Orquestr

Legal

Privacy notice

Last updated: September 24, 2026

Version: 2026-09-24

This notice explains how Orquestr collects, uses, shares, and protects personal data when you visit the site, create an account, communicate with us, or use the API, point-of-sale connectors, and related services (the “Services”).

Orquestr offers the Services and determines these purposes. Privacy requests go to legal@orquestr.com.

1. When this notice applies

This notice applies when Orquestr decides why and how personal data is processed: account administration, billing, product analytics, communications, security, and support.

The customer also submits business records and other information for the Services to process on the customer's behalf (“Customer Content”). For personal data inside that content, the customer generally decides the purposes and acts as controller, and Orquestr acts as processor. That processing is governed by the customer's agreement and the data processing agreement. If you are an end user of an Orquestr customer, direct a request about that content to the customer first.

This notice does not govern independent products of a point of sale, an ERP, a payment processor, or a model provider, even when they connect with Orquestr.

2. Information we collect

Information you provide

Information collected automatically

Information from third parties

We may receive information from account and authentication providers; from the point-of-sale systems, payment processors, and other systems you connect; from customers or users who invite or administer you; from analytics and security providers; and from public sources where the law allows.

3. How we use information

Primary purposes, needed to provide the service:

Secondary purposes:

If you do not want your information used for marketing messages, you can ask at legal@orquestr.com or use the unsubscribe link in the message. We may still send transactional, billing, security, and service communications. We may aggregate or de-identify information for analytics and security, and we do not attempt to re-identify what we keep de-identified.

4. Automated features

If you use an automated or model feature, we process the inputs, context, files, outputs, and metadata needed to provide it. Depending on the feature, that information may be sent to a provider named on the subprocessor list.

Orquestr does not use Customer Content to train general-purpose models, its own or a provider's, except under a written agreement. Where commercially available, providers are engaged under arrangements that restrict them from using that data to train their general models. The customer should not submit restricted data to an automated feature without written approval.

5. Legal bases

Where a law such as the GDPR requires a legal basis, we process personal data on one or more of these:

When we process Customer Content as a processor, the customer identifies the lawful basis and gives us instructions. If the person is in Mexico, access, rectification, cancellation, and objection rights are exercised as the rights section describes. This notice does not place the contract under Mexican law: the contract's governing law is that of the State of Delaware, under the Terms.

6. How we disclose information

We may disclose personal data to:

We do not sell personal data for money. We do not rent it or transfer it to outsiders without a basis this notice describes. If a U.S. state law treats a particular advertising cookie as a “sale,” “sharing,” or targeted advertising, you may opt out at legal@orquestr.com. This site does not describe an active advertising network today.

7. Cookies and similar technologies

We and our providers may use cookies, local storage, and similar technologies to keep you signed in, remember language, secure the site, and understand use. Some are necessary. The browser can block others, and blocking necessary ones can affect features. The language switcher stores the preference in a cookie named NEXT_LOCALE. This site uses Google Analytics, from Google LLC, to measure visits. That measurement does not include the customer's point-of-sale or ERP content.

8. International transfers

Orquestr may use providers in the United States and other countries. Personal data may be processed outside the country where it was collected.

Where the law requires it, we use recognized mechanisms, such as adequacy decisions, the European Commission's standard contractual clauses, and the United Kingdom addendum. The data processing agreement adds terms for Customer Content.

9. Retention

We keep information for as long as reasonably necessary for the purposes in this notice, including to provide the service, comply with law, resolve disputes, secure systems, and enforce the contract. The period depends on the type of information.

10. Security

We use technical and organizational measures designed to protect information: access controls, authentication safeguards, encryption to the extent the infrastructure supports it, monitoring, change management, incident response, and vendor review. No system is completely secure, and we cannot guarantee absolute security.

Point-of-sale operations run in the customer's cloud. You protect your credentials and systems, configure the Services, limit permissions, and tell us promptly if you suspect a compromise. The infrastructure list is waiting on confirmed providers: we do not claim a data center here that is not published on Subprocessors.

11. Your rights

Depending on where you live, you may:

If the person is in Mexico, those rights include access, rectification, cancellation, and objection. The request goes to legal@orquestr.com and states the full name, a way to reply, the data the request covers, and documents that prove identity or authority to represent.

We may verify identity and authority before acting. An authorized agent may submit a request where the law allows. If the information is in Customer Content controlled by an Orquestr customer, contact that customer first. We will assist the customer as the data processing agreement requires.

People in the EEA, the United Kingdom, or Switzerland may complain to their data-protection authority. We prefer that you write to us first. We do not discriminate for exercising a privacy right.

12. Children

Accounts are not intended for anyone under 18. We do not knowingly collect personal data from children under 18 to register an account. If we learn that a child under 18 created an account, we will take steps to close it and delete the associated personal data, subject to law. Write to legal@orquestr.com if you believe this happened. Customer Content is processed on the customer's behalf under the data processing agreement.

13. Business customers and end users

Anyone who uses Orquestr to provide products to their own customers must give those people the privacy notice that applies, obtain required permissions, and configure the Services consistently with that notice. If we receive a request from an end user, we may direct it to the relevant customer.

14. Changes

We may update this notice as the Services or our practices change. If a change is material, we will give reasonable notice through the Services, by email, or by another appropriate method. The update date shows the revision.

15. Contact

Orquestr. Email: legal@orquestr.com.