Privacy Policy
How Orbiant collects, uses, stores, protects and discloses personal information in connection with the Orbiant platform, website and related services.
1. Who we are
Orbiant is operated by Orbiant Group Pty Ltd (ABN 694 330 633), based in Queensland, Australia.
Orbiant provides a deterministic business review and decision-support platform for advisory firms and business users. The platform helps users assess structured business inputs against documented rules, surface priority issues for review, and record decisions, actions and supporting context.
For privacy questions, requests or complaints, contact us at:
Email: privacy@orbiant.co
2. What this policy covers
This Privacy Policy explains how Orbiant collects, uses, stores, protects and discloses personal information in connection with the Orbiant platform, website and related services.
It applies to Orbiant users, including advisors, client users, direct business users, invited users and people who interact with Orbiant through support, sales or website channels.
This policy should be read together with Orbiant’s Customer Terms, the Orbiant V1 Service Schedule, any applicable Order Form, and the Advisor Addendum where the customer is an advisor or advisory firm.
3. Customer responsibility for data provided to Orbiant
Customers and authorised users are responsible for ensuring they have authority to provide information to Orbiant, invite users, connect data sources, upload files, and enter business or entity information into the platform.
Where an advisor uses Orbiant for a client, the advisor is responsible for ensuring it has the authority or consent required to enter or connect client information and to permit Orbiant to process that information for the authorised purpose.
Users must not upload excluded, unnecessary or sensitive personal information to Orbiant unless Orbiant has expressly requested it in writing for a lawful purpose.
4. What information we collect
Orbiant collects the minimum information reasonably required to operate the platform, support customers, maintain security, and meet legal and operational obligations.
Orbiant does not intentionally collect sensitive personal information and the platform should not be used to upload or store sensitive personal information.
4.1 Tenant and firm information
Orbiant may collect tenant and firm information, including:
- Firm or business name
- Business contact details
- Billing contact details
- Workspace configuration
- Tenant type
- Timezone
- Subscription and account status
- Advisor/client relationship settings
4.2 User information
Orbiant may collect user information, including:
- Name
- Work email address
- User role
- Authentication metadata
- Access permissions
- Invitation status
- Account activity
- Audit activity within the platform
4.3 Entity information
Orbiant may collect entity information, including:
- Entity name
- Legal name
- ABN or ACN, where applicable
- Industry
- Revenue model
- Headcount
- Director count
- Entity count
- Active registration count
- Entity timezone
- Optional governance or business context fields
4.4 Financial and business inputs
Orbiant may collect or process structured business inputs through CSV upload, manual entry, authorised read-only Xero integration, or other approved input methods.
These inputs may include:
- Cash balance
- Monthly revenue
- Cost of goods sold
- Operating expenses
- Aggregate monthly payroll expense
- Accounts receivable
- Receivables over 60 days
- Top customer revenue percentage
- Derived annual revenue
- Business context fields
- Governance or statutory status fields
Orbiant does not require employee-level payroll data.
4.5 Evaluation, decision and audit records
Orbiant may collect and store evaluation, decision and audit records, including:
- Input snapshot references
- Ruleset and threshold versions
- Evaluation outputs
- Priority rankings
- Top 5 and Full Register outputs
- Rule explanations
- Decision records
- Action owners
- Review dates
- Notes
- Evidence references
- Export records
- Audit logs showing user, timestamp, action, tenant and entity context
4.6 System, security and support information
Orbiant may collect system, security and support information, including:
- Security logs
- Access logs
- Error logs
- Integration status logs
- Support tickets
- Correspondence with users
- Device and browser metadata
- Information required to investigate faults, misuse or security incidents
5. Information Orbiant does not collect
Orbiant V1 must not request, store, process or require the following information:
- Tax File Numbers
- Dates of birth
- Identity documents
- Employee-level payroll records
- Payslips
- Superannuation details
- Salary-by-person data
- Employee bank details
- Personal tax records
- Individual credit information
- Health information
- Unnecessary residential addresses
- Unnecessary personal contact details
- Other sensitive personal information not required for the platform
If a user uploads excluded, unnecessary or sensitive information, Orbiant may ask the user to remove it and may delete the relevant file or data where appropriate.
