Orbinth

This notice explains what personal data Orbinth collects, why, who we share it with, how long we keep it and the rights you have under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003.

1.Who we are

1.1Orbinth Ltd (company number [Companies House number], registered office [Registered office address], United Kingdom) is the controller of the personal data described in this notice. We are registered with the Information Commissioner's Office (ICO) under reference [ICO registration reference].

1.2Questions about this notice or your data: [email protected], or write to our registered office marked "Data Protection".

1.3This notice covers visitors to orbinth.com, account holders, sub-users invited to a server, people who contact us, and people who join a waiting list. It does not cover personal data stored inside customers' servers (for example player names in game logs); for that data the customer is the controller and we are their processor, as explained in section 8.

2.The personal data we collect

CategoryExamplesSource
Identity and contactName, email address, company name (business customers)You
Account and securityPassword (stored only as a salted hash), role, sub-user permissions, login timestampsYou; generated by us
Billing and transactionsStripe customer ID, invoice history, amounts, VAT status, payment status. We never receive full card numbers.You; Stripe
Service dataServer names, plans, region, IP address and port allocations, startup settings, backup names, power and file actions, console commands you sendYou; our nodes
Support and communicationsTicket subjects and messages, contact form submissions, emails you send usYou
Technical and log dataIP address, browser type, device information, request timestamps, pages visited, error logsAutomatically
Waiting listEmail address and the product you asked to be notified aboutYou

2.1We do not collect special category data (such as health or political opinions) and ask you not to send it to us.

3.Why we use your data and our lawful bases

Under the UK GDPR we must have a lawful basis for each use of your personal data. These are:

PurposeData usedLawful basis
Creating and managing your account, provisioning and running your servers, providing the control panelIdentity, account, service dataPerformance of a contract (Art. 6(1)(b))
Taking payment, issuing invoices, chasing unpaid balancesIdentity, billingPerformance of a contract; legal obligation for tax and accounting records (Art. 6(1)(c))
Sending service emails: order confirmations, renewal reminders, payment failures, maintenance and incident noticesIdentity, service dataPerformance of a contract; legal obligation (subscription reminder requirements)
Answering support tickets and enquiriesIdentity, support data, service dataPerformance of a contract; legitimate interests in helping prospective customers (Art. 6(1)(f))
Keeping the platform secure: detecting abuse, fraud, attacks and unauthorised access; activity logs in the panelTechnical, service and account dataLegitimate interests in protecting our systems and customers; legal obligation
Improving the Services using aggregated usage statisticsTechnical data (aggregated)Legitimate interests in running and improving our business
Telling you when a product you joined the waiting list for launchesWaiting-list emailConsent (Art. 6(1)(a)); withdraw any time
Complying with law, responding to lawful requests from courts, regulators and law enforcementAnyLegal obligation; legitimate interests

3.1Where we rely on legitimate interests we have considered the impact on you and concluded that our interests are not overridden by your rights. You can object at any time (section 9).

3.2Marketing. We only send marketing emails with your consent, or about our own similar services where you have bought from us and have not opted out (the "soft opt-in" under PECR). Every marketing email includes an unsubscribe link.

3.3We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.

4.Who we share data with

4.1We never sell personal data. We share it only with the following categories of recipient, and only as needed:

RecipientPurposeLocation
Stripe Payments UK Ltd / Stripe Inc.Payment processing, fraud prevention, invoicingUK, EU and USA
Data-centre and node providers hosting our platform and game serversRunning the Services in the region you chooseUK, EU, USA, Singapore, Australia (by your region choice)
Database hosting provider (MongoDB)Storing account and service recordsUK or EU
Transactional email providerDelivering account and service emailsUK or EU
Professional advisers (accountants, lawyers, insurers)Running our businessUK
Courts, regulators, law enforcementWhere required by law or to protect rights and safetyAs applicable

4.2If we sell or reorganise our business, personal data may be transferred to the new owner, who must use it in accordance with this notice.

4.3Community spaces such as our Discord server are run by third parties under their own privacy policies; joining them is optional.

