Skip to content
ProjectRBIT
Legal

Privacy Policy

How Intelligent Systems collects, uses, and protects personal information.

Effective July 18, 2026Questions? info@orbitcrm.ai

Our promise. Your data is yours. We help you store it and put it to work for you, and that is as far as it goes. We will never sell it, and we will never use it to learn your business advantages or train our models without your permission. We do study how Orbit is used, but only to fix bugs and make the platform better; if a feature ever needs to study more, like your calls or emails to power forecasting, we will ask you first. When you leave, your data goes with you: it is gone as fast as the law allows, and it is no longer ours to study. What we learned about running Orbit while you were here stays with us, but your account data never does. If you put your data in, we will make sure you can take it out. Software should answer to the people who use it. If this promise ever changes, we advise you to move your business elsewhere.

The rest of this policy is the operating detail behind that promise. Intelligent Systems LLC is a Wisconsin limited liability company, governed by Wisconsin law. We build Orbit, and this policy explains, plainly, how we handle personal information across our products, services, and website at orbitcrm.ai (together, the "Services"). In this policy, "we," "us," and "Company" mean Intelligent Systems LLC. You can reach us anytime at info@orbitcrm.ai, or by mail at the address in Section 12.

Who this covers. Most people use the Services through an organization that has its own agreement with us (a "Customer"). The information a Customer puts into or creates in the Services ("Customer Data") is the Customer's: we handle it on their behalf under their agreement with us (including a Data Processing Addendum, once in place), not under this policy; until those documents are in place for a Customer, our Terms of Use describe how we handle Customer Data. What this policy covers is the personal information we control ourselves, such as your account details, website-visit information, and the operational telemetry described below. So if your request is about Customer Data, the quickest path is to ask your organization; if it is about the information we control, contact us.

1

Information We Collect

  • Information you provide: name, business email address and phone number, account credentials and settings, and the content of your communications with us.
  • Information collected automatically: Internet Protocol (IP) address, device and browser characteristics, and usage information, collected through cookies and similar technologies (see our Cookie Notice).
  • Operational telemetry: non-content usage, diagnostic, and performance data, such as feature-usage counts, performance metrics, and error information.

We collect this information from:

  • you, when you provide it directly;
  • your device or browser, through cookies and similar technologies;
  • your Customer organization, in connection with account administration and use of the Services;
  • our service providers; and
  • publicly available business-contact sources, such as company websites, professional networking sites, and business directories.

Where we do not collect personal information directly from you, the categories generally are business-contact details (such as name, business email address, business phone number, employer, and job title), account-administration information, and communications related to the Services.

Some personal information (such as account registration details and authentication credentials) is necessary to create and maintain an account, provide and secure the Services, authenticate users, respond to requests, and meet our legal obligations. Where we request such information and you do not provide it, we may be unable to create or administer your account or provide the relevant feature, support, or response.

2

How We Use Personal Information

We use personal information to provide, secure, and operate the Services; create and manage accounts and communicate about the Services; provide support; monitor and improve the Services using non-content operational telemetry; detect and prevent fraud, abuse, and security incidents; and comply with legal obligations and establish or defend legal claims. We use publicly available business-contact information to respond to business inquiries, manage Customer and prospective-Customer relationships, and send business communications where permitted by law; you may opt out of marketing communications at any time using the unsubscribe link or by contacting info@orbitcrm.ai.

Where we use in-product session-study tools that record detailed interaction patterns, such as mouse movements or navigation paths, we turn them on only after asking you, and we configure them to exclude the content of your records.

If you are in the European Economic Area or the United Kingdom, the laws we rely on to use your information are: performing our contract with you; our legitimate interests in operating, securing, and improving the Services, managing our business relationships, and preventing misuse; your consent where we ask for it (for example, for non-essential cookies or marketing); and compliance with our legal obligations. You can contact us at info@orbitcrm.ai for more detail on any of these. Outside the European Economic Area, the United Kingdom, and Switzerland, we rely on similar legal grounds to process personal information, including the need to provide the Services, our legitimate interests in operating and improving our business, your consent where we request it, and compliance with legal obligations. Customer Data that we process only on a Customer's behalf is outside this Policy and is governed by the applicable Customer agreement and, once in place, the Data Processing Addendum; until then, our Terms of Use describe how we handle Customer Data.

