This privacy notice explains how ORION GLE LTD collects, uses, stores, and protects personal data when you use our website, contact us, or access our client/admin portal.
1. Controller Information
Data Controller: ORION GLE LTD (Company No. 16933963), registered in England and Wales.
Registered office: 23a Meadowgate Croft, Wakefield, WF3 3SS, United Kingdom.
Email: support@oriongle.co.uk
2. Scope
This notice applies to personal data processed through:
- public website pages and contact forms;
- client and admin portal access;
- client file/document areas in the portal;
- business communications and service enquiries.
3. Personal Data We Process
- Identity and contact data: name, email address, phone number, company details, and message content you submit.
- Portal account data: account role, login email, hashed passwords, session information, reset metadata, and account status.
- Client project data: portal notes, project information, uploaded documents, and folder metadata.
- Technical/usage data: IP-related request logs, browser/device data, pages visited, and performance events.
- Cookie/consent data: consent preferences and analytics choices.
4. Purposes and Lawful Bases (UK GDPR)
- Responding to enquiries and requests: legitimate interests and/or pre-contract steps.
- Delivering services and account access: contract performance.
- Security, fraud prevention, and system integrity: legitimate interests and legal obligations.
- Operational communications (service emails/reset links): contract performance and legitimate interests.
- Optional analytics: consent (where required).
- Compliance with legal obligations: legal obligation.
5. Data Recipients and Processors
We use carefully selected third-party providers acting as processors and/or independent controllers depending on service context, including:
- Vercel (hosting/infrastructure);
- Resend (transactional email delivery);
- Upstash/KV infrastructure (application data storage);
- Google Analytics (only where optional analytics consent is granted).
6. International Data Transfers
Where personal data is processed outside the UK, we rely on appropriate safeguards (for example, contractual safeguards and equivalent transfer mechanisms) in accordance with UK data protection requirements.
7. Data Retention
- Contact enquiries: retained for as long as needed to respond and manage follow-up, then archived/deleted in line with business need.
- Portal accounts: retained while account access is active and for a reasonable period after closure for security and audit purposes.
- Client documents/data: retained for service delivery duration and agreed post-service period unless law requires longer retention.
- Security and operational logs: retained for a limited period necessary for monitoring, troubleshooting, and legal compliance.
- Analytics data: retained according to tool configuration and consent choices.
8. Your Rights
Subject to applicable law, you may request to:
- access your personal data;
- correct inaccurate or incomplete data;
- erase data in certain circumstances;
- restrict or object to certain processing;
- receive your data in a portable format (where applicable);
- withdraw consent for consent-based processing at any time.
To exercise rights, email support@oriongle.co.uk.
9. Complaints
If you are not satisfied with our response, you can complain to the Information Commissioner's Office (ICO): ico.org.uk.
10. Security
We use reasonable technical and organisational controls to protect personal data, including access controls, authentication safeguards, and secure service providers. No internet service is completely risk-free, and users should also maintain good security practices.
11. Children
Our services are not directed to children under 13. If you believe a child has provided personal data to us, contact us so we can take appropriate action.
12. Changes to This Notice
We may update this notice from time to time. Material updates will be posted on this page with a revised effective date.