions of this Policy.
  • Access controls. Access to personal data by OrbitAlert personnel is restricted on a need-to-know basis and is logged for audit purposes.
  • Default privacy. New features are assessed for privacy impact before deployment. Privacy-protective settings are the default where technically feasible.
  • Storage limitation. Personal data is not retained beyond the periods set out in Section 8 unless required by law or for the establishment, exercise, or defence of legal claims.

Our privacy-by-design commitments are operational standards, not contractual guarantees. Failure to achieve any specific design outcome does not create independent legal liability beyond OrbitAlert’s obligations under applicable data protection law.

17. Job Applicants

If you apply for a position at OrbitAlert (whether through our website, a job board, or direct contact), we will process personal data you submit — including your name, contact details, CV, work history, qualifications, and any other information you provide — for the purpose of evaluating your application and, if successful, managing your employment or engagement.

Legal basis: legitimate interests (evaluating candidates) and, where applicable, pre-contractual steps at your request. We retain applicant data for 12 months after the conclusion of a recruitment process, after which it is deleted unless you have consented to being considered for future roles.

Applicant data is processed separately from customer account data. Applicants have the same GDPR rights described in Section 13 with respect to their applicant data. Requests may be directed to legal@orbitalert.net.

18. Children's Privacy

The Service is not directed to, and we do not knowingly collect personal data from, individuals under the age of 18. If you are a parent or guardian and believe that a minor has provided personal data to us without appropriate consent, please contact us at legal@orbitalert.net and we will take prompt steps to identify and delete that data.

19. Law Enforcement & Government Requests

OrbitAlert may disclose personal data to law enforcement, regulatory authorities, or government bodies when required to do so by applicable law, court order, subpoena, or other legal process. We will:

  • Evaluate each request to verify its legal validity before complying.
  • Disclose only the data specifically requested and no more.
  • Notify affected users of the request unless we are legally prohibited from doing so or unless doing so would risk harm to an investigation or person.
  • Resist requests that we believe are overbroad or legally defective.

We do not voluntarily share data with government entities beyond what is legally required.

20. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes (such as new purposes of processing, new categories of data collected, or changes to your rights), we will provide at least 14 days’ advance notice via email or a prominent in-dashboard notice before the changes take effect.

The “Effective date” at the top of this page reflects when the current version took effect. We encourage you to review this policy periodically. Continued use of the Service after a revised policy takes effect constitutes acceptance of the changes.

21. Contact & Complaints

For any questions, concerns, or rights requests regarding this Privacy Policy or the processing of your personal data:

OrbitAlert — Privacy Team

Email: legal@orbitalert.net

Website: orbitalert.net

We aim to respond to all privacy requests within 30 days. If you are not satisfied with our response, you may lodge a complaint with your local data protection authority.

EEA / Greece

Hellenic Data Protection Authority (HDPA)

dpa.gr

United Kingdom

Information Commissioner’s Office (ICO)

ico.org.uk