01Who we are and how to contact us
ORBITRA ONE™ (“we”, “us”, “our”) is the controller of the personal data described in this policy. You can contact us about it at any time at hello@orbitraone.com.
Our data protection team can be reached at hello@orbitraone.com with any question about this policy or your personal data, including requests to exercise your rights. Questions that do not concern personal data can be sent to hello@orbitraone.com.
02What this policy covers
This policy applies when you visit orbitraone.com in any of its languages, submit one of its forms, subscribe to updates or correspond with us about ORBITRA ONE™. It covers visitors, prospective clients, developers, validators, asset issuers, security researchers, journalists and representatives of institutions.
Accounts and products within Orbitra Prime, Orbitra L1 and Orbitra Realm are governed by their own terms and privacy notices, presented during onboarding. Those notices cover identity verification and account data, which this website does not collect.
Where we process personal data on behalf of an institutional client, the client is the controller and our data processing addendum governs that processing.
03Categories of personal data
The personal data we hold depends on how you interact with us:
- Contact and professional data — your name, email address and, where a form asks for them, your organization, role and country or jurisdiction.
- Inquiry data — what you choose to tell us in a form or message, such as your area of interest, an estimated activity range, a description of what you plan to build, operate or issue, or the details of a security report.
- Consent and preference records — your cookie choices, your subscription status, the wording and time of any consent you give, and the language and theme you select.
- Technical and security data — IP address, browser and device type, request times, pages requested, referring page and error diagnostics.
- Measurement data — page views, performance metrics and interaction events, collected only with your consent.
- Correspondence — emails and messages you exchange with us, including media inquiries and complaints.
We do not seek special categories of personal data, such as health or biometric data, through this website.
04Where personal data comes from
Most personal data comes directly from you, when you complete a form, subscribe to updates or write to us.
Technical data is generated automatically when your browser requests a page. If you have not chosen a language and your browser does not indicate a supported one, an approximate country derived from your network address by our hosting infrastructure may be used to select a default language. It is used for no other purpose.
We may also receive business contact details from a person who refers you to us, from public professional sources, or from providers that help us detect spam and abusive traffic.
05Purposes and lawful bases
We use personal data only for the purposes below. Where data-protection law requires a lawful basis, it is stated for each purpose.
- Responding to inquiries and access requests — reviewing what you submitted, replying and following up. Basis: steps taken at your request before a possible contract, or our legitimate interest in answering business inquiries.
- Routing your request — directing it to the right team and indicating whether a product may be offered where you are. Formal eligibility is decided only during onboarding. Basis: legitimate interests.
- Sending updates you requested — newsletters and announcements. Basis: consent, which you can withdraw at any time through the unsubscribe link in each message or by contacting us.
- Operating and protecting the website — delivering pages, applying your essential choices, preventing spam, fraud and abuse, and investigating incidents. Basis: legitimate interests in a secure, functioning website.
- Measuring and improving the website — understanding performance and which content is useful. Basis: consent.
- Handling security reports and complaints — assessing, responding and keeping a record. Basis: legitimate interests and, where applicable, legal obligation.
- Meeting legal obligations and protecting rights — record keeping, responding to lawful requests from authorities, and establishing, exercising or defending legal claims. Basis: legal obligation or legitimate interests.
When we rely on legitimate interests, we weigh them against your interests and rights, and you can ask us for details of that assessment.
06Account and access inquiries
This website offers the forms below. Each one states what it collects and why, and collects only the information it shows:
- Request access — contact details, the products you are interested in and how you intend to use them.
- Institutional inquiry — business contact details, institution, role, jurisdiction, area of interest and an estimated activity range.
- Developer, validator and issuer interest — contact details and a description of what you plan to build, operate or issue.
- Security report — contact details and the technical details of the vulnerability you found.
- General contact and media inquiries — contact details, your organization or publication, and your message.
- Newsletter and updates — your email address and your consent to receive updates.
With each submission we record the time, the language version of the page, the referring page and, where the form includes a consent statement, the wording and time of the consent you gave. This lets us reply in your language and demonstrate that consent was obtained.
Submitting a form is not an account application. Identity verification and customer due diligence take place only in a separate onboarding process, described in our AML, KYC and sanctions statement. No form asks for identity documents, passwords, private keys, seed phrases or payment details; if you include them in a message, we will not use them and will delete them unless the law requires us to keep them.
07Device, security and analytics data
Our servers log each request, including IP address, time, page requested, response status, browser type and referring page. Server and form-endpoint logs exclude the contents of form submissions. We use them to deliver the website, rate-limit automated traffic, detect abuse and investigate security incidents.
Performance and interaction measurement is first-party and cookieless, and runs only if you consent. It captures page views, web-vitals performance metrics and product-exploration events — which technology pages and market illustrations are explored, language and theme changes, and form starts and completions. It never records what you type into a form.