We do not currently use personal information covered by this Policy to make solely automated decisions, within the meaning of Article 22 of the GDPR, that produce legal or similarly significant effects. We also do not use it for targeted advertising or covered profiling, as those terms are defined under applicable law.

3

Artificial Intelligence

We do not use the records you keep in the Services, such as your contacts, accounts, and deal data, to train, fine-tune, or improve artificial-intelligence models, and we do not sell those records, in each case as those terms are defined under applicable law. These records are Customer Data, which we process on a Customer's behalf under the applicable Customer agreement (and Data Processing Addendum, once in place; until then, our Terms of Use describe how we handle Customer Data); we would use Customer Data to train or improve artificial-intelligence models only under a separate signed agreement with that Customer.

For other personal information covered by this Policy, we likewise do not currently use it to train, fine-tune, or improve artificial-intelligence models. We may use de-identified and aggregated usage information to operate, evaluate, and improve the Services and their features, and where we de-identify information we maintain and use it only in de-identified form and do not attempt to re-identify it, except as reasonably necessary to test that our de-identification is effective. If we later use personal information to train or improve artificial-intelligence models, we will do so only with your permission. We evaluate any such artificial-intelligence features against our privacy and security obligations and applicable law before deploying them.

If a feature needs to study the content you keep in the Services, such as call recordings or emails to power forecasting or intelligence features, we will ask you first: that use requires your express, feature-specific permission, which you can withdraw at any time. When you leave the Services, we stop studying your data and delete it as described in Section 7. Learning we gained while you were a customer, in de-identified and aggregated form that does not identify you or reveal your data, may remain; your account data, meaning the records you keep in the Services, does not. (Our own administrative records about the relationship, such as registration and billing information, are retained as described in Section 7.)

4

How We Disclose Personal Information

We do not sell personal information or share it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act. We disclose personal information only:

  • to service providers and processors that support the Services (such as hosting, security, analytics, support, and incident-response providers) and are bound by confidentiality and data-protection obligations; for Customer Data we process on a Customer's behalf, we use a subset of these providers, identified in our sub-processor list at orbitcrm.ai/legal/subprocessors;
  • to our professional advisers (such as lawyers, accountants, and auditors) under confidentiality obligations;
  • to administrators within your Customer organization, for administration, auditing, and reporting;
  • as required for legal compliance, lawful requests, and to protect rights, property, and safety; and
  • in connection with a merger, acquisition, financing, reorganization, or sale of assets, as reasonably necessary for that transaction and subject to appropriate confidentiality or data-protection terms; we do not sell personal information as part of any such transaction, and any successor must honor commitments materially consistent with this Policy.
5

Cookies

We use essential cookies and similar technologies, and do not use advertising or marketing cookies. We use analytics and other non-essential technologies only where permitted by law or after obtaining any required consent; where consent is required, those technologies are disabled unless and until enabled by the user. Our Cookie Notice at orbitcrm.ai/legal/cookies describes the categories of cookies and similar technologies we use, their purposes and duration, the providers involved where applicable, and how you can manage your preferences. We honor recognized opt-out preference signals, such as Global Privacy Control (GPC), where required by law, by treating them as a request to opt out of any sale or sharing of personal information or processing for targeted advertising, even though we do not currently engage in such processing. Because there is no common standard for "Do Not Track" browser signals, we do not respond to them. Where we rely on consent for non-essential technologies, you may withdraw that consent through any cookie or preference controls we make available in the Services or by contacting us.

