1. Scope and Relationship to Platform Agreements
These Terms govern Orbt Networks' use of third-party platform APIs provided by operators including Google LLC, Microsoft Corporation, LinkedIn Corporation, and Slack Technologies LLC (each, a "Platform Provider"). These Terms supplement — and do not supersede — each Platform Provider's developer agreement. Where a conflict exists, the Platform Provider's agreement controls.
2. Permitted Uses of Platform APIs
Orbt accesses Platform APIs solely to: build and maintain each user's private Relationship Graph from metadata within granted OAuth scopes; generate relationship-strength signals and contextual notes within a user's own graph; process structured, permissioned Network Queries between opted-in users as described in our Privacy Policy; display users' own connected-account information to support their networking activities; and maintain technical operation of the Orbt service.
3. Prohibited Uses
Orbt does not and will not use Platform APIs for: advertising, ad targeting, ad measurement, or retargeting of any kind; training or improving AI/ML models on user-specific Platform Data without separate explicit consent; selling or licensing Platform Data or any derivative thereof; building data-broker products accessible to parties other than the source user and other users that the source user allows to use; accessing data beyond granted OAuth scopes or after a user revokes authorization; or circumventing rate limits, access controls, or security measures of any Platform Provider.
4. Google API Services — Limited Use Commitment
Orbt's use and transfer of data received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google user data is used only to provide or improve user-facing Orbt features clearly disclosed to end users; it is not used to develop or train generalized AI/ML models; it is not made readable by humans except with affirmative user consent, for security investigation, for legal compliance, or where fully aggregated and anonymized; and it is transferred to third parties only to provide disclosed features, comply with law, or as part of an acquisition where the successor assumes equivalent obligations.
5. OAuth Scope Management
Orbt requests only minimum necessary OAuth scopes, documented and approved before production use. Current scope lists will be published on our website and updated within 14 days of any change. When a user disconnects an integration, access tokens are revoked within 24 hours.
6. Security and Incident Response
Orbt maintains written information security policies, role-based access controls, encryption at rest and in transit, annual third-party penetration testing, and a documented incident response plan. Platform Providers are notified within 72 hours of a confirmed security incident affecting their data.
7. Compliance and Audit
Orbt reviews data handling practices against applicable developer agreements at least annually and upon any material product change, and responds to Platform Provider compliance inquiries within 30 days. Sub-processors are bound by data processing agreements requiring equivalent privacy and security standards.
8. Representations and Contact
Orbt represents that it has authority to enter these Terms, that its API use complies with applicable law, and that information provided to Platform Providers in connection with API access and compliance review is accurate and complete. Orbt will promptly notify Platform Providers of any material change to these representations. Mail: team.adjunctx@gmail.com.