Privacy Policy
This page is maintained by Orbit Engine to explain how we handle personal data on this website, through our services, and in our own B2B outreach. It is written to be understood rather than to impress, and it should be read alongside your own contractual agreements with us. Where we process personal data, we do so in line with UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations (PECR).
This policy covers: what we collect, prospect data used in B2B outreach, why we use it, your right to object to direct marketing, how long we keep data, website analytics and your rights.
What we collect
We collect information you provide directly — for example, when you complete the contact form or book a call — including your name, work email, company and role.
How we use it
We use this information to respond to your enquiry, arrange calls, and (where relevant) deliver our services. We do not sell personal data.
B2B outreach and prospect data
Orbit Engine is an outbound lead generation business. To find people who may genuinely benefit from our services, we may collect and process limited professional information about business contacts. This is normally limited to:
- Name
- Job title or professional role
- Company
- Business email address
- Business contact information, such as a work telephone number
- Publicly available professional information relevant to determining whether Orbit Engine’s services may be relevant to the business
We do not collect special category data (for example health, religion or political beliefs), and we do not build detailed personal profiles of individuals. The information we hold relates to people in a professional capacity, not to their private lives.
This information may be obtained from publicly available or legitimate business sources, including:
- Company websites
- Companies House
- Professional networking platforms such as LinkedIn
- Reputable business-data providers
Where a source imposes its own terms of use, we aim to respect them. If you believe we are holding information about you that is inaccurate or should not be held, tell us and we will correct or remove it.
Why we use prospect data
We use this information to identify and contact relevant decision-makers at businesses that may reasonably have an interest in Orbit Engine’s B2B services — in practice, hiring managers and owners of UK recruitment agencies who are likely to need a consistent flow of client conversations.
Where it is appropriate to do so, we rely on legitimate interests as our lawful basis for this processing under UK GDPR. In plain English: Orbit Engine has a genuine commercial interest in promoting its services to businesses that are likely to find them useful, and we take steps to make sure the outreach is targeted, proportionate and as minimally intrusive as we can make it — limited data, relevant audiences, a clear sender identity and a straightforward way to stop hearing from us.
Legitimate interests is not an automatic justification for everything we do. We consider it case by case: whether the contact is genuinely relevant, whether the individual would reasonably expect to hear from us, and whether our interest is outweighed by their privacy rights. Where legitimate interests is not the right basis — for example where PECR requires consent to send a particular marketing message — we do not rely on it, and we either obtain consent or do not send the message. We do not claim that all cold email is lawful, and we do not send marketing where the rules require consent we do not have.
PECR rules in the UK differ depending on whether a recipient is a corporate body or an individual such as a sole trader, and we take that distinction into account when deciding who may be contacted. Every message we send identifies who we are and includes a simple way to opt out.
Direct marketing and your right to object
You have the right to object at any time to the use of your personal data for direct marketing. This is an absolute right: once we receive an objection, we must stop using your personal data for that purpose. There is no need to give a reason and no charge.
If you receive outreach from Orbit Engine, you can opt out by:
- Replying to the email and asking not to be contacted
- Replying “opt out”
- Contacting us at hello@orbitengine.co.uk
Once somebody objects to direct marketing, Orbit Engine will stop using their personal data for that purpose.
So that your choice is respected properly, we may keep the minimum information necessary on a suppression list — typically an email address and a note of your objection and its date — so that you are not accidentally contacted again. That record exists only to honour your preference; it is not used for marketing, sold or shared for marketing purposes.
Data retention
We keep personal data only for as long as reasonably necessary for the purpose for which it was collected — for example, to respond to an enquiry, to carry out our own B2B outreach, or to deliver a service. When data is no longer needed for those purposes, we delete or anonymise it. We review the information we hold periodically rather than keeping it indefinitely.
We may retain limited suppression records where necessary to honour marketing objections and make sure somebody who has opted out is not contacted again. Records relating to the services we provide may also be kept for as long as needed for our own legitimate business, contractual, tax and legal purposes.
