Legal

Privacy Policy

Last updated: 2026/10/01 Version: 1

1. Who We Are

This Privacy Policy explains how Smotics - Unipessoal, Lda ("we", "us" or "our") processes personal data in connection with the Orbitar SaaS platform.

Controller contact details:

  • Legal name: Smotics - Unipessoal, Lda
  • Tax identification number: 508871751
  • Registered office: Estrada da Garganta, Quinta Saude Rio Seco, 8005-130 Faro, Portugal
  • Email: geral@smotics.pt
  • Data protection contact: geral@smotics.pt

As of this date, we have not appointed a dedicated Data Protection Officer (DPO). Data protection matters are handled by our representative/legal team through the contact channel above.

This policy is designed to align with:

  • Regulation (EU) 2016/679 (GDPR)
  • Portuguese data protection law (Law no. 58/2019)
  • the Portuguese ePrivacy framework, including Law no. 41/2004, as amended, for cookies and electronic communications

This policy is intended for platform users and tenant representatives. It does not replace each tenant's own privacy notice addressed to its customers, employees, suppliers and other entities.

2. Scope and Roles Under the GDPR

Orbitar is a multi-tenant SaaS platform with logical isolation between tenants, through separate database schemas or a separate database per tenant.

In this context:

  • We primarily act as Processor in relation to tenant business data.
  • Each tenant (customer company) acts as Controller of the personal data it decides to collect and process on the platform.
  • We act as Controller in relation to limited data we need for our own purposes, such as account administration, billing, service security, abuse prevention and compliance records.
  • Some optional features, such as artificial intelligence ("AI") agents and voice transcription, may process personal data on behalf of a tenant when activated and configured by that tenant.

3. Categories of Data

3.1 Data we control directly

  • Account and identity data: name, business email, username and role.
  • Authentication and security data: login metadata, IP address, browser information, session events and security/audit records.
  • Commercial data: subscription, billing and support history.
  • Usage preferences: basic interface settings, such as light/dark theme, sidebar size and other customisations saved to improve the user experience.

3.2 Data controlled by tenants (processed by us on their behalf)

Tenants may store personal data relating to their own entities, including for example:

  • customers/consumers
  • employees/candidates
  • suppliers/partners
  • other business contacts

The specific categories and purposes are defined by each tenant, not by us.

When a tenant uses AI or voice transcription features, processed data may also include:

  • messages, prompts, responses and conversation metadata with AI agents
  • documents, images, attachments or excerpts used as context for AI agents
  • embeddings, memories, notes or knowledge sources associated with agents, where configured by the tenant
  • audio and transcripts generated during voice transcription sessions
  • technical execution metadata, such as provider, model, token count, duration, errors and request identifiers

3.3 Google user data and OAuth

Orbitar offers two separate, optional Google OAuth features:

  • Google account authentication: Orbitar requests the openid and email scopes. We access the Google account's stable identifier, email address, email-verification status and identity issuer solely to link the Google identity to an existing Orbitar user, authenticate that user and keep the platform account email aligned with the linked Google account. We do not request the Google profile scope for this feature.
  • Gmail sending: when a tenant administrator explicitly connects a Google mailbox as an outgoing email configuration, Orbitar additionally requests https://www.googleapis.com/auth/gmail.send. This permission is used only to send messages created or authorised by the tenant through the connected mailbox. Orbitar does not use this permission to read, list, modify or delete inbox messages, contacts, Google Drive files or calendar data.

For Google account authentication, Orbitar stores the stable Google account identifier, email address, issuer, connection date and last-login date in the relevant tenant. It does not retain the Google authorization code, access token, refresh token or ID token after authentication is completed.

For an outgoing Gmail configuration, Orbitar stores the connected mailbox address, granted scopes, token expiry information and the OAuth access and refresh tokens needed to send authorised email. Tokens are encrypted within the relevant tenant's data schema, access is restricted to the email-delivery service and the credentials are removed locally when the mailbox is disconnected. Orbitar also attempts to revoke the Google authorization when the connection is removed.

Google user data is not sold, used for advertising or used to train general-purpose AI models. We do not disclose it to unrelated third parties. It may be processed by service providers acting on our behalf only where necessary to host, secure and operate Orbitar, or disclosed where required by law. Platform account and audit data follow the retention rules in section 9; a disconnected Google identity record is removed, although an email address retained as part of the Orbitar user account remains subject to the platform account retention period.

Users can disconnect their Google identity from their Orbitar profile, and tenant administrators can disconnect an outgoing Gmail configuration. Users can also revoke Orbitar's access from their Google Account permissions. Privacy and deletion requests may be sent to geral@smotics.pt.

