Orbit data-handling statement
Orbit is a Microsoft 365 posture assessment operated by Planet IT. This page states exactly what Orbit reads, what it stores and for how long — written for security reviews and data-protection records.
What Orbit reads
With a one-time consent granted by your organisation's Global Administrator, Orbit reads configuration and usage data from Microsoft Graph under read-only application permissions — every permission and its purpose is listed on the Permissions page. None of them can read email, files or chat content, and none can change anything in your tenant. The only signal read outside Microsoft Graph is public DNS (SPF, DKIM and DMARC records) for your verified domains. Orbit holds no credentials for your tenant: access uses tokens issued by Microsoft against that consent, and deleting the Orbit enterprise application in Microsoft Entra ends all access immediately.
What Orbit stores
| Data | Contents | Retention |
|---|---|---|
| Report snapshots | The configuration and usage data behind your reports, as read from Microsoft Graph: policies, settings, device inventory, licence and usage reports, and the user, group and app details your reports list. | Replaced on each refresh; deleted automatically 30 days after the last refresh, and immediately if your service is suspended. |
| Assessment run archive | One scored run per day: each check's name, result, severity and summary note, plus report scores — never raw configuration values, and never the user, device or app lists behind a finding. | Deleted 12 months after each run is written; immediately if your service is suspended, and on request. Powers run comparison and drift detection. |
| Daily score history | One row per day of derived score numbers (per-hub and overall) and your licensed-user count — never the findings or configuration behind them. | Kept while you use Orbit, so your trend line has history; deleted on request. |
| Access record | Your sign-in domain, Microsoft tenant ID, plan status and first/last sign-in timestamps. | Retained after service ends, so a closed account cannot re-enrol itself as a new trial. Contains no configuration or personal data beyond the signing-in organisation's domain. |
Never stored: passwords, credentials or security tokens; email, file or chat content; anything Orbit's read-only permissions cannot see. Orbit stores no data about a tenant until its administrator has consented and signed in.
Where it lives and who can see it
All stored data lives in Planet IT's Azure Storage account in the UK South region, encrypted at rest by Azure Storage encryption and in transit with TLS. It is keyed by your Microsoft tenant ID and served only to your own organisation's signed-in administrators — one tenant can never read another's data. Within Planet IT, access is limited to the named operators who run Orbit. Microsoft Azure is the hosting provider; no stored data is shared with, or sold to, anyone else, and no automated decisions about individuals are made from it.
Deletion on request
Ask Planet IT to delete your stored assessment data at any time: your report snapshots and score history are removed in one step, and only the access record described above remains. Independently of Planet IT, deleting the Orbit enterprise application in the Microsoft Entra admin centre revokes Orbit's read access at the source — that part is always in your hands. Requests and questions: planet-it.net/contact.