Privacy Policy

How Orkestra handles personal data, worldwide.

This policy explains what personal data we process, why, the safeguards we apply, and the rights available to individuals across the regions we serve.

Trust controls

Tenant ACME verified

RBAC

Active

Audit chain

Verified

AI budget

72% used

Data stores

Isolated

Draft — pending legal review. Version 2026-07-08 · last updated July 8, 2026. Retention periods, regional representatives, and the exact subprocessor list/regions are placeholders to be confirmed with counsel and operations before production launch.

Privacy Policy

Written for a globally distributed customer base; regional rights are called out in section 11.

1. Scope & our roles

This policy covers personal data processed through the Orkestra platform and website. For data your organisation puts into its workspace (contacts, cases, conversations, records), Orkestra acts as a PROCESSOR on the customer’s behalf. For account, billing and website data, Orkestra acts as a CONTROLLER. A Data Processing Addendum (DPA) governs the processor relationship.

2. Data we collect

Account & identity (name, work email, workspace/tenant details); operational records you enter (which may include personal data of your own contacts/end-users); usage and device/technical data; audit and security logs (including IP addresses and actor identifiers); support communications; and billing information processed via our payment provider (we do not store raw card numbers).

3. Sensitive & children’s data

The platform is a general business tool and is not intended for special-category (sensitive) personal data unless separately agreed; if you choose to input such data you are responsible for having a lawful basis. The service is not directed to children and we do not knowingly collect data from anyone under 16.

4. How we use data & legal bases

To provide and secure the service and process your workflows (performance of contract); to maintain reliability, prevent abuse and protect the platform (legitimate interests); to meet legal and tax obligations (legal obligation); and, for marketing communications, on the basis of consent where required. You can withdraw consent at any time.

5. AI processing

When you use AI features (copilot, retrieval-grounded answers, agents), relevant workspace records may be sent to our AI subprocessor to generate a response. AI providers are engaged under terms that do not permit using your content to train their foundation models, and grounding is limited to your own tenant’s data. Human review of AI output remains your responsibility.

6. International data transfers

The platform is hosted in the European Union (Germany / EU region) and is accessed by customers worldwide. Where personal data is transferred across borders (including to subprocessors outside your region), we rely on appropriate safeguards such as Standard Contractual Clauses or an adequacy decision. Unless otherwise agreed, primary data residency is the EU.

7. Subprocessors

We use vetted subprocessors to run the service (see the table below). We impose data-protection obligations on each, and we will give at least 30 days’ notice of a new or replacement subprocessor, during which enterprise customers may object on reasonable data-protection grounds.

8. Sharing & disclosure

We do not sell personal data. We share it only with the subprocessors listed, with authorities where legally required, and in connection with a corporate transaction subject to equivalent protections.

9. Retention

We retain personal data for the life of the account and for a defined period after termination to meet legal, tax and dispute-resolution needs [retention periods — to be confirmed by counsel], after which data is deleted or anonymised. Customers can export data during the post-termination export window.

10. Security

We apply tenant isolation with database row-level security, encryption in transit, access controls, MFA, and a tamper-evident audit trail. See our Security page for the current, honestly-stated posture and roadmap.

11. Your privacy rights

Subject to applicable law you may request access, correction, deletion, portability, restriction, or objection, and may withdraw consent. Rights and mechanisms vary by region: GDPR/UK GDPR (EU/UK), CCPA/CPRA (California — including the right to know/delete/correct and to opt out of “sale/share”; we do not sell data), LGPD (Brazil), PIPEDA (Canada), POPIA (South Africa), the Privacy Act (Australia) and PDPA (Singapore). To exercise rights, contact privacy@direction10.com; where we act as processor we will refer your request to the relevant customer (controller).

12. Cookies

Our use of cookies and similar technologies, including consent for non-essential cookies, is described in the Cookie Policy.

13. Breach notification

If a personal-data breach occurs we will notify affected controllers and, where required, supervisory authorities and individuals within the timeframes set by applicable law (for example, within 72 hours under the GDPR).

14. Regional representatives & contact

Controller/DPO contact: privacy@direction10.com. EU/UK representative and any other statutorily required local representatives: [to be appointed by counsel]. We will publish these before serving those regions in production.

15. Changes

We may update this policy; material changes will be notified by email and/or in-app with a reasonable notice period, and the effective date above will be revised.

Subprocessors

Illustrative — confirm exact entities and regions before publishing.

SubprocessorPurposeDataRegion
Hetzner Online GmbHCloud hosting & computeAll platform data at rest/in useGermany (EU)
NeonManaged PostgreSQL databaseAll platform dataEU (Frankfurt)
VercelFrontend hosting & CDNTechnical/usage data, IPUS / global edge
ZeptoMail (Zoho) / BrevoTransactional & marketing emailRecipient email + message contentEU / global
OpenAIAI copilot / retrieval generationPrompts incl. relevant tenant recordsUS
TwilioSMS / WhatsApp (when enabled)Phone numbers + message contentUS / global
Razorpay / StripePayment processingBilling contact + payment tokenIndia / US