Legal

Privacy Policy

How Orbiant handles personal information · Version 1.3 · Published 29 July 2026

This Policy explains how Orbiant Group Pty Ltd handles personal information in connection with its websites, Platform, support and business operations.

Orbiant handles personal information in line with the Australian Privacy Principles where they apply.

1. Information we collect

  • Account and identity information, such as name, business email, role, organisation and authentication details.
  • Workspace and usage information, including tenant, entity and permission records, messages, decision records, audit events and support requests.
  • Business information supplied by users or retrieved from authorised connected systems, which may include information relating to customers, suppliers, staff counts or business contacts.
  • Evidence URLs, references and descriptions. Orbiant does not store the external source document as part of standard V1.
  • Technical and security information, such as device, browser, IP address, login events, error logs and security events.
  • Billing and subscription information. Payment card data is generally processed by the payment provider rather than stored by Orbiant.
  • Website and product analytics collected through privacy-configured analytics tools.

2. How we collect information

We collect information directly from users, from organisations and advisors that invite users or provide authorised data, through authorised integrations such as Xero, from service providers, and automatically when websites or the Platform are used.

3. Why we use information

  • Provide, secure, maintain and improve the Platform.
  • Authenticate users, manage roles, tenants, entities and permissions.
  • Apply deterministic rules and thresholds and display Priority Issues and Connected Risks.
  • Support monthly reviews, notifications, messaging, evidence requests, audit history and exports.
  • Provide support, billing, customer administration and service communications.
  • Detect, investigate and respond to fraud, misuse, incidents and security risks.
  • Comply with law, enforce agreements and resolve disputes.
  • Develop de-identified or aggregated insights that do not reasonably identify a person or customer.

4. AI-supported features

Orbiant may use an AI-supported retrieval assistant to answer questions about the Platform, explain displayed information, provide examples or navigation links, and generate draft text summaries from structured Platform data. Standard exports remain CSV and Excel; formatted or bespoke reports are governed by the Service Schedule. The assistant does not determine rule outcomes, thresholds, severity, Priority Issues, Connected Risks or decisions and does not give recommendations or professional advice.

The assistant may use authorised context from the user’s workspace and Platform documentation where required to answer the query or create the requested report. Orbiant applies access controls designed to restrict the assistant to information available to the requesting user. Users should avoid submitting unnecessary sensitive personal information.

5. Xero

When authorised, Orbiant uses read-only Xero access and processes supported information required for Platform features. Orbiant does not write data back to Xero. Connection credentials and tokens are protected and managed according to the connection status and type of disconnection selected.

6. Evidence links

Orbiant stores the evidence URL or reference and any description supplied by a user. The source file remains with the external provider and document owner. Access to, retention of and security for the source document are governed by the external service and permissions selected by the Customer or document owner.

7. Who we disclose information to

Orbiant does not sell personal information. We disclose personal information only to authorised users according to their permissions, to service providers where necessary to operate and secure the Platform, or where required or authorised by law.

8. Overseas processing

Production customer data is hosted in AWS Sydney, Australia. Approved providers or support personnel may process or access limited information from overseas where global service providers operate support, security, analytics or AI infrastructure. Orbiant will take reasonable steps appropriate to the circumstances to protect personal information.

9. Hosting and security

Production data is hosted in AWS Australia (Sydney) and encrypted in transit and at rest. Controls include role-based access, tenant separation, MFA, secrets management, controlled and logged production access, monitoring, incident response and backup processes. No service can guarantee absolute security.

Current backup settings include daily backups retained for approximately 35 days and monthly backups retained for approximately 365 days, encrypted and protected through AWS Backup controls in Australia.

10. Retention and deletion

Orbiant retains information for as long as reasonably required to provide the service, maintain auditability, support customers, comply with law, resolve disputes and protect security. Retention depends on the record, account status, contractual requirements and backup cycles. When Orbiant no longer needs personal information for a permitted purpose, it will take reasonable steps to destroy it or ensure it is de-identified, unless retention is required or authorised by law or a court or tribunal order.

After account closure or a valid request, Orbiant may delete active data, de-identify information, allow backup copies to expire under normal backup cycles, and retain limited records required for legal, audit, security, billing or dispute-resolution purposes.

11. Access and correction

A person may request access to or correction of personal information Orbiant holds about them by contacting privacy@orbiant.co. Orbiant may need to verify identity and may refuse or limit a request where permitted by law, explaining the reason where required.

12. Marketing

Users may opt out of marketing emails using the unsubscribe facility or by contacting Orbiant at hello@orbiant.co. Service, security, billing and account communications may still be sent where necessary.

13. Data incidents

Orbiant maintains an incident-response process to contain, investigate, assess and remediate suspected data incidents. Where the law requires, Orbiant will notify affected individuals, customers and the Office of the Australian Information Commissioner.

14. Privacy Complaints

Privacy questions, requests or complaints may be sent to privacy@orbiant.co. Please provide sufficient information for Orbiant to investigate the matter. Orbiant will acknowledge the complaint within a reasonable time, work in good faith with the complainant to seek a resolution, and aim to provide its response within 30 days.

15. Changes

Orbiant may update this Policy as its services, providers or legal obligations change. Material changes will be notified through the Platform, email or website where reasonable. The effective date at the start of the Policy identifies the current version.

16. Contact

Orbiant Group Pty Ltd

ABN 17 694 330 633

Privacy email: privacy@orbiant.co

© 2026 Orbiant Group Pty Ltd · An Australian company. All rights reserved.