6

Security

We maintain an information security program with administrative, technical, organizational, and physical safeguards designed to protect personal information against unauthorized or unlawful access, use, alteration, disclosure, loss, or destruction, appropriate to the nature of the information we process. Our safeguards are designed to align with industry-standard practices for services of this type. We maintain internal policies, limit access to personal information to authorized personnel who require it for the purposes described in this Policy, and review our privacy and security practices periodically. Although no method of transmission or storage can be guaranteed to be completely secure, we take reasonable and appropriate measures to protect personal information in light of the risks and the nature of the information.

Where we are responsible for personal information covered by this Policy and become aware of a breach of security leading to its accidental or unlawful destruction, loss, or alteration, or its unauthorized disclosure or access, we will investigate, take steps aimed at mitigating resulting risks where appropriate, and, where required by law, notify affected individuals or other parties. Security obligations for Customer Data are governed by the applicable Customer agreement and Data Processing Addendum, and by our Terms of Use until those documents are in place.

For security-related questions or to report a potential vulnerability, you may contact us at info@orbitcrm.ai or at the postal address in Section 12.

7

Data Retention

We retain personal information for as long as reasonably necessary for the purposes described above and to meet our legal and recordkeeping obligations, after which we delete or de-identify it. Customer Data is governed by the applicable Customer agreement and Data Processing Addendum, and by our Terms of Use until those documents are in place. We generally retain personal information as follows:

If you delete your data, or ask us to delete it, we delete or de-identify it promptly. After that, we keep only what a specific legal obligation, an active dispute or security investigation, or tax and accounting requirements make us keep, and only for as long as they require. Residual copies in routine encrypted backups are deleted or overwritten in the ordinary course of our backup cycles, and if we restore from a backup we re-apply deletions. The periods below are maximums for information that has not been deleted, not holds we place on deleted data.

CategoryRetention target
Account registration and administrative contact data (our records about the relationship, not the records you keep in the Services)Duration of the account or Customer relationship, plus the period needed for legal, audit, dispute, and recordkeeping purposes, generally up to six (6) years
Security and access logsTwelve (12) to twenty-four (24) months
Website, cookie, analytics, device, browser, and usage dataUp to twenty-four (24) months, unless a longer period is needed for security, fraud-prevention, legal, audit, dispute, or recordkeeping purposes
Operational telemetryUp to twenty-four (24) months in identifiable form, then deleted or de-identified unless needed for security, legal, audit, dispute, or recordkeeping purposes
Support recordsUp to three (3) years
Communications not tied to a support ticketUp to three (3) years, unless needed longer for legal, audit, dispute, or recordkeeping purposes
Business-contact and prospective-Customer recordsDuration of the business relationship or inquiry cycle, plus the period needed for legal, audit, dispute, and recordkeeping purposes, generally up to six (6) years
8

International Transfers

The Services are hosted in the United States, and your information may be processed here and in other countries where we or our service providers operate, as described in our sub-processor list. If you are in the European Economic Area, the United Kingdom, or Switzerland and we transfer your information to a country without an applicable adequacy decision, we rely on appropriate safeguards, such as the EU Standard Contractual Clauses and the UK equivalent. We also implement technical and organizational measures designed to protect personal information during and after transfer. You may contact us at info@orbitcrm.ai for more information about these safeguards or to obtain a copy or description of the relevant transfer mechanism, where legally required.

9

Your Rights

Depending on where you live, you may have rights to confirm whether we process your personal information; to access, correct, delete, or obtain a portable copy of it; to receive a list of the specific third parties to whom we disclosed personal information, or categories of third parties where applicable, as required by law; to opt out of any sale, sharing, targeted advertising, or covered profiling; to limit the use and disclosure of sensitive personal information; to restrict or object to processing where applicable; to withdraw consent where processing is based on consent; and, under the GDPR, UK GDPR, or other applicable law, to lodge a complaint with a supervisory authority, in each case where we engage in the relevant processing and the applicable conditions are met. To exercise a right, you may email us at info@orbitcrm.ai or write to us at the postal address in Section 12. We may ask for information reasonably necessary to verify your identity and process the request, will respond within the time required by law, and will not discriminate against you. Authorized agents must provide proof that you have given them signed permission to submit the request, and we may require you to verify your identity directly with us unless prohibited by law. Where the law provides a right of appeal, you may appeal a denied request by emailing info@orbitcrm.ai with the subject line "Privacy Appeal."

