Orbilyn

Privacy Policy

Last updated: 2026-08-14

1. Data Controller

The controller of personal data processed via Orbilyn is:
REMIGIUS Tomasz Karkoszka

NIP: PL6462625370

Contact: Contact page

2. What data we process

Depending on how you use the Service, we may process:

  • email and account data (login via Supabase Auth),
  • data you enter in the platform (file imports, product data, integration settings, comparison results, and account settings),
  • technical data (IP-derived hash, browser/device metadata, timestamps),
  • analytics and usage data where configured,
  • billing-related data (for example the account email linked to payment, and customer/subscription/transaction identifiers at our Merchant of Record) when you use a paid package.

3. Purposes and legal bases (GDPR)

  • service operation and security (Art. 6(1)(f) GDPR – legitimate interest),
  • handling your requests and providing the B2B platform, including paid packages (Art. 6(1)(b) and (f) GDPR),
  • fraud/spam prevention (Art. 6(1)(f) GDPR),
  • analytics and product improvement (Art. 6(1)(f) GDPR),
  • legal obligations, where applicable (Art. 6(1)(c) GDPR).

4. Recipients and processors

We use trusted processors and infrastructure providers, including: Supabase (database/auth), hosting and CDN providers, email providers, and — for paid packages — Paddle as Merchant of Record (payments, buyer documents, eligible refunds). We may also use analytics providers configured in the Service.

5. Data retention

We keep personal data only as long as necessary for the purposes above, or as required by law. Moderation and security-related records may be kept longer where needed to prevent abuse and protect the Service. Billing data held by Paddle is also subject to Paddle’s policies and retention periods.

6. Cookies and similar technologies

The Service may use cookies/local storage that are necessary for operation, authentication, security, and analytics. You can manage cookies in your browser settings.

7. Your rights

Subject to GDPR, you may request access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interest. You also have the right to lodge a complaint with a competent supervisory authority.

8. International transfers

If data is transferred outside the EEA, we use appropriate safeguards (for example SCCs or equivalent mechanisms required by law).

9. Contact

For privacy-related requests, use the Contact page (subject: Privacy / GDPR).