Skip to main content
  • _csp_line_me_R_ti_p__40uhl4994a
Languages

Privacy Policies

Loxley Orbit Public Company Limited
​Personal Data Protection Act (PDPA) 
​for External Individuals​

1. Introduction

This Privacy Notice explains how Loxley Orbit Public Company Limited (the "Company"), a provider of cloud, IT, and digital solutions, collects, uses, and discloses the personal data of its external individuals, including current and prospective business partners, customers, vendors, service providers, and website/facility visitors.

2. Definitions

  • "Company" refers to Loxley Orbit Public Company Limited.

  • "Personal Data" means data about an identified or identifiable natural person, directly or indirectly.

  • "Sensitive Personal Data" means personal data requiring special protection under the PDPA, including data relating to race, ethnicity, political opinions, religious or philosophical beliefs, sexual behavior, criminal records, health data (including disabilities and health status), trade union information, genetic data, and biometric data.

3. What Personal Data We Collect

We collect data relevant to our provision of IT and digital services, including:

  • Identity Data: Name, age, gender, date of birth, nationality, ID card/passport number, and signature.

  • Contact Data: Address, phone number, email, and social media account details.

  • Professional/Work Data: Job title, department, company name, work email, and business card information.

  • Financial/Transaction Data: Purchase orders, quotations, invoices, payment details, and bank account information.

  • Technical/Digital Data: IP address, email/system access logs, cookies, clickstream data, and data processed through our cloud and digital platforms provided to customers.

  • CCTV/Visual Data: Photos, videos, and CCTV footage from visits to Company premises or events.

  • Health & Safety Data (Sensitive): Body temperature, health data, and contact history with infected individuals (collected only for necessary public health or safety purposes).

  • Sensitive Data (Other): Religion (often found on ID documents, but not actively processed unless required by law or explicit consent is given), and any biometric data used for access control (e.g., fingerprint, facial scan).

  • Documentation Data: Copies of contracts, company certificates, VAT registration certificates, driver's licenses, and service confirmation forms.

4. Sources of Personal Data

We collect your Personal Data from the following sources:

  • Directly from You: Through verbal communication, physical documents, online forms, email, or your usage of our website and digital platforms.

  • Indirectly from Third Parties: Your employer (e.g., a business partner), service providers, recruitment agencies, public sources, and our corporate affiliates.

5. Lawful Basis and Purposes of Collecting Personal Data

We will process your Personal Data only when we have a lawful basis to do so. The primary purposes for collection include:

  • Contractual Necessity: For the execution of a contract, or in order to take steps at your request prior to entering a contract (e.g., contract negotiation, processing payments, delivering IT/cloud services, providing customer support).

  • Legal Obligation: To comply with applicable laws, including but not limited to accounting, tax, government reporting, public health requirements, and legal claims or investigations.

  • Legitimate Interest: For managing our business relationship with you, internal auditing, ensuring network and information security, improving our services, managing access to our premises, and protecting our legal rights.

  • Consent: Where required by law, especially for processing Sensitive Personal Data (unless a legal exemption applies) or for certain marketing communications. Consent will be requested in a clear and granular manner.

6. Impact of Not Providing Personal Data

The provision of certain Personal Data is mandatory for us to fulfill our legal obligations or to enter into or perform a contract.

  • Failure to provide mandatory data may result in our inability to: enter into or perform the contract, provide you with the requested service, grant you access to our premises, or comply with legal requirements.

  • For users of our website or digital platforms, not providing data may affect website functionality or limit access to certain information and services.

7. Disclosure and Cross-Border Transfer of Personal Data

Your Personal Data may be disclosed to:

  • Internal Departments: Relevant departments within the Company and our affiliated companies for necessary business operations.

  • External Recipients: Third-party service providers (e.g., cloud hosting, payment processors, auditors), business partners, and financial institutions.

  • Public Authorities: Government agencies, regulators, or courts, when required by law or necessary to protect our legal rights.

In cases where Personal Data must be transferred outside of Thailand, the Company will ensure compliance with PDPA requirements by:

  • Transferring data only to a country/jurisdiction deemed by the Personal Data Protection Committee (PDPC) to have adequate data protection standards; OR

  • Implementing appropriate safeguards such as Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or other legally permissible mechanisms.

8. Data Retention

We will retain your Personal Data only for as long as is necessary to fulfill the purposes for which it was collected, or as required by applicable laws.

  • Business Partners/Vendors: Retained for the duration of the relationship plus a period not exceeding 10 years for legal and accounting purposes.

  • Customers: Retained for the duration of the service contract plus a period not exceeding 2 years after termination for service-related claims and analysis.

  • Visitors (e.g., CCTV): Retained for a period not exceeding 1 year.

  • Data may be retained longer if required for legal compliance, debt collection, establishing a legal defense, or other legitimate purposes.