European Economic Area, United Kingdom, and Switzerland. Where the GDPR or UK GDPR applies, you have the right to request access to your personal information, to request its rectification or erasure, to request restriction of processing, to object to processing (including where we rely on legitimate interests), and to request data portability, in each case where the relevant conditions are met. You also have the right to withdraw consent at any time where we rely on consent, and to lodge a complaint with a supervisory authority.

California. This section, together with the table under "U.S. state privacy disclosures" below, is our notice at collection for California residents. We do not sell personal information or share personal information for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act, and we have not done so in the preceding twelve (12) months. The categories of personal information we collect, the categories of sources, the business or commercial purposes for which we collect and use each category, the categories of third parties to whom we disclose each category, and our retention periods are set out in that table and in Sections 1, 2, 4, and 7. We may collect account log-in credentials, which may be sensitive personal information; we use and disclose such information only to provide, secure, and administer the Services, and not for any purpose that gives a right to limit its use or disclosure under California law, and we do not use or disclose sensitive personal information to infer characteristics about you. Because we do not use sensitive personal information for additional purposes, we do not offer a separate right to limit its use or disclosure. Under California's "Shine the Light" law, we do not disclose personal information to third parties for their direct marketing purposes.

U.S. state privacy disclosures. In the preceding twelve (12) months, we collected and disclosed the following categories of personal information for the business purposes described below. We do not sell personal information, share it for cross-context behavioral advertising, process it for targeted advertising, or use it for profiling that produces legal or similarly significant effects, as those terms are defined under applicable law.

CategorySourcesPurposesCategories of recipients
Identifiers and business-contact information (including commercial relationship information, such as Customer and prospective-Customer relationship history)You, your device or browser, Customer organizations, service providers, and publicly available business-contact sourcesAccount administration, support, communications, security, legal compliance, and permitted business communicationsService providers and processors; Customer administrators; professional advisers; courts, regulators, law enforcement, and other parties where legally required or necessary to protect rights; security and incident-response providers; and parties to business transactions
Account credentialsYouAuthentication, account access, security, and administrationAuthentication, hosting, security, and support providers
Device, browser, and Internet or network activity data, usage data, telemetry, and any inferences we derive from that data (used only for service operation, security, diagnostics, and improvement, and not sold or shared)Your device or browser and service providersService operation, security, diagnostics, analytics, fraud prevention, and improvementHosting, security, analytics, support, and infrastructure providers; Customer administrators where applicable
Communications content and support recordsYou and Customer organizationsSupport, inquiry response, dispute handling, legal compliance, and administrationSupport providers, professional advisers, legal recipients, and security recipients

Scroll table sideways to see more

Other jurisdictions. Where Canadian or other regional privacy laws apply, we handle personal information in accordance with those laws, including by providing any additional rights and protections they require. You may contact us at info@orbitcrm.ai with any question or complaint.

10

Children's Privacy

The Services are intended for use by organizations and their adult representatives. We do not direct the Services to children and do not knowingly collect personal information from children.

11

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version and revise the Effective Date above. If we make material changes, we will provide notice through the Services, by email, or by another legally sufficient method before the changes take effect where required by law.

12

Contact Us

Intelligent Systems LLC, 790 N Milwaukee St, Ste 302 #309812, Milwaukee, WI 53202. Email: info@orbitcrm.ai.

If you have a question or concern about how we handle personal information, you may contact us at info@orbitcrm.ai, and we will review and respond to complaints in accordance with applicable law.

As of the Effective Date, we do not believe we are required under Article 27 of the GDPR or the UK GDPR to designate a representative in the European Union or the United Kingdom, because we do not offer the Services to individuals in those regions or monitor their behavior in the sense of the GDPR or UK GDPR. If our obligations change, we will comply with applicable requirements and update this Privacy Policy as needed.