Legal
Privacy Policy
Version 2026-05-20
How ORBID collects, uses, stores and shares your personal data. Required to use the Platform.
ORBID — Privacy Policy Version 2026-05-20 ORBID OÜ (registry code 17120234, Tuukri tn 19-202, 10120 Tallinn, Estonia; "ORBID", "we") processes personal data in accordance with Regulation (EU) 2016/679 (GDPR), the Estonian Personal Data Protection Act, and other applicable EU/Estonian data-protection law. 1. Data controller and contact 1.1 ORBID is the controller of the personal data you provide directly (account profile, full name, email, role). 1.2 For personal data you upload as part of your company information (signee names, contact persons, employee counts within org structure), ORBID acts as processor on your instructions; the controller is your company. 1.3 Data protection contact: privacy@orbid.one. 2. Categories of personal data we process 2.1 Account data: full name, email, role, role in company, last sign-in, IP address at signup and at material consent events. 2.2 Company profile data: legal name, registration number, VAT, headquarters country, service regions, capacity, team size, organisation structure, founded year, references, licenses, machinery, insurances, revenue figures. 2.3 Platform activity data: tenders posted, offers submitted, interests, questions, contracts, meetings, notifications. 2.4 Audit data: Terms of Service acceptances (kind, version, timestamp, IP, user agent); admin moderation actions. 2.5 Communications: in-platform notifications, email sent through our email provider (currently SendGrid stub). 3. Purposes and legal bases 3.1 Operating the Platform — performance of contract (Article 6(1)(b) GDPR). 3.2 Verifying companies, screening, fraud and AML compliance — legitimate interests (Article 6(1)(f)) and compliance with legal obligations (Article 6(1)(c)). 3.3 MERIT score computation and tender matching — performance of contract and legitimate interests. 3.4 Account moderation and audit log — legitimate interests in maintaining platform integrity. 3.5 Service communications (notifications, e-sign envelopes, password resets) — performance of contract. 3.6 Marketing communications (orbid.one newsletter) — consent (Article 6(1)(a)); revocable at any time. 4. Recipients 4.1 Other ORBID users — strictly limited to the anonymity-aware model: identities are exchanged only on award, MERIT signals are computed server-side and exposed only as scores, asker identities are hidden in public Q&A. 4.2 ORBID staff (administrators) — only as necessary to operate the Platform, with all admin actions captured in the audit log. 4.3 Subprocessors: Supabase (Frankfurt, EU) for database and authentication; Vercel (EU edge) for hosting; SendGrid or successor email provider for transactional email; DocuSign or successor for e-signature; Anthropic / Claude API for AI assessment of company verification and tender review. A current list is available on request. 5. International transfers 5.1 ORBID's primary infrastructure is hosted in the EU (Supabase Frankfurt, Vercel EU edge). Where a subprocessor processes data outside the EEA (e.g., Anthropic in the US), the transfer is governed by the European Commission's Standard Contractual Clauses (Decision 2021/914). 6. Retention 6.1 Account and profile data — for the duration of the account plus seven (7) years after termination, as required by the Estonian Accounting Act and Law of Obligations Act. 6.2 Audit log and ToS acceptance records — seven (7) years after the event. 6.3 Notifications — twelve (12) months from creation, then anonymised counters retained for analytics. 6.4 Uploaded documents — until the user / company deletes them, subject to the seven-year retention obligation above. 7. Your rights 7.1 You have the right to access, rectify, erase, restrict processing, port your data, and object to processing. 7.2 To exercise any of these rights, email privacy@orbid.one or use the in-app data request form (forthcoming). 7.3 You have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or your national supervisory authority. 8. Cookies and similar technologies 8.1 ORBID uses essential cookies necessary for authentication and session management. No third-party analytics or advertising cookies are set without your prior consent. 9. Security 9.1 ORBID employs industry-standard measures including TLS in transit, encryption at rest, row-level security, principle of least privilege for admin access, and a full audit log of administrative actions. 9.2 Personal data breaches are reported to the supervisory authority within 72 hours where required under Article 33 GDPR. 10. Changes to this policy 10.1 We notify you of material changes via the in-app notification system and prompt re-acceptance on next login. — ORBID OÜ · Registry code 17120234 · Tuukri tn 19-202, 10120 Tallinn, Estonia · VAT EE102660451