orgo community Get a demo
Platform Pricing Platform Documentation About us Blog Pricing
Membership
Membership Management Fees, renewals and records, automated
Contacts CRM Every contact and member in one database
Multi-Chapter National, regional and local chapters in one account
Community
Events Ticketing, QR check-in and attendance
Discussions & Groups Forums and groups that keep members active
Newsletter Segmented emails with open analytics
Fundraising Donation campaigns and recurring giving
Courses & Badges Training, certification and badges for members
Governance
e-Voting Anonymous, verifiable elections and decisions
eDocuments & eSignatures Send, e-sign and archive documents
Files Drive Secure shared storage for your documents
Project Management Member support tickets and team tasks
Privacy & Security GDPR compliance, EU hosting, access control
Operations
Analytics Reports and dashboards for board decisions
Branding & Customization Your logo, domain, languages and fields
Integrations Stripe, SSO, HubSpot, n8n and more
Ask Orgo AI Plain-language answers from your data
MCP Server Connect AI assistants to your data
Documentation
API Reference
Changelog
Sign in
Get a demo
Sign in Get a demo

Privacy Policy

Last Updated: August 1, 2026


1. Introduction

S.C. ORGO INFORMATICS SRL ("Orgo," "we," "us," or "our") operates Orgo.space, a multi-tenant SaaS cloud platform that enables organizations to manage and connect their members, volunteers, beneficiaries, and supporters.

This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our website (orgo.space and orgo.space/docs), mobile applications, and services (collectively, the "Services").

Our Commitment:

  • Registered in Romania: Str. Gheorghe Grigore Cantacuzino nr 14, etaj PARTER, ap 1, Ploiești, județul Prahova
  • Registration: J29/2796/2019
  • Fiscal Code: RO41650396
  • Compliant with GDPR (EU), UK GDPR, CCPA (USA), COPPA, and international privacy standards

Our Business Model:

  • We do NOT sell your personal data to third parties or data brokers
  • We do NOT display advertisements to users
  • We do NOT monetize your data through advertising networks
  • Our revenue comes exclusively from subscription fees paid by organizations using our Services

This Privacy Policy is part of our Terms of Service. By using the Services, you agree to the practices described in this policy.

Which Terms Apply to You:

  • Organizations subscribing to Orgo: See our Organization Terms of Service
  • Individual users (members, volunteers, beneficiaries): See our User Terms of Service

2. Important Distinctions: Data Controller vs. Data Processor

When Orgo is the Data Controller

We act as the Data Controller for:

  • Visitors to our website (orgo.space)
  • Prospective customers and demo requestors
  • Organization administrators who register and manage accounts
  • Newsletter subscribers
  • Job applicants

When Your Organization is the Data Controller

When you create an organization on Orgo.space, your organization becomes the Data Controller for:

  • Your members, volunteers, and beneficiaries
  • Any personal data collected through your Orgo instance
  • Content and communications within your community

In this case, Orgo acts as a Data Processor on behalf of your organization, as defined in our Data Processing Agreement (DPA). We process data only according to your instructions and the DPA.

Important: If you are a member of an organization using Orgo, please review that organization's privacy policy to understand how they handle your personal data. This Privacy Policy does not govern how organizations use the data they collect through our Services.

Your Rights:

  • As a member/user: See our User Terms of Service for your rights and responsibilities
  • As an organization: See our Organization Terms of Service for your obligations as Data Controller

Organization Responsibilities as Data Controller

When your organization acts as Data Controller, it is responsible for:

Data Protection Compliance

  • Complying with GDPR, CCPA, COPPA, and all applicable data protection laws
  • Obtaining valid consent or establishing another legal basis for processing member data
  • Implementing appropriate technical and organizational security measures
  • Having a privacy policy that informs members about data processing

Administrator Access and Confidentiality

  • Ensuring all administrators with access to member data have:
    • Signed confidentiality agreements or are bound by professional secrecy obligations
    • Received appropriate training on data protection requirements
    • Authorization and legitimate need to access the data
  • Conducting background checks for administrators who have access to children's data (under 18, or under 16 in EU, or under 13 in US)
  • Implementing access controls based on the "need-to-know" principle
  • Revoking access immediately when an administrator's role ends

Data Security and Breach Response

  • Monitoring for unauthorized access or misuse of member data
  • Notifying affected members if a data breach occurs (as required by law)
  • Taking corrective action if an administrator misuses member data
  • Maintaining documentation of access controls and security measures

Children's Data Protection If your organization serves children:

  • Obtaining verifiable parental consent before collecting children's data
  • Implementing age verification mechanisms
  • Ensuring administrators with access to children's data have appropriate background checks and safeguarding training
  • Responding promptly to parental requests to access, correct, or delete children's data

Member Rights

  • Responding to member requests to access, correct, or delete their personal data
  • Honoring opt-out requests for marketing communications
  • Providing data portability when requested

For detailed contractual obligations, please see our Organization Terms of Service, Section 5.5 (Rights and Obligations of Organizations).


