Orbit

Privacy Policy

Effective Date / Last Updated: August 11, 2026

ORBIT is a real-world asset tokenization platform operated by ORA RWA LLC, a Wyoming limited liability company.

1. Introduction and Scope

ORA RWA LLC, a Wyoming limited liability company with its principal office at 1908 Thomes Ave, Cheyenne, Wyoming 82001 ("ORA," "Company," "we," "us," or "our"), operates the ORBIT platform (the "Platform" or "ORBIT"), a technology platform focused on the tokenization of real-world assets ("RWAs"). This Privacy Policy explains how we collect, use, disclose, and protect personal data in connection with the Platform, and describes the privacy rights available to you and how to exercise them.

This Privacy Policy applies to visitors, registered Users, and prospective Users of the Platform worldwide, including individuals located in the European Economic Area ("EEA"), the United Kingdom ("UK"), and the United States. Where the General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"), the UK GDPR, or a U.S. state privacy law such as the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") or another applicable U.S. state privacy law grants you specific rights, Section 12 describes those rights in detail.

This Privacy Policy also applies to the authorized representatives, directors, officers, and beneficial owners of an Issuer whose personal data ORA collects when onboarding that Issuer and providing Minting Services to it, as described in Section 3.5. It does not govern personal data that an Issuer itself collects from its own customers or investors outside the Platform, which is that Issuer's own responsibility.

This Privacy Policy is incorporated by reference into, and should be read together with, our Terms and Conditions. Capitalized terms not defined here have the meaning given in the Terms and Conditions.

Because ORA is not currently offering the Platform's transactional features to U.S. Persons (see our Terms and Conditions), most current Users are located outside the United States; this Privacy Policy is written to also anticipate the U.S. expansion described in our Terms and Conditions.

2. Definitions

  • "Personal Data" (or "Personal Information" under U.S. state law) means information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, with a particular individual.
  • "Processing" means any operation performed on Personal Data, including collection, recording, storage, use, disclosure, and deletion.
  • "Controller" means the entity that determines the purposes and means of Processing Personal Data. ORA acts as the Controller of Personal Data collected through the Platform, except where we act as a Processor on behalf of an Issuer, as described in Section 5.
  • "Sub-processor" or "Service Provider" means a third party that Processes Personal Data on our behalf and under our instructions.
  • "Digital Wallet Address" means the public blockchain address associated with a User's self-hosted or third-party Digital Wallet.

3. Personal Data We Collect

We collect the following categories of Personal Data:

3.1 Identity and KYC Data

  • Full name, date of birth, nationality, and residential address;
  • Government-issued identification documents (such as passport, national ID, or driver's license) and the information they contain;
  • Proof-of-address documentation;
  • Selfie images or biometric liveness-check data used to verify that you are the person depicted in your identification document, where our identity-verification provider uses this method;
  • Tax residency and tax-identification information, including certifications such as IRS Form W-8 series or equivalent;
  • Source-of-funds and source-of-wealth information, and, where applicable, information about beneficial owners of an entity account.

3.2 Account and Transaction Data

  • Account credentials and registration information;
  • Digital Wallet Addresses you connect to the Platform;
  • Records of your transactions, Token holdings, and interactions with Issuers and other Users on the Platform;
  • Correspondence with our support team.

3.3 Device, Usage, and Technical Data

  • IP address, browser type and version, device identifiers, operating system, and general location data derived from your IP address;
  • Log data, pages viewed, referring URLs, and interactions with the Platform;
  • Cookie and similar tracking-technology data, as described in Section 6.

3.4 Publicly Available Blockchain Data

When you transact on a public blockchain network through the Platform, your Digital Wallet Address, transaction hash, and transaction details are recorded permanently and publicly on that blockchain. This data is not controlled by ORA and exists independently of the Platform, as described further in Section 13.

