1. Who we are and when this policy applies
Orbis Sign is a service of Orbis Digital Ltd (the Provider, Orbis, we or us). The person or organisation buying or using the Service is the Customer. A person invited to sign is a Signer.
Orbis Digital LtdCompany number 17116737
Registered in England and Wales
Registered office: 66 Paul Street, London, EC2A 4NA, United Kingdom
For privacy enquiries or complaints, use the contact form and select Data protection, or email . Orbis is the contact for the processing described here and does not publish a separate data protection officer contact.
2. Controller and processor roles
Orbis is normally a controller for website enquiries, account creation and administration, user authentication and security, billing administration, customer service, service communications and its own legal and operational records. Orbis decides why and how that data is used.
For documents, recipients, signatures, field responses and workflow evidence submitted and controlled by a Customer, the Customer is normally the controller and Orbis acts as its processor. The Customer decides why the document is sent and must give Signers its own privacy information. Roles depend on the facts and cannot be changed merely by labelling them.
3. Information handled
Account and organisation data: name, email, password hash, role, membership, organisation details, business and billing contacts, account status, support correspondence and preferences.
Document and signer data: uploaded PDF contents and metadata; document title and status; recipient name, email, telephone number and role; signing order and delivery method; field definitions and responses, including signatures and initials; consent and disclosure records; signing-link and one-time-code status.
Technical and evidence data: session records, IP addresses, user-agent information, timestamps, audit events, document hashes, email provider message IDs and delivery/open/click/bounce events. Contact-form submissions contain the name, email, company (if supplied), enquiry category and message. Where Stripe is used, billing records may include customer and subscription identifiers and status; full payment-card details are handled by Stripe rather than stored by Orbis Sign.
4. Purposes and lawful bases when Orbis is controller
- Provide accounts, subscriptions and requested support: contract or steps requested before contract.
- Authenticate users, prevent misuse, operate audit logs, troubleshoot and defend claims: legitimate interests in running a secure, accountable service.
- Administer invoices, accounting and legal requests: contract and legal obligation, as applicable.
- Respond to contact enquiries: steps requested before contract or legitimate interests in responding to business enquiries.
- Send essential service communications: contract and legitimate interests.
Where we rely on ordinary legitimate interests, we assess necessity and balance our interests against the individual's rights. Core service processing does not rely on consent. Orbis Sign does not use behavioural advertising or marketing trackers, and this policy does not describe an optional marketing-email programme. If those practices change, Orbis will provide the required notice, lawful basis and controls before beginning the processing.
5. Customer-controlled processing
When Orbis is processor, it uses personal data to host, display, route and complete Customer-configured document workflows; deliver invitations and codes; produce audit evidence; secure and support the Service; and delete or return data on documented instructions. The Customer determines its lawful basis, recipients, retention and whether special-category or criminal-offence data may lawfully be included.
7. International transfers
Orbis does not promise UK-only hosting or processing. Providers may process data outside the United Kingdom or use onward providers in other countries. For a restricted transfer, Orbis uses the applicable UK adequacy regulation or appropriate safeguards such as the International Data Transfer Agreement or UK Addendum, together with the transfer assessment and supplementary measures required by law. Provider-level information is linked from the Subprocessor Schedule.
8. Retention and deletion
The authenticated session cookie and its server-side session record are configured for up to eight hours. We retain controller data only for as long as reasonably needed for the purpose collected, taking account of the account or enquiry relationship, Customer instructions, security and audit needs, limitation periods and disputes, accounting or other legal duties, and any required legal hold.
When an authorised user permanently deletes an individual document, Orbis Sign deletes the document and its recipient, field and email-delivery records in one database transaction. Original and completed PDF data is deleted where no document or template still refers to it and it belongs to the same workspace. Limited metadata-only signing, security and deletion evidence is retained without its document and signer links.
When Orbis is processor, the Customer normally determines retention through its instructions and Agreement. Individual-document deletion does not delete a Customer's workspace, provider-held records or backups. A workspace deletion request or in-product status is not confirmation of complete tenant erasure. Orbis will confirm the outcome and identify any data it must retain. No fixed backup-deletion period is promised.
9. Security
Application controls include scrypt password hashes for database users, HttpOnly production-secure session cookies, server-side sessions, role and workspace checks, optional TOTP, origin or referer checks for session-authenticated state changes, rate limits, API security headers, server-side validation on key workflows, expiring tokens and audit records. Documents are held in PostgreSQL. Orbis does not promise UK data residency, a particular hosting region, encrypted backups or a certification. Read the Security page for a high-level overview.
10. Your UK data-protection rights and complaints
Depending on the circumstances, you may have rights of access, rectification, erasure, restriction, objection and portability, and the right to withdraw consent without affecting earlier processing. These rights are not absolute. We may ask for information reasonably needed to identify you and locate the data. The usual response period is one month after receiving a request; under the Data (Use and Access) Act 2025 rules, that period does not begin until reasonably requested identity or request-clarification information is received. We will carry out a reasonable and proportionate search. For data in a Customer's document, contact that Customer first; Orbis will assist it where required.
Submit a request or complaint through Contact by selecting Data protection, or email . We will acknowledge a data-protection complaint within 30 days, investigate without undue delay, keep you informed and tell you the outcome. If you remain dissatisfied, you may complain to the Information Commissioner's Office using its official data protection complaint service. You may also seek a judicial remedy.
11. Children, automated decisions and changes
The Service is designed for business workflows, not for children. Customers must assess capacity and any additional protections before involving a child. Orbis does not use solely automated decision-making that produces legal or similarly significant effects. If that changes, Orbis will provide the information and safeguards required by law, including applicable rights to make representations, obtain human intervention and contest a significant decision.
Material changes will be versioned and communicated as required. Retention periods are determined by purpose, Customer instructions and applicable legal duties rather than a single period for every data category.

