orgo community
Platform Resources Pricing Platform Documentation About us Blog Pricing
Membership
Membership Management Fees, renewals and records, automated
Contacts CRM Every contact and member in one database
Multi-Chapter National, regional and local chapters in one account
Community
Events Ticketing, QR check-in and attendance
Discussions & Groups Forums and groups that keep members active
Newsletter Segmented emails with open analytics
Fundraising Donation campaigns and recurring giving
Courses & Badges Training, certification and badges for members
Governance
e-Voting Anonymous, verifiable elections and decisions
eDocuments & eSignatures Send, e-sign and archive documents
Files Drive Secure shared storage for your documents
Project Management Member support tickets and team tasks
Privacy & Security GDPR compliance, EU hosting, access control
Operations
Analytics Reports and dashboards for board decisions
Branding & Customization Your logo, domain, languages and fields
Integrations Stripe, SSO, HubSpot, n8n and more
Ask Orgo AI Plain-language answers from your data
MCP Server Connect AI assistants to your data
Documentation
API Reference
Changelog
Sign in
Get a demo
Sign in Get a demo

ORGO ORGANIZATION TERMS OF SERVICE

Last Updated: August 1, 2026


Welcome to Orgo!

These Organization Terms of Service ("Terms") govern your organization's access to and use of the Orgo platform and services (the "Service"), provided by Orgo Informatics SRL ("Orgo", "we", "us", or "our").

By creating an organization account, clicking "I Agree," or accessing the Service on behalf of your organization, you ("you", "your", or "Organization") agree to be bound by these Terms, our Privacy Policy, Data Processing Agreement, and User Terms of Service.

If you do not agree to these Terms, do not use the Service.

IMPORTANT: These Terms govern the relationship between Orgo and your organization. Individual members, volunteers, and users who access your organization's Orgo space must accept our separate User Terms of Service.


1. DEFINITIONS

1.1 Key Terms

  • "Orgo Platform" or "Service": The cloud-based software accessible at orgo.space and related mobile applications, enabling community management, member databases, communications, events, and payments.

  • "Account": Your organization's Orgo account, created upon registration.

  • "Subscription Plan": The tier of service you purchase — Grow, Impact or Scale, as described at orgo.space/pricing — or a Free plan where Orgo has expressly granted one (see Section 6.5). Where an Order Form applies, it prevails over the published description for the terms it addresses.

  • "Customer Data" or "Member Data": All data, content, and information you or your members upload, store, or transmit through the Service, including personal data of your members, volunteers, beneficiaries, and other end-users.

  • "End Users" or "Members": Individuals you authorize to access your Account (admins, facilitators, members, volunteers, beneficiaries, etc.).

  • "Administrator" or "Admin": Individual(s) you designate with administrative access to your Account, including the ability to add/remove End Users, manage settings, access Member Data, and authorize payments.

  • "Fees": Amounts owed to Orgo for your Subscription Plan, as specified at orgo.space/pricing or in your account settings.

  • "Agreement": These Organization Terms, together with our Privacy Policy, Data Processing Agreement (DPA), and User Terms of Service.


2. ELIGIBILITY & ACCOUNT REGISTRATION

2.1 Eligibility

To use the Service, you must:

(a) Represent an organization, association, club, school, or similar entity authorized to enter into binding agreements.

(b) Be at least 18 years old (or the age of majority in your jurisdiction), or be authorized by your organization to bind it to these Terms.

(c) Provide accurate, current, and complete information during registration.

(d) Comply with all applicable laws and regulations.

2.2 Account Creation

When you create an Account:

(a) You designate a primary Administrator ("Admin") with full control over your Account, including the ability to add/remove End Users, manage settings, and authorize payments.

(b) You are responsible for maintaining the confidentiality of your login credentials and for all activities under your Account.

(c) You agree to notify us immediately at security@orgo.space if you suspect unauthorized access or a security breach.

2.3 Organizational Use Only

The Service is designed for organizational use (non-profits, associations, clubs, educational institutions, etc.). You may not:

(a) Use the Service for personal, household, or individual purposes unrelated to an organization.

(b) Resell, white-label, or sublicense the Service to third parties without a written agreement with Orgo.

(c) Third-Party Monetization Restrictions:

(i) Permitted Revenue Activities: You may collect revenue from your own Members through the Service, including: - Membership dues and subscription fees - Event ticket sales - Donations and fundraising campaigns - Sales of your own products or services to Members - Incidental sponsorship acknowledgments from third parties (per Section 5.5.8)

(ii) Prohibited Activities Without Prior Written Consent: You may not, without our express written approval: - Create Orgo spaces on behalf of separate third-party organizations as a primary business activity - Resell Orgo subscriptions or access to third-party entities for profit - Act as a platform aggregator, franchiser, or network operator where multiple independent legal entities pay you for access to separate Orgo spaces - White-label Orgo as your own proprietary software product - Charge third-party entities "platform fees" or "software access fees" for using Orgo infrastructure

(iii) Multi-Chapter Clarification: The Multi-Chapter feature is designed for organizations with: - Regional branches or chapters that are part of the same legal entity, OR - Closely affiliated entities with legitimate operational relationships (federations, umbrella organizations, parent-subsidiary structures)

  If your chapters are **independent legal entities** with separate governance, finances, and missions, contact **sales@orgo.space** to discuss a Scale configuration or a partnership agreement.