3. Information We Collect

3.1 Personal Information You Provide Directly

Registration and Profile Information

  • Name, email address, phone number
  • Organization name and role
  • Profile photo and bio
  • Location (city, country)
  • Topics of interest
  • Custom profile fields set by your organization

Social Media Integration When you register or log in using Google, Microsoft, Apple, or LinkedIn:

  • Profile information (name, photo)
  • Email address
  • LinkedIn/social media profile URL

Payment Information

  • Credit card information (processed directly by Stripe - we do not store full card details)
  • Billing address and VAT/tax identification
  • Transaction history (last 4 digits of card, amount, date)

Communications

  • Messages sent through contact forms
  • Support tickets and customer service interactions
  • Email correspondence
  • Direct messages and discussions within organizations
  • Comments, posts, and user-generated content

Events and Activities

  • Event registrations and attendance
  • RSVP responses
  • Livestream participation (video/audio recordings when you agree to participate)

Documents and Files

  • Uploaded documents, images, videos
  • eSignatures and electronic document approvals
  • Files stored in your organization's drive

Donations and Fundraising

  • Donation amount and frequency
  • Membership fee payments
  • Event ticket purchases

3.2 Information We Collect Automatically

Device and Technical Information

  • IP address
  • Browser type and version
  • Operating system
  • Device type (mobile, tablet, desktop)
  • Unique device identifiers
  • Language preferences

Usage Information

  • Pages visited and time spent
  • Features used
  • Links clicked
  • Search queries
  • Navigation paths
  • Actions taken (posts, comments, votes, task completions)
  • Login dates and times

Location Information

  • Approximate location from IP address
  • Precise GPS location (only if you enable location services in our mobile app)

Cookies and Similar Technologies We use cookies, web beacons, local storage, and similar technologies to:

  • Remember your preferences and settings
  • Authenticate your session
  • Analyze how you use our Services (using privacy-focused analytics)
  • Improve service performance and reliability

See Section 12 (Cookies) for more details.

3.3 Information from Third Parties

Integrated Services (Optional - at your organization's choice) Your organization may choose to connect third-party services (such as HubSpot, Google Tag Manager, Meta Pixel, SSO providers, webhooks, or custom API integrations). When your organization enables these integrations:

  • Data shared according to your organization's integration settings
  • Activity and engagement metrics (if configured by your organization)
  • The integration and data sharing is controlled by your organization, not by Orgo

Public Sources

  • Publicly available information for business prospecting
  • Social media profiles (when you use social login)

Organization Administrators If your organization administrator creates an account for you or imports your information:

  • Data provided by the organization about you

4. How We Use Your Information

4.1 To Provide and Improve the Services

Service Delivery

  • Create and manage your account
  • Enable you to join and participate in organizations
  • Facilitate communication between members
  • Process payments and donations
  • Deliver events, courses, and content
  • Provide customer support

Personalization

  • Customize your experience based on your interests and activity
  • Recommend relevant content, groups, and members
  • Tailor notifications and communications

Analytics and Improvement

  • Understand how the Services are used (using privacy-focused analytics - Plausible)
  • Identify usage trends and patterns
  • Improve features and develop new functionality
  • Conduct research and analysis
  • Generate aggregated and anonymized statistics

4.2 Communications

Transactional Communications

  • Account notifications
  • Security alerts
  • Payment receipts and invoices
  • Service updates and changes
  • Responses to your inquiries

Marketing Communications (with your consent where required)

  • Newsletter and product updates
  • Educational content and webinars
  • Promotional offers and announcements
  • Event invitations

You can opt out of marketing communications at any time (see Section 10).

4.3 Legal and Security Purposes

  • Comply with legal obligations
  • Enforce our Terms and Conditions
  • Prevent fraud and abuse
  • Protect rights, property, and safety
  • Respond to legal requests and investigations
  • Maintain appropriate records

4.4 With Your Consent

We will obtain your consent for processing when required by law, including for:

  • Special categories of personal data (health, biometric, children's data)
  • Marketing communications in certain jurisdictions
  • Non-essential cookies
  • Recording of video/audio in livestreams

5. How We Share Your Information

5.1 Within Your Organization

Organization Administrators Your organization's administrators can access:

  • Your profile information (name, email, custom fields)
  • Your activity and engagement metrics
  • Content you post or share
  • Event registrations and attendance
  • Payment and donation history
  • Usage analytics (aggregated and individual)

Other Members Depending on your organization's privacy settings (Public, Private, Secret):

  • Public Organizations: All content and profile information is visible to anyone, including search engines
  • Private Organizations: Content visible only to approved members
  • Secret Organizations: Only invited members can find and access the organization

Search and Discovery Members may search for you by:

  • Name
  • Location
  • Topics of interest
  • Custom profile fields

5.2 Service Providers (Subprocessors)

We share information with trusted third-party service providers who assist us with:

Infrastructure and Hosting

  • AWS (Frankfurt, Germany) - Primary cloud hosting and data storage for all organization data
  • Cloudflare - CDN for static application assets only (JavaScript, CSS, images). Organization data is NOT processed through Cloudflare CDN.