9. Your Rights as the Data Subject

You have the following rights under the PDPA, subject to legal limitations and exceptions:

  • Right to Withdraw Consent: Where we process data based on your consent.

  • Right of Access: To request a copy of your Personal Data and information about its processing.

  • Right to Data Portability: To request your data be transferred to another Data Controller or directly to you in a machine-readable format.

  • Right to Object: To object to the collection, use, or disclosure of your Personal Data based on legitimate interest or direct marketing.

  • Right to Erasure: To request the deletion, destruction, or anonymization of your data.

  • Right to Restriction of Processing: To request the suspension of data processing.

  • Right to Rectification: To request the correction of inaccurate or incomplete Personal Data.

  • Right to Lodge a Complaint: To file a complaint with the relevant regulatory authority (the PDPC) regarding non-compliance.

10. Data Security and Breach Notification

The Company maintains appropriate security measures (technical, administrative, and physical) to prevent unauthorized or unlawful access, alteration, disclosure, or loss of Personal Data.

In the event of a Personal Data Breach, the Company has an established protocol to assess the risk and will notify the PDPC within 72 hours of becoming aware of the breach, and will also notify you if the breach is likely to result in a high risk to your rights and freedoms.

11. Changes to Privacy Notice

We will review and update this Notice periodically to reflect changes in our practices and the law. The most current version will always be available on our website.

12. Contact Information

For questions regarding this Privacy Notice, the processing of your Personal Data, or to exercise your rights, please contact: dpo@loxleyorbit.com

Personal Data Protection Policy for Using the MVIS Application

Loxley Orbit Public Company Limited ("the Company") recommends that you familiarize yourself with this privacy policy. This policy outlines how the Company handles your personal data, including collection, storage, usage, disclosure, and your rights. To inform you of the Company's personal data protection policy, the Company hereby announces the following privacy policy:

​

Limited Collection of Personal Data

The collection of personal data shall be conducted with a lawful and fair purpose, scope, and method. Data collection and storage shall be limited to what is necessary for providing services or other electronic services under the Company's objectives. The Company will ensure that data subjects are informed and provide consent electronically, via Short Message Service (SMS), or according to the Company's methods.

​

The Company will seek your consent prior to collecting data, except in cases where it is required by law, such as the Telecommunications Business Act, the Computer Crime Act, the Anti-Money Laundering Act, etc., or where it is for your benefit and obtaining consent is not possible at that time, or for the benefit of your life, health, or safety, or for the benefit of the investigation of an inquiry official or court proceedings, or for the use of providing network services, maintaining and improving the network, or for the benefit of education, research, statistics, or public benefit.

​

The Company will not collect your sensitive personal data, such as genetic data, sexual behavior data, or data that may cause harm, damage reputation, or lead to unfair discrimination or inequality, unless it has received your express written consent or it is required by law, such as the Telecommunications Business Act, the Computer Crime Act, the Anti-Money Laundering Act, etc., or where it is for your benefit and obtaining consent is not possible at that time, or for the benefit of your life, health, or safety, or for the benefit of the investigation of an inquiry official or court proceedings, or for the benefit of education, research, or statistics, or for the benefit of the public.

​

Your personal data obtained by the Company, such as your name, age, address, phone number, ID card number, usage time, device activity within the service, device ID, location and time, geographic location data, etc., which can identify you and is complete and current, will be used only in accordance with the Company's operational objectives. The Company will implement strict measures to maintain security and prevent unauthorized use of personal data.

​

Purpose of Collecting and Storing Personal Data

The Company collects, stores, and uses your personal data for the Company's operations in providing telecommunications services, improving network quality, calculating and charging for services, and conducting research and data analysis in accordance with the Company's operational objectives and to improve the quality of the Company's services for greater efficiency. If there are any subsequent changes to the purpose of personal data collection, the Company will notify you.

​

The data collected and the reasons for collection are as follows:

Data Collected and Reasons for Collection

The Company will use the data collected from all of the Company's applications to provide services, maintain, protect, improve, develop new services, and protect the Company and you, as well as to present content that is customized to suit your usage, such as displaying search results relevant to you, displaying advertisements for services that may interest you and benefit you.

​

In addition, when you contact the Company, the Company may keep records of conversations between you and the Call Center that the Company has provided as a channel for receiving notifications, providing advice, and recommending solutions related to the use of the application. The Company may also keep records of the email address you provide to receive various recommendations in order to improve and develop the Company's services and those of its affiliates, and to notify you via the address you provide.

​

Data Collected and Reasons for Collection

Name, age, address, phone number, ID card number, usage time, device activity within the service, device ID, location and time, geographic location data. If you wish to take full advantage of using the application, the Company may ask you to create a public profile with your name and picture.