(iv) Consultancy and Implementation Services: If you provide consultancy services that include setting up or managing Orgo spaces for clients: - Each client organization must have its own Orgo Account and pay Orgo directly, OR - You must have a written reseller or partner agreement with Orgo - You may charge professional fees for your services (setup, training, management) but not for software access itself

(v) Corporate Sponsorship Programs: If you wish to: - Collect corporate sponsorship fees exceeding €10,000 per year from third parties in exchange for branded spaces, premium visibility, or platform access within your Orgo space, OR - Operate a B2B model where corporations pay to access a network of organizations via Orgo

  Please contact **sales@orgo.space** for approval and appropriate licensing terms.

(vi) Violation and Enforcement: Violation of this Section 2.3(c) may result in: - Immediate Account suspension - Termination without refund of prepaid fees - Adjustment of your subscription to Scale pricing reflecting actual usage - Legal action to recover unpaid fees and damages

2.4 Account Suspension

We reserve the right to suspend or terminate your Account if:

(a) You violate these Terms or the Acceptable Use Policy incorporated in our User Terms.

(b) Your payment method fails or you have overdue invoices (see Section 4.6).

(c) We are required to do so by law or court order.

(d) We reasonably believe your Account poses a security or legal risk.


3. SERVICE DESCRIPTION & LICENSE

3.1 Service Provision

Subject to your compliance with these Terms and payment of applicable Fees, Orgo grants you a limited, non-exclusive, non-transferable, revocable right to access and use the Service during your subscription term, solely for your internal organizational purposes.

3.2 Features Included

Your Subscription Plan includes the features described at orgo.space/features and in your account dashboard. Standard features include:

  • Member database and profile management
  • Communication tools (email, SMS, in-app messaging)
  • Event creation, RSVP tracking, and calendar
  • Payment processing (via third-party processors like Stripe)
  • File storage and document sharing
  • Groups, roles, and permissions
  • Mobile apps (iOS and Android)
  • Reporting and analytics
  • API access (rate limits apply per plan)

3.3 Service Changes

We may:

(a) Add or improve features at any time at no additional cost (we'll notify you of major enhancements).

(b) Modify or discontinue features with at least 30 days' notice if such changes materially degrade core functionality. You may cancel per Section 4.5 if you object.

(c) Perform maintenance with advance notice (typically 48 hours for scheduled downtime; emergency maintenance may occur without notice).

3.4 Beta, Experimental, and Pre-Release Features

3.4.1 What They Are

We may offer features that are not ready for general availability, labelled "Beta", "Alpha", "Preview", "Early Access", "Experimental", "Labs" or similar (collectively, "Non-GA Features"). They are always clearly labelled in the Service, and are opt-in — you have to enable them.

3.4.2 The Terms on Which They Are Offered

(a) "AS IS", with no warranty of any kind. Non-GA Features may contain bugs, defects, security vulnerabilities, performance problems and data-loss risks.

(b) Outside the SLA. The uptime commitment and service credits in Sections 6.1–6.3 do not apply, and neither do the support response targets in Section 6.4.2.

(c) Not for production. They are for testing and evaluation. Do not use them for critical operations, regulatory compliance functions, or anything where failure would cause real harm.

(d) We may change or withdraw them at any time, in our sole discretion, without releasing them generally and without advance notice.

(e) Keep your own backups of anything you store in a Non-GA Feature. We do not guarantee data preservation, and we are not liable for data loss, corruption or unavailability arising from a Non-GA Feature, its withdrawal, or your failure to keep backups.

(f) No obligation to release. Offering a Non-GA Feature does not oblige us to keep it, to release it generally, to deliver any particular functionality, or to support it after the testing period.

3.4.3 Withdrawal, Pricing and Transition

(a) If we withdraw a Non-GA Feature that stores your data, we will give at least 30 days' notice and provide an export where technically feasible. Where export is not feasible we will tell you the deletion timeline instead.

(b) Non-GA Features are normally free during testing. We will give at least 30 days' notice before charging for one that was previously free. If we withdraw a Non-GA Feature you paid to access, no refund is due where the feature was clearly designated Non-GA.

(c) When a feature becomes generally available we remove the designation, communicate any pricing, and it becomes subject to Section 6 and to the warranty in Section 9.2.

(d) You may disable a Non-GA Feature at any time in account settings or via support@orgo.space — export your data first, as disabling it may lose data stored there. Feedback is welcome at the same address, on the terms in Section 8.4.

3.5 Third-Party Integrations

The Service integrates with third-party services (e.g., payment processors, email providers, social login, marketing tools). Your use of third-party services is subject to their own terms and privacy policies. We are not responsible for third-party failures or terms.

Important: When you enable third-party integrations (such as HubSpot, Google Tag Manager, Meta Pixel, webhooks, or custom APIs), you act as the Data Controller and determine how data is shared with those third parties. See our Data Processing Agreement for details.


4. SUBSCRIPTION PLANS, BILLING & CANCELLATION

4.1 Subscription Plans

Current plans and pricing are available at orgo.space/pricing. Plans are based on:

(a) Number of member accounts (active users)

(b) Features and limits (storage, emails sent, API calls, etc.)