Payment Processing

  • Stripe - Payment processing and subscriptions

Analytics and Marketing (Orgo-controlled)

  • Plausible Analytics - Privacy-focused, GDPR-compliant analytics for our website and service usage (no personal data tracking, no cookies)
  • Google Tag Manager - Tag delivery on the orgo.space marketing website only. Loads Google and Meta measurement and advertising tags after consent. Not used inside the Orgo application, and no Customer Personal Data is processed through it

Communications

  • AWS SES - Email service for transactional emails and notifications
  • OneSignal - Mobile push notifications (optional, only if organization enables branded mobile app)
  • Google Firebase Cloud Messaging - Web push notifications (optional, only if enabled)

Customer Support

  • Intercom - Support ticketing and in-product chat, including an AI support assistant that answers questions about configuring and using Orgo from our published product documentation. It receives the name, email address and organisation name of the person contacting us, together with their message. It has no access to any organization's database and performs no analysis on member data. Hosted in the European Union. You can ask to speak to a person at any time

Optional Integrations (at your organization's choice) Your organization may choose to enable integrations with third-party services. When enabled, data sharing is controlled by your organization:

  • SSO Providers (Google, Microsoft, Apple, LinkedIn) - For authentication only
  • Marketing Tools (HubSpot, Google Tag Manager, Meta Pixel) - Only if your organization configures them
  • Automation (Webhooks, n8n, custom APIs) - Only if your organization enables them
  • OAuth Applications - Third-party apps authorized by your organization

Important:

  • We enter into data processing agreements with all core service providers and limit their use of your data to the services they provide on our behalf
  • Optional integrations are the responsibility of your organization - we act only as a processor to facilitate the connection
  • A complete list of core subprocessors is available in our Subprocessors List document

5.3 Legal Requirements and Protection

We may disclose information when:

  • Required by law (subpoena, court order, legal process)
  • Responding to government or regulatory requests
  • Enforcing our agreements and policies
  • Protecting rights, property, or safety of Orgo, users, or the public
  • Investigating fraud or security issues
  • Defending legal claims

5.4 Business Transfers

If Orgo is involved in a merger, acquisition, asset sale, or bankruptcy:

  • Your information may be transferred as part of that transaction
  • We will notify you via email and/or prominent notice on our website
  • Your privacy rights will continue to be protected

5.5 We Do Not Sell Your Personal Data

Important: Orgo does not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration.

What This Means:

  • We do not sell your data to data brokers
  • We do not sell your data to advertisers
  • We do not sell your data to marketing companies
  • We do not monetize your personal information through advertising

Our Revenue Model:

  • We earn revenue exclusively through subscription fees paid by organizations
  • We do not display advertisements to users
  • We do not track you across the web for advertising purposes

CCPA "Sale" Definition: Under California law (CCPA), "sale" has a broad definition that may include some data sharing. However:

  • We do not engage in traditional data sales
  • If your organization enables optional third-party integrations (like Meta Pixel), that may be considered a "share" under CCPA, but it is controlled by your organization, not by Orgo
  • You can opt-out of any such sharing by disabling integrations or using Global Privacy Control (GPC)

5.6 With Your Consent

We will share information with third parties when you explicitly authorize us to do so.

5.7 Aggregated and Anonymized Data

We may share aggregated, anonymized, or de-identified data that cannot reasonably identify you:

  • For research and analysis
  • With business partners
  • For public reporting

This data cannot be used to identify you and is not considered personal information.


6. Children's Privacy (COPPA Compliance)

Organizations Without Children

Most of our customers serve adult members. If your organization does not serve children under 13 (or under 16 in the EU), standard data protection practices apply.

Organizations Serving Children

Some organizations using Orgo (educational institutions, scouting organizations) serve children under 13 years old (USA - COPPA) or under 16 years old (EU - GDPR).

Special Protections for Children:

Under Age 13 (USA - COPPA)

  • Organizations must obtain verifiable parental consent before collecting personal information from children under 13
  • Organizations must provide parents with:
    • Notice of data collection practices
    • Ability to review their child's information
    • Ability to request deletion
    • Option to consent to collection but not to disclosure to third parties

Under Age 16 (EU - GDPR)

  • Consent for data processing requires parental authorization for children under 16 (or younger, depending on EU member state)

Orgo's Responsibilities:

  • We do not knowingly collect personal information from children without proper parental consent mechanisms in place
  • Organizations serving children must implement appropriate consent mechanisms
  • If we learn we have collected data from a child without proper consent, we will delete it promptly

Organization Administrator Responsibilities: If your organization serves children, you must:

  • Implement verifiable parental consent mechanisms
  • Provide clear privacy notices to parents
  • Enable parents to access, review, and delete their child's data
  • Comply with COPPA, GDPR, and applicable children's privacy laws
  • Clearly mark child accounts in your organization settings

Reporting: If you believe we have collected information from a child without proper consent, contact us immediately at privacy@orgo.space.