6. How we collect information
Orbiant may collect information through:
- Account creation
- User invitations
- User input
- CSV uploads
- Manual entry
- Authorised read-only Xero connections
- Advisor-provided data
- Customer support interactions
- Platform activity
- System logs
- Security monitoring
Orbiant does not intentionally collect personal information from third parties without authorisation.
7. How we use information
Orbiant may use information to:
- Create and manage accounts
- Authenticate users
- Manage roles and permissions
- Configure tenants and entities
- Connect authorised data sources
- Process structured business inputs
- Run deterministic evaluations
- Generate Top 5 and Full Register outputs
- Explain priority issues
- Record decisions, actions and review dates
- Maintain audit history
- Provide exports
- Send service, security and platform notifications
- Provide customer support
- Maintain platform reliability and security
- Investigate errors, misuse or incidents
- Manage billing and subscriptions
- Improve the platform
- Meet legal and operational obligations
8. Deterministic decision-support outputs
Orbiant V1 uses documented, deterministic rules to generate business review outputs.
Orbiant V1 does not use:
- AI inference
- Machine learning
- Hidden scoring
- Probabilistic ranking
- Undisclosed automated reasoning to determine priority outputs
Orbiant provides rule-based decision-support outputs for review by authorised users.
Orbiant does not make final legal, financial, employment, tax, lending, insurance, compliance or professional advice decisions.
Users remain responsible for reviewing Orbiant outputs, applying professional judgement, and deciding what action to take.
9. Direct marketing and service communications
Orbiant may use business contact details to send account and service messages, onboarding communications, security notices, product updates, billing communications, support communications and marketing communications where permitted.
Users may opt out of marketing communications.
Users cannot opt out of essential service, billing, security or legal notices.
10. Website, cookies and analytics
When you visit an Orbiant website, Orbiant may collect basic technical information such as browser type, device information, pages visited, referring website, approximate location derived from IP address, and website usage information.
Orbiant may use cookies or similar technologies to operate the website, improve user experience, understand website performance and support security.
Where required, users may manage cookie preferences through their browser or available website controls.
11. Who we share information with
Orbiant does not sell personal information.
Orbiant may share information only where reasonably required to operate Orbiant, support customers, comply with law, or protect the platform.
11.1 Authorised users
Information may be shared within a tenant according to user roles and permissions.
11.2 Advisors and clients
Where advisor/client access is enabled, information may be shared between authorised advisor users and authorised client users according to the permissions configured for that tenant or entity.
11.3 Service providers
Orbiant may share information with service providers required to operate Orbiant, including cloud hosting providers, database and storage providers, authentication providers, email delivery providers, logging, monitoring and security tools, payment and billing providers, customer support tools and professional advisers.
Service providers are only permitted to use information for the purpose of providing services to Orbiant.
11.4 Technical support access
Orbiant may use approved technical support personnel to maintain, support and improve the platform.
Production access must be controlled and limited.
Where production access is required, Orbiant will apply controls such as approval by Orbiant, least-privilege access, time-limited access where practicable, MFA where available, access logging, confidentiality obligations, secure credential handling, and restrictions on copying production data into local developer environments.
11.5 Overseas access
Orbiant’s production customer data is intended to be hosted in Australia.
In limited circumstances, approved technical support personnel located overseas may access production systems for support, maintenance, security or incident response purposes.
Any such access must be approved, controlled, logged and subject to confidentiality and data protection obligations.
Where practicable, Orbiant will identify the countries in which overseas support personnel are located.
11.6 Legal requirements
Orbiant may disclose information where required or authorised by law, regulation, court order, government authority or law enforcement request.
12. Data hosting and residency
Production customer data is intended to be hosted in Australia using Orbiant-approved infrastructure.
Orbiant does not intentionally store or back up production customer data outside Australia unless disclosed to the customer or required for an approved operational purpose.
13. Xero integration
Where a customer authorises a Xero connection:
- Xero access is read-only
- OAuth tokens are stored securely
- Tokens are deleted or revoked when the connection is disconnected
- Orbiant does not write data back to Xero
- Orbiant does not email full Xero data
- Orbiant does not intentionally log full Xero data
- Orbiant only processes the Xero data required to operate approved platform features
Customers are responsible for ensuring they have authority to connect a Xero organisation to Orbiant.