(c) Support level (email, priority, or dedicated support)

(d) Mid-Cycle Plan Changes and Add-Ons:

(i) Upgrades (Higher-Tier Plans or Additional Features): - You may upgrade to a higher-tier plan or purchase additional features (storage, member capacity, add-on modules) at any time during your Subscription Term - Prorated Pricing: You will be charged the prorated difference between your current plan and the new plan for the remainder of your Subscription Term - Calculation Example: If you upgrade mid-cycle on day 15 of a 30-day cycle, you pay the difference between the two monthly fees for the remaining 15 days — that is, (new fee − current fee) × 15/30. Your applicable fees are those in your Order Form or quote. - Upgrades take effect immediately upon payment confirmation - Your renewal date remains unchanged

(ii) Downgrades (Lower-Tier Plans or Feature Removal): - You may request a downgrade to a lower-tier plan at any time - Downgrades take effect at your next renewal date (not mid-cycle) - No refunds for the current Subscription Term - Data Preservation: If downgrading results in loss of features or storage limits: * We will notify you of affected features at least 30 days before the downgrade takes effect * You have 90 days from downgrade date to export data that exceeds your new plan limits * After 90 days, data exceeding limits may be archived or deleted per Section 7.7 - If your current usage exceeds the lower plan's limits (e.g., you have 500 members but downgrade to a 200-member plan), you must reduce usage before the downgrade takes effect, or we may deny the downgrade request

(iii) Adding Users or Storage Mid-Cycle: - If you exceed your plan's member capacity or storage limits: * We will notify you via email and in-app notification within 5 business days * You have 15 days to either: a) Upgrade to a plan that accommodates your usage, OR b) Reduce usage to within your current plan limits (delete inactive members, remove files) * If you take no action within 15 days, we may: - Automatically upgrade you to the next appropriate plan tier and charge prorated fees, OR - Suspend features that exceed limits (e.g., disable new member registrations, restrict file uploads) until you upgrade or reduce usage - Prorated Add-On Pricing: Additional users or storage purchased mid-cycle are charged on a prorated basis for the remainder of your Subscription Term, then billed at full price upon renewal

(iv) Overage Charges (if applicable to your plan): - Some plan features have soft limits with overage billing (e.g., API calls, SMS messages sent) - Overage charges are billed monthly in arrears at the rates specified in your Order Form or at orgo.space/pricing - We will notify you when you reach 80% of your plan limit to help you avoid unexpected charges

(v) Scale and Custom Plans: - Customers on the Scale plan, or on any plan with custom pricing, may have different mid-cycle change terms as specified in their Order Form or written agreement - Contact sales@orgo.space for changes to a Scale or custom plan

4.2 Free Trial / Free Plan

(a) We may offer a free trial or free plan with limited features.

(b) Free plans carry the usage limits agreed when the plan was granted (e.g., members, storage, emails). Exceeding them may require moving to a paid plan. See Section 6.5.

(c) We may discontinue free plans with 60 days' notice.

4.3 Billing & Payments

(a) Billing Cycle: You will be billed:

  • Monthly (on the same day each month), or
  • Annually (in advance, with optional discounts).

(b) Payment Methods: Credit card, debit card, or bank transfer (as available in your region).

(c) Currency: Fees are charged in EUR (€) or your local currency. Exchange rates (if applicable) are determined at the time of billing.

(d) Automatic Renewal: Your subscription renews automatically at the end of each billing cycle unless you cancel per Section 4.5.

(e) Taxes: Fees are exclusive of taxes. You are responsible for all applicable taxes (VAT, sales tax, etc.), which will be added to your invoice.

4.4 Fee Changes

(a) We may increase Fees upon 90 days' advance notice via email or in-app notification.

(b) Fee increases apply at your next renewal date (not mid-cycle).

(c) If you object to a fee increase, you may cancel per Section 4.5 before the increase takes effect.

4.5 Cancellation & Refunds

4.5.1 By You

(a) You may cancel your subscription at any time via your account settings or by emailing support@orgo.space.

(b) Cancellation takes effect at the end of your current billing cycle. You retain access until then.

(c) No refunds for partial months/years. If you cancel mid-cycle, you will not be billed for the next cycle, but prepaid fees are non-refundable.

(d) Downgrading: If you downgrade to a lower-tier plan, the change takes effect at the next billing cycle. No refunds for the current cycle.

4.5.2 By Orgo

We may terminate your subscription with 30 days' notice if:

(a) We discontinue the Service (unlikely, but we'll refund unused prepaid fees on a pro-rata basis).

(b) You materially breach these Terms and fail to cure within 15 days of notice.

(c) We terminate per Section 4.6 (late payment) or due to violations of Section 5 (Your Responsibilities).

4.6 Late Payment & Suspension

(a) If your payment fails or is overdue by more than 15 days, we may suspend your Account after 5 business days' email notice.

(b) During suspension, you and your End Users cannot access the Service, but your data is preserved for 30 days.

(c) Reactivation: Pay all overdue amounts via your account dashboard. Service resumes within 24 hours of payment.

(d) Termination for Non-Payment: If payment is overdue for 45 days, we may terminate your Account and delete your data per Section 9.3.

(e) Late Payment Interest: Overdue amounts (unpaid for more than 15 days past the due date) accrue interest at the rate of 1.5% per month (18% per annum), or the maximum rate permitted by applicable law, whichever is lower, calculated from the original due date until the date payment is received in full.

(i) Interest is compounded monthly on unpaid principal and accrued interest.