3.5 Issuer and Business ("KYB") Data

Separately from the User data described above, ORA's Platform performs the technical minting of Tokens ("Minting Services") at the direction of Issuers, as described in our Terms and Conditions. To onboard an Issuer and provide Minting Services to it, we collect know-your-business ("KYB") information about the Issuer entity and about the individuals associated with it, including:

  • Corporate formation documents, registration numbers, and registered-agent information for the Issuer entity;
  • Names, titles, contact details, and government-issued identification of the Issuer's authorized representatives, directors, officers, and signatories who instruct or interact with ORA on the Issuer's behalf;
  • Beneficial-ownership information for the Issuer entity, including names, ownership percentages, and identification of individuals who own or control the Issuer;
  • Minting instructions and related data the Issuer submits to ORA to configure a Token (such as proposed token supply and metadata), which may incidentally include the names or other identifying details of individuals associated with the Underlying Asset (for example, a property manager or authorized signatory named in supporting documentation).

We use this KYB data to verify the Issuer's identity and authority, to perform sanctions and AML screening on the Issuer and its representatives and beneficial owners, to perform Minting Services under the applicable Issuer Agreement, and to comply with Applicable Law. The legal bases, sharing, retention, and rights described elsewhere in this Privacy Policy apply equally to this KYB data, except where this Section 3.5 states otherwise.

4. Sources of Personal Data

  • Directly from you, when you register for an account, complete identity verification, contact support, or otherwise interact with the Platform;
  • Automatically, through cookies and similar technologies when you use the Platform;
  • From third-party identity-verification, sanctions-screening, and anti-money-laundering ("AML") service providers we engage to perform KYC checks;
  • From publicly available sources, including sanctions and watch lists and public blockchain records;
  • From Issuers, where necessary to facilitate a transaction you have chosen to enter into;
  • From an Issuer itself, and from corporate-registry, beneficial-ownership, and KYB-verification providers, when we onboard that Issuer and provide it with Minting Services.

We use Personal Data for the following purposes, and, where the GDPR or UK GDPR applies, we rely on the following legal bases under Article 6(1) of the GDPR:

  • To create and administer your account, and to provide, operate, and improve the Platform (legal basis: performance of a contract with you).
  • To perform identity verification, sanctions screening, AML monitoring, and other compliance checks required by Applicable Law, and to detect and prevent fraud, market abuse, and other illegal activity (legal basis: compliance with a legal obligation, and/or our legitimate interests in protecting the Platform and its Users).
  • To communicate with you about your account, transactions, and changes to our policies (legal basis: performance of a contract, and/or legitimate interests).
  • To send you marketing communications where permitted (legal basis: consent, which you may withdraw at any time; or legitimate interests where permitted by Applicable Law).
  • To analyze and improve the Platform's functionality, security, and user experience (legal basis: legitimate interests).
  • To comply with legal, regulatory, tax, and reporting obligations, and to respond to lawful requests from courts, regulators, and law-enforcement authorities (legal basis: compliance with a legal obligation).
  • To establish, exercise, or defend legal claims (legal basis: legitimate interests).
  • To onboard, verify, and provide Minting Services to Issuers, including performing KYB checks on an Issuer and its authorized representatives and beneficial owners (legal basis: performance of the Issuer Agreement, and/or compliance with a legal obligation relating to AML and sanctions).

Where our identity-verification process involves biometric data (such as a facial-recognition liveness check), which may constitute "special category data" under Article 9 of the GDPR, we rely on your explicit consent or, where applicable, the exception for processing necessary for compliance with legal obligations relating to AML and countering the financing of terrorism, and we implement additional safeguards for this data.

5.1 Automated Decision-Making

Our identity-verification and sanctions-screening providers may use automated tools to assess identity-document authenticity, match names against watch lists, or generate a risk score. Automated matches that could result in a denial or restriction of your account are subject to human review before a final adverse decision is made. You may contact us using the details in Section 16 to request human review of an automated decision that produces legal or similarly significant effects on you, to the extent required by Applicable Law.

6. Cookies and Tracking Technologies

We and our service providers use cookies, pixels, and similar tracking technologies on the Platform for purposes including: (a) enabling core functionality, such as keeping you logged in; (b) remembering your preferences; (c) measuring and analyzing Platform usage through analytics tools; and (d) where applicable, supporting marketing and advertising measurement.