Orbitar's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

4. Purposes and Legal Bases

When acting as controller, we rely on:

  • Art. 6(1)(b) GDPR (contractual necessity): providing account access, authentication and the essential service.
  • Art. 6(1)(c) GDPR (legal obligation): legal, accounting and compliance duties.
  • Art. 6(1)(f) GDPR (legitimate interests): platform security, fraud prevention, service reliability and incident response.
  • Art. 6(1)(a) GDPR (consent): only where legally required for non-essential processing.

When acting as processor, processing is carried out in accordance with the tenant's instructions and the Data Processing Agreement (DPA).

AI features are intended for operational support, search, response generation, summarisation, information extraction, transcription and assisted automation. Unless specifically agreed by contract, we do not use the platform to make solely automated decisions producing legal or similarly significant effects on data subjects.

5. Cookies and Similar Technologies

We use cookies and similar technologies necessary for the platform to operate securely and reliably, including authentication, session continuity, CSRF protection, technical device/browser identification and security.

The essential cookies currently used by the platform include:

  • orbitar_sessionid: maintains the authenticated session
  • orbitar_csrftoken: helps protect forms and requests against CSRF
  • orbitar_device: technically identifies the browser/device for security, support and session management

Important:

  • The platform does not provide an optional cookie consent centre for essential service cookies.
  • Acceptance of these necessary cookies is a condition of accessing and using the platform.
  • If a user does not accept the necessary cookies, they will not be able to authenticate or use the service.

If non-essential cookies are introduced in the future, we will update this policy and apply any legally required consent mechanism.

The platform may also use browser local storage for technical state or interface preferences, such as an editor's current page, light/dark theme or sidebar size. These preferences may also be stored in the user's account to synchronise them between sessions. This storage is not used for behavioural advertising.

6. Sources of Personal Data

We receive personal data from:

  • users directly, through account creation, profile updates and support contacts
  • tenant administrators, through user provisioning and management
  • technical systems, through security and operations logs and limited telemetry

7. Recipients and Sub-processors

We may disclose data to trusted providers strictly to the extent necessary to operate the service, such as:

  • hosting/infrastructure providers
  • email and notification providers
  • monitoring/logging/security providers
  • backup and disaster recovery providers
  • AI gateway/model providers, including Requesty.ai for routing through European infrastructure and OpenAI when contracted or authorised by the tenant
  • voice transcription providers, such as AssemblyAI and Deepgram, using configured European endpoints

All sub-processors are bound by contractual confidentiality and data protection obligations.

Current sub-processors:

Sub-processorPurposeData processedRegion/transfers
PTISPHosting, infrastructure, email, primary backups and monitoringData hosted on the platform, technical data, backups, logs and data necessary for sending emailPortugal/EEA
Firebase Cloud MessagingWeb push notificationsFirebase installation tokens/identifiers, technical device/browser identifiers and the minimum technical notification content necessary for deliveryGoogle/Firebase service subject to applicable data processing terms; international transfers with applicable safeguards may occur
rsync.netExternal auxiliary backupsEncrypted or protected backups according to operational configuration and technical storage metadataLocation configured in Zurich, Switzerland
Requesty.aiAI gateway/modelsPrompts, responses, attachments or excerpts sent to models, technical execution and usage metadataEuropean infrastructure configured to route AI requests, with effective models and regions determined by the contracted configuration
OpenAIAI models for agents and assisted featuresPrompts, responses, attachments or excerpts sent to models, technical execution and usage metadataOptional provider, used only when configured/authorised by the tenant; may involve transfer outside the EEA, including to the United States, with applicable safeguards
AssemblyAIVoice transcriptionAudio transmitted in real time, transcripts and technical session metadataConfigured European endpoint
DeepgramVoice transcriptionAudio transmitted in real time, transcripts and technical session metadataConfigured European endpoint

The detailed legal designation of sub-processors is included in the DPA. The list may be updated when relevant sub-processors are added, replaced or removed. Material changes are communicated to customers under the DPA.

Regarding FCM, the platform uses the service to deliver push notifications to subscribed browsers/devices. Firebase indicates that FCM uses Firebase Installation IDs to determine which devices should receive messages and retains those identifiers until deletion is requested by the Firebase customer, after which they are removed from active and backup systems within 180 days. Functional notification content must be limited to what is necessary to alert the user and direct them to the platform.

For AI and transcription features configured for European processing, the platform uses European providers and configurations designed to support compliance with the GDPR, the European Union Artificial Intelligence Act and other applicable European legislation. This compliance also depends on service configuration, tenant instructions and the actual use by authorised users.