(ii) Late payment interest applies to all overdue amounts, including: - Subscription Fees - Overage charges - Professional services fees - Any other fees owed under this Agreement

(iii) Payment of late fees does not waive our right to suspend or terminate your Account per Section 4.6(a)-(d).

(iv) Collection Costs: If we engage a collection agency or attorney to collect overdue amounts, you agree to reimburse us for all reasonable collection costs, including: - Collection agency fees (typically 25-35% of amount owed) - Attorney fees and legal costs - Court costs and filing fees

(v) Romanian Law Compliance: Under Romanian law (Law 72/2013 on measures to combat late payment), we are entitled to: - Interest at the reference rate of the European Central Bank plus 8 percentage points (currently ~12-13% per annum) - Fixed compensation of €40 for recovery costs - Additional reasonable recovery costs exceeding €40

  We may elect to apply Romanian statutory late payment terms in lieu of the 1.5% monthly rate above if more favorable to us.

5. YOUR RESPONSIBILITIES

5.1 Account Security

You are responsible for:

(a) Keeping your Admin login credentials confidential.

(b) All activities that occur under your Account, whether authorized or not.

(c) Notifying us immediately at security@orgo.space if you suspect unauthorized access.

5.2 Customer Data

You represent and warrant that:

(a) You own or have the necessary rights to all Customer Data you upload to the Service.

(b) Customer Data does not violate any third-party rights (intellectual property, privacy, publicity, etc.) or applicable laws.

(c) You have obtained all necessary consents from End Users for processing their personal data, including:

  • GDPR consent (EU users)
  • Parental consent for minors under 16 (GDPR Article 8) or under 13 (COPPA in the US)
  • Any other consents required by local privacy laws

(d) You will not upload content that violates our User Terms of Service (Acceptable Use Policy).

5.3 Compliance with Laws

You agree to use the Service in compliance with:

(a) All applicable local, national, and international laws and regulations.

(b) GDPR (if you process EU personal data), CCPA (if you process California residents' data), and other privacy laws.

(c) Anti-spam laws (CAN-SPAM, GDPR, CASL, etc.) when sending emails or SMS via the Service.

5.4 Backup Responsibility

While we maintain regular backups for disaster recovery, you are responsible for maintaining your own backups of critical Customer Data. Use our data export feature (Section 10.4) to download your data regularly.

5.5 Rights and Obligations of Organizations (Admins)

5.5.1 Access to Member Data

When End Users (members, volunteers, beneficiaries, etc.) join your organization's Orgo space, you (as Organization Admin) receive access to their name, email, phone number, and other contact information ("Member Contact List") to facilitate community management and organizational operations.

5.5.2 Permitted Uses of Member Contact List

You may use the Member Contact List solely to:

(a) Communicate with Members about activities, events, volunteer opportunities, and purposes directly related to your organization's mission and operations.

(b) Manage membership, volunteers, beneficiaries, fundraising campaigns, and organizational administration.

(c) Comply with legal obligations applicable to your organization (tax reporting, safeguarding requirements, etc.).

(d) Provide services and benefits that Members reasonably expect when joining your organization.

5.5.3 Prohibited Uses of Member Contact List

You agree NOT to:

(a) Sell, rent, lease, or otherwise provide the Member Contact List to third parties for monetary or other consideration.

(b) Use Member Contact List for commercial purposes unrelated to your organization's stated mission and activities.

(c) Share Member Contact List with third parties without Member consent, except:

  • Service providers who assist your organization (accountants, event platforms, email marketing tools) under confidentiality obligations
  • As required by law or court order
  • Parent organizations or chapters within your organizational structure (if using Multi-Chapter features)

(d) Use Member Contact List for political campaigning, unless your organization is explicitly a political organization and Members joined with that understanding.

(e) Combine Member Contact List with purchased, scraped, or third-party email lists for bulk email campaigns.

5.5.4 Data Export and External Use

(a) You may export Member Contact Lists using our data export features (Section 7.8).

(b) Upon export, you assume full responsibility for:

  • Compliance with data protection laws (GDPR, CCPA, etc.) for any use outside the Service
  • Security of exported data (encryption, access controls, secure storage)
  • Honoring Member deletion, access, and portability requests
  • Maintaining accuracy and updating exported data

(c) If you import Member Contact Lists into external systems (email marketing platforms, CRM tools, accounting software):

  • You represent that you have obtained necessary consents from Members
  • You remain the Data Controller for such data
  • Orgo has no liability for your use of exported data outside the Service

5.5.5 Email Marketing Compliance

If you send emails to Members (via the Orgo platform or using exported lists):

(a) You must comply with all applicable anti-spam laws, including CAN-SPAM (US), GDPR (EU), CASL (Canada), and local regulations.

(b) For Members in the European Union or UK: You represent and warrant that you have obtained explicit opt-in consent before sending marketing emails. EU and UK law requires affirmative consent; pre-checked boxes or implied consent are insufficient.

(c) You must provide a clear and functional unsubscribe mechanism in all emails.

(d) You must honor unsubscribe requests within 10 business days.

(e) You must include your organization's physical postal address in all marketing emails (required by CAN-SPAM and other regulations).

