This notice explains what personal data Orbinth collects, why, who we share it with, how long we keep it and the rights you have under the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003.
1.Who we are
1.1Orbinth Ltd (company number [Companies House number], registered office [Registered office address], United Kingdom) is the controller of the personal data described in this notice. We are registered with the Information Commissioner's Office (ICO) under reference [ICO registration reference].
1.2Questions about this notice or your data: [email protected], or write to our registered office marked "Data Protection".
1.3This notice covers visitors to orbinth.com, account holders, sub-users invited to a server, people who contact us, and people who join a waiting list. It does not cover personal data stored inside customers' servers (for example player names in game logs); for that data the customer is the controller and we are their processor, as explained in section 8.
2.The personal data we collect
| Category | Examples | Source |
|---|---|---|
| Identity and contact | Name, email address, company name (business customers) | You |
| Account and security | Password (stored only as a salted hash), role, sub-user permissions, login timestamps | You; generated by us |
| Billing and transactions | Stripe customer ID, invoice history, amounts, VAT status, payment status. We never receive full card numbers. | You; Stripe |
| Service data | Server names, plans, region, IP address and port allocations, startup settings, backup names, power and file actions, console commands you send | You; our nodes |
| Support and communications | Ticket subjects and messages, contact form submissions, emails you send us | You |
| Technical and log data | IP address, browser type, device information, request timestamps, pages visited, error logs | Automatically |
| Waiting list | Email address and the product you asked to be notified about | You |
2.1We do not collect special category data (such as health or political opinions) and ask you not to send it to us.
3.Why we use your data and our lawful bases
Under the UK GDPR we must have a lawful basis for each use of your personal data. These are:
| Purpose | Data used | Lawful basis |
|---|---|---|
| Creating and managing your account, provisioning and running your servers, providing the control panel | Identity, account, service data | Performance of a contract (Art. 6(1)(b)) |
| Taking payment, issuing invoices, chasing unpaid balances | Identity, billing | Performance of a contract; legal obligation for tax and accounting records (Art. 6(1)(c)) |
| Sending service emails: order confirmations, renewal reminders, payment failures, maintenance and incident notices | Identity, service data | Performance of a contract; legal obligation (subscription reminder requirements) |
| Answering support tickets and enquiries | Identity, support data, service data | Performance of a contract; legitimate interests in helping prospective customers (Art. 6(1)(f)) |
| Keeping the platform secure: detecting abuse, fraud, attacks and unauthorised access; activity logs in the panel | Technical, service and account data | Legitimate interests in protecting our systems and customers; legal obligation |
| Improving the Services using aggregated usage statistics | Technical data (aggregated) | Legitimate interests in running and improving our business |
| Telling you when a product you joined the waiting list for launches | Waiting-list email | Consent (Art. 6(1)(a)); withdraw any time |
| Complying with law, responding to lawful requests from courts, regulators and law enforcement | Any | Legal obligation; legitimate interests |
3.1Where we rely on legitimate interests we have considered the impact on you and concluded that our interests are not overridden by your rights. You can object at any time (section 9).
3.2Marketing. We only send marketing emails with your consent, or about our own similar services where you have bought from us and have not opted out (the "soft opt-in" under PECR). Every marketing email includes an unsubscribe link.
3.3We do not use automated decision-making or profiling that produces legal or similarly significant effects on you.
5.International transfers
5.1Your account data is stored in the United Kingdom or the European Economic Area, which the UK recognises as providing adequate protection.
5.2If you choose a server region outside the UK or EEA (for example the United States, Singapore or Australia), the data on that server and the connection logs for it are processed there. Where we transfer personal data to a country without a UK adequacy decision we use the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, plus additional safeguards where needed. You can ask us for a copy of the relevant safeguards.
6.How long we keep your data
| Data | Retention |
|---|---|
| Account details | While your account is open, then 30 days after you ask us to close it (so it can be restored if closed by mistake) |
| Server files and configuration | 7 days after a service ends at period end or for non-payment; immediately on immediate cancellation |
| Backups on our nodes | Up to 30 days after the service ends |
| Invoices and transaction records | 6 years from the end of the financial year, as required by HMRC and the Companies Act 2006 |
| Support tickets and contact messages | 24 months after the last message |
| Panel activity logs and request logs | 12 months, then deleted or anonymised |
| Waiting-list email | Until the product launches and you have been notified, or until you unsubscribe, whichever is sooner |
6.1We may keep data for longer where needed to establish, exercise or defend legal claims, or where the law requires.
7.How we protect your data
7.1We use technical and organisational measures appropriate to the risk, including encryption in transit (TLS), password hashing, access controls limited to staff who need access, node authentication tokens, isolated containers for each server, activity logging and regular security updates.
7.2No system is completely secure. If we become aware of a personal data breach that is likely to result in a risk to you we will notify the ICO within 72 hours where required and tell you without undue delay.
8.Data on your servers (where we are a processor)
8.1Files, worlds, chat logs, player lists and similar content on your servers may contain personal data about your players. For that data you are the controller and we act only on your instructions as a processor, under the data processing terms in section 14 of our Terms of Service.
8.2If you run a community you should provide your players with your own privacy information, respond to their data requests, and use the panel's tools (file manager, backups, deletion) to meet your obligations. We will assist where reasonably possible.
9.Your rights
9.1Under the UK GDPR you have the right to:
- Access the personal data we hold about you and receive a copy;
- Rectification of inaccurate or incomplete data (you can edit most details in the client area);
- Erasure of your data in certain circumstances, for example when it is no longer needed;
- Restriction of processing while a query is resolved;
- Portability: to receive the data you gave us in a machine-readable format (your server files can be downloaded as a backup at any time);
- Object to processing based on legitimate interests, and to direct marketing at any time;
- Withdraw consent at any time where we rely on it, without affecting earlier processing.
9.2To exercise a right, email [email protected] from the address on your account or open a support ticket. We may ask you to confirm your identity. We respond within one month, extendable by two further months for complex requests, and we do not charge a fee unless a request is manifestly unfounded or excessive.
9.3You have the right to complain to the Information Commissioner's Office: ico.org.uk/make-a-complaint, telephone 0303 123 1113, or Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. We would appreciate the chance to resolve your concern first.
11.Children
11.1Our Services are for people aged 18 or over. We do not knowingly collect personal data from anyone under 18 as an account holder. If you believe a child has created an account, contact us and we will delete it.
12.Changes to this notice
12.1We review this notice regularly and will post any changes here with a new effective date. If a change materially affects how we use your data we will also tell you by email or in the client area before it takes effect.