7. International Data Transfers

Our Infrastructure

Current Data Residency

  • Primary Hosting: AWS Frankfurt, Germany (EU)
    • All organization data is stored and processed in the EU
    • Data remains in EU/EEA unless you explicitly choose otherwise
  • CDN: Cloudflare (global network)
    • Used only for static application assets (JavaScript, CSS, images)
    • Organization data does NOT transit through Cloudflare
  • Payment Processing: Stripe (EU and USA operations)

Future North American Data Residency (Planned) For organizations based in North America, we plan to offer optional data hosting in the United States:

  • AWS US regions (e.g., us-east-1 Virginia or us-west-2 Oregon)
  • Organizations will choose their data residency location upon signup
  • Data will remain in the chosen region and will not be transferred between regions without explicit consent
  • This option will be available for organizations that prefer US-based data storage for latency or regulatory reasons

Your Control Over Data Location

  • You choose where your organization's data is stored (EU or US, when available)
  • Data residency is locked to your chosen region
  • Cross-region transfers only occur with your explicit authorization

Transfers Outside the EU/EEA

When we transfer personal data outside the EU/EEA, we ensure appropriate safeguards in accordance with GDPR Chapter V:

Standard Contractual Clauses (SCCs)

  • We use the EU Commission's Standard Contractual Clauses (2021 version) with all non-EU service providers
  • These clauses provide GDPR-level protection for your data
  • We implement supplementary measures as required by the Schrems II decision
  • We conduct Transfer Impact Assessments (TIAs) for all international transfers

Service Providers with International Operations Some of our core service providers operate globally but have implemented GDPR-compliant safeguards:

Service Provider Service Data Location Safeguard
AWS Hosting EU (Frankfurt) Data Processing Agreement, EU data residency
Cloudflare CDN (static assets only) Global network Data Processing Agreement, EU-US Data Privacy Framework
Stripe Payment processing EU and USA Data Processing Agreement, SCCs, EU-US Data Privacy Framework
Plausible Analytics Privacy-focused analytics EU GDPR-compliant by design, no personal data tracking

EU-US Data Privacy Framework

  • For transfers to the United States, we rely on service providers certified under the EU-US Data Privacy Framework where applicable
  • We verify certification status regularly
  • We implement SCCs as a backup safeguard mechanism

Adequacy Decisions We transfer data to countries recognized by the EU Commission as providing adequate protection under Art. 45 GDPR.

Supplementary Measures In addition to SCCs, we implement supplementary technical and organizational measures:

  • Encryption in transit and at rest
  • Access controls and authentication
  • Data minimization
  • Contractual obligations for data protection
  • Vulnerability and dependency scanning

Your Rights

  • You may request copies of the Standard Contractual Clauses we use by contacting privacy@orgo.space
  • You may request information about Transfer Impact Assessments for specific service providers
  • You may object to specific international transfers where we rely on legitimate interests

8. Data Retention

How Long We Keep Your Data

Active Accounts

  • We retain your information for as long as your account is active or as needed to provide Services

Organization Data

  • Data within organizations is retained according to the organization's retention settings
  • Enterprise plan customers can customize retention policies

After Account Deletion

  • Most personal data is deleted within 90 days
  • Some information may be retained longer for legal, security, or operational purposes:
    • Transaction records: 10 years (accounting requirements)
    • Fraud prevention: 5 years
    • Legal claims: until the claim is resolved
    • Backup systems: up to 90 days

Specific Retention Periods:

Data Type Active Database Archive Period
Account information Duration of account 90 days after deletion
Support tickets Until resolution 5 years
Payment records Duration of relationship 10 years (legal requirement)
Marketing contacts Until opt-out 3 years from last interaction
Analytics data 26 months Anonymized
Server logs 12 months N/A
Content and messages Customizable by organization Per organization settings

Edited and Deleted Content

  • Standard: Only the most recent version is retained
  • Enterprise plan: Organizations can choose to retain edit history

9. Your Privacy Rights

Rights for All Users

Access

  • Request a copy of the personal data we hold about you

Correction

  • Update or correct inaccurate information in your account settings

Deletion

  • Request deletion of your account and associated data
  • Some data may be retained for legal obligations (see Section 8)

Portability

  • Request your data in a structured, machine-readable format

Object to Processing

  • Object to certain types of processing (e.g., direct marketing)

Restrict Processing

  • Request temporary restriction of processing

Withdraw Consent

  • Withdraw consent at any time (does not affect prior lawful processing)

Additional Rights for EU/EEA/UK Residents (GDPR)

Legal Basis for Processing We process your data based on:

  • Contract: To provide Services you requested
  • Legitimate Interest: To improve Services, prevent fraud, ensure security
  • Consent: For marketing, special categories of data, non-essential cookies
  • Legal Obligation: To comply with laws and regulations

Right to Lodge a Complaint You may file a complaint with your local data protection authority:

  • Romania: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP)
  • EU/EEA/UK: Your national data protection authority

EU Representative For EU data protection matters, you may contact our EU representative (details available upon request).

