Skip to content

SHEET L-01 · LEGAL

Orbiseed Privacy Policy

Effective Date: August 7, 2026

This Privacy Policy describes how Orbiseed Technology Inc. (“Orbiseed,” “we,” “us”) collects, uses, discloses, and protects Personal Information when we act for our own business purposes, including when you visit our websites (including orbiseed.com and its subpages, the “Website”), communicate with us, request a demonstration, or administer a customer account. Orbiseed Technology Inc. controls Personal Information collected through the Website and for our sales, marketing, account-administration, and business operations, and administers privacy requests for the Orbiseed group at the contact information in Section 16. Where an Order Form identifies Orbiseed North America Inc. or another Orbiseed affiliate as the contracting supplier, that affiliate may process Customer Data and related account information as described in the applicable customer agreement.

Orbiseed provides business-to-business services intended for representatives of businesses and organizations. This Policy is not directed at consumers acting for personal, family, or household purposes, and nothing in it limits any rights an individual may have under applicable privacy law.

1. Scope and Roles

1.1 This Policy (Orbiseed as controller). This Policy applies to Personal Information that Orbiseed determines the purposes and means of processing for, such as information about Website visitors, sales and marketing contacts, demonstration participants, event contacts, account administrators, billing contacts, and support contacts.

1.2 Customer Data (Orbiseed as processor or service provider). Orbiseed’s customers use the Services to process documents, catalogs, emails, quotes, product records, and related business information (“Customer Data,” as defined in the Orbiseed Terms of Service). Customer Data may contain Personal Information collected or controlled by the customer. For Customer Data, the customer generally determines the purposes and means of processing, and Orbiseed processes the information as a processor or service provider on the customer’s documented instructions under the Terms of Service, the applicable Order Form, and any data processing addendum. This Policy provides a high-level public description of those processing practices; the applicable customer agreements contain the parties’ contractual obligations. If your Personal Information appears in Customer Data, please direct requests to the relevant customer; we will assist that customer as required by our agreement and applicable law.

1.3 Definitions. “Personal Information” means information about an identifiable individual, or any equivalent term (such as “personal data”) under applicable privacy law. Capitalized terms not defined in this Policy have the meanings given in the Orbiseed Terms of Service.

1.4 Demonstration and evaluation data. Documents and related information submitted to Orbiseed for a demonstration, proof of concept, evaluation, or pilot are treated as Customer Data, even where the submitting organization has not yet purchased a subscription. We use that information only to conduct the requested demonstration or evaluation, provide related support, secure and administer the Services, and comply with applicable law; we do not use it for generalized or cross-customer model training. It is retained and deleted in accordance with the applicable evaluation terms — for files provided solely for a one-time demonstration before an account is created, the Orbiseed Terms of Service provide for deletion or return within thirty days after the demonstration unless the customer requests continued retention or proceeds with a pilot or subscription — subject to limited backup retention and legal obligations.

2. Personal Information We Collect

2.1 Information you provide. We collect Personal Information you provide directly, such as: name, title, company, email address, and phone number when you contact us, book a demonstration, register for the platform, or attend an event; the content of your communications with us (including support requests and sales correspondence); billing contact details; and account information. Authentication for the platform is handled by our identity service or by a customer-configured single sign-on provider; Orbiseed does not store user passwords in its own systems.

2.2 Information collected automatically on the Website. When you visit the Website, we and our hosting provider automatically collect limited technical information, such as IP address, browser type, device type, pages viewed, referring page, and timestamps, through server logs and privacy-preserving analytics. Our Website analytics are cookieless: they do not use advertising cookies, do not build cross-site profiles, and report in aggregate. See Section 5.

2.3 Information from other sources. We may receive business contact information from publicly available sources, business partners, event organizers, or referrals, and combine it with information you provide, for the business purposes described in Section 4.

2.4 Scheduling and communications tools. If you book a demonstration through our scheduling link or correspond with us by email, the applicable scheduling and email providers process your information as our service providers, as described in Section 7.

2.5 Platform usage information. When Authorized Users use the platform, we collect technical and usage information about that use for our own operational purposes (“Service Data” under the Terms of Service), such as event logs, feature usage, processing durations, device and browser information, error records, and usage counts. Service Data generally does not include the substantive content of Customer Data; limited Customer Data may appear in support or diagnostic records where necessary to investigate a specific issue, and any such content remains subject to the protections applicable to Customer Data. We use Service Data for the purposes described in Section 4, such as operating and securing the Services, billing, support, and capacity planning.

