Public Demo
You are welcome to explore this solution. Prior to official go-live, you may use it freely — however, your data may be lost in future updates. No guarantees or liability are given. Use at your own discretion.

Last updated: July 2026

1. Controller

Alexander Köhler
Aemtlerhofweg 8
8912 Obfelden
Switzerland

Email: [email protected]. Full legal disclosure: Imprint.

We have not appointed a Data Protection Officer; we are not required to under Art. 37 GDPR.

2. Controller vs. processor

This policy covers data for which we are the controller: the public website, account registration, and operating the hosted service.

Content you enter into your workspace — production requests, resources, spaces, people records, schedules — is processed by us on your behalf as a processor (Art. 28 GDPR). Your organisation remains the controller for it and decides what is entered and how long it is kept. If you are an employee whose data appears in a customer's workspace, please direct requests to that organisation.

The self-hosted Community Edition runs entirely on your own infrastructure. We receive no data from it and are neither controller nor processor for it.

3. Visiting the website

Our servers and our CDN provider record technical connection data (IP address, timestamp, requested URL, referrer, user agent, response status) in server logs. This is necessary to deliver the site and to detect and defend against attacks.

Legal basis: Art. 6(1)(f) GDPR — our legitimate interest in a secure, functioning service.
Retention: logs are retained for up to 30 days, then deleted automatically.

The website uses no tracking, analytics, advertising, or profiling cookies, and embeds no third-party fonts, tag managers, or social plugins. Because we set no non-essential cookies, no consent banner is required.

4. Account and authentication

To create an account we process your email address, display name, password credential (stored only as a salted hash by our self-hosted identity server), and — if enabled — your multi-factor authentication secret. We record sign-in events, session device/browser metadata and IP address so you can review and revoke your own active sessions.

If you choose to sign in with Google, Google transmits your email address, name, and account identifier to us. We do not receive your Google password. Signing in with Google is optional and entirely your choice.

Legal basis: Art. 6(1)(b) GDPR — performance of the contract; for security logging and session records, Art. 6(1)(f) GDPR.

5. Email we send

We send transactional email only: account verification, invitations, security notices, and the lifecycle notices described in section 7. We do not send marketing email and operate no newsletter.

Legal basis: Art. 6(1)(b) GDPR, and Art. 6(1)(c) for notices we are legally required to send.

6. Contact form

Messages sent through our contact form, together with the name and email address you supply, are used solely to answer your enquiry and are deleted once the matter is concluded and no retention obligation applies.

Legal basis: Art. 6(1)(b) or Art. 6(1)(f) GDPR depending on the nature of the enquiry.

7. Retention and automated deletion

We do not keep dormant data indefinitely. Both accounts and workspaces are subject to an automated lifecycle:

User accounts

  • After 12 months without a sign-in, we email you a reactivation notice.
  • Two further reminders follow at 14-day intervals if you do not respond.
  • 14 days after the final reminder the account is disabled.
  • 90 days after that, the account and its personal data are permanently deleted.

A single sign-in — or clicking the link in any of those emails — resets the process entirely.

Workspaces

  • A workspace with no activity for 30 days receives a warning, and is suspended shortly after.
  • After 90 days suspended, it is marked for deletion and administrators are notified.
  • A 7-day grace period follows, during which the workspace can be restored in full.
  • After the grace period, the workspace and its database are permanently deleted.

You may also delete your account or workspace yourself at any time, which starts the same final deletion. Where statutory retention obligations apply (e.g. commercial or tax law), the affected records are restricted from processing rather than deleted until those periods expire.

8. Recipients and processors

We keep the number of third parties deliberately small. All of them process data on our documented instructions under a data processing agreement (Art. 28 GDPR).

ProviderPurposeLocation
Hetzner Online GmbHServer hosting, backupsGermany (EU)
Cloudflare, Inc.CDN, TLS termination, DDoS protectionGlobal edge; EU Standard Contractual Clauses
Sinch Email (Mailgun)Transactional email deliveryEU endpoint; EU Standard Contractual Clauses
Google Ireland Ltd.Optional "Sign in with Google" onlyEU / Standard Contractual Clauses

Application data is stored on servers in Germany. The controller is established in Switzerland, which holds an EU adequacy decision (Art. 45 GDPR), so data may be accessed from there without further safeguards. Each customer workspace lives in its own separate database. We do not sell personal data and do not share it for advertising purposes. Disclosure to authorities occurs only where legally required.

9. Security

Transport is encrypted (TLS), credentials are never stored in plaintext, sensitive fields are encrypted at rest, and access to production systems is restricted and logged. See our Security page for detail.

10. Your rights

Under the GDPR you have the right to:

  • Access your personal data (Art. 15)
  • Rectification of inaccurate data (Art. 16)
  • Erasure (Art. 17)
  • Restriction of processing (Art. 18)
  • Data portability in a machine-readable format (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)
  • Withdraw consent at any time, without affecting processing already carried out (Art. 7(3))

To exercise any of these, email [email protected]. We respond within one month.

You also have the right to lodge a complaint with a supervisory authority, in the EU member state of your residence, workplace, or the place of the alleged infringement (Art. 77 GDPR).

11. Automated decision-making

Orkyo's scheduling engine proposes assignments of resources and spaces to production requests. These are suggestions that a human reviews and applies; the system makes no automated decision producing legal or similarly significant effects on a person within the meaning of Art. 22 GDPR.

12. Changes to this policy

We may update this policy as the service evolves or the law requires. The current version is always available at this address, with the revision date shown above. Material changes affecting you will be communicated by email.

See also: Imprint  ·  Terms & Policies  ·  Security