← RETURN TO BASE
CLASSIFIED: PUBLIC RELEASABLE

GLOBAL PRIVACY POLICY

Entity: OrbitHelm Inc. ("OrbitHelm")

Effective Date: July 30, 2026

Document ID: OH-LGL-PRV-2026-V1.4

1. Purpose and Scope

This Global Privacy Policy ("Policy") establishes the comprehensive framework under which OrbitHelm Inc., its subsidiaries, and globally distributed aerospace, defense, and AI engineering divisions collect, process, store, and protect personal and machine-generated data. This Policy applies to all digital interfaces, including but not limited to orbithelm.com, ir.orbithelm.com, and our proprietary enterprise networks. By accessing OrbitHelm infrastructure, you consent to the strictly regulated data practices outlined herein.

2. Data Controller Designation

For the purposes of the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and applicable international data protection frameworks, OrbitHelm Inc. acts as the primary Data Controller. All inquiries regarding fiduciary data responsibilities must be directed to our Legal Operations Directorate.

3. Categorization of Collected Data

OrbitHelm employs a minimalist, zero-trust approach to data collection. However, maintaining global infrastructure requires the processing of specific telemetry and user data, categorized as follows:

  • Identity & Communication Data: Names, corporate affiliations, email addresses (processed via routing to hq@orbithelm.com, investors@orbithelm.com, etc.), and cryptographic signatures voluntarily provided through secure contact channels.
  • Technical & Telemetry Data: Internet Protocol (IP) addresses, browser fingerprinting, operating system metrics, time-zone configurations, and node-routing histories.
  • Behavioral & Analytics Data: Interaction metrics on our interfaces, session durations, and navigation paths monitored via integrated Google Analytics arrays to ensure network stability.

4. Lawful Basis for Processing

We process your data strictly under the following lawful bases:

  • Legitimate Interests: To secure our network against cyber kinetic threats, DDoS attacks, and unauthorized reconnaissance.
  • Contractual Necessity: To fulfill requests for investor relations documentation, media kits, or enterprise software demonstrations.
  • Explicit Consent: Where mandated by law, specifically regarding non-essential tracking cookies and marketing communications.
  • Legal Obligation: To comply with international aviation, defense, and export control regulations (e.g., ITAR, EAR) necessitating the logging of specific access requests.

5. Infrastructure & Third-Party Data Sharing

OrbitHelm does not monetize, sell, or indiscriminately distribute personal data. Data sharing is heavily compartmentalized and restricted to:

  • Cloud & Security Providers: Encrypted data may traverse highly secure third-party servers necessary for hosting, load balancing, and threat mitigation.
  • Analytics Processors: We utilize Google Analytics (via Tag Manager) under strict data processing agreements. IP anonymization protocols are enforced where legally required.
  • Government & Legal Entities: We will disclose data only when presented with a legally binding subpoena, warrant, or court order from a recognized international jurisdiction, maintaining transparency unless gagged by national security statutes.

6. International Data Transfers

As a global entity, OrbitHelm may transfer data across international borders. All cross-border data flows originating from the European Economic Area (EEA) or the United Kingdom are protected by Standard Contractual Clauses (SCCs) and advanced cryptographic transit protocols (TLS 1.3+). Data at rest is encrypted utilizing AES-256 standards.

7. Data Retention Protocol

Data is retained only for the duration necessary to fulfill its original collection purpose. Communication logs with non-contracted entities are purged after 24 months. Telemetry and analytic data are aggregated and stripped of personally identifiable markers within 90 days. Legal and investor relations records are retained indefinitely or as mandated by financial compliance laws.

8. Your Rights & Sovereignty Over Your Data

Under international law, you retain sovereign rights over your personal data. You possess the right to:

  • Access & Portability: Request a complete cryptographic export of your personal data held by OrbitHelm.
  • Rectification: Demand immediate correction of inaccurate or incomplete corporate records.
  • Erasure (Right to be Forgotten): Request the permanent deletion of your data, provided it does not conflict with our legal or defense compliance obligations.
  • Restriction: Halt the processing of your data while a legal or accuracy dispute is being resolved.

To execute any of these rights, transmit a formal request to legal@orbithelm.com. Verification of identity will be required prior to any data extraction.

9. Cookie and Tracking Matrix

Our digital interfaces utilize cookies (small encrypted text files) and web beacons to optimize the user experience and maintain session integrity. Essential cookies are deployed automatically to prevent cross-site request forgery (CSRF). Non-essential analytics cookies (e.g., Google Analytics `_ga` and `_gid`) require your navigation consent. You may configure your terminal's browser to reject all tracking matrices, though this may degrade interface functionality.

10. Modifications to this Policy

OrbitHelm reserves the right to amend this Global Privacy Policy autonomously to reflect technological advancements, legal shifts, or operational requirements. Substantial modifications will be highlighted on our public interfaces. Continued use of OrbitHelm infrastructure following such amendments constitutes acceptance of the revised protocols.

For immediate legal assistance or data protection officer (DPO) contact, relay your transmission to: legal@orbithelm.com

ORBITHELM INC. © 2026
PRIVACY POLICYTERMS OF SERVICESECURITY & COMPLIANCEGLOBAL CONTACT
hq@orbithelm.com
↑