Skip to content
Orbitra
Product Trust Responses Company Guides
Sign in Book a walkthrough
Product Trust Responses Company Guides Sign in Book a walkthrough

Privacy Policy

How Orbitra handles personal information.

This policy explains how Orbitra Security, a Canadian company, collects, uses, shares, and protects information from website visitors, prospects, business contacts, product support and automatic reports, and Microsoft Teams connection, setup and help interactions.

Effective date
September 7, 2026
Company
Orbitra Security, a Canadian company
Contact
hello@orbitrasecurity.com
On this page Scope Information we collect Microsoft Teams interactions How we use information How we share information Cookies and local storage Automatic application reports Retention Your choices Contact

Scope

This policy applies to information collected through the Orbitra public website, demo requests, email conversations, event follow-ups, related business communications, product support, automatic application reports, and Microsoft Teams connection, setup and help interactions. Orbitra Security is a Canadian company and handles personal information in accordance with applicable Canadian privacy requirements.

Customer use of an Orbitra product, pilot, proof of concept, or paid service may also be governed by a separate agreement, order form, data processing addendum, or security schedule.

Information We Collect

We may collect information you provide directly, including name, work email, company, team size, message content, and any details you choose to include in a demo request or email.

We may also collect limited technical information from website visits, such as browser type, device type, approximate region, referring page, and pages viewed, when needed to operate, secure, or improve the site. If you accept optional visitor analytics, our analytics and visitor-identification providers may also associate a visit with business or company information available to them.

If you participate in a demo, pilot, or evaluation, we may receive business contact information, implementation context, and security or identity environment details that you authorize us to review.

Microsoft Teams Interactions

When enabled for your organization, Orbitra Response uses Microsoft Teams for setup guidance and selected workspace notifications. Setup and help interactions can occur before you sign in to or connect an Orbitra workspace.

Microsoft may supply organization, user, team, channel, conversation and message identifiers, display names, message content, installation or removal events, and technical authentication and delivery information. Orbitra uses this information to authenticate requests, process supported setup steps, choose a fixed guidance reply, check authorized connections and prevent duplicate messages.

Guidance replies contain fixed instructions. They do not use a model to interpret your message, grant workspace access, confirm a successful connection or authorize a response. A reply may show a cleaned and shortened Microsoft-provided display name to identify who added the app or requested help. This display name is not proof of workspace administrator authority.

Orbitra saves the minimum reply destination and any displayed sender name in encrypted guidance records. The original callback body, authentication token, message text and setup code are not saved in those records. Hashes, timestamps, processing status and available provider message references support duplicate prevention and reconciliation. See guidance retention for the cleanup thresholds.

The public Teams callback and setup/help processing use US services, including for India workspaces. Connection and alert records use the workspace's home region; shared ownership and authorization metadata use US services. Selected notifications may contain identity or incident context visible to people with access to the destination channel. Microsoft Teams and Azure Bot Service also process information under their own terms and your organization's arrangements.

See Teams data use and connection support for setup, disconnect and data-request guidance.

How We Use Information

  • Respond to demo requests, questions, and business inquiries.
  • Schedule meetings and provide product information.
  • Operate, maintain, secure, and improve the website.
  • Understand customer needs and evaluate product fit.
  • Understand website engagement and follow up with potential business customers when optional visitor analytics are accepted.
  • Detect, prevent, and investigate misuse, security issues, or fraud.
  • Comply with legal, accounting, contractual, and compliance obligations.

How We Share Information

We do not sell personal information. We may share information with service providers who help us operate the website, communicate with prospects, schedule demos, host systems, provide email, or support security and business operations.

We may disclose information if required by law, to protect rights and safety, to investigate misuse, or as part of a business transaction such as a merger, financing, acquisition, or asset transfer.

Cookies and Local Storage

The public website uses local storage to remember whether you accepted or declined the cookie and trust notice. We may use essential cookies or similar technologies for site reliability, security, and basic preference storage.

If you accept, Orbitra loads optional visitor analytics and identification technology provided through Instantly and Leadsy. Their technology and supporting service providers may process technical, engagement, approximate location, and business-identity signals associated with the visit. If you decline or have not made a choice, Orbitra does not load this visitor tag.

You can clear local storage or cookies through your browser settings to reset your choice. Some site preferences may reset when you do this.

Automatic Application Reports

Orbitra automatically reports selected application failures to its internal support service in the United States, including failures during sign-in and account recovery. This reliability reporting operates independently of optional analytics choices and Do Not Track settings.

Reports use a restricted set of technical fields: application version, error category, a page category without record identifiers or query strings, time, and, when available, an application file reference, source position, HTTP status and request reference. They do not include arbitrary error messages, console contents, passwords, access tokens, setup codes, webhook signatures, form entries or chat content. Authenticated reports may be linked to your verified Orbitra user and workspace. Public recovery reports are sent without account credentials.

Automatic reports expire 14 days after they are first recorded; additional occurrences do not extend that expiry. Duplicate-detection receipts expire after one day, and temporary rate-limit records use hashed source-address keys. Expired records are removed by scheduled cleanup. Access to the report inbox requires Orbitra platform administration permission. See Data use for processing locations and the scope of these retention periods.

A separate issue report you choose to submit can include your description and an attachment you explicitly provide.

Retention and Security

We keep information for as long as needed for the purposes described in this policy, including responding to requests, maintaining business records, meeting legal obligations, and protecting our rights.

We use reasonable administrative, technical, and organizational safeguards designed to protect information. No internet service or email communication can be guaranteed to be completely secure.

Your Choices and Rights

You may ask us to access, correct, update, delete, or limit use of personal information you have provided to us, subject to legal, security, and contractual limits.

You can also ask us to stop sending non-transactional messages. We may still send administrative, security, or relationship-related communications when appropriate.

For a request about a Teams setup or help interaction, including one without an Orbitra account, contact hello@orbitrasecurity.com. Include the approximate time with time zone and enough context to identify the interaction. Do not send passwords, setup codes, access tokens or unredacted chat content. Additional information may be needed to verify the request and locate the records.

Disconnecting a Teams connection stops Orbitra from using that connection. Removing the app in Teams is a separate action. Neither action recalls provider-held messages or automatically deletes every historical record. Public guidance records can exist without a linked Orbitra account, so deleting a workspace alone does not identify every such interaction.

Contact

For privacy questions or requests, contact Orbitra Security at hello@orbitrasecurity.com.

Last updated: September 7, 2026

Orbitra

Identity threat detection and approved response for Microsoft Entra ID and Azure. Find risky access, act with named approval, and verify supported changes.

© 2026 Orbitra Security. All rights reserved.
Product Product tour Response actions Workflow and coverage Works alongside Microsoft Evidence Plans FAQ Book a response walkthrough
Learn Guides Glossary Field notes For lean security teams Business Premium and E3 Evidence for insurers
Company and trust About Contact Trust Vulnerability disclosure Privacy Terms Data use