5.5.6 Multi-Chapter and Affiliated Organizations

(a) If you use our Multi-Chapter feature to manage branches, chapters, or regional divisions:

  • Each chapter may have its own Admin with access to that chapter's Member data
  • You represent that all chapters are part of your organization or affiliated entities with legitimate data-sharing relationships
  • You remain responsible for ensuring chapter Admins comply with these Terms

(b) Separate Legal Entities: If your chapters or affiliates are separate legal entities (e.g., regional branches with independent legal status):

  • Each entity should have its own Orgo Account, OR
  • You must have a written data-sharing agreement between entities that complies with GDPR Article 26 (joint controllers) or equivalent local law
  • Contact sales@orgo.space for guidance on Scale configurations for federated organizations

5.5.7 Payment Processing and Member Financial Data

(a) When you collect donations, membership fees, or event ticket payments via Orgo (powered by Stripe):

  • Member payment information (credit card numbers, bank details) is processed and stored by Stripe, not by Orgo or you
  • You have access to transaction records (amounts, dates, payer names) but not full payment credentials
  • Stripe's terms and privacy policy govern payment processing

(b) You agree to use transaction data solely for:

  • Financial reporting and accounting
  • Issuing receipts and tax documents
  • Fraud prevention and dispute resolution
  • Purposes directly related to the transaction

(c) Refund Responsibility: You are solely responsible for:

  • Determining refund eligibility and amounts
  • Processing refunds via the Service or Stripe dashboard
  • Communicating refund policies to Members
  • Orgo is not a party to transactions between you and your Members

5.5.8 Advertising and Sponsorships

(a) You may display sponsorship acknowledgments, partner logos, or non-intrusive advertising within your Orgo space, provided such content:

  • Complies with all applicable laws and regulations
  • Follows FTC guidelines on native advertising and disclosures (if applicable)
  • Does not mislead Members or misrepresent relationships
  • Does not promote illegal, harmful, or prohibited content (per User Terms, Acceptable Use Policy)

(b) Revenue Sharing Not Required: You may retain sponsorship revenue collected from third parties without sharing revenue with Orgo, provided:

  • Sponsorships are incidental to your organizational mission (not your primary business model)
  • You do not resell or sublicense the Service itself (see Section 2.3(c))

5.5.9 Representation and Warranty of Organization Admins

By accepting these Terms as an Organization Admin, you represent and warrant that:

(a) You are authorized to bind your organization to this Agreement.

(b) You will comply with all applicable data protection laws (GDPR, CCPA, UK DPA, etc.) in your processing of Member data.

(c) You will honor the trust of Members who share their personal data with your organization.

(d) You have obtained, or will obtain, all necessary consents from Members for processing their personal data, including:

  • GDPR-compliant consent (EU users)
  • Parental consent for minors under 16 (GDPR Article 8) or under 13 (COPPA in the US)
  • Opt-in consent for email marketing (where required by law)

(e) All advertising, sponsorships, and promotions you introduce to your Orgo space comply with applicable laws, regulations, and industry guidelines.

5.5.10 Breach of Member Trust

We may suspend or terminate your Account if:

(a) You violate this Section 5.5 (including failure to ensure administrator confidentiality per Section 5.5.11).

(b) We receive credible complaints from multiple Members about misuse of their data, spam, or unauthorized communications.

(c) You engage in systematic violations of anti-spam laws or data protection regulations.

(d) You sell or lease Member Contact Lists to third parties.

(e) You fail to implement appropriate safeguards for administrators with access to sensitive data, including:

  • Lack of confidentiality agreements for administrators with access to member data
  • Missing background checks for administrators with access to children's data
  • Failure to revoke access for terminated administrators
  • Allowing unauthorized individuals to access Member data

(f) An administrator under your control misuses Member data and you fail to:

  • Notify affected Members as required by law (typically within 72 hours under GDPR)
  • Take corrective action (revoke access, investigate, report to authorities if required)
  • Cooperate with our investigation or provide requested documentation

In the event of suspension or termination for violations of this Section, you are not entitled to any refund of prepaid fees (per Section 4.5.1(c)).

5.5.11 Administrator Access Controls and Confidentiality

As the Data Controller for Member data within your organization, you are responsible for ensuring that administrators and staff members with access to Member personal data handle such data securely and lawfully.

5.5.11.1 Need-to-Know Principle

You must grant administrator access to Member data only to individuals who require such access to perform legitimate organizational functions. Access should be:

(a) Role-based: Administrators should have access only to the data and features necessary for their role (e.g., event coordinators access event data, finance staff access payment records).

(b) Documented: You should maintain internal records of which administrators have access, the scope of access granted, and the business justification.

(c) Reviewed periodically: Access rights should be reviewed at least annually to ensure they remain appropriate.

5.5.11.2 Confidentiality Obligations

You represent and warrant that all administrators with access to Member personal data:

(a) Have signed confidentiality agreements, non-disclosure agreements (NDAs), or are bound by professional secrecy obligations (e.g., lawyers, doctors, clergy) that prohibit unauthorized use or disclosure of Member data.