​

Data the Company Receives from Your Use of the Application

The Company collects data from your use of the application, which consists of at least the following data:

Mobile phone/digital device data: The Company will collect device-specific data such as hardware model, operating system and version, mobile network data, phone number, and device identifier that allows the Company to know which device you are using to access the application in order to customize services and analyze problems appropriate for that device. Recorded data: When you browse data and/or content from this application, the Company will record such browsing data and/or content in the following collection sources: on the Company's own server, and/or on the server of an affiliate, and/or on the server of a reliable partner of the Company that manages the data in the application under contract. Phone state data: The Company may access and process data about the operating status of your mobile phone, whether it is on or off, and/or data about network connections, such as whether it is connected via a mobile network or Wi-Fi.

 

This is for the following purposes:

To be able to check if you can use the application immediately without having to enter OTP information before use. To create a splash screen before accessing the main page of the application. To customize the application service to suit the usage status of each device, such as switching usage modes and adjusting the volume for navigation. Camera data: When you use this application, the Company may access, collect, and process photo data, video, and location of your photos and/or videos for the following purposes:

​​

To allow the application to scan QR codes of usable digital devices. SMS data: When you use this application, the Company may access and process data about your contacts and mobile phone numbers for use in sending SMS messages for the following purposes:

​

To allow the application to scan QR codes of usable digital devices. Location data: When you use the Company's application, the Company may access, collect, and process data about your actual location. The Company uses a variety of technologies to determine location, such as IP address, GPS sensors, or other tools that may provide the Company with data about devices in close proximity to Wi-Fi access points and cell towers. This is for the following purposes:

​

To identify the current location of the user on the map. Storage data: The Company may collect and store data on the storage space of your mobile phone/digital device, including personal data on your device, using various methods such as web browser storage and application data caching. This is for the following purposes:

​

To allow the application to read and/or update map data and saved areas. Account data: When you use the Company's application, the Company may access, collect, and process data about your application account to verify the Token and/or UDID of your mobile phone/digital device. This is for the following purposes: Cookies and similar technologies: The Company, its affiliates, and/or its business partners may use various technologies to collect and store data when you visit the Company's website and/or use its services. This includes using cookies and similar technologies to identify your browser or device and/or to collect and store data when you interact with services that the Company provides to its affiliates and/or business partners, such as advertising services. This is for the following purposes:

​

To provide promotional messages about the application to you. To verify and authenticate user accounts. Unique Application Number data: This application has a unique application number for sending data to the Company when the user installs or uninstalls the application, or when the application contacts the Company's service servers from time to time. This is for the following purposes:

​

To automatically update application data. Limited Collection of Personal Data, Quality of Personal Data

Your personal data obtained by the Company, such as your name, age, address, phone number, ID card number, etc., which can identify you and is complete and current, will be used only in accordance with the Company's operational objectives. The Company will implement strict measures to maintain security and prevent unauthorized use of personal data.

​

Security Measures

The Company will use and disclose your personal data with your consent, and it must be used in accordance with the purpose of the Company's data collection and storage.

The Company will ensure that its staff does not disclose, display, or make apparent in any other manner your personal data beyond the intended purpose or to external parties, except that the Company may share or disclose your personal data with its affiliates, group companies, and partners who are directly responsible for managing the application under contract with the Company, or other companies with credible privacy policies, in order to provide services, maintain, protect, improve, develop new services, and protect the Company and you, as well as to present content that is customized to suit your usage, such as displaying search results relevant to you, displaying advertisements for services that may interest you and benefit you, by following the recommendations and privacy policy of the Company, including appropriate confidentiality and security measures.

​

This may also be done in cases where it is required by law, such as the Telecommunications Business Act, the Computer Crime Act, the Anti-Money Laundering Act, etc., or where consent has been obtained from you, or for the benefit of your life, health, or safety, or for the benefit of the investigation of an inquiry official or court proceedings, or for the benefit of education, research, or statistics, or for the benefit of the public.

​

The Company recognizes the importance of maintaining the security of your personal data. The Company has therefore established appropriate security measures that are consistent with the confidentiality of personal data to prevent the loss, access, destruction, use, alteration, modification, or disclosure of personal data without authorization or unlawfully, as stipulated in the Information Security Policy. The Company has restricted access to personal data to only those employees, agents, and representatives of the Company who have a need to access such data (Need to Know Basis) to process the data. Such persons must strictly comply with the confidentiality requirements under the contract. Any violation will result in severe penalties.

 

Disclosure Regarding Practices, Procedures, and Policies Relating to Personal Data

The Company has a policy of complying with the law, including the announcement of the National Broadcasting and Telecommunications Commission (NBTC) on measures to protect the rights of telecommunications users with respect to personal data, privacy rights, and freedom of communication via telecommunications, and laws related to personal data. The Company has also issued measures to protect user data on the Company's website.

Orbit Meet Transcriber​

Privacy Policy​

Effective Date: January 16, 2025

​

Loxley Orbit Public Company Limited ("Loxley Orbit") is committed to protecting the privacy of our users. This Privacy Policy describes how we collect, use, disclose, and protect your personal data when you use our "Orbit Meet Transcriber" application (the "App"). This policy is designed to comply with the Thailand Personal Data Protection Act B.E. 2562 (PDPA) and relevant internet laws.  

