Integritetspolicy

1. Who we are

OrbGIS is provided by OrbGIS AB, org. no. 559598-2785, Olaus Magnus väg 48, 121 38 Johanneshov, Sweden (“we”, “us”). We are the data controller for the personal data described in this policy. You can reach us at support@orbgis.se.

2. Two roles: controller and processor

This policy covers the personal data we decide how to process — your account, your use of the platform, and our communication with you. For personal data inside the content that organizations upload to OrbGIS (for example a dataset containing addresses, or responses to a survey an organization publishes), the organization is the data controller and we process that data only on its behalf, under our Data Processing Agreement. If you have questions about data in a map or survey published by an organization, contact that organization.

3. Personal data we process

  • Account data: email address, display name, and a hashed password (we never store your password in readable form).
  • Organization data: which organizations you belong to, your role and privileges, and invitations sent to your email address.
  • Content metadata: titles, descriptions, timestamps, and ownership of the items you create — not analyzed for any purpose beyond providing the Service.
  • Technical logs: IP address, browser/user-agent, and timestamps in server and security logs, kept to operate and secure the Service.
  • Support communication: emails you send us and our replies.
  • Legal acceptance records: which version of the Terms of Service you accepted and when.

We do not use advertising trackers or sell personal data. There are no analytics scripts on the platform or on this website.

4. Purposes and legal bases

PurposeDataLegal basis (GDPR)
Providing the Service (accounts, organizations, content)Account, organization, content metadataArt. 6(1)(b) — performance of a contract
Security, abuse prevention, and troubleshootingTechnical logsArt. 6(1)(f) — legitimate interest in a secure, working service
Transactional email (confirmation, invitations, password reset)Email addressArt. 6(1)(b) — performance of a contract
SupportSupport communicationArt. 6(1)(b) and (f)
Demonstrating terms acceptanceLegal acceptance recordsArt. 6(1)(f) — legitimate interest; Art. 6(1)(c) where applicable

5. Where your data is stored

The Service runs on infrastructure operated by GleSYS AB in data centers in Sweden. Encrypted backups are additionally kept at a secondary location in Sweden. Your data does not leave Sweden in normal operation, with the exceptions described in Sections 6 and 7.

6. Recipients and sub-processors

  • GleSYS AB (Sweden): infrastructure hosting.
  • Google Ireland Limited (Ireland): delivery of transactional email (account confirmations, invitations, password resets) via Google’s email infrastructure. Any onward transfer within the Google group is safeguarded under Google’s Chapter V mechanisms (standard contractual clauses / EU–US Data Privacy Framework).
  • Berget AI (Sweden): only when you actively use an AI feature (for example AI-assisted text generation), the content you submit to that feature is sent to Berget AI’s API for processing on infrastructure in Sweden. It is not used to train AI models. If you never use AI features, nothing is sent.
  • Basemap providers: when you view a map, your browser fetches background map tiles directly from third-party providers (for example Carto or Esri), which therefore receive your IP address and the tile requests. This is a direct request from your browser, governed by those providers’ privacy policies.

We may engage additional sub-processors as described in the DPA.

7. International transfers

The personal data we process is stored and processed within Sweden and the EU/EES. Two exceptions apply. First, basemap tiles (Section 6): your browser requests them directly from map providers that may be located outside the EU/EES, under those providers’ own privacy policies. Second, transactional email is delivered through Google Ireland Limited (EU), whose group-internal onward transfers are safeguarded under Chapter V of the GDPR (Section 6). Should we ever engage any other sub-processor outside the EU/EES, the transfer will likewise be safeguarded by an appropriate mechanism under Chapter V.

8. Retention

  • Account and organization data: for as long as your account exists.
  • Content: until you delete it. Deleted items sit in a recycle bin for 30 days before permanent purge.
  • Technical logs: rotated on a short cycle, typically within 90 days.
  • Backups: deleted data disappears from backups as they rotate out on our backup schedule.
  • Legal acceptance records: retained as long as needed to demonstrate acceptance.

9. Security

All traffic is encrypted in transit (TLS). Data is logically isolated per organization with row-level access controls enforced in the database. Administrative access to production systems is restricted to authorized personnel over an encrypted private network. Passwords are stored hashed.

10. Cookies and local storage

We use only what is strictly necessary to operate the Service: your browser stores an authentication session (token) when you sign in, and functional preferences may be kept in local storage. We set no advertising or analytics cookies, so no cookie consent banner is required.

11. Your rights

Under the GDPR you have the right to access, rectify, and erase your personal data, to restrict or object to processing, and to data portability. To exercise these rights, contact support@orbgis.se. You also have the right to lodge a complaint with a supervisory authority — in Sweden, the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se.

12. Changes to this policy

We will update this policy when our processing changes and adjust the “Last updated” date above. For material changes we will notify you by email or in the Service.