(b) Have received training on:

  • Your organization's data protection policies
  • Applicable data protection laws (GDPR, CCPA, COPPA, etc.)
  • The importance of protecting Member privacy and handling data securely
  • Procedures for reporting suspected data breaches or misuse

(c) Understand and agree not to:

  • Use Member data for personal purposes unrelated to organizational functions
  • Disclose Member data to unauthorized third parties
  • Access Member data out of curiosity or for reasons unrelated to their role
  • Export or copy Member data to personal devices or unsecured systems without authorization

5.5.11.3 Background Checks for Administrators with Access to Children's Data

If your organization serves individuals under 18 years of age (or under 16 in the EU/EEA, or under 13 in the US), you must ensure that administrators with access to children's personal data:

(a) Undergo appropriate background checks as required by applicable law, which may include:

  • Criminal record checks (e.g., DBS checks in the UK, FBI background checks in the US, criminal record certificate in Romania)
  • Child safeguarding clearances (e.g., Working with Children Checks in Australia)
  • References from previous employers or organizations
  • Verification of identity and employment history

(b) Complete safeguarding training appropriate to your jurisdiction and organizational context, including:

  • Recognizing signs of abuse, neglect, or exploitation
  • Mandatory reporting obligations
  • Safe communication practices with minors
  • Data protection specific to children (COPPA, GDPR Article 8)

(c) Maintain records of background checks and safeguarding training, updated periodically (typically every 3-5 years or as required by local law).

(d) Immediately revoke access for any administrator who:

  • Fails a background check or safeguarding screening
  • Is subject to safeguarding concerns, allegations, or investigations
  • Poses a risk to children based on credible information

5.5.11.4 Access Control Documentation

You should maintain internal documentation (not required to be shared with Orgo unless requested per Section 5.5.11.7) that includes:

(a) Administrator Access Log:

  • List of administrators with access to the Orgo platform
  • Scope of access granted (e.g., full access, chapter-specific, read-only, financial data access)
  • Date access was granted
  • Business justification for access (role, responsibilities)
  • Date of last access review

(b) Confidentiality Agreement Records:

  • Confirmation that administrators have signed confidentiality agreements or NDAs
  • Date agreements were signed
  • Storage location of signed agreements

(c) Background Check Records (for organizations serving children):

  • Type of background check conducted (criminal record, DBS, etc.)
  • Date of background check
  • Result (cleared/not cleared)
  • Date of next scheduled renewal

(d) Training Records:

  • Data protection training completion dates
  • Safeguarding training completion dates (if applicable)
  • Training provider or method (in-person, online course, etc.)

5.5.11.5 Revocation of Access Upon Termination or Role Change

When an administrator's role ends (due to resignation, termination, retirement, or role change that no longer requires access to Member data):

(a) Immediate Access Revocation: You must immediately revoke their access to the Orgo platform by:

  • Disabling their user account or removing administrator permissions
  • Revoking API keys or integrations they controlled
  • Changing shared passwords or access credentials they may have known

(b) Data Return or Deletion: You must ensure the departing administrator:

  • Returns any exported Member data (CSV files, backups, printed reports)
  • Deletes Member data from personal devices, email accounts, cloud storage, or other systems
  • Confirms in writing that they have returned or deleted all Member data

(c) Reminder of Ongoing Confidentiality: You must remind the departing administrator that:

  • Confidentiality obligations continue after their role ends (typically indefinitely or as specified in their NDA)
  • They must not use or disclose Member data for any purpose after departure
  • Violations of confidentiality may result in legal action

(d) Timely Action: Access revocation should occur:

  • Immediately upon termination for cause or security concerns
  • Within 24 hours for voluntary resignations or retirements
  • On the effective date for planned role changes or transitions

5.5.11.6 Data Breach Notification by Organizations

If you discover or suspect that:

(a) An administrator has misused, disclosed, or accessed Member data without authorization;

(b) Member data under your control has been accessed, acquired, disclosed, or compromised by unauthorized parties;

(c) There has been a security incident affecting Member data (lost laptop, stolen files, hacked email account, etc.);

(d) Member data has been inadvertently exposed (e.g., sent to wrong recipients, posted publicly by mistake);

You must:

(i) Notify Affected Members within the timeframes required by applicable law:

  • GDPR (EU/EEA/UK): Within 72 hours of becoming aware of the breach (Article 33-34)
  • CCPA (California): "Without unreasonable delay" (typically within 72 hours)
  • COPPA (US, children's data): As soon as practicable
  • Other jurisdictions: Per local data breach notification laws

(ii) Notify Orgo at privacy@orgo.space within 24 hours if:

  • The incident may affect our systems, security, or other customers
  • The breach involves a vulnerability in the Orgo platform
  • You need our assistance to investigate or remediate the breach
  • The breach involves a large number of Members (more than 100 individuals)

(iii) Document the Incident: Maintain records of:

  • Date and time the breach was discovered
  • Nature of the breach (what data was affected, how it occurred)
  • Number of affected Members and categories of data involved
  • Actions taken to contain and remediate the breach
  • Notifications sent to Members, authorities, and Orgo

(iv) Take Corrective Action:

  • Immediately contain the breach (revoke access, secure systems, recover data)
  • Investigate the root cause
  • Implement measures to prevent recurrence
  • If an administrator caused the breach, take appropriate disciplinary action
  • Report to data protection authorities if required by law (GDPR Article 33)

(v) Cooperate with Investigations: If Orgo, data protection authorities, or law enforcement investigate the breach, you must:

  • Provide requested information and documentation
  • Preserve evidence
  • Implement recommended remedial measures

5.5.11.7 Orgo's Right to Audit and Request Documentation

Upon reasonable notice (typically 15 days), we may request that you provide evidence of compliance with this Section 5.5.11, including:

(a) Confidentiality Agreements: Confirmation (not necessarily copies) that administrators have signed confidentiality agreements or NDAs.