3. Platform Integrations and Connected Accounts

3.1 Customer-directed integrations. The Orbiseed platform allows Authorized Users, at the direction of our customer, to connect third-party services such as email mailboxes (for example, Gmail or Microsoft 365), CRM, ERP, storage, and identity systems. Information obtained through these integrations is processed as Customer Data under the Orbiseed Terms of Service: we use it only to provide the features the customer requests, and it is not used for advertising and is not sold. For mailbox integrations specifically, and only after an Authorized User grants access through the provider’s consent screen, the platform: reads email messages — including headers, bodies, snippets, and attachments — to identify and organize project- and quote-related correspondence; sends or updates messages when, and only when, the user requests it; and stores relevant message content and attachments as Customer Data for the customer’s use in the platform. To establish and operate the connection, we also receive basic account information from the provider, of which we store the account’s email address and a stable account identifier to identify the connected mailbox, associate messages with it, and secure the integration. The user can disconnect the integration in the platform, which stops ongoing synchronization and new collection, although processing already in progress or queued at the time of disconnection may complete; removing the mailbox connection deletes the stored connection credentials. The user or an administrator can also revoke Orbiseed’s access at any time in the provider’s security settings, which invalidates the credentials in accordance with the provider’s revocation process (providers may take a short time to propagate revocation, and tokens already issued may remain valid until they expire). Content previously imported into the customer’s workspace remains Customer Data and is retained or deleted in accordance with the customer’s instructions, account settings, and the applicable customer agreement (see also Section 9).

3.2 Google API Services — Limited Use. Orbiseed’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy and the Google Workspace User Data and Developer Policy, including their Limited Use requirements. Without limiting the foregoing: (a) we use Google user data only to provide and improve user-facing features of the platform that are visible and prominent to the user; (b) we do not transfer Google user data to others except, with the user’s consent, as necessary to provide or improve those user-facing features; for security purposes (such as investigating abuse); to comply with applicable law; or as part of a merger, acquisition, or sale of assets after obtaining the user’s explicit prior consent; (c) we do not use Google user data for advertising, and we do not use Google user data to develop, improve, or train generalized artificial-intelligence or machine-learning models; and (d) we do not permit humans to read Google user data except with the user’s affirmative agreement for specific data, as necessary for security or abuse investigation, to comply with applicable law, or where the data has been aggregated and anonymized.

3.3 Microsoft account data. Depending on the connected feature, Orbiseed may access and store the Microsoft mailbox and account information described in Section 3.1. We request only the Microsoft permissions reasonably necessary to provide the features selected by the customer or Authorized User and use Microsoft API data only within the permissions granted. We do not sell Microsoft API data; we do not use it for advertising or marketing; and we do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models. Users and customer administrators may revoke Orbiseed’s access through Microsoft’s account or application-consent management tools; they may also disconnect the integration in the platform, with the effects described in Section 3.1.

3.4 No generalized model training. Consistent with our Terms of Service, we do not use Customer Data, Generated Output, Customer-Specific Configurations, or Customer Confidential Information to train or fine-tune models for other customers or for general model development unless the customer expressly opts in through a signed writing that identifies the permitted data, purpose, and scope. Data received through Google APIs or Microsoft APIs is excluded from any such opt-in: we do not use it to develop, improve, or train generalized artificial-intelligence or machine-learning models, regardless of consent.

4. How We Use Personal Information

4.1 We use Personal Information described in this Policy to:

(a) operate, secure, and improve the Website and our business;

(b) respond to inquiries, schedule and conduct demonstrations, and manage sales relationships;

(c) create and administer accounts, provide the Services, provide support, and send operational, billing, and security notices;

(d) invoice and collect fees and maintain business records;

(e) send marketing communications in accordance with applicable law and Section 12;

(f) monitor, investigate, and prevent security incidents, fraud, and abuse;

(g) comply with legal obligations, enforce agreements, and establish, exercise, or defend legal claims; and

(h) evaluate and complete a corporate transaction such as a financing, merger, or acquisition, subject to appropriate safeguards.

4.2 Legal bases (where applicable law requires one). Where GDPR, UK GDPR, or similar law applies, our legal bases are: for purposes (b), (c), and (d), performance of a contract with you, or steps taken at your request before entering a contract, where you are the contracting party — and, where you act on behalf of your organization, our legitimate interests in establishing, serving, and administering our relationship with that organization; for purposes (a), (f), and (h), our legitimate interests in operating, securing, improving, and developing our business, balanced against your interests and rights; for purpose (e), your consent where required (which you may withdraw at any time) and otherwise our legitimate interest in marketing our services; and for purpose (g), compliance with our legal obligations and, for the establishment, exercise, or defence of legal claims, our legitimate interests in protecting our legal position. Where Canadian privacy law applies, including Québec law, we collect, use, and disclose Personal Information with consent or as otherwise permitted or required by applicable law.

