Skip to content
orbo.work
How it worksThe filmQuestions
  • Privacy Policy
  • Terms of Service
  • Cookie Notice
  • Subprocessors
  • Security

Legal

Privacy Policy

Last updated 9 October 2026

orbo.work/privacy

In short

  • This policy covers orbo.work. Details live on their own pages: cookies, subprocessors and security.
  • We do not sell personal data, show ads, or use your company's content to train AI models.
  • Data from a Google account you connect is used only for the features you see in orbo.work, as Google user data below explains.
  • orbo.work stores its data in the European Union.
  • We set no tracking cookies.
  • A company's Owner can delete the company in Settings. After a period in which it can still be restored, its data is erased.

On this page

  1. 01Who we are and what this covers
  2. 02What we collect
  3. 03How we use it
  4. 04Who receives it
  5. 05Google user data
  6. 06Cookies
  7. 07Where your data is kept
  8. 08How long we keep it
  9. 09Deleting your data
  10. 10Who can see what
  11. 11Security
  12. 12Your rights
  13. 13Children
  14. 14Changes to this policy

01Who we are and what this covers

Orbo Technologies Ltd, a company registered in the Dubai International Financial Centre (DIFC), Dubai, United Arab Emirates ("Orbo", "we", "us"), runs orbo.work. This policy explains what personal data we collect through orbo.work, why, who else receives it, how long we keep it, and what you can ask us to do with it. Our details are under Contact us at the end of this page.

Anyone can ask for an orbo.work account, including someone setting up a new business on their own. While orbo.work is invitation only, accounts come through the waitlist, an Owner's invitation or a company's join code. Your account is your own sign-in (your name, email address and how you sign in), whether you are a company's Owner or a Member. There are no company accounts: a company is a workspace that people belong to as Owners or Members, and someone who sets one up alone is its Owner. A company's Owners decide what is put into its workspace and who can see it, and we handle that content for the company to provide the service. For your account and running our business, we decide how the data is used and are responsible for it.

02What we collect

  • Account information: your name, email address, password (stored in a protected form that cannot be read back), language, and your company's time zone, and your profile picture if you sign in with Google.
  • Company and work content: the company's name, its people and their roles, and what people and agents create or bring into orbo.work, such as chats, tasks, projects, files, notes, apps, automations, and the record of actions taken and approved.
  • Calls: when a company uses orbo.work in a meeting, or someone talks to orbo.work by voice in Chat, what is said there, turned into text and labelled with each participant's displayed name, the notes made from it, and any recording the meeting allows. Voice in Chat becomes an ordinary Chat message; its audio is never stored.
  • Connected accounts: the access a company grants to services it connects, such as email, calendar, code hosting or its AI provider; what agents and people read and write through those accounts; and the website sign-ins made inside its agents' isolated computers. Section 05 describes this for Google accounts.
  • Payment information: the company's billing details and subscription status. Card details go to our payment provider, never to us.
  • Waitlist information: what you send when you join the orbo.work waitlist, and where you came from (campaign tags and the referring website).
  • Technical and usage information: IP address and browser for each signed-in session; how orbo.work is used, counted without cookies, with your company's name and where a visit came from; and error reports. These carry identifiers and technical details, never the content of your work.

03How we use it

  • To provide orbo.work and its features: sign you in, run the agents and tools your company sets up, work with the accounts it connects, and show each person what they are allowed to see.
  • To send the messages the service needs, such as sign-in, invitations, approvals and questions from agents.
  • To decide who gets access while orbo.work is invitation only, and to answer messages sent to us.
  • To keep orbo.work secure and working: find and fix errors, prevent abuse and protect accounts.
  • To understand, in numbers, how orbo.work is used so we can improve it.
  • To bill companies that pay, and to meet our legal obligations.

We do not sell personal data, use it for advertising, or use a company's content to train AI models.

Where the law asks for a legal basis: we use data to perform our contract with you and your company; for security, error fixing and product numbers, because we have a legitimate interest in a safe, working product; and to meet legal obligations.

04Who receives it

We share personal data only with companies that help us run orbo.work, each receiving only what its job needs:

  • Cloud hosting and network providers, which host orbo.work in the European Union and carry its traffic securely.
  • Meeting and speech services, which join calls, turn speech into text and give orbo.work its spoken voice.
  • AI model providers, which do the agents' thinking and writing: the provider your company chooses and connects, or providers we supply that keep nothing and do not train on it.
  • Web search, email delivery, browser notification, payment and sign-in providers.
  • Error, usage and alerting services, which receive technical and usage information, such as identifiers, counts, your company's name and where a visit came from, never the content of your work.

The full list, with what each does and where, is on our Subprocessors page. Services your company connects, such as its email, calendar or code hosting, receive data on your company's instructions under their own terms.

  • Subprocessors

Some of these companies handle data outside your country and outside the European Union. When data goes abroad, we use the safeguards the law requires, such as each company's data protection terms. We may also disclose data when the law requires it, or to a buyer if our business is sold, under this policy.

A data processing agreement (DPA) for business customers is available on request: email [email protected].

05Google user data

When you sign in with Google, or connect Gmail or Google Calendar, orbo.work receives data from Google.