Additional Rights for California Residents (CCPA/CPRA)

Right to Know

  • Categories of personal information collected
  • Purposes for collection
  • Categories of sources
  • Categories of third parties we share with

Right to Delete Request deletion (subject to legal exceptions)

Right to Opt-Out

  • Opt-out of "sale" or "sharing" of personal information for targeted advertising
  • Orgo does not sell personal information in the traditional sense
  • If your organization enables third-party tracking integrations (e.g., Meta Pixel), this may be considered a "share" under CCPA's broad definition
  • You can opt-out by: (1) contacting your organization to disable integrations, (2) using Global Privacy Control (GPC), or (3) using browser cookie controls

Right to Non-Discrimination We will not discriminate against you for exercising your privacy rights

Shine the Light Request information about data shared with third parties for marketing purposes

Additional Rights for Texas Residents (TDPSA)

The Texas Data Privacy and Security Act applies to us regardless of our size, so it applies to Orgo today. You have the right to confirm whether we process your personal data, to access, correct, delete, and obtain a portable copy of it, and to opt out of targeted advertising, sale, and profiling with legal or similarly significant effects.

Orgo does not sell personal data — including sensitive data such as religious or political affiliation — and does not use it for targeted advertising or profiling of that kind. Where your organization enables a third-party tracking integration, your organization decides that, and it is the controller for it.

We honour universal opt-out signals, including Global Privacy Control. To exercise any of these rights, contact privacy@orgo.space. If we decline a request, you may appeal by replying to our decision, and you may complain to the Texas Attorney General.

Additional Rights for Other US State Residents

Residents of Colorado, Connecticut, Montana, Oregon, Utah, and Virginia have substantially similar rights under their state privacy laws — access, correction, deletion, portability, and opt-out of targeted advertising and sale. The statements above apply equally: we do not sell personal data and we do not use it for targeted advertising. Contact privacy@orgo.space to exercise any of them.

How to Exercise Your Rights

For Your Organization Account:

  • Log in to your account settings to update, correct, or download your data
  • Contact your organization administrator for data managed by them

For Orgo-Controlled Data:

  • Email: privacy@orgo.space
  • Write: S.C. ORGO INFORMATICS SRL, Str. Gheorghe Grigore Cantacuzino nr 14, etaj PARTER, ap 1, Ploiești, județul Prahova, Romania

Response Time:

  • We will respond to verified requests within one month (GDPR Article 12(3)) or 45 days (CCPA)

Verification: We may require verification of your identity before processing your request to protect your privacy.


10. Your Choices and Controls

10.1 Account Settings

Control your profile information, privacy settings, and preferences in your account dashboard.

10.2 Notification Preferences

Choose which notifications you receive:

  • Email notifications
  • Mobile push notifications
  • In-app notifications
  • Notification frequency and type

Customize in: Account Settings > Notifications

10.3 Email Communications

Marketing Emails

  • Click "Unsubscribe" in any marketing email
  • Update preferences in account settings
  • Email privacy@orgo.space

Transactional Emails You cannot opt out of essential service communications (receipts, security alerts, account notifications).

10.4 Mobile App Permissions

Location Services

  • Disable in device settings: Settings > Apps > Orgo > Permissions

Push Notifications

  • Disable in device settings or app notification settings

Camera/Microphone

  • Required only for specific features (livestreams, video content)
  • Disable in device settings

10.5 Cookie Controls

Browser Settings

  • Configure cookie preferences in your browser
  • Block all cookies (may affect functionality)

Cookie Preference Center

  • Manage cookie preferences on our website
  • See Section 12 for details

10.6 Do Not Track / Global Privacy Control

Do Not Track (DNT)

  • Our Services do not currently respond to DNT browser signals due to lack of industry standard

Global Privacy Control (GPC)

  • We honor GPC signals where required by law (e.g., California, Colorado)
  • GPC is recognized as an opt-out of data "sales"

10.7 Third-Party Tracking Controls

Organization-Controlled Tracking If your organization has enabled third-party tracking tools (Google Tag Manager, Meta Pixel, etc.):

  • Contact your organization administrator to opt-out
  • Use browser cookie controls to block third-party cookies
  • Network Advertising Initiative: networkadvertising.org/choices
  • Digital Advertising Alliance: aboutads.info/choices
  • Your Online Choices (EU): youronlinechoices.eu

Orgo's Analytics

  • Within the Orgo application we use Plausible Analytics, which is privacy-focused, uses no cookies and does not track personal data
  • On our marketing website (orgo.space) we additionally operate Google Tag Manager, through which Google and Meta advertising and measurement tags may load. These set cookies and are loaded only after you consent via the cookie banner, using Google Consent Mode v2 (all non-essential storage denied by default)
  • You can withdraw or change that consent at any time through the cookie settings link on our website
  • The full list of cookies, their purposes and retention periods is in our Cookie Policy

10.8 Social Media Integrations

Disconnect social media accounts in: Account Settings > Connected Accounts

10.9 Organization Visibility

Control how you appear to others in your organization settings (depending on organization type).


11. Security

Our Security Measures

Technical Safeguards

  • Encryption in transit (TLS/SSL)
  • Encryption at rest (AWS encryption)
  • Regular vulnerability scanning
  • DDoS protection and Web Application Firewall (Cloudflare, on orgo.space)
  • Secure authentication (OAuth 2.0, SSO)
  • Multi-factor authentication (MFA) available

Organizational Safeguards

  • Access controls (least privilege principle)
  • Confidentiality agreements with staff and contractors
  • Security incident response plan
  • Regular backups

Compliance

  • GDPR-compliant data processing
  • ISO/IEC 27001 certification in preparation
  • Regular compliance reviews

Your Responsibilities

  • Choose strong, unique passwords
  • Enable multi-factor authentication
  • Do not share login credentials
  • Report security incidents immediately
  • Log out from shared devices

No Absolute Security

No method of transmission or storage is 100% secure. While we implement industry-standard security measures, we cannot guarantee absolute security.