 

1. In

The App collects the following information when you use it:

  • Meeting Content: This includes audio and video recordings of your Google Meet meetings for the purpose of transcription.

  • Transcribed Text: The text generated from the meeting recordings.

  • Usage Data: This includes information about how you use the App, such as the features you use and the time and date of your usage.

  • Device Information: This includes information about your device, such as the operating system, browser type, and IP address.

 

2. How We Use Your Information

We use your information for the following purposes:

  • To provide and improve the App: We use the meeting content to generate transcripts and to improve the accuracy of our transcription service. We use usage data to understand how users interact with the App and to identify areas for improvement.

  • To communicate with you: We may use your information to send you updates about the App or to respond to your inquiries.

  • To comply with legal obligations: We may use your information to comply with applicable laws and regulations.

 

3. Disclosure of Your Information

We may disclose your information to the following third parties:

  • Google: As the App is a Chrome extension that integrates with Google Meet, we may share your meeting content and transcribed text with Google only for the purpose of providing and improving the App.

  • Legal Authorities: We may disclose your information to legal authorities if required by law or legal process.

​

4. Data Security

We take reasonable measures to protect your information from unauthorized access, use, or disclosure. These measures include data encryption, access controls, and regular security assessments.  

 

5. Data Retention

We will retain your information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.  

 

6. Your Rights

Under the PDPA, you have the following rights with respect to your personal data:

  • Right to access: You have the right to access your personal data that we hold.

  • Right to rectification: You have the right to request that we correct any inaccurate or incomplete personal data that we hold.  

  • Right to erasure: You have the right to request that we erase your personal data in certain circumstances.

  • Right to restriction of processing: You have the right to request that we restrict the processing of your personal data in certain circumstances.  

  • Right to data portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format.  

  • Right to object: You have the right to object to the processing of your personal data in certain circumstances.  

​

7. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Loxley Orbit Public Company Limited

[dpo@loxleyorbit.com]

​​

8. Updates to this Privacy Policy

We may update this Privacy Policy from time to time. We will post any changes on our website and notify you as required by law.  

​

9. Governing Law

This Privacy Policy is governed by the laws of Thailand.

​

By using the Meet Transcriber app, you consent to the collection, use, and disclosure of your information as described in this Privacy Policy.


Poh Teck Tung Application

Privacy Policy​

Effective Date: August 1st , 2023

​

This Privacy Policy describes how Loxley Orbit Public Company Limited ("we," "us," or "our"), as the developer of the [Poh Teck Tung] mobile application (the "App"), processes your personal data.

​

1. Data Collection

We collect the following types of personal data:

  • Information you provide directly:

    • Account registration data (e.g., username, password, email address, phone number)

    • Profile information (e.g., name, date of birth, gender)

    • Content you submit (e.g., photos, messages, posts)

    • Communications with us (e.g., customer support inquiries)

  • Information we collect automatically:

    • Device information (e.g., device model, operating system, unique device identifiers)

    • Log data (e.g., IP address, access times, browser type)

    • Location data (if applicable and with your consent)

    • App usage data (e.g., features used, interactions within the App)

    • Cookies and similar technologies (to the extent applicable)

 

2. Legal Basis for Processing

We process your personal data based on the following legal bases as permitted by the PDPA:

  • Consent: We process your data when you have given us explicit consent for a specific purpose (e.g., marketing communications). You have the right to withdraw your consent at any time.

  • Contract: We process your data when it is necessary for the performance of a contract with you (e.g., providing the services you requested).

  • Legal obligation: We process your data when it is necessary to comply with a legal obligation (e.g., responding to a court order).

  • Legitimate interests: We process your data when it is necessary for our legitimate interests, provided that your interests and fundamental rights do not override those interests. Our legitimate interests may include:

    • Improving and personalizing the App

    • Analyzing App usage

    • Preventing fraud

    • Ensuring the security of the App

  • Public interest: We may process your data if it is necessary for the performance of a task carried out in the public interest.

 

3. Purposes of Processing

We use your personal data for the following purposes:

  • To provide and maintain the App's functionality.

  • To personalize your experience and deliver relevant content.

  • To communicate with you, including responding to your inquiries and providing customer support.

  • To process transactions (if applicable).

  • To analyze App usage and improve our services.

  • To send you marketing communications (with your consent, where required).

  • To detect and prevent fraud and ensure the security of the App.

  • To comply with legal obligations.

  • To display user-generated content and facilitate social interactions within the App.

 

4. Data Disclosure

We may disclose your personal data to the following categories of recipients:

  • Service providers: Third-party companies that provide services to us, such as hosting, data analysis, payment processing, and customer support. These providers are contractually bound to protect your data and only process it according to our instructions.