Website analytics
With your consent, we may collect behavioural information about your visit: pages viewed, referring source, approximate location (derived from IP address), device and browser details, clicks, scrolling, navigation paths, session duration, heatmaps and privacy-masked session recordings. We use this only to understand how the website is used and to improve its clarity and performance. We do not build personal profiles from anonymous browsing behaviour, and session-recording tools must mask form fields, passwords, payment details and free-text messages.
We use Microsoft Clarity (project ybm4bimlwg) for this purpose. Clarity records page interactions, heatmaps and privacy-masked session replays, and sets cookies such as _clck, _clsk, CLID, ANONCHK, MUID, SM and MR (durations from 10 minutes to 13 months). Clarity is loaded only after you grant Analytics consent, we send Microsoft’s Consent API a “denied” signal for advertising storage at all times, and every form field on this site is masked so names, email addresses, telephone numbers, messages and payment details are never captured. Microsoft acts as a processor and may also use the data as described in the Microsoft Privacy Statement. No marketing or advertising providers (for example LinkedIn or Meta) are installed. Our hosting platform separately records basic page-hit and session information for service delivery and security.
We also use Google Analytics 4 (property G-HTYY9WDEP7) for aggregate traffic measurement: pages and routes viewed, referring source, approximate location derived from a truncated IP address, device, browser and language, session duration and standard Enhanced Measurement interactions such as scrolls, outbound clicks and file downloads. It sets the first-party cookies _ga and _ga_HTYY9WDEP7 (both 2 years). We operate Google Consent Mode v2: analytics_storage, ad_storage, ad_user_data and ad_personalization all default to denied, the Google tag is not loaded before you grant Analytics consent, and granting consent updates only analytics_storage to granted — the advertising signals remain denied because we do not use Google Ads, Google Signals or remarketing. IP anonymisation is enabled, and we never transmit names, email addresses, telephone numbers, form contents or Calendly booking details to Google. Google acts as our processor and also processes data as described in the Google Privacy & Terms.
If you withdraw Analytics consent, Clarity stops collecting and receives a denied consent signal, Google Analytics collection is disabled and its consent state returns to denied, and the Clarity and Google Analytics cookies we can access are deleted from your browser.
You can withdraw or change consent at any time using the “Cookie settings” link in the footer. Full detail is in our Cookie Policy.
Your rights
Under UK data protection law you have the following rights in relation to personal data we hold about you. Contact hello@orbitengine.co.uk and we will handle your request.
- The right to be informed — how and why we use your personal data, as set out in this policy.
- The right of access — to request a copy of the personal data we hold about you.
- The right to rectification — to ask us to correct inaccurate or incomplete information.
- The right to erasure — to ask us to delete your personal data where we have no compelling reason to keep it.
- The right to restrict processing — to ask us to pause the use of your data in certain circumstances.
- The right to object to direct marketing — to tell us to stop using your personal data for direct marketing at any time, free of charge. We must stop as soon as we receive your objection. You can also object to processing based on legitimate interests, which we will assess and explain.
- The right to data portability — to receive the data you have given us in a structured, commonly used format, where processing is by consent or under a contract and carried out automatically.
- The right to withdraw consent — where we rely on your consent, such as website analytics, at any time without affecting the lawfulness of processing before you withdrew it.
Requests are usually free of charge and answered within one month. We may need to verify your identity before responding. If you are unhappy with how we have handled your personal data, you can raise a complaint with us first, and you also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority, at ico.org.uk.
Other privacy information
Orbit Engine has not appointed a Data Protection Officer, which is not required for our type of processing. Privacy enquiries, requests and objections should be sent to hello@orbitengine.co.uk. We are not ICO-certified or GDPR-certified and make no such claim; this policy describes how we handle personal data and the choices available to you.
We may update this page over time, particularly if our services, the tools we use or the law change. Material changes will be reflected here, with the date below revised.
Last updated: September 2026.