Phishing and Fraud

We will never ask for your password via email. If you receive suspicious communications claiming to be from Orgo, report them to security@orgo.space.

Data Breaches

In the event of a data breach affecting your personal data:

  • We will notify you within 72 hours (GDPR requirement)
  • We will inform relevant authorities as required by law
  • We will provide guidance on protective actions

For detailed security practices, see our Security Policy.


12. Cookies and Tracking Technologies

What Are Cookies?

Cookies are small text files stored on your device that help websites function and provide analytics.

Types of Cookies We Use

Essential Cookies (always active)

  • Authentication and session management
  • Security and fraud prevention
  • Load balancing and performance
  • Remember your preferences

Analytics Cookies

  • Plausible Analytics - Privacy-focused, GDPR-compliant analytics (no cookies, no personal data tracking)
  • Internal analytics - feature usage and performance
  • A/B testing and optimization

Marketing Cookies (optional - only if your organization enables them)

  • Google Tag Manager - Only if configured by your organization
  • Meta Pixel (Facebook) - Only if configured by your organization
  • Custom tracking pixels - Only if configured by your organization
  • These cookies are controlled by your organization, not by Orgo

Third-Party Cookies (only when used)

  • Social media plugins (LinkedIn, Facebook, Twitter) - Only if your organization enables social sharing
  • Payment processing (Stripe) - Only during payment transactions
  • Video embeds (YouTube, Vimeo) - Only when embedded by your organization
  • Integrated services - Only if your organization configures them

Other Tracking Technologies

Web Beacons (Pixels)

  • Email open tracking
  • Page view tracking
  • Ad impression tracking

Local Storage

  • HTML5 local storage for app-like functionality
  • Session data for mobile apps

Mobile SDKs

  • In-app analytics
  • Push notification delivery
  • Crash reporting

Managing Cookies

Cookie Preference Center

  • Available on our website footer
  • Customize cookie categories
  • Withdraw consent at any time

Browser Controls

  • Chrome: Settings > Privacy and security > Cookies
  • Firefox: Settings > Privacy & Security > Cookies
  • Safari: Preferences > Privacy > Cookies
  • Edge: Settings > Privacy > Cookies

All About Cookies Visit allaboutcookies.org for detailed cookie management instructions.

Impact of Blocking Cookies

Blocking essential cookies may prevent you from using certain features:

  • Cannot stay logged in
  • Settings not remembered
  • Some features may not work properly

For a complete list of cookies, see our Cookie Policy (separate document available upon request).


13. Third-Party Links and Integrations

Third-Party Websites

Our Services may contain links to external websites not controlled by Orgo:

  • We are not responsible for their privacy practices
  • Review their privacy policies before providing information
  • Links do not imply endorsement

Examples: YouTube channels, external documentation, partner websites

Integrated Services

Orgo supports various integrations that your organization controls. When your organization enables these integrations:

  • Your organization authorizes data sharing, not Orgo
  • The third party's privacy policy governs their use of the data
  • Your organization can disconnect integrations at any time

Core Integrations (Always Available):

  • SSO Providers: Google, Microsoft, Apple, LinkedIn - For authentication only
  • Stripe: Payment processing - Required for paid features

Optional Integrations (Your Organization's Choice):

  • HubSpot - CRM and marketing (only if your organization configures it)
  • Google Tag Manager - Analytics and marketing (only if your organization configures it)
  • Meta Pixel - Facebook tracking (only if your organization configures it)
  • Webhooks - Custom automation (only if your organization configures it)
  • n8n - Workflow automation (only if your organization configures it)
  • Custom OAuth Apps - Third-party applications authorized by your organization
  • API Integrations - Custom API consumers authorized by your organization

What Gets Shared (When Your Organization Enables Integrations):

  • Account information (name, email) - If configured by your organization
  • Profile data - If configured by your organization
  • Usage activity - If configured by your organization
  • Organization membership - If configured by your organization

SSO Data We Receive:

  • Profile information (name, photo)
  • Email address
  • Authentication tokens

Important:

  • Orgo does not share your data with third parties unless (1) you use SSO authentication, (2) you make a payment via Stripe, or (3) your organization explicitly configures an integration
  • Your organization is responsible for their choice of integrations and compliance with privacy laws
  • Review your organization's privacy policy and integration settings for details

14. Social Sharing Features

Our Services include social sharing features:

  • Share content to Facebook, Twitter, LinkedIn
  • Invite members via social media
  • Display social media feeds

Privacy Implications:

  • Information shared is governed by the social media platform's privacy policy
  • Your privacy settings on those platforms control visibility
  • We do not control how social platforms use shared data

Check your privacy settings on social media platforms to control what information is shared.


