1. Data Controller
This Privacy Policy explains how Orkosi collects, uses, and protects your personal data when you use Orkosi and any related services accessible via orkosi.com (collectively, the “Service”).
We act as the data controller within the meaning of Article 4(7) of Regulation (EU) 2016/679 (the “General Data Protection Regulation” or “GDPR”) and Lei n.º 58/2019 of 8 August, which implements the GDPR in Portuguese national law.
For all privacy-related matters, contact us at privacy@orkosi.com.
2. Personal Data We Collect
We collect the following categories of personal data:
- Account information — name, email address, and a securely hashed password when you register.
- Billing and payment data — subscription plan, payment status, and invoice history. Full payment card details are processed exclusively by Stripe, Inc. and are never stored on our servers.
- Credit and usage records — credit balance, credit purchase history, credit consumption logs, and feature usage data tied to your account.
- Content and project data — code, files, configurations, and other content you create or upload through the Service.
- Technical data — IP address, browser type and version, operating system, device identifiers, referral URLs, and access timestamps collected automatically when you interact with the Service.
- Location data: the IP address you connect from and the country and region it belongs to, recorded when you visit the website, use the website chat, sign up and log in. We use it for security, fraud prevention and analytics.
- Communication data — messages you send to our support channels and any feedback you voluntarily provide.
3. Legal Basis for Processing
Under Article 6 of the GDPR and the corresponding provisions of Lei n.º 58/2019, we process your personal data on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) — processing necessary to provide the Service you have subscribed to, including account management, credit allocation, and service delivery.
- Legitimate interests (Art. 6(1)(f)) — processing necessary for fraud prevention, security monitoring, service improvement, and analytics. We have conducted balancing tests to ensure these interests do not override your fundamental rights.
- Legal obligation (Art. 6(1)(c)) — processing required to comply with applicable laws, including Portuguese tax and accounting regulations and EU anti-money-laundering directives.
- Consent (Art. 6(1)(a)) — for optional analytics cookies and marketing communications. You may withdraw consent at any time without affecting the lawfulness of prior processing.
4. How We Use Your Data
We process your personal data for the following purposes:
- To create and manage your account and authenticate your identity
- To provide, operate, and maintain the Service, including credit-based features
- To process payments, issue invoices, and manage subscriptions via Stripe
- To send transactional communications (account confirmations, security alerts, billing notifications)
- To monitor and improve service performance, reliability, and security
- To detect, prevent, and respond to fraud, abuse, and security incidents
- To comply with legal obligations under Portuguese and EU law
- To respond to your support requests and communications
We do not engage in automated decision-making or profiling that produces legal effects or similarly significant effects on you, as defined in Article 22 of the GDPR.
5. Third-Party Processors
We share personal data with the following categories of sub-processors, each bound by data processing agreements:
- Stripe, Inc. (United States) — payment processing. Stripe acts as an independent controller for payment data under its own privacy policy.
- Cloud infrastructure providers (EU/EEA where available) — hosting, storage, and compute services for application data.
- Internal Analytics (self-hosted) — privacy-friendly website analytics, processing only anonymised, aggregate data. No personal identifiers or third-party data sharing.
We do not sell, rent, or trade your personal data to any third party. We do not share your data with advertisers or data brokers.
6. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described in this policy:
- Active accounts — data is retained for the duration of your account plus 30 days after deletion to allow for recovery.
- Financial records — invoices and billing data are retained for 10 years as required by Portuguese tax law (Código do IRC, Art. 123).
- Security logs — access and authentication logs are retained for 12 months for security and fraud prevention purposes.
- IP addresses: the raw IP address stored with website visits, chat sessions, sign-up and login is deleted after 90 days. The country and region are kept for analytics.
- Credit transaction history — retained for the duration of your account and the legally required financial record retention period.
Upon account deletion, we erase or anonymise all personal data within 30 days, except where retention is mandated by law. You will receive a confirmation email when deletion is complete.
7. Your Rights
Under Articles 15 to 22 of the GDPR and Lei n.º 58/2019, you have the following rights regarding your personal data:
- Right of access (Art. 15) — obtain confirmation of whether we process your data and request a copy.
- Right to rectification (Art. 16) — request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17) — request deletion of your data. You may also delete your account directly from your account settings.
- Right to restriction (Art. 18) — request that we limit processing of your data in certain circumstances.
- Right to data portability (Art. 20) — receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21) — object to processing based on legitimate interests, including for direct marketing purposes.
- Right to withdraw consent (Art. 7(3)) — withdraw consent at any time where processing is based on consent.
To exercise any of these rights, contact privacy@orkosi.com. We will respond within 30 days. If your request is complex or we receive a high volume of requests, we may extend this period by a further 60 days in accordance with Article 12(3) of the GDPR, and will inform you of any such extension.
You have the right to lodge a complaint with the Portuguese Data Protection Authority (CNPD — Comissão Nacional de Proteção de Dados), Av. D. Carlos I, 134 — 1.º, 1200-651 Lisboa, Portugal, or with the supervisory authority in the EU Member State of your habitual residence.
8. Cookies
We use cookies and similar technologies to operate and improve the Service. Our cookie usage is categorised as follows:
- Strictly necessary cookies — authentication tokens, CSRF protection, and session management. These are essential for the Service to function and cannot be disabled.
- Functional cookies — theme preferences, cookie consent record, and interface settings. These enhance your experience but are not essential.
- Analytics — aggregated usage patterns via our internal analytics system. No cookies are written; page paths are logged with hashed, non-identifiable IPs.
We do not use third-party advertising or tracking cookies. You can manage your cookie preferences at any time through the consent banner or your browser settings. Essential cookies cannot be disabled as they are required for the basic operation of the Service.
9. International Data Transfers
We store and process data within the European Economic Area (EEA) wherever possible. Where data is transferred outside the EEA (for example, to Stripe in the United States), we ensure appropriate safeguards are in place, including:
- EU Standard Contractual Clauses (SCCs) adopted by the European Commission
- Adequacy decisions of the European Commission, where applicable
- Binding corporate rules of the receiving organisation, where applicable
You may request a copy of the relevant safeguards by contacting privacy@orkosi.com.
10. Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption of data in transit and at rest, access controls, regular security assessments, and incident response procedures.
While we take all reasonable steps to protect your data, no method of transmission over the Internet or electronic storage is completely secure. In the event of a personal data breach, we will notify the CNPD and affected data subjects in accordance with Articles 33 and 34 of the GDPR.
11. Children
The Service is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete it promptly. If you believe a child has provided us with personal data, please contact privacy@orkosi.com.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date at the top of this page and notify registered users via email at least 30 days before the changes take effect. Continued use of the Service after the effective date constitutes acceptance of the revised policy.
Previous versions of this policy are available upon request.
13. Contact
For privacy-related questions, data subject requests, or to report a concern: