Orbit by LogicFlowOrbit by LogicFlow

Privacy Notice

Version 1.1 · Effective 2026-10-05

Initial operational draft for review. It is not a statement of legal certification.

This Privacy Notice explains how personal data is processed when you use LogicFlow Orbit (the “Service”) and when you contact us through the enquiry form on its public website.

1. Who is responsible

LogicFlow, the operator of the Service, decides how and why personal data is processed in the Service (the controller). Contact: office@logicflow.pl.

2. Data we process

  • Account and profile data: your name, email address and the internal user identifier, your role and membership status.
  • Identity-provider data: when you sign in with Google or Microsoft we receive an identifier, your name and your verified email address. We use no provider access tokens after sign-in and do not store them.
  • Project and business data: information you or your colleagues enter about projects, customers, contacts (names, emails, phone numbers, job titles), sites, equipment, shipments, comments and uploaded documents.
  • Security and usage records: sign-in sessions, an audit log of important actions (who did what and when) and technical logs needed to run and protect the Service.
  • Contact enquiries: when you use the “Contact us” form on the public website we process your name, company, email address, phone number (optional) and the contents of your message, together with technical and security information needed to prevent abuse of the form (such as your IP address, used to limit repeated submissions).

3. Why we process it

  • To provide the Service and manage access (performance of the arrangement under which you use the Service, and the operator's legitimate interest in running a business operations tool).
  • To keep the Service secure, prevent misuse and keep an audit trail (legitimate interest, and legal obligations where they apply).
  • To communicate with you about the Service when needed.
  • To respond to business enquiries sent through the contact form, maintain the resulting correspondence and protect the form from abuse (the operator's legitimate interest in answering and handling business enquiries and in keeping the website secure, and steps taken at your request before entering into an agreement where that applies).
  • Where a specific feature relies on your consent, we will ask for it separately. We do not rely on consent for ordinary use of the Service.

4. Service providers

We use service providers (processors) to run the Service. Depending on the enabled functionality they may include: Cloudflare (hosting and file storage), Neon (database), Google and Microsoft (sign-in), OpenAI (AI features, only when you use them and only with the data needed for the request) and Resend (email delivery of enquiries sent through the contact form).

5. Retention

  • Project and business records: retained during the business relationship and for up to 5 years afterwards, unless longer retention is required by law or for the establishment, exercise or defence of legal claims.
  • Audit and security records: retained for 24 months, unless longer retention is needed for security, investigation, legal or compliance purposes.
  • User account data: retained for the lifetime of the account and afterwards only as necessary for legal, security or compliance purposes.
  • Sessions: last at most 12 hours and end earlier when revoked.
  • Contact enquiries: the form does not store enquiries in the Service's database. Each enquiry is delivered by email to our business inbox and kept there as business correspondence for as long as needed to handle it and any resulting business relationship, unless longer retention is required by law or for the establishment, exercise or defence of legal claims.

6. Security

We use access control by role and assignment, encrypted connections, server-side sessions, encrypted storage of device credentials and an audit log. No system is perfectly secure; please report suspected incidents to the contact below.

7. Your rights

Under the GDPR you may request access to your personal data, rectification, erasure, restriction, portability and object to processing based on legitimate interests, as far as the law provides. You may also withdraw consent where processing is based on consent. Contact us to exercise your rights.

8. Contact and complaints

For questions about this notice or to exercise your rights, contact office@logicflow.pl. You may lodge a complaint with a supervisory authority; in Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, uodo.gov.pl).

9. Changes

We may update this notice. When it changes materially you will be asked to acknowledge the new version.

Terms of UseSign in