  • Business partners: Third parties with whom we collaborate to offer certain features or services within the App (e.g., if the App integrates with social media platforms).

  • Legal authorities: When required by law or to protect our rights, we may disclose your data to law enforcement agencies, government authorities, or other legal bodies.

  • Other users: If you choose to share information in public areas of the App (e.g., chat rooms, forums), that information may be visible to other users.

  • With your consent: We may disclose your data to other parties with your explicit consent.

  • Affiliates: Our subsidiaries or parent company.

 

5. Data Transfers

  • Your personal data may be transferred to and processed in countries outside of Thailand. These countries may have data protection laws that are different from the laws of Thailand.

  • We will take appropriate safeguards to ensure that your personal data is protected when transferred internationally, including:

    • Transferring data to countries that have been deemed to provide an adequate level of protection by the Thai Personal Data Protection Committee (PDPC).

    • Using standard contractual clauses approved by the PDPC.

    • Obtaining your explicit consent for the transfer.

    • Other appropriate safeguards permitted under the PDPA.

 

6. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, use, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit and at rest.

  • Access controls and authentication.

  • Regular security assessments and audits.

  • Data minimization and purpose limitation principles.

  • Employee training on data protection.

 

7. Data Retention

We will retain your personal data for as long as necessary to fulfill the purposes outlined in this Privacy Policy, or as required by law. The retention period will vary depending on the type of data and the purpose of processing. We will establish data retention schedules. After the retention period, we will securely delete or anonymize your data.

 

8. Your Rights

Under the PDPA, you have the following rights regarding your personal data:

  • Right to access: You have the right to request access to your personal data and to obtain a copy of it.

  • Right to rectification: You have the right to request that we correct any inaccurate or incomplete personal data.

  • Right to erasure: You have the right to request that we delete your personal data under certain circumstances (e.g., when the data is no longer necessary for the purposes for which it was collected).

  • Right to restriction of processing: You have the right to request that we restrict the processing of your personal data under certain circumstances (e.g., when you contest the accuracy of the data).

  • Right to data portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit it to another data controller.

  • Right to object: You have the right to object to the processing of your personal data under certain circumstances, including processing for direct marketing purposes.

  • Right to withdraw consent: If we process your data based on your consent, you have the right to withdraw your consent at any time.

  • Right to lodge a complaint: You have the right to lodge a complaint with the Personal Data Protection Committee (PDPC) if you believe that we have violated your rights under the PDPA.

 

9. Children's Privacy

The App is not intended for children under the age of 20. We do not knowingly collect personal data from children under 20. If you are a parent or guardian and believe that your child has provided us with personal data, please contact us, and we will take steps to delete that information.

 

10. Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy within the App and/or by other means (e.g., email). Your continued use of the App after the changes take effect constitutes your acceptance of the updated Privacy Policy.

 

11. Contact Us

If you have any questions about this Privacy Policy or your rights under the PDPA, please contact us at:

 

Loxley Orbit Public Company Limited

บริษัท ล็อกซเล่ย์ ออบิท จำกัด (มหาชน)

[dpo@loxleyorbit.com]

[+6624606816]


Loxley Orbit Workspace Theme Chrome Extension


Last Updated:** September 10, 2026 

Extension Name:** Loxley Orbit Workspace Theme 

Current Version: 0.3.76 

1. Overview & Single Purpose



**Loxley Orbit Workspace Theme** ("the Extension") is an enterprise productivity and UI personalization extension designed for users of Google Workspace. Its single purpose is to provide:

1. **Custom visual styling and branding:** Enhancing Google Workspace web applications (Gmail, Google Drive, Google Docs, Sheets, Slides, Vids, Google Meet, Google Chat, and Google Calendar) with signature blush-to-coral gradients, refined high-contrast controls, and light/dark mode adaptation.

2. **Company New Tab Launchpad:** A dedicated, clean new tab portal featuring company tools, curated Google & Zoho app directories, live office weather, real-time cloud service status, and tech updates.



We are committed to absolute transparency and data privacy. **We do not track, sell, broker, or monetize user data under any circumstances.**



---



2. Information Handled & Technical Justifications



The Extension requires the minimum necessary browser permissions to deliver its UI and new tab portal experience. The table below details every permission, why it is needed, and how data is handled:



| Permission / Scope | Why It Is Required | Data Handling & Storage |



| `identity.email` | **Required to personalize the New Tab user interface.** The Extension calls `chrome.identity.getProfileUserInfo` to retrieve the signed-in user's email address in order to display their name and profile initials on the company launchpad header, and locally verify authorized access to internal company tools. | **100% Local.** The email is evaluated in-memory and cached locally in `chrome.storage.local`. **It is NEVER transmitted to external servers, third-party analytics, or any remote database.** |

| `identity` | **Required for Chrome profile identification.** Allows the extension to read basic profile status locally to ensure seamless corporate single sign-on alignment. | **100% Local.** No authentication tokens, passwords, or personal credentials are exposed, logged, or exfiltrated. |