(b) Background Check Compliance (for organizations serving children):

  • Attestation that administrators with access to children's data have undergone appropriate background checks
  • Dates of background checks and renewal schedules
  • (We do not require copies of background check results, which may contain sensitive personal data)

(c) Access Control Documentation: Summary of access controls, administrator roles, and periodic access reviews.

(d) Training Records: Confirmation that administrators have received data protection and safeguarding training (if applicable).

(e) Breach Incident Reports: Documentation of any data breaches or security incidents affecting Member data.

When We May Request Audits:

We may request such documentation if:

(i) Your organization serves vulnerable populations (children, disabled individuals, elderly, healthcare recipients).

(ii) We receive complaints or reports suggesting inadequate data protection practices.

(iii) You experience a data breach or security incident.

(iv) You handle Special Categories of Personal Data (GDPR Article 9: health data, biometric data, etc.).

(v) We are required to demonstrate compliance to regulators or as part of our own compliance audits.

(vi) You are a large organization (more than 1,000 Members or annual revenue exceeding €100,000 via the platform).

Failure to Provide Documentation:

If you fail to provide requested documentation within a reasonable timeframe (typically 30 days):

  • We may suspend your Account until documentation is provided (particularly for organizations serving children or vulnerable populations).
  • We may terminate your Account if you repeatedly fail to demonstrate compliance.
  • We may report concerns to relevant data protection authorities if required by law.

5.5.11.8 High-Risk Organizations and Special Categories of Personal Data

If your organization processes Special Categories of Personal Data as defined by GDPR Article 9, including:

(a) Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership;

(b) Genetic data or biometric data for the purpose of uniquely identifying a person;

(c) Data concerning health, sex life, or sexual orientation;

(d) Data concerning criminal convictions and offenses;

You must implement enhanced safeguards, including:

(i) Multi-Factor Authentication (MFA): Mandatory MFA for all administrators with access to Special Categories of data.

(ii) Encryption of Exported Data: Any export of Special Categories data must be encrypted (AES-256 or equivalent) when stored outside the Orgo platform.

(iii) Data Protection Impact Assessments (DPIAs): Conduct DPIAs as required by GDPR Article 35 before processing Special Categories of data.

(iv) Regular Access Audits: Review administrator access at least quarterly (vs. annually for standard data).

(v) Enhanced Training: Administrators must receive specialized training on handling sensitive personal data.

(vi) Legal Basis Documentation: Maintain clear documentation of the legal basis for processing Special Categories of data (explicit consent, legal claims, medical treatment, etc.).

The Scale Plan for High-Risk Use Cases:

If your organization handles high-risk data, we strongly recommend the Scale plan, which includes:

  • Dedicated support for compliance and data protection questions
  • Assistance with DPIAs and compliance documentation
  • Custom data retention and deletion policies
  • Enhanced security features (advanced access controls, audit logs, IP whitelisting)
  • Service Level Agreements (SLAs) with higher uptime guarantees

Contact sales@orgo.space to discuss a Scale plan tailored to high-risk use cases.

5.5.11.9 Acknowledgment and Agreement

By accepting these Terms as an Organization Admin, you acknowledge and agree that:

(a) You are responsible for ensuring administrators comply with confidentiality, background check, and access control requirements outlined in this Section 5.5.11.

(b) Failure to comply with these requirements may result in:

  • Suspension or termination of your Account
  • Liability for data breaches or misuse by administrators under your control
  • Regulatory enforcement actions by data protection authorities
  • Legal claims from affected Members

(c) Orgo acts as a Data Processor and is not responsible for:

  • Your administrators' conduct or compliance with confidentiality obligations
  • Background checks or safeguarding failures by your organization
  • Breaches caused by administrators' misuse of exported data or access to the platform
  • Your failure to notify Members of data breaches as required by law

(d) You will cooperate with Orgo's reasonable requests for documentation and audit information to demonstrate compliance with data protection obligations.


6. SERVICE LEVEL & SUPPORT

6.1 Availability

The Service runs on shared infrastructure. All Customers are served from the same platform and therefore experience the same availability, regardless of Subscription Plan.

Orgo's operational availability target is 99.9% monthly uptime.

A contractual uptime commitment, backed by the service credits in Section 6.3, is included in:

(a) The Scale plan; and

(b) Any plan where an Order Form expressly provides for one.

On the Grow and Impact plans, and on Free plans, the figure above is an operational objective that Orgo works to, not a contractual guarantee, and no service credits arise. This is stated plainly so that you can assess it rather than infer a commitment that is not in place. If you need a contractual uptime commitment on any plan, contact sales@orgo.space.

6.2 Exclusions

Uptime measurement excludes:

(a) Scheduled maintenance (announced at least 48 hours in advance).

(b) Emergency maintenance for security or critical fixes.

(c) Downtime caused by your internet provider, third-party services (AWS, Stripe, etc.), or DDoS attacks.

(d) Force Majeure events (see Section 14.8).

(e) Beta/Non-GA features (Section 3.4).

6.3 Service Credits

This Section applies only where a contractual uptime commitment is in place under Section 6.1.