Where required by Applicable Law, we will request your consent before placing non-essential cookies, through a cookie-consent banner or preference center on the Platform, and will allow you to withdraw that consent at any time. You can also control cookies through your browser settings, though disabling certain cookies may affect the functionality of the Platform.

7. How We Share Personal Data

We do not sell Personal Data for money. We disclose Personal Data only in the following circumstances:

  • Service Providers: to third-party identity-verification, sanctions-screening, AML, cloud-hosting, analytics, customer-support, and payment-processing providers that Process Personal Data on our behalf, under contractual confidentiality and data-protection obligations.
  • Issuers and Counterparties: where necessary to facilitate a specific transaction you have chosen to enter into, we may share limited information (such as your Digital Wallet Address and, where legally required for a specific offering, verified accredited-investor or eligibility status) with the relevant Issuer.
  • Service Providers to Issuers: KYB data we collect about an Issuer's representatives and beneficial owners (Section 3.5) may be shared with the same categories of identity-verification, sanctions-screening, and AML service providers described above, on the same basis.
  • Regulators and Law Enforcement: where required by Applicable Law, court order, or valid legal process, or where we believe disclosure is necessary to comply with AML, sanctions, tax, or other legal obligations, or to protect the rights, property, or safety of ORA, our Users, or the public.
  • Corporate Transactions: in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case Personal Data may be disclosed to the parties involved, subject to confidentiality obligations.
  • With Your Consent: for any other purpose disclosed to you at the time of collection, or with your consent.

8. International Data Transfers

ORA is a U.S. entity, and Personal Data we collect may be transferred to, stored, and Processed in the United States and other countries that may not have data-protection laws equivalent to those in your home jurisdiction.

Where we transfer Personal Data originating in the EEA or the UK to a country that has not been recognized as providing an adequate level of data protection, we rely on appropriate safeguards recognized under the GDPR and UK GDPR, such as the European Commission's Standard Contractual Clauses and the UK's International Data Transfer Addendum, or an applicable derogation under Article 49 of the GDPR (such as where the transfer is necessary for the performance of a contract with you). You may contact us using the details in Section 16 to request further information about, or a copy of, the safeguards we use.

9. Data Retention

We retain Personal Data for as long as necessary to fulfill the purposes described in this Privacy Policy, including to satisfy legal, accounting, and regulatory requirements.

In particular, KYC, identity-verification, and transaction records are generally retained for a minimum of five (5) years following the closure of your account or the completion of the relevant transaction, in line with common AML record-keeping requirements, and may be retained longer where required by Applicable Law or to resolve disputes and enforce our agreements. Device, usage, and analytics data are generally retained for shorter periods appropriate to their operational purpose. KYB data we collect about an Issuer's representatives and beneficial owners (Section 3.5) is retained on the same five-year minimum basis, generally measured from the termination of the applicable Issuer Agreement or the delisting of the Issuer's last Token, whichever is later.

10. Data Security

We implement administrative, technical, and organizational measures designed to protect Personal Data against unauthorized access, disclosure, alteration, and destruction, including encryption in transit, access controls, and vendor due diligence. No system is completely secure, however, and we cannot guarantee the absolute security of Personal Data. You are responsible for maintaining the confidentiality of your account credentials and, as described in our Terms and Conditions, for the security of your Digital Wallet, which we never control.

If we become aware of a security incident affecting your Personal Data that requires notification under Applicable Law, we will notify you and, where required, the relevant supervisory authority, without undue delay and in accordance with the timelines required by that law (for example, within 72 hours of becoming aware of a qualifying breach under the GDPR, where feasible).

11. Children's Privacy

The Platform is not directed to, and we do not knowingly collect Personal Data from, individuals under the age of 18. If we learn that we have collected Personal Data from someone under 18, we will take reasonable steps to delete that information, consistent with our record-retention obligations under Applicable Law.