5.International transfers

5.1Your account data is stored in the United Kingdom or the European Economic Area, which the UK recognises as providing adequate protection.

5.2If you choose a server region outside the UK or EEA (for example the United States, Singapore or Australia), the data on that server and the connection logs for it are processed there. Where we transfer personal data to a country without a UK adequacy decision we use the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, plus additional safeguards where needed. You can ask us for a copy of the relevant safeguards.

6.How long we keep your data

DataRetention
Account detailsWhile your account is open, then 30 days after you ask us to close it (so it can be restored if closed by mistake)
Server files and configuration7 days after a service ends at period end or for non-payment; immediately on immediate cancellation
Backups on our nodesUp to 30 days after the service ends
Invoices and transaction records6 years from the end of the financial year, as required by HMRC and the Companies Act 2006
Support tickets and contact messages24 months after the last message
Panel activity logs and request logs12 months, then deleted or anonymised
Waiting-list emailUntil the product launches and you have been notified, or until you unsubscribe, whichever is sooner

6.1We may keep data for longer where needed to establish, exercise or defend legal claims, or where the law requires.

7.How we protect your data

7.1We use technical and organisational measures appropriate to the risk, including encryption in transit (TLS), password hashing, access controls limited to staff who need access, node authentication tokens, isolated containers for each server, activity logging and regular security updates.

7.2No system is completely secure. If we become aware of a personal data breach that is likely to result in a risk to you we will notify the ICO within 72 hours where required and tell you without undue delay.

8.Data on your servers (where we are a processor)

8.1Files, worlds, chat logs, player lists and similar content on your servers may contain personal data about your players. For that data you are the controller and we act only on your instructions as a processor, under the data processing terms in section 14 of our Terms of Service.

8.2If you run a community you should provide your players with your own privacy information, respond to their data requests, and use the panel's tools (file manager, backups, deletion) to meet your obligations. We will assist where reasonably possible.

9.Your rights

9.1Under the UK GDPR you have the right to:

  • Access the personal data we hold about you and receive a copy;
  • Rectification of inaccurate or incomplete data (you can edit most details in the client area);
  • Erasure of your data in certain circumstances, for example when it is no longer needed;
  • Restriction of processing while a query is resolved;
  • Portability: to receive the data you gave us in a machine-readable format (your server files can be downloaded as a backup at any time);
  • Object to processing based on legitimate interests, and to direct marketing at any time;
  • Withdraw consent at any time where we rely on it, without affecting earlier processing.

9.2To exercise a right, email [email protected] from the address on your account or open a support ticket. We may ask you to confirm your identity. We respond within one month, extendable by two further months for complex requests, and we do not charge a fee unless a request is manifestly unfounded or excessive.

9.3You have the right to complain to the Information Commissioner's Office: ico.org.uk/make-a-complaint, telephone 0303 123 1113, or Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would appreciate the chance to resolve your concern first.

10.Cookies and similar technologies

10.1Under the Privacy and Electronic Communications Regulations 2003 (PECR) we must tell you about cookies and get your consent for any that are not strictly necessary. We use only strictly necessary cookies, so no consent banner is shown.

CookiePurposeTypeExpiry
orbinth_sessionKeeps you signed in to the client area and admin panelStrictly necessary, first-party, HttpOnly30 days

10.2We do not use analytics, advertising or social-media tracking cookies. Some pages use your browser's local storage to remember interface preferences (for example a collapsed sidebar); this data never leaves your device.

10.3Stripe may set its own cookies on its checkout pages for fraud prevention; see Stripe's cookie policy. If we introduce non-essential cookies in future we will ask for your consent first and update this section.

11.Children

11.1Our Services are for people aged 18 or over. We do not knowingly collect personal data from anyone under 18 as an account holder. If you believe a child has created an account, contact us and we will delete it.

12.Changes to this notice

12.1We review this notice regularly and will post any changes here with a new effective date. If a change materially affects how we use your data we will also tell you by email or in the client area before it takes effect.