4.3 Whether you must provide information. Providing Personal Information is voluntary, but some of it is necessary for us to respond to you, provide the Services, or invoice fees — for example, we cannot create an account or process billing without the relevant contact and billing details. If required information is not provided, we may be unable to do those things. We will indicate at the point of collection where specific information is required.

5. Cookies and Analytics

5.1 Essential operation only. The Website uses only the cookies and similar technologies strictly necessary to operate and secure it. Our analytics are cookieless, first-party, and aggregate: they measure page views and interactions (such as clicks on “Request a demo”) without advertising identifiers or cross-site tracking.

5.2 No ad tech. We do not use third-party advertising cookies, social-media pixels, or cross-context behavioural advertising on the Website, and we do not sell Personal Information or share it for targeted advertising. Because the Website does not track visitors across third-party websites or over time for advertising, it does not respond to browser “Do Not Track” signals, and there is no sale or sharing for a Global Privacy Control signal to opt out of.

5.3 Platform. The logged-in platform uses cookies or similar technologies necessary for authentication, session management, security, and user preferences.

6. How We Disclose Personal Information

We disclose Personal Information only:

(a) to service providers who process it on our behalf and under our instructions (see Section 7), such as cloud hosting, database, identity, payments, communications, scheduling, and analytics providers;

(b) to our Affiliates (including Orbiseed North America Inc.) for the purposes described in this Policy, consistent with this Policy;

(c) to professional advisers (lawyers, accountants, auditors, insurers) under duties of confidentiality;

(d) in connection with a business transaction (financing, merger, acquisition, reorganization, or sale of assets), subject to customary confidentiality protections, with notice of any resulting change in control or use as required by law;

(e) to comply with law, respond to lawful requests by public authorities, or protect the rights, safety, or property of Orbiseed, our customers, or others; and

(f) with your consent or at your direction.

We do not sell Personal Information, and we do not disclose it to third parties for their own marketing.

7. Service Providers

7.1 We use service providers to run our business, in categories including: cloud infrastructure and storage; website hosting, content delivery, and cookieless analytics; database hosting; identity and authentication; payment processing; document- and email-processing services, including OCR and third-party artificial-intelligence model providers used for certain features; email, calendaring, and productivity tools; and customer-communication and support tools.

7.2 Service providers are bound by contractual obligations appropriate to the information they process and to their role, and may use Personal Information only to provide their services to us. Certain providers — such as payment, scheduling, identity, and communications providers — may also process limited information as independent controllers under their own privacy notices, for purposes such as fraud prevention, legal compliance, or their own account administration. A current list of the sub-processors that process Customer Data is available to customers as described in the Orbiseed Terms of Service; other inquiries about our service providers may be sent to privacy@orbiseed.com.

8. International Transfers

Orbiseed is based in Ontario, Canada. Our service providers may store or process information in Canada, the United States, or other jurisdictions. Where Personal Information is transferred outside your jurisdiction, it may be subject to the laws of the destination jurisdiction, and we use contractual and organizational safeguards designed to require an appropriate level of protection. For Personal Information subject to Québec law, we assess cross-border communication of Personal Information as required by applicable law. Where GDPR or UK GDPR applies to a transfer, we rely on an adequacy decision where available (for example, the adequacy recognition applicable to commercial organizations in Canada) or on appropriate safeguards such as standard contractual clauses, and you may obtain a copy of the relevant safeguards (or the location where they have been made available) by contacting privacy@orbiseed.com.

9. Retention

We retain Personal Information only as long as reasonably necessary for the purposes described in this Policy, including maintaining business and financial records, complying with legal obligations, resolving disputes, and enforcing agreements. Retention periods depend on the nature of the information and the purpose: for example, sales correspondence is retained while a relationship remains active and for a reasonable period afterward; billing records are retained as required by tax law. When retention is no longer necessary, we securely destroy the information or anonymize it in accordance with applicable law — for Personal Information subject to Québec law, anonymization is carried out only for serious and legitimate purposes and in accordance with the criteria and terms prescribed by regulation. Residual copies may persist in encrypted backups until overwritten in the ordinary cycle, during which they remain protected. For connected accounts, stored connection credentials are deleted when the connection is removed, and provider-side revocation is available at any time, as described in Section 3; content imported before disconnection remains Customer Data and follows the customer-instructed retention described in this Section and in the applicable customer agreement, including the post-termination export and deletion process described in the Terms of Service.

10. Security

We maintain administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized access, use, alteration, disclosure, or destruction, appropriate to the sensitivity of the information — including encryption in transit and at rest, access controls, logging, and monitoring. No system is perfectly secure. Where Orbiseed determines the purposes and means of processing and an incident affecting Personal Information requires notification under applicable law, we will notify affected individuals and competent authorities as required. Where an incident affects Customer Data that Orbiseed processes for a customer, we will notify and assist the customer in accordance with the applicable agreement and applicable law; the customer is responsible for notifications to affected individuals and authorities unless applicable law requires Orbiseed to provide them directly. Security questions and vulnerability reports may be sent to ciso@orbiseed.com.