15. AI and Automated Decision-Making

The short version

Orgo's AI features are administrator tools. They are used by the people who run your organization, not by members, and they are not used to make decisions about you automatically. Nothing you post, message, or upload is sent to an AI model by Orgo.

The AI features that exist

Feature Who uses it What it does
Ask Orgo Your organization's administrators Turns a plain-language question into a query against your organization's own data
List suggestions Your organization's administrators Proposes member list criteria from a plain-language description
Support assistant Your organization's administrators Answers questions about how to configure and use Orgo
MCP server Your organization's administrators, if they choose to enable it Lets an AI assistant your organization selects connect to its Orgo data

We do not offer AI moderation of discussions, and no Orgo AI feature reads member-written content — your posts, comments, direct messages and files are not sent to an AI model by us.

What this means for your data

For Ask Orgo and list suggestions, what leaves Orgo is the administrator's question and the structure of the database — table and field names, without values. The query runs inside our Frankfurt infrastructure and the results stay there. An administrator can attach an image to a question, and that image is sent to the model provider, so whatever the administrator chose to show in it goes with it.

For the support assistant, the administrator's name, email address, organization name and message are sent to our support provider. It has no access to your organization's data.

For the MCP server, if your organization's administrators enable it, real records — potentially including yours — are sent to an AI assistant your organization has selected, not one we have chosen or vetted. From that point the data is in your organization's hands and its own privacy notice governs it. Ask your organization's administrator whether this is enabled and which assistant they use.

Our AI providers are named, with their locations and transfer safeguards, in Annex 3 — Subprocessors. The full terms are in the AI Addendum, which is where these facts are maintained; this section summarizes them for you and does not add to them.

We do not train AI models on your data

We do not use your personal data — or your organization's data — to train, fine-tune, or improve any AI model, whether our own or a third party's, and we do not permit our model provider to do so. There is no opt-in that changes this, because there is no training programme to opt into. Children's data is subject to an additional absolute prohibition, described in Annex 5 to our Data Processing Agreement.

Automated decision-making

We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you, within the meaning of Article 22 GDPR.

We do use automated systems for spam and abuse detection, fraud prevention, and security threat detection. These protect the platform; they are not used to decide your membership status, your eligibility, or anything of similar consequence.

Where your organization uses Ask Orgo to inform a decision about you, your organization is required by its contract with us to apply human review before acting on the output in any decision with a legal or similarly significant effect — including membership status, eligibility, discipline, exclusion, financial obligation, or access to benefits. AI output can be wrong, and it is provided to your organization on that basis.

Your rights

Under GDPR Article 22 you have the right not to be subject to a decision based solely on automated processing that significantly affects you, to obtain human intervention, to express your point of view, and to contest the decision.

Because the decisions that affect your membership are made by your organization rather than by us, direct these requests to your organization in the first instance. If you cannot reach them, or they do not respond, write to privacy@orgo.space and we will help you identify the right contact and, where we are able to act, act.


16. Changes to This Privacy Policy

Updates

We may update this Privacy Policy to reflect:

  • Changes in our practices
  • Legal or regulatory requirements
  • New features or services
  • User feedback

Notification

When we make material changes:

  • Update the "Last Updated" date at the top
  • Notify you via email (for significant changes)
  • Post a notice on our website
  • May require re-acceptance for material changes

Review Regularly

We encourage you to review this policy periodically to stay informed about how we protect your privacy.

Previous Versions

Contact privacy@orgo.space to request previous versions of this policy.


17. Contact Us

Privacy Questions

For questions about this Privacy Policy or our privacy practices:

Privacy Contact: privacy@orgo.space Mail: S.C. ORGO INFORMATICS SRL Str. Gheorghe Grigore Cantacuzino nr 14, Ploiești, județul Prahova, Romania J29/2796/2019

Data Subject Requests

To exercise your privacy rights (access, deletion, portability):

  • Email: privacy@orgo.space
  • Subject line: "Data Subject Request - [Your Request Type]"
  • Include: Your name, email, organization (if applicable), and specific request

Security Issues

Report security concerns or incidents:

  • Email: security@orgo.space

Support

For general support questions:

  • Visit: orgo.space/docs
  • Email: contact@orgo.space

We aim to respond to all inquiries within 48 hours (business days).


18. Jurisdiction-Specific Information

European Union / EEA / UK

GDPR Compliance This policy complies with GDPR and UK GDPR requirements.

Legal Basis:

  • Contract (Art. 6(1)(b)) - to provide Services
  • Legitimate Interest (Art. 6(1)(f)) - to improve Services, prevent fraud
  • Consent (Art. 6(1)(a)) - for marketing, special categories of data
  • Legal Obligation (Art. 6(1)(c)) - to comply with laws

Supervisory Authority (Romania): Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP) B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, București www.dataprotection.ro

EU Representative: Available upon request

United States

California (CCPA/CPRA) See Section 9 for complete CCPA disclosures and how to exercise your rights.

Texas (TDPSA) The Texas Data Privacy and Security Act has no revenue threshold and applies to Orgo. See Section 9. We do not sell personal data, including sensitive data such as religious or political affiliation, and we honour universal opt-out signals including Global Privacy Control.

