This is a starting template, not legal advice. Have a Malaysian lawyer review and adapt it before relying on it.
Legal
Privacy Policy
Orbit HR is built local-first. The short version: your employee and payroll data stays on your device, and we never collect or see it.
Last updated: 09/08/2026
1. The local-first truth (read this first)
Orbit HR stores your HR and payroll records on your own device. That includes employee records, NRIC or passport and work permit details, bank account numbers, salaries, statutory numbers (EPF, SOCSO, EIS, PCB and HRD Corp), payroll runs, payslips, leave records, attendance and timesheets, expense claims, letters, and any documents you upload. The app works fully offline. We, the vendor, do not collect, receive, store, or have any access to that data. There is no account login that uploads your employee files to us, and there is no server holding your payroll records.
Encryption on your device. Sensitive identifiers (NRIC, passport, bank account and statutory numbers) are encrypted at rest on your machine using AES-256-GCM. The app also has an auditor role that only ever sees masked identifiers, so you can hand over a review without exposing the underlying numbers.
You are the data controller. The records in Orbit HRare your employees’ personal data, and you (the employer) remain the data user and controller of that data under the PDPA. Orbit HRis software running on your own machine, not a cloud service holding your employees’ data. Collecting, securing, retaining and disclosing that data lawfully, including giving your employees a notice and honouring their access and correction requests, stays your responsibility.
The one outbound call. The app checks a public releases page for new versions. That check sends no identifiers, no employee data and no telemetry. Everything else stays offline unless you turn on the optional features in clauses 4 and 5.
This means your most sensitive information never passes through us by default. The only data we handle is the small amount needed to sell you a license and support you, described below.
The data controller for that limited order data is Mushnor Heritage Resources (Registration No. 201803323851 (002884313-T)), No 2-12-13A, Solaria Residences, Medan Rajawali, Sungai Ara, 11900 Bayan Lepas, Pulau Pinang. Reach us at support@orbitsuite.io.
2. What the sales & licensing flow collects
When you buy a license, we collect only what we need to process the order and issue your key:
- Your name: to address you and issue the license.
- Your email: to send your license key, download link, receipt, and support replies. Your key is tied to this email.
- Your company name: for the license record and your purchase reference.
- Payment proof: the screenshot or file you upload (for example, a DuitNow or bank-transfer receipt) so we can verify payment manually.
This data is processed through Supabase, our hosting and database provider, and stored securely there. We use it only to verify your payment, issue and support your license, and keep basic records of the sale. We do not sell your data or use it for advertising.
We never ask for your employees’ personal data in order to sell or support a license. Please do not send us employee records, NRIC numbers, bank details or payroll files when you contact support.
3. Retention
We keep your order and license details for as long as your license is active and for as long as we are required to for legitimate business and legal/tax record-keeping. Uploaded payment proofs are kept only as long as needed to verify and evidence the transaction, then deleted on a routine basis. You can ask us to delete your personal data where we are not legally required to keep it (see clause 8).
4. Optional sync subscription (end-to-end encrypted)
If you subscribe to sync, your data is synchronised across your own devices and apps using end-to-end encryption. Your data is encrypted on your device before it is transmitted, and only your devices hold the keys to decrypt it, so we cannot read your synced content. We process the minimum metadata required to route the sync and to manage your subscription billing. If you cancel sync, syncing stops and your data remains on your devices.
5. AI assistant (optional, off by default)
The AI assistant is off unless you turn it on. It runs through your own Claude subscription on your machine (the Claude CLI), not through us. When you use it, the relevant content is redacted on your device and then sent directly from your machine to Anthropic under Anthropic’s terms and privacy policy. We do not receive or store your prompts, your employee data, or the responses. If you never enable the assistant, nothing is ever sent to any AI provider.
6. Cookies & this website
This marketing and checkout website aims to keep tracking minimal. We do not use third-party advertising cookies. Any cookies used are limited to what is necessary to operate the site and process your order securely.
Referral cookie. If you arrive through a link shared by one of our partners, that link carries a referral code (for example ?ref=PARTNER). We store that code in a first-party cookie named orbit_reffor up to 60 days, so that if you buy later we can credit the partner who introduced you. The cookie holds only the partner's code. It does not identify you, it is not shared with anyone, and it is not used for advertising or profiling. If you already have one, a later referral link will not overwrite it.
Language cookie. If you switch language, we remember that choice in a cookie named orbit_lang so the site stays in the language you picked on your next visit.
7. Affiliate portal
If you are an affiliate partner, we store your name, email and phone number to run the programme and pay your commission. When you sign in to the affiliate portal we store a session record (and the single-use sign-in link emailed to you) purely so that only you can see your own earnings. You only ever see your own sales: we never disclose a buyer’s name, email or details to an affiliate.
8. Your rights under the PDPA
We process personal data in line with Malaysia’s Personal Data Protection Act 2010 (PDPA). Under the PDPA you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Withdraw consent to our processing, where processing is based on consent;
- Limit how we process your data; and
- Ask us to delete data we are not legally required to keep.
These rights are exercised against us for the limited order and license data we hold. They do not cover the employee records you keep inside the app: those sit on your device and never reach us.
For your employees’ personal data, you are the data user under the PDPA and your employees exercise their PDPA rights against you, not against us. If one of your employees asks us for their data, we will tell them to contact their employer, because we do not hold it.
9. Security
We take reasonable technical and organisational measures to protect the limited data we hold, including secure hosting via Supabase and restricted access to order records. No system is perfectly secure, but because we deliberately hold so little of your data, the exposure is minimal by design.
10. Contact & data requests
To exercise any of your rights, or for any privacy question, email support@orbitsuite.io. We will respond within a reasonable time and in line with the PDPA.
11. Changes to this policy
We may update this policy from time to time. The “Last updated” date above shows the current version; material changes will be reflected on this page.