  • What we access: your name, email address and profile picture when you sign in with Google; when Gmail is connected, messages with their attachments, labels and drafts; when Google Calendar is connected, calendars, events with their attendees, and free and busy times.
  • How we use it: only to provide features you can see in orbo.work: showing your mail and calendar, letting agents read, answer and organise mail and arrange meetings for the tasks your company gives them, and noticing new mail, replies and calendar changes.
  • How we store it: the access Google grants to Gmail and Calendar is encrypted with your company's own key, and the access from signing in with Google is encrypted with the key that protects every sign-in. We keep details of incoming mail (sender, recipients, subject and a short preview), a copy of upcoming calendar events, and what agents read or send in a task, in the European Union, until they are deleted or the company is deleted. Section 09 explains how to disconnect an account.
  • Who we share it with: the AI model provider that does the agents' work (the one your company connects, under your company's own agreement with it, or one we supply that keeps nothing and does not train on it); our hosting providers; our web search provider, which receives only the search words and page addresses an agent writes when it searches the web (never in Private mode); and other services your company has connected, only when a task you or your company gives an agent uses them. A buyer of our business receives it only with your consent. We do not sell it, use it for ads, or use it to train AI models, and our staff do not read it except through a support report your company sends, for security, or when the law requires it.

If your company connects a personal AI subscription rather than a business plan, turn off that account's setting that lets the provider use your chats to improve its models. Business plans usually do not train on your data by default.

orbo.work's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

  • Google API Services User Data Policy

06Cookies

orbo.work uses only the cookies it needs to work: to keep you signed in and to remember your language, time zone and layout. We set no tracking or advertising cookies, and page views are counted without cookies. Each cookie, its purpose and how long it lasts are on our Cookie notice.

  • Cookie notice

07Where your data is kept

orbo.work stores its data, and its backups, in the European Union. Some services that help us run it handle data in other countries, as our Subprocessors page lists, with the safeguards the law requires.

08How long we keep it

  • Notes, transcripts and any recordings from calls are kept only as long as needed to run the service, then deleted. The record of actions taken in a company is kept at most until the company is deleted, then erased with it as section 09 describes; only anonymous counts, with no names or content, remain after that. A company can delete any of these sooner.
  • Apart from a recording the meeting allows, call audio is held in memory only while it is turned into text, never stored.
  • Chats, tasks, projects, files, notes, and what is saved from connected accounts stay until someone in the company deletes them, or the company is deleted.
  • Accounts stay until you ask us to delete yours. Waitlist entries stay until you ask us to remove them.
  • We may keep some records longer where the law requires it, to resolve disputes, or to enforce our agreements.
  • Server logs are kept for a short time to fix problems, then deleted. We keep backups so data can be restored, and delete them on a fixed cycle, so deleted data leaves the backups when that cycle ends.

09Deleting your data

  • A company: its Owner can delete it in Settings, Danger zone. It can be restored for the period shown there; after that its content, connected accounts, people and invitations are erased, and any subscription is cancelled.
  • A connected account: disconnect it on its app's page in orbo.work, such as Mail or Calendar. Its sign-in is deleted at once. For a Google account, orbo.work also asks Google to end its access, unless another account connected in orbo.work still uses the same Google account. What was already saved from it stays with the company's tasks and records until they are deleted. You can also remove orbo.work's access at myaccount.google.com/permissions.
  • A single chat, project or agent: delete it where it is.
  • Your account: email [email protected] from the address you sign in with, and we will delete it.

10Who can see what

  • Your conversations with the Chief of Staff are shown only to you: other people in your company, including its Owners, cannot open them in orbo.work. What can reach your company is what comes out of a conversation: what you teach the Chief of Staff can be saved to your company's shared memory, and tasks you create are shared with the people who work on them. Private mode stops anything from the conversation being saved to shared memory unless you choose to keep it, and turns web search off for that conversation.
  • Tasks, projects, files and notes are shared with the company. A connected account belongs to a person, a project or the whole company, and only they can use it.
  • Our staff see a company's content only to answer a support report it sends (and then only what the report shares, for a limited time), to keep the service safe, or when the law requires it.
  • Companies share anonymous counts, such as how many tasks ran, with our staff overview by default. An Owner can turn this off in Settings.

11Security

Each agent works in its own isolated computer, connected accounts are encrypted with a key that belongs to the company, and some actions, such as deletions and invitations, wait for a person's approval. Our Security page describes the safeguards. If a breach affects your data, we will tell you and the authorities as the law requires.

  • Security

12Your rights

Depending on where you live, you may have the right to see the data we hold about you, get a copy of it, correct it, delete it, limit or object to how we use it, and withdraw any consent you gave. To do any of these, email [email protected]. We answer within one month.

If your company runs your orbo.work account, some requests about the company's content are for your company to decide, and we will pass them to it. You can also complain to the DIFC Commissioner of Data Protection, or to the data protection authority where you live.

13Children

orbo.work is for people at work and is not meant for anyone under 18. We do not knowingly collect children's data; if you think we have, tell us and we will delete it.

14Changes to this policy

When we change this policy we update the date at the top. If a change matters to how we use your data, we will tell companies using orbo.work by email or in the product before it takes effect.

Contact us

Questions, requests about your data, or a complaint: write to us and a person will answer.

Email
[email protected]
Phone
+971 50 993 4521
Address
Orbo Technologies Ltd
Unit GA-00-SZ-L1-RT-201, Level 1

Gate Avenue - South Zone

Dubai International Financial Centre

P.O. Box 507311

Dubai, UAE
orbo.work

Everyone gets a team.

Product

How it worksThe filmQuestionsUse casesCompare

Company

AboutSign inTalk to usTermsPrivacy

Languages

English中文Españolالعربية

Built by Orbo Technologies. © 2026 orbo.work