Other States: Colorado, Connecticut, Montana, Oregon, Utah, and Virginia residents have substantially similar rights — see Section 9.

COPPA (Children under 13) See Section 6 for children's privacy protections.

Nevada Orgo does not sell personal information as defined by Nevada law. We do not engage in the sale of covered information for monetary consideration. If you have questions, contact privacy@orgo.space.

Canada

PIPEDA Compliance We comply with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA).

Canadian Office of the Privacy Commissioner: www.priv.gc.ca

Other Jurisdictions

We strive to comply with privacy laws in all jurisdictions where we operate. Contact us for jurisdiction-specific questions.


19. Dispute Resolution

Disputes with Organizations

If you have a privacy dispute with an organization using Orgo:

  • Contact the organization directly (they are the Data Controller)
  • If unresolved, contact us at privacy@orgo.space and we will facilitate

Disputes with Orgo

  • First contact privacy@orgo.space
  • We will work to resolve disputes informally
  • EU residents may contact their data protection authority
  • California residents may contact the California Attorney General

Arbitration

Dispute resolution provisions in our Terms and Conditions may apply.


20. Definitions

Personal Data/Personal Information: Any information relating to an identified or identifiable person.

Special Categories of Personal Data: Data revealing racial/ethnic origin, political opinions, religious beliefs, health information, biometric data, sexual orientation.

Processing: Any operation on personal data (collection, storage, use, disclosure, deletion).

Data Controller: The entity that determines the purposes and means of processing personal data.

Data Processor: An entity that processes personal data on behalf of a Data Controller.

Consent: Freely given, specific, informed, and unambiguous indication of agreement to processing.

Subprocessor: A third-party service provider that processes data on behalf of a Data Processor.

Aggregated Data: Data combined in summary form for statistical analysis, with personal identifiers removed.

Anonymized Data: Data that can no longer identify an individual, even with additional information.

Pseudonymization: Processing data so it cannot identify an individual without additional information kept separately.


Appendix: Summary of Privacy Practices

What We Collect

  • Name, email, profile information
  • Payment and billing information
  • Communications and content
  • Usage and device information (via Plausible Analytics - no personal tracking)
  • Location data (with permission)

Why We Collect It

  • Provide and improve Services
  • Process payments
  • Communicate with you
  • Ensure security
  • Comply with laws

Who We Share With

  • Your organization administrators - They control your member data
  • Other members - Based on privacy settings (Public/Private/Secret)
  • Core service providers:
    • AWS Frankfurt (hosting - all organization data stays in EU)
    • Cloudflare (static assets only - NOT organization data)
    • Stripe (payment processing)
    • Plausible (privacy-focused analytics - no personal data)
  • Optional integrations - Only if YOUR ORGANIZATION enables them (HubSpot, Google Tag Manager, Meta Pixel, webhooks, etc.)
  • Legal authorities - When required by law

Key Privacy Protections

  • We do NOT sell your data: No data sales to brokers, advertisers, or third parties
  • No advertisements: We do not display ads or monetize through advertising
  • EU data residency: All organization data stored in AWS Frankfurt (Germany)
  • Privacy-focused analytics: Plausible (no cookies, no personal tracking)
  • Organization control: Integrations are opt-in by your organization
  • Transparent processing: Clear Controller/Processor roles
  • Subscription-based: Revenue from subscriptions, not from your data

Your Rights

  • Access your data
  • Correct inaccuracies
  • Delete your account
  • Export your data
  • Opt-out of marketing
  • Object to processing

How to Contact Us

privacy@orgo.space


This Privacy Policy was last updated on August 1, 2026.

Document Version: 2.2

Table of Contents

    orgo community
    • Platform
    • Features
    • Branded App
    • Trust & Security
    • iOS app↗
    • Android app↗
    • Company
    • About us
    • Contact
    • Get a demo
    • Resources
    • Documentation↗
    • Changelog↗
    • API reference↗
    • Blog
    • Alternatives
    • Comparisons
    • Delete your account
    • Guides
    • Sitemap
    • Use Cases
    • NGOs
    • Scouts
    • Associations
    • Federations
    • Trade Associations
    • Political Parties
    • Fundraising Campaign
    🇬🇧 English
    🇩🇪 Deutsch 🇫🇷 Français 🇮🇹 Italiano 🇪🇸 Español 🇵🇱 Polski 🇷🇴 Română 🇨🇿 Čeština 🇸🇰 Slovenčina
    © 2026 Orgo Informatics.
    Terms User Terms Privacy Cookies DPA Subprocessors AI Addendum

    Before you go — got 2 minutes?

    No newsletters. No 10 follow-up calls. We just want to see if Orgo is the right fit for you. A 20-min demo, calendar open right now.

    Please complete this required field.

    Please complete this required field.

    Please enter a valid email address.

    Please complete this required field.

    Something went wrong on our side. Please try again, or email us at hello@orgo.space.

    By submitting, I acknowledge I have read and understand Orgo's Privacy Notice.

    Dear ,

    Your meeting is booked! We look forward to learning about your organization and showing you how Orgo can help.