11. Your Rights and Choices

11.1 Canada (PIPEDA and provincial laws, including Québec). Subject to applicable law, you may request access to, and correction of, your Personal Information in our custody or control; withdraw consent to certain processing (subject to legal or contractual restrictions and reasonable notice); and request information about our handling of your Personal Information. For Personal Information subject to Québec law, you may also request that we cease disseminating it or de-index it in the circumstances provided by law; you have the right to be informed of decisions based exclusively on automated processing, where applicable; and, where provided by law, you may request computerized Personal Information collected from you in a structured, commonly used technological format (data portability).

11.2 European Economic Area and United Kingdom (where applicable). If GDPR or UK GDPR applies to our processing of your personal data, you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to withdraw consent at any time without affecting prior processing. You may lodge a complaint with your supervisory authority.

11.3 United States state laws (where applicable). We are a Canadian business-to-business company and may not meet the applicability thresholds of US state privacy statutes. Where such a law does apply to you, you may have rights to know, access, correct, delete, and obtain a copy of Personal Information, and to opt out of sale, sharing, or targeted advertising — and, as stated in this Policy, we do not sell Personal Information or share it for targeted advertising, and we do not discriminate against individuals for exercising privacy rights. We verify requests by matching the information you provide against the records we hold and may request additional information where reasonably necessary. You may submit requests through an authorized agent: where the agent provides a valid power of attorney under applicable law, we will not require anything further from you; otherwise, the agent must provide reasonable proof of your signed authorization, and we may also ask you to verify your identity or confirm the authorization with us directly. If we become subject to a particular state privacy statute, we will supplement this Policy with the disclosures that statute requires.

11.4 Exercising rights. You may exercise applicable rights by emailing privacy@orbiseed.com. We will verify your request, respond within the time required by applicable law, and explain any legal basis for declining a request. Where applicable law provides an appeal right, you may appeal a refusal by replying to our decision or emailing privacy@orbiseed.com with the subject line “Privacy Appeal”; if your appeal is denied, you may contact your state Attorney General or applicable supervisory authority. If your request concerns Personal Information contained in Customer Data, we will refer it to the relevant customer and assist as required.

11.5 Complaints. If you have concerns about our handling of Personal Information, please contact us first at privacy@orbiseed.com. You may also complain to the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information du Québec, or your local supervisory authority, as applicable.

12. Marketing Communications

We send commercial electronic messages only in accordance with applicable law, including Canada’s Anti-Spam Legislation (CASL). You may unsubscribe from marketing emails at any time using the unsubscribe mechanism in the message or by emailing privacy@orbiseed.com. Unsubscribing does not affect operational, billing, security, or other transactional messages.

13. Children

The Website and Services are intended for business users and are not directed at individuals under the age of majority. We do not knowingly collect Personal Information from children. If you believe a child has provided Personal Information to us, contact privacy@orbiseed.com and we will delete it in accordance with applicable law and Section 9 (or, where it forms part of Customer Data, refer the request to the relevant customer).

14. Third-Party Websites

The Website may link to third-party websites and resources (including scheduling and social platforms). Their privacy practices are governed by their own policies, which we encourage you to review.

15. Changes to This Policy

We may update this Policy from time to time to reflect changes in law, technology, or our practices. We will post the updated Policy on the Website with a revised effective date and disseminate notice of amendments by appropriate means as required by applicable law. For material changes, we may also provide direct notice by email, through the Services, or by another prominent method before or when the changes take effect. The “Effective Date” at the top indicates when this Policy was last revised.

16. Contact and Privacy Officer

Orbiseed has designated a person in charge of the protection of Personal Information (Privacy Officer). The Privacy Officer is responsible for Personal Information throughout its lifecycle at Orbiseed — overseeing its collection, use, disclosure, retention, and destruction; approving our privacy policies and practices; assessing the privacy impacts of new projects and of communicating Personal Information outside Québec or Canada; and handling access requests, complaints, and incidents — assisted by the engineering and operations personnel who apply these practices in the systems they operate. Complaints are handled as follows: send your complaint to privacy@orbiseed.com; we will acknowledge it, investigate, and respond in writing within the time required by applicable law; and if you are not satisfied with our response, you may escalate to the authorities identified in Section 11.5. Questions, requests, and complaints under this Policy may be directed to:

Orbiseed Technology Inc.
Attention: Privacy Officer

Email: privacy@orbiseed.com

Mailing address: available on request from privacy@orbiseed.com and in our corporate registry filings

For security matters: ciso@orbiseed.com. For general inquiries: info@orbiseed.com.