14. Security
Orbiant applies technical and organisational controls designed to protect information from misuse, interference, loss, unauthorised access, modification or disclosure.
Controls may include:
- HTTPS/TLS encryption
- Encrypted databases and object storage
- MFA for privileged access where available
- Role-based access controls
- Tenant isolation
- Secure secrets management
- No hardcoded credentials
- Controlled production access
- Access and security logging
- Backup and recovery processes
- Append-only audit records
- Restricted developer access to production data
- Incident response procedures
No platform can guarantee absolute security.
Users must also protect their accounts, use strong passwords, maintain secure devices and promptly notify Orbiant of suspected unauthorised access.
15. Data retention and deletion
Orbiant retains information for as long as reasonably required to provide the platform, support customers, maintain auditability, meet legal obligations, resolve disputes and protect security.
15.1 Retention
Indicative retention periods may include:
- Platform account and workspace data while the account is active
- Evaluation outputs, decision records and related audit history for up to 7 years
- Security and access logs for 90 days to 12 months
- Support records for the period reasonably required to manage the customer relationship
- Backup copies for the configured backup retention period
Orbiant is not intended to operate as a customer’s primary record-keeping system, document archive, accounting system, payroll system, tax record system, or legal compliance repository.
Customers remain responsible for maintaining their own source records, accounting records, employment records, tax records, governance documents and other business records outside Orbiant.
Actual retention periods may vary depending on the customer agreement, legal requirements, backup settings, operational needs, and the nature of the relevant record.
15.2 Offboarding
Customers may export available platform data before account closure using standard export features.
Additional managed export, reconstruction, reporting or handover services are excluded and may be subject to separate agreement.
15.3 Deletion
Upon request or account closure, Orbiant may delete active customer data, de-identify information where appropriate, allow backup copies to expire in accordance with backup retention cycles, and retain limited records where required for legal, audit, security, dispute resolution or legitimate business purposes.
Some records, including audit logs and security records, may be retained where necessary.
16. Data breach response
Orbiant maintains an incident response process for suspected or actual data breaches.
16.1 Containment
Where appropriate, Orbiant may disable affected accounts, revoke credentials, rotate secrets, pause integrations, restrict access, preserve logs and evidence, and take other steps to contain the incident.
16.2 Assessment
Orbiant will assess what happened, what information was involved, who may be affected, whether personal information was accessed, disclosed or lost, whether serious harm is likely, and whether notification is required.
16.3 Notification
Where required, Orbiant will notify affected customers, affected individuals and/or the Office of the Australian Information Commissioner in accordance with applicable law.
16.4 Review
After an incident, Orbiant may document root cause, corrective actions, security improvements, customer communications, and changes to controls, processes or procedures.
17. Your rights and choices
Depending on your jurisdiction and the circumstances, you may request:
- Access to personal information Orbiant holds about you
- Correction of inaccurate personal information
- Deletion of personal information, where appropriate
- Restriction of processing, where applicable
- Export of available data, where applicable
- Withdrawal of consent, where processing is based on consent
- Opt-out from marketing communications
Requests should be sent to: privacy@orbiant.co
Orbiant may need to verify your identity before responding to a request.
18. Privacy complaints
If you believe Orbiant has not handled your personal information appropriately, you may contact Orbiant at: privacy@orbiant.co
Please include enough information for Orbiant to understand and respond to your complaint.
Orbiant will acknowledge your complaint within a reasonable time and aim to respond within 30 days.
If you are not satisfied with Orbiant’s response, you may contact the Office of the Australian Information Commissioner.
19. Changes to this policy
Orbiant may update this Privacy Policy from time to time.
If Orbiant makes material changes, it will take reasonable steps to notify affected users, such as through the platform, by email or by publishing an updated version on the website.
The current version will apply from the effective date shown at the top of the policy.
20. Contact us
For privacy questions, requests or complaints:
Orbiant Group Pty Ltd
ABN: 694 330 633
Email: privacy@orbiant.co
© 2026 Orbiant. All rights reserved.