1. Controller
AdventureKingz GmbHUnter den Linden 7
38112 Braunschweig
Germany
support@orbitone.io
2. Data processed
Depending on use, we process identity and contact data, account and authentication data, tenant roles, settings, device and token identifiers, security logs, support communications, and contract, billing and payment status data. Workspace content is processed to provide the selected functions.
3. Purposes and legal bases
- Registration, authentication and contract performance: Art. 6(1)(b) GDPR,
- security, abuse prevention, troubleshooting and reliable operation: Art. 6(1)(f) GDPR,
- accounting and statutory retention: Art. 6(1)(c) GDPR,
- optional communication or functions where required: Art. 6(1)(a) GDPR.
Processing necessary for the contract is not presented as voluntary consent. Consent can be withdrawn prospectively.
4. Tenant responsibility
Organisations decide which users, permissions and content are used in their tenant. Where OrbitOne processes personal content solely on a business customer's instructions, the customer is generally controller and OrbitOne processor. A data processing agreement can be concluded.
5. Hosting and development in Germany
The core platform is developed and operated in Germany; primary application and storage systems use German data-centre locations. HTTPS, tenant separation, role controls and logging support privacy-conscious operations. Optional third-party integrations may use additional locations.
6. Recipients and optional services
Hosting, email and infrastructure providers receive only data required for their purpose. Stripe may process payments. Apple, Google, Microsoft or other enabled providers may process push or voluntary sign-in data. Third-country transfers follow Art. 44 et seq. GDPR, including adequacy decisions or appropriate safeguards.
7. Retention
Account and contract data are stored for the contract term. Content is removed after announced export, grace and deletion periods unless legal duties or legitimate security needs require retention. Accounting documents follow statutory periods; inactive tokens and device identifiers follow operational cleanup periods.
8. Rights
Subject to legal requirements, data subjects have rights of access, rectification, erasure, restriction, portability and objection under Arts. 15–21 GDPR. Contact support@orbitone.io. Complaints may be made to a supervisory authority, generally the State Commissioner for Data Protection of Lower Saxony.
9. Security and changes
We use appropriate technical and organisational measures. Users remain responsible for protecting credentials and granting minimum necessary access. Material changes to this notice will be communicated appropriately. The German version is authoritative; this English text is a convenience translation.