What we process, why, and the rights you have over it.
Last updated: July 2026
Email: [email protected]. Full legal disclosure: Imprint.
We have not appointed a Data Protection Officer; we are not required to under Art. 37 GDPR.
This policy covers data for which we are the controller: the public website, account registration, and operating the hosted service.
Content you enter into your workspace — production requests, resources, spaces, people records, schedules — is processed by us on your behalf as a processor (Art. 28 GDPR). Your organisation remains the controller for it and decides what is entered and how long it is kept. If you are an employee whose data appears in a customer's workspace, please direct requests to that organisation.
The self-hosted Community Edition runs entirely on your own infrastructure. We receive no data from it and are neither controller nor processor for it.
Our servers and our CDN provider record technical connection data (IP address, timestamp, requested URL, referrer, user agent, response status) in server logs. This is necessary to deliver the site and to detect and defend against attacks.
Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a secure, functioning service.
Retention: logs are retained for up to 30 days, then deleted automatically.
The website uses no tracking, analytics, advertising, or profiling cookies, and embeds no third-party fonts, tag managers, or social plugins. Because we set no non-essential cookies, no consent banner is required.
To create an account we process your email address, display name, password credential (stored only as a salted hash by our self-hosted identity server), and — if enabled — your multi-factor authentication secret. We record sign-in events, session device/browser metadata and IP address so you can review and revoke your own active sessions.
If you choose to sign in with Google, Google transmits your email address, name, and account identifier to us. We do not receive your Google password. Signing in with Google is optional and entirely your choice.
Legal basis: Art. 6(1)(b) GDPR — performance of the contract; for security logging and session records, Art. 6(1)(f) GDPR.
We send transactional email only: account verification, invitations, security notices, and the lifecycle notices described in section 7. We do not send marketing email and operate no newsletter.
Legal basis: Art. 6(1)(b) GDPR, and Art. 6(1)(c) for notices we are legally required to send.
Messages sent through our contact form, together with the name and email address you supply, are used solely to answer your enquiry and are deleted once the matter is concluded and no retention obligation applies.
Legal basis: Art. 6(1)(b) or Art. 6(1)(f) GDPR depending on the nature of the enquiry.
We do not keep dormant data indefinitely. Both accounts and workspaces are subject to an automated lifecycle:
A single sign-in — or clicking the link in any of those emails — resets the process entirely.
You may also delete your account or workspace yourself at any time, which starts the same final deletion. Where statutory retention obligations apply (e.g. commercial or tax law), the affected records are restricted from processing rather than deleted until those periods expire.
We keep the number of third parties deliberately small. All of them process data on our documented instructions under a data processing agreement (Art. 28 GDPR).
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online GmbH | Server hosting, backups | Germany (EU) |
| Cloudflare, Inc. | CDN, TLS termination, DDoS protection | Global edge; EU Standard Contractual Clauses |
| Sinch Email (Mailgun) | Transactional email delivery | EU endpoint; EU Standard Contractual Clauses |
| Google Ireland Ltd. | Optional "Sign in with Google" only | EU / Standard Contractual Clauses |
Application data is stored on servers in Germany. The controller is established in Switzerland, which holds an EU adequacy decision (Art. 45 GDPR), so data may be accessed from there without further safeguards. Each customer workspace lives in its own separate database. We do not sell personal data and do not share it for advertising purposes. Disclosure to authorities occurs only where legally required.
Transport is encrypted (TLS), credentials are never stored in plaintext, sensitive fields are encrypted at rest, and access to production systems is restricted and logged. See our Security page for detail.
Under the GDPR you have the right to:
To exercise any of these, email [email protected]. We respond within one month.
You also have the right to lodge a complaint with a supervisory authority, in the EU member state of your residence, workplace, or the place of the alleged infringement (Art. 77 GDPR).
Orkyo's scheduling engine proposes assignments of resources and spaces to production requests. These are suggestions that a human reviews and applies; the system makes no automated decision producing legal or similarly significant effects on a person within the meaning of Art. 22 GDPR.
We may update this policy as the service evolves or the law requires. The current version is always available at this address, with the revision date shown above. Material changes affecting you will be communicated by email.
See also: Imprint · Terms & Policies · Security