Measurement data is analyzed in aggregate to improve content, navigation and performance. It is not used for advertising, and we do not sell personal data collected through this website.
09Processors and other recipients
We share personal data only as needed for the purposes above, with the following categories of recipient:
- hosting, content-delivery and security providers that serve the website, protect it from attack and filter spam and automated abuse;
- communication and customer-relationship tools that store inquiries, route them to the right team and send the messages you request;
- measurement infrastructure that processes consented performance and interaction data on our behalf;
- professional advisers, such as lawyers, auditors and insurers, who are bound by confidentiality;
- affiliated companies, where they help answer your request or provide a product you asked about;
- public authorities, regulators and courts, where the law requires disclosure or where it is necessary to protect rights, safety or the integrity of our services;
- a buyer or successor in a merger, acquisition or reorganization, subject to equivalent protection.
Service providers act as our processors under written contracts that limit their use of personal data to our instructions and require appropriate security. A list of processor categories and their locations is available from hello@orbitraone.com.
10International transfers
Our service providers and teams may access or store personal data in countries other than the one where you live, including countries whose data-protection laws differ from yours.
Where the law requires it, we protect these transfers with recognized safeguards — such as transfers to countries recognized as providing adequate protection, or standard contractual clauses approved by the competent authorities — supported by additional technical and organizational measures where needed. You can ask hello@orbitraone.com which safeguards apply to your data.
11How long we keep personal data
We keep personal data only as long as it is needed for the purpose for which it was collected, including to meet legal, accounting and reporting requirements and to establish or defend legal claims.
We keep each category — including inquiries, subscriber records, consent records, security reports, complaints and server logs — only for as long as its purpose requires, and then delete or anonymize it, unless the law requires us to keep it for longer.
When a retention period ends, we delete the data or anonymize it so that it can no longer be linked to you.
12Your privacy rights
Depending on where you live and the law that applies, you may have the right to:
- Access — confirm whether we process your personal data and receive a copy of it.
- Rectification — have inaccurate data corrected and incomplete data completed.
- Erasure — have your data deleted when there is no longer a valid reason to keep it.
- Restriction — have the use of your data limited while a concern is resolved.
- Portability — receive data you provided in a structured, machine-readable format, or have it sent to another organization where technically feasible.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time.
- Withdrawal of consent — withdraw consent at any time, without affecting processing carried out before you withdrew it.
- Complaint — lodge a complaint with a data-protection supervisory authority.
Some laws also give you the right to know which categories of personal data we collect and disclose, to opt out of the sale or sharing of personal data and of targeted advertising, to limit the use of sensitive data and not to be treated differently for exercising your rights. You can exercise these rights in the same way, and a Global Privacy Control signal is honored as an opt-out where the law gives it that effect.
To make a request, contact hello@orbitraone.com. We may need to verify your identity and will ask only for the information required to do so. Where the law allows, you may act through an authorized agent. We respond within the period set by applicable law and do not charge a fee unless a request is manifestly unfounded or excessive.
13Children and age restrictions
This website and the products of ORBITRA ONE™ are not directed to minors. We do not knowingly collect personal data from anyone below the age of majority in their jurisdiction, and products are available only to people who meet the eligibility requirements of the applicable product terms.
If you believe a minor has sent us personal data, contact hello@orbitraone.com and we will delete it.
14Automated decision-making and AI
We do not make decisions with legal or similarly significant effects about you based solely on automated processing of data collected through this website.
Automated tools, which may include machine-learning models, may help us filter spam, detect abusive traffic and route inquiries; people review inquiries before any decision about access. Personal data submitted through this website is not used to train artificial-intelligence models; if that changes, we will update this policy beforehand and ask for consent where required.
Automated processing within Orbitra products — such as eligibility checks, risk limits, fraud and market-abuse surveillance, and Cortex agents acting under your policies — is described in the product privacy notice and the automated and AI-assisted trading disclosure, including any right you have to request human review.
15How we protect personal data
We apply technical and organizational measures proportionate to the risk, including encrypted connections, strict security headers, protection against cross-site request forgery, rate limiting and bot protection on forms, server-side validation, least-privilege access to inquiries and logging that excludes form contents. Service providers are selected with security in mind and bound by contract.
No system is completely secure. If you find a vulnerability, report it through our responsible disclosure process or to hello@orbitraone.com. If a personal-data breach occurs, we will notify the supervisory authority and affected individuals where the law requires.
16Complaints and supervisory authorities
If you are concerned about how we handle personal data, please contact hello@orbitraone.com first so that we can try to resolve the matter. Our complaints procedure explains how complaints are acknowledged, investigated and escalated.
You also have the right to complain to a data-protection supervisory authority, in particular in the country where you live or work or where you believe an infringement took place.
17Changes to this policy
We update this policy when our practices, services or legal obligations change, and the version label on this page identifies the version in force. If a change materially affects how we use personal data you have already provided, we will tell you before it takes effect and ask for your consent where the law requires.