12. Your Privacy Rights

12.1 Rights Under the GDPR and UK GDPR

If you are located in the EEA or the UK, you have the following rights in relation to your Personal Data, subject to certain exceptions and limitations under Applicable Law:

  • Right of access to the Personal Data we hold about you and information about how we Process it;
  • Right to rectification of inaccurate or incomplete Personal Data;
  • Right to erasure ("right to be forgotten") of your Personal Data in certain circumstances;
  • Right to restrict our Processing of your Personal Data in certain circumstances;
  • Right to data portability, to receive certain Personal Data you provided to us in a structured, commonly used, machine-readable format;
  • Right to object to Processing based on our legitimate interests, or to direct marketing at any time;
  • Right to withdraw consent at any time, where Processing is based on consent, without affecting the lawfulness of Processing before withdrawal;
  • Right to lodge a complaint with your local data-protection supervisory authority.

Please note that, because AML, sanctions, and other legal obligations require us to retain certain KYC and transaction records, we may not always be able to fully erase or restrict Personal Data subject to those obligations, and we will explain any applicable limitation when responding to your request.

12.2 Rights Under U.S. State Privacy Laws

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, or another U.S. state with a comprehensive consumer privacy law, you have rights that may include:

  • The right to know or access the categories and specific pieces of Personal Information we have collected about you, and the categories of sources, purposes, and third parties with whom it is shared;
  • The right to request deletion of your Personal Information, subject to legal exceptions such as our KYC/AML record-keeping obligations;
  • The right to correct inaccurate Personal Information;
  • The right to opt out of the "sale" or "sharing" of Personal Information (we do not sell Personal Information for money and do not share it for cross-context behavioral advertising, except to the extent certain analytics or advertising cookies described in Section 6 are deemed a "sale" or "share" under Applicable Law, in which case you may opt out through our cookie-preference center);
  • The right to limit the use and disclosure of sensitive Personal Information (such as government-ID or precise-geolocation data) to what is necessary to provide the Platform and comply with legal obligations;
  • The right not to be discriminated against for exercising any of these rights.

12.3 How to Exercise Your Rights

You may exercise these rights by contacting us using the details in Section 16. We will verify your identity before responding to your request, using information proportionate to the sensitivity of the data requested, and will respond within the timeframe required by Applicable Law. You may also designate an authorized agent to submit a request on your behalf, subject to verification.

13. Blockchain-Specific Notice

PLEASE READ THIS SECTION CAREFULLY. BECAUSE ORBIT IS A NON-CUSTODIAL PLATFORM, MANY TRANSACTIONS YOU CONDUCT THROUGH ORBIT ARE RECORDED ON PUBLIC BLOCKCHAIN NETWORKS THAT ORA DOES NOT OPERATE OR CONTROL. YOUR DIGITAL WALLET ADDRESS AND ASSOCIATED TRANSACTION DATA MAY BE PERMANENTLY AND PUBLICLY VIEWABLE, AND, ONCE RECORDED, GENERALLY CANNOT BE DELETED, CORRECTED, OR MADE PRIVATE BY ORA OR ANYONE ELSE, INCLUDING IN RESPONSE TO AN ERASURE OR DELETION REQUEST UNDER THE GDPR, UK GDPR, OR U.S. STATE PRIVACY LAW.

A Digital Wallet Address may be considered Personal Data under the GDPR and similar laws where it can reasonably be linked to an identifiable individual, including through the KYC information we hold. Because we cannot alter or erase records on a public blockchain, our ability to honor erasure, rectification, or restriction requests is limited to the Personal Data we hold in our own systems, and does not extend to on-chain data recorded by the blockchain network itself.

The Platform may link to, or integrate with, third-party websites, Digital Wallets, blockchain networks, and other services that are not operated by ORA. This Privacy Policy does not apply to those third-party services, and we encourage you to review their own privacy policies before providing Personal Data to them.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time by posting a revised version on the Platform with a new "Last Updated" date. For material changes, we will use reasonable efforts to provide additional notice, such as an in-app notification or email, before the change takes effect. Your continued use of the Platform after a revised Privacy Policy takes effect constitutes your acceptance of the changes.

16. Contact Us

If you have questions about this Privacy Policy, or wish to exercise any of the rights described in Section 12, please contact us at:

ORA RWA LLC

1908 Thomes Ave, Cheyenne, Wyoming 82001

Registered Agent: AAA Corporate Services, Inc., 1908 Thomes Ave, Cheyenne, Wyoming 82001

Privacy contact: info@orbitrwa.io