| `storage` | **Required to store local UI preferences.** Saves user preferences including manual light/dark theme toggle, accordion folded/expanded section states, weather display preferences, and custom launchpad shortcuts. | **100% Local.** Stored exclusively in the user's browser sandbox via `chrome.storage.local`. |

| Host Permissions (`mail.google.com`, `drive.google.com`, `docs.google.com`, `vids.google.com`, `chat.google.com`, `meet.google.com`, `calendar.google.com`) | **Required for CSS theme injection.** Applies visual styling to header bars, search fields, and primary action buttons across Google Workspace applications. | **Visual Styling Only.** The extension injects stylesheets and lightweight DOM styling. It **never** reads, intercepts, or collects email contents, documents, chat messages, meetings, or calendar events. |

| Host Permissions (`api.open-meteo.com`, `status.*`, `news/rss`) | **Required for launchpad live widgets.** Fetches public office weather forecasts (Open-Meteo), public cloud infrastructure status (GCP, Zoho, Datadog), and public RSS news feeds (Google Blog, Blognone). | **No User Identifiers.** Network calls contain only public query parameters (e.g. office coordinates). No personal data or user identity is included in these requests. |



---



3. What We Do NOT Do (Our Privacy Guarantees)



- **No Remote Tracking or Telemetry:** The Extension contains no Google Analytics, Firebase Analytics, telemetry beacons, tracking pixels, or third-party advertising SDKs.

- **No Data Selling or Brokering:** We never sell, transfer, license, or monetize any user data, email addresses, or browsing activities.

- **No Keystroke or Content Logging:** We do not monitor user inputs, form entries, passwords, documents, emails, or personal conversations.

- **No Unrelated Advertising:** The Extension will never inject third-party ads, pop-ups, or affiliate referral links into your browsing experience.




4. Google Chrome Web Store & API User Data Policy Compliance



The Extension strictly adheres to the Chrome Web Store Developer Program Policies, including the Limited Use Policy:



Single Purpose:

The extension's functionality is strictly limited to user interface theming, visual accessibility enhancements, and providing the corporate new tab dashboard.

Limited Use:

Any data accessed via Chrome APIs (such as `chrome.identity`) is used solely to provide and improve the user-facing functionality on the local device.

No Secondary Use:

User data is never used for serving advertisements, user profiling, creditworthiness assessment, or any purpose outside the explicit UI features described.

Data Minimization:

 We request only the permissions strictly required to execute the stated features.

Data Retention & User Control

Because all settings and profile information are stored exclusively on your local device:

- **Clearing Data:** You can delete all stored preferences at any time by right-clicking the extension icon, selecting **Remove from Chrome**, or clearing site and extension data via Chrome Settings (`chrome://settings/clearBrowserData`).

- **No Cloud Footprint:** Uninstalling the extension permanently removes all associated local data from your computer.

5. Contact & Inquiries

For privacy questions, support, or security inquiries, please contact our team at:
Email:support@loxleyorbit.com
Website:loxleyorbit.com

Loxley Orbit Ai Transcriber for Google Meet


- Privacy Policy -


 

 · last updated 16 September 2026

Loxley Orbit Ai Transcriber for Google Meet is an internal tool published by Loxley Orbit for use by people with a loxleyorbit.com Google Workspace account. It captures Google Meet captions, saves them to your own Google Drive, and can write meeting notes from them.

The short version. Meeting content goes to your own Google Drive and to a summarizing service running in Loxley Orbit's own Google Cloud project. It is not sold, not shared with third parties, not used for advertising, and not used to train any model. No analytics or tracking of any kind are collected.

What the extension handles

DataWhyWhere it goes
Google Meet caption text, speaker names, and chat messages shown in the meetingThis is the transcript the tool exists to produceHeld in the browser tab during the meeting, then written to a Google Doc in your Drive
Meeting title, participant list, meeting codeTo title the document and find the meeting's calendar eventThe same document; the meeting code is sent to our service to locate a recording or event
Your email addressTo confirm you are allowed to use the summarizing service and to apply per-person rate limitsOur service, in request logs only
Meeting recording audio (only if you ask for a recording summary)Meet does not offer Thai captions, so notes for a Thai meeting are produced from the recordingDownloaded to our service, transcribed, then deleted — see below
Your settings, and the transcript of the meeting you just leftSo a transcript is not lost when a call ends before you have saved itYour browser only (chrome.storage), never transmitted

Where meeting content is processed

Summaries and transcription run on a service operated by Loxley Orbit in its own Google Cloud project, hosted in Singapore (asia-southeast1). That service calls Google's Gemini models through Google Cloud's Agent Platform (formerly Vertex AI) under Loxley Orbit's Google Cloud agreement. The public Gemini API is deliberately not used.