Some tenants may choose AI providers involving the processing of or access to data outside the EEA, including OpenAI. In those cases, use of that provider must result from a contractual configuration, authorisation or instruction by the tenant, and international transfers are handled under the following section.

8. International Transfers

If personal data is transferred outside the EEA/United Kingdom, we apply appropriate safeguards, such as:

  • adequacy decisions, or
  • Standard Contractual Clauses (SCCs) and supplementary measures, where necessary.

When providers with a location configured in Switzerland are used, such as rsync.net for auxiliary backups in Zurich, we treat that location as a transfer to a country recognised by the European Union as providing adequate protection, without prejudice to verification of the applicable contractual terms.

When a tenant contracts or authorises the use of OpenAI as an AI provider, data sent to models may be processed outside the EEA, including in the United States. In such cases, we apply the contractual and legal safeguards applicable to international transfers, including SCCs where required, and limit the data sent to what is necessary to perform the configured feature.

9. Retention

We retain personal data only for as long as necessary for the relevant purpose and to comply with legal obligations.

Default retention logic:

  • platform account data: for the duration of the contract and an additional period where required by legal/compliance obligations
  • security and access records (login, logout, failed login attempts): while necessary for security, abuse prevention, incident investigation, audit, defence of legal rights or legal obligations, with periodic review
  • change history records (model change history): while necessary for operational integrity, traceability, audit, defence of legal rights or legal obligations, with minimisation or anonymisation where feasible
  • audit records (access, creation, editing and deletion of data): while necessary for security, traceability, audit, defence of legal rights or legal obligations, with periodic review
  • AI execution records and metadata: while necessary for security, debugging, billing, audit, abuse prevention, operational improvement or contractual/legal compliance
  • voice transcription audio: processed for real-time transcription and not retained by the platform beyond what is necessary for the session, unless the tenant expressly stores the content or transcript in a platform feature
  • backup copies: retained for up to 15 days
  • tenant business data: according to the tenant's instructions and contractual terms

Additional lifecycle rules:

  • if an individual user leaves a tenant, the user's identifying information is masked where applicable, preserving the integrity of historical records
  • if a tenant ends the service, tenant data is deleted and remaining backups are removed within a maximum of 15 days, unless retention is required by law

After the retention periods, data is deleted or anonymised where feasible.

10. Security Measures

We apply appropriate technical and organisational measures, including:

  • encryption in transit (TLS)
  • tenant isolation controls (separate schemas and access boundaries)
  • role-based access controls
  • least-privilege administrative access
  • audit logs and monitoring of security events
  • backup and restore procedures
  • internal confidentiality obligations and confidentiality agreements for authorised personnel
  • technical records and usage controls for AI and transcription features, including tool limitation, call traceability and abuse protection

No system can be guaranteed to be 100 per cent secure, but we continuously improve security controls based on risk.

11. Support Access by Our Team

Authorised personnel may access tenant data only when necessary for legitimate operational reasons, such as:

  • support requested by the tenant
  • incident investigation
  • maintenance/security tasks

Such access is restricted, logged and subject to confidentiality commitments.

12. Data Subject Rights

Under the GDPR, data subjects may have rights of access, rectification, erasure, restriction, portability and objection.

Routing of requests:

  • For data controlled by tenants, requests should primarily be directed to the relevant tenant (controller).
  • We assist tenants with fulfilling valid requests in accordance with the DPA.
  • For data we control directly, requests may be sent to geral@smotics.pt

Data subjects may also lodge a complaint with their supervisory authority, including the CNPD in Portugal.

When a person interacts directly with an AI agent on the platform, the interface must make clear that the interaction is with an AI agent and not a person, unless this is evident from the context.

13. Tenant Responsibilities

Each tenant, as controller, is responsible for:

  • establishing a lawful basis for processing
  • providing privacy notices to its own entities/data subjects
  • managing consent obligations where required
  • responding to data subject requests relating to tenant-controlled data
  • configuring and using AI agents, voice transcription, tools and knowledge sources lawfully, proportionately and consistently with its own obligations
  • not using AI agents for solely automated decisions producing legal or similarly significant effects, nor for high-risk cases under the European Union Artificial Intelligence Act, without a specific agreement and appropriate legal, technical and organisational controls

14. Changes to the Policy

We may update this policy to reflect legal, technical or commercial changes.

For material updates, we will:

  • publish the new version and date
  • require acceptance where legally or contractually necessary before continued use of the platform

15. Contact

For privacy questions:

  • Email: geral@smotics.pt
  • Postal address: Estrada da Garganta, Quinta Saude Rio Seco, 8005-130 Faro, Portugal

For complaints in the EU/EEA in Portugal:

  • Comissão Nacional de Proteção de Dados (CNPD)