Recording audio, specifically

A recording summary is only ever started by you pressing the button. When you do:

  • The recording is read from Google Drive using your own Google sign-in, never a service account, so Google decides what you are allowed to see.
  • Its audio is extracted and split into chunks on our service.
  • Each chunk is placed in a private Cloud Storage bucket only because the transcription model reads audio from Cloud Storage, and is deleted as soon as the model has read it. The bucket blocks all public access and deletes anything left behind within one day.
  • The audio file and every temporary copy are removed when the job ends, whether it succeeded or failed.
  • Jobs are held in memory for at most 30 minutes and are readable only by the person who started them.

What we log

Our service records the shape and timing of requests — which route was called, how many transcript entries it contained, how long it took, the resulting status, and the email of the caller. It does not log transcript text, notes, or audio. There is an automated test asserting that transcript content never reaches the logs.

Sharing

When a document is attached to a calendar event, it is shared as view-only to loxleyorbit.com, with link-discovery turned off — colleagues with the link can open it, and it does not become searchable across the company. Nothing is shared outside the domain, and nothing is shared with anyone outside your organisation at any point.


Shared Screen Capture

When shared screen capture is on and you are transcribing a meeting, the App can read what is presented on screen, so that slides, documents and figures shown during the meeting can be included in your meeting notes.

  • What is captured: Only while the App detects that someone in the meeting is presenting, it checks the shared screen every few seconds and keeps a still image only when the picture has changed. Images are reduced to at most 1,280 pixels wide, and no more than 24 are kept per meeting. Anything visible on the shared screen at that moment may be captured, including confidential material. Nothing is captured before you start transcribing, after you stop, or while no one is presenting.
  • Where images are kept: During the meeting, captured images stay in your browser's memory. If you leave the meeting without summarizing, they are kept in your browser's temporary storage so the meeting can still be summarized, and are erased when you close the browser. They are never saved to your Google Drive.
  • When images leave your computer: Only when you choose Summarize. The images are sent over an encrypted connection to Loxley Orbit's service on Google Cloud, held briefly in private cloud storage, and read by Google's Gemini models on Vertex AI to extract the visible text and figures. They are deleted as soon as reading is finished; anything left behind by an interrupted request is deleted automatically within one day. Saving a transcript without a summary never sends images anywhere.
  • What is kept: Only the text read from the screen. It appears in your draft labelled "Shared screen", so you can check or remove it before saving. Images that turn out not to show shared content are discarded and do not appear in your notes.
  • Recordings: If you summarize a meeting from its Google Meet recording and screen capture is on, still images where the shared screen changed are taken from the recording and read in the same way.
  • Your choice: You can turn screen capture on or off at any time in the App's Settings under "Read shared screens"; the setting applies to both live meetings and recordings. In the version of the App distributed through the Chrome Web Store it is off until you turn it on. While it is on, the transcription panel shows how many screens have been captured.


Google Account Data and AI Processing


This section describes how the App uses your Google account and processes meeting content. Where it is more specific than sections 1 to 5, this section applies.

  • Meeting content: The App builds your transcript from Google Meet's live captions and the meeting's chat messages, as they appear during the meeting. Captions are only captured after you start transcribing.
  • Google Drive: The App creates Google Docs in a "Meeting Transcriptions" folder in your Drive. It can access only files it has created, not the rest of your Drive.
  • Google Calendar: After saving, the App attaches the document to the meeting's calendar event, but only on events you own. The attached document is shared view-only with your organisation, with link discovery turned off, so it does not appear in search. You can turn this off in the App's Settings.
  • Google Meet recordings: Only when you ask the App to summarize a recording does it look up the meeting and read its recording from your Drive. The recording's audio is transcribed and then deleted.
  • Your account email: Used to confirm to Loxley Orbit's service that you belong to a permitted organisation. Requests from other accounts are refused.
  • AI processing: When you choose Summarize, your transcript, chat messages and any text read from shared screens are sent over an encrypted connection to Loxley Orbit's service, which runs on Google Cloud in Singapore. Google's Gemini models on Vertex AI draft a summary, key points, decisions, action items and an assessment of the meeting's tone. You review and can edit the draft before anything is saved; nothing is written to your Drive until you choose to save it.
  • What Loxley Orbit's service keeps: Nothing from your meetings. Transcripts, drafts and notes are not stored on Loxley Orbit's servers. Operational logs record your account email and the size and timing of requests, never meeting content. Audio and images are held only while being processed and are deleted immediately afterwards, with automatic deletion within one day as a safeguard.
  • Drafts on your computer: Drafts are kept in your browser's temporary storage until you save or discard them. A discarded draft can be restored for 15 minutes. All drafts are erased when you close the browser.
  • Limited Use: The App's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Information is used only to provide the features you choose to use. It is not sold, not used for advertising, and not transferred to anyone except as needed to provide those features, for security, or to comply with the law. It is not used to develop, train or improve artificial intelligence or machine learning models, whether Loxley Orbit's or Google's, and no person reads it without your permission except where required for security or by law.
  • About section 2: Where section 2 refers to improving transcription accuracy, it means improving how the App processes your meetings for you. Your meeting content is not used to train or improve AI models.


Limited Use of Google user data

This extension's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Specifically:

  • Data obtained through Google APIs is used only to provide and improve the features described above — live transcription, meeting notes, saving to your Drive, and attaching the result to the meeting's calendar event.
  • It is never used for advertising of any kind, and never sold or transferred to data brokers, information resellers, or any other third party.
  • It is not used to develop, train, or improve generalized artificial intelligence or machine learning models. Summaries are produced by Google's Gemini models on Vertex AI, which does not retain prompts or responses to train its models.
  • No human reads your meeting content. The exceptions are the narrow ones the policy allows: with your explicit consent, for security purposes such as investigating abuse, to comply with applicable law, or where the data has been aggregated and de-identified.

Permissions, and why each is needed

PermissionReason
identitySign in to Google so documents can be created as you
storageRemember your settings, and hold the last transcript until you save or discard it
Access to meet.google.comRead the captions shown on the page. This is the only site the extension runs on
drive.fileCreate and update only the documents this extension itself creates. It cannot see anything else in your Drive
userinfo.emailConfirm you are in the allowed domain
meetings.space.readonlyFind the recording belonging to a meeting you attended
drive.meet.readonlyRead only files that Meet itself created — the recording. It reaches nothing else in your Drive
calendar.events.ownedAttach the finished document to the meeting's event, on calendars you own. Narrower than full calendar access

Retention

  • Documents: yours, in your Drive, for as long as you keep them.
  • Recording audio on our service: deleted as each chunk is transcribed; anything stranded is deleted within one day.
  • Jobs: discarded after 30 minutes.
  • Request logs: retained by Google Cloud Logging under the project's default retention (30 days), and contain no meeting content.
  • In your browser: settings persist until you remove the extension; a kept transcript is cleared when you close the browser.

What we never do

  • Sell or transfer your data to third parties.
  • Use meeting content for advertising, profiling, or credit assessment.
  • Use meeting content to train models.
  • Collect analytics, telemetry, or browsing history.
  • Run on any site other than meet.google.com.

Your choices

Transcription is off unless you turn it on, and summaries only run when you ask for one. You can revoke the extension's access to your Google account at any time at myaccount.google.com/permissions, and remove the extension from chrome://extensions. Documents already in your Drive are yours to keep or delete.


- Terms of Service -

 · effective 18 September 2026

These Terms govern use of Loxley Orbit Ai Transcriber for Google Meet (the “Extension”), an internal tool provided by Loxley Orbit. By installing or using the Extension, you agree to these Terms.

Internal use only. The Extension is initially available only to people using a Google Workspace account ending in @loxleyorbit.com. Do not use it with a personal account or share it outside Loxley Orbit unless Loxley Orbit expressly authorizes that use.

What the Extension does

The Extension can capture captions displayed in Google Meet, create a Google Doc in your Google Drive, prepare meeting notes, and—when you choose the recording-summary feature—process a Google Meet recording that your account is permitted to access. It may also attach the resulting document to a calendar event on a calendar you own.

Your responsibilities

  • Use the Extension only for legitimate Loxley Orbit business purposes and in accordance with company policies.
  • Before capturing, recording, transcribing, summarizing, or sharing meeting content, make sure you have given any notice and obtained any consent required by applicable law, company policy, and the meeting organizer.
  • Do not use the Extension to process information that you are not authorized to access, including another person’s Google Meet recording or calendar event.
  • Keep your Google account secure and do not attempt to bypass the Extension’s domain, access, or security controls.
  • Review generated transcripts and notes before relying on or distributing them. Automated captions and summaries can be incomplete or inaccurate.

Google services

The Extension works with Google Meet, Google Drive, Google Calendar, and related Google APIs using the permissions you approve. Your use of Google services remains subject to Google’s applicable terms and policies. You can remove the Extension’s Google account access at any time through Google Account permissions.

Privacy and data handling

Our handling of Google user data and meeting content is described in the Privacy Policy, which forms part of these Terms. The Extension’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Availability and changes

The Extension is provided for internal use and may be changed, suspended, or withdrawn at any time. Features can depend on Google services, browser updates, network availability, and permissions outside Loxley Orbit’s control. Loxley Orbit may update these Terms when the Extension or its data practices change; the current version will be published at this page.

Ending access

Loxley Orbit may limit or end access to the Extension, including when your employment or authorization ends, when use violates these Terms or company policy, or when necessary to protect people, data, or systems. You may stop using it at any time by removing the Extension. Google Docs already created in your Drive remain subject to your organization’s retention and access policies.


Contact

Questions, or a request to delete something, go to support@loxleyorbit.com.