(a) If we fail to meet the committed uptime in a given month, you may request a service credit equal to 5% of your monthly fee for each 0.5% below the commitment, up to 100% of your monthly fee.

(b) How to Claim: Email support@orgo.space within 15 days of month-end with details of the outage.

(c) Credits are applied to your next invoice (not refundable in cash).

(d) Sole and Exclusive Remedy: Service credits are your SOLE AND EXCLUSIVE REMEDY for Service availability issues, downtime, or performance problems, EXCEPT in cases of:

  • Our gross negligence or willful misconduct
  • Force Majeure events lasting more than 30 consecutive days (in which case you may terminate per Section 14.8)

By claiming service credits, you waive any right to pursue additional damages or legal claims for the same availability issue.

6.4 Support

Support channels follow your Subscription Plan, as published at orgo.space/pricing:

Plan Channels Onboarding and migration
Free Documentation and knowledge base Not included
Grow Email and chat Included
Impact Email, chat and live online support, prioritized Included, prioritized
Scale Email, chat and live online support, prioritized, plus a dedicated point of contact Included, prioritized

Business hours are Monday to Friday, 9:00–18:00 EET, excluding Romanian public holidays. Response targets below are expressed in business hours and are measured from when a request is received; a request arriving outside business hours is treated as received at the start of the next business hour.

6.4.1 AI-assisted first response

Requests submitted through in-product chat receive an automated first response from an AI assistant, drawing on Orgo's published product documentation. This layer operates continuously, including outside business hours.

(a) The AI assistant answers documented questions and performs no action on your data beyond reading your request.

(b) You may request a human at any time, and the assistant will escalate on request without requiring you to justify it. You are never obliged to interact with the AI assistant to reach support.

(c) A request is escalated to a human automatically where the assistant cannot resolve it, where you indicate the answer did not resolve your issue, or where the request concerns a security matter, a personal data request, billing, or a suspected Service outage.

(d) Escalation does not restart the response clock. The targets in Section 6.4.2 run from when the request was first received, not from the point of escalation.

6.4.2 Severity levels and response targets

Severity is assessed by Orgo on receipt, taking your description into account. If you believe a request has been assessed at too low a severity, say so and we will reassess.

Severity What it means Target first human response
Critical The Service is unavailable or unusable for your organization as a whole; suspected data loss; a suspected security or personal data breach 1 business hour
High A core function is unavailable or materially degraded with no workaround 8 business hours
Normal A function is impaired but a workaround exists, or a defect that does not block use 24 business hours
Low Questions, guidance, configuration help, feature requests, cosmetic issues 72 business hours

A response means a substantive reply from a member of the Orgo team, acknowledging the issue and stating what happens next. It is not the same as a resolution: resolution time depends on the nature of the issue and cannot be committed to in advance.

Requests raising a suspected personal data breach are handled under the incident process in the Data Processing Agreement, whose notification timelines apply in addition to, and override, the targets above.

6.4.3 Nature of these targets

The targets in Section 6.4.2 are operational objectives that Orgo works to, not contractual guarantees, except where an Order Form expressly makes them binding. Failure to meet a target does not on its own give rise to service credits or other remedies. They are published so that you know what to expect, and so that you can tell when something has gone wrong.

On Free plans no response target applies (Section 6.5).

Contact: support@orgo.space

6.5 Free Plans

Free plans are not publicly available and cannot be obtained through self-service. A Free plan exists only where Orgo has expressly granted one following a direct discussion with your organization.

Where you hold a Free plan:

(a) Support is limited to documentation and the knowledge base. Orgo undertakes no support response commitment. We may assist as capacity allows, and any such assistance is discretionary and does not create an obligation for the future.

(b) No contractual uptime commitment applies, and no service credits arise (Section 6.1).

(c) Usage limits apply as agreed when the plan was granted. Exceeding them may require moving to a paid plan.

(d) Orgo may discontinue Free plans, or withdraw an individual Free plan, on 60 days' written notice. Within that period you may export your data under Section 7.8, or move to a paid plan.

(e) Orgo's aggregate liability on a Free plan is capped as set out in Section 10.1.2.

(f) All other provisions of these Terms — including your obligations in Section 5, our data protection obligations, and the Data Processing Agreement — apply to Free plans in full and without reduction. A Free plan changes what you receive commercially; it does not change either party's obligations in respect of personal data.

7. DATA PROTECTION & PRIVACY

7.1 Data Controller and Data Processor

7.1.1 You Are the Data Controller

For Member Data processed through the Service:

  • You (the Organization) are the Data Controller under GDPR, CCPA, and other data protection laws.
  • You determine the purposes and means of processing Member Data.
  • You are responsible for complying with all data protection laws, including obtaining consents, providing privacy notices, and responding to data subject rights requests.

7.1.2 Orgo Is the Data Processor

  • Orgo acts as a Data Processor (or "Service Provider" under CCPA) on your behalf.
  • We process Member Data only according to your instructions and our Data Processing Agreement (DPA).
  • We implement appropriate security measures to protect Member Data.

7.2 Data Processing Agreement (DPA)

7.2.1 Incorporation

Our Data Processing Agreement (DPA) is incorporated into these Terms by reference and is available at orgo.space/dpa/.

7.2.2 Applicability

The DPA applies automatically wherever you process personal data subject to a data protection law — including the EEA, the United Kingdom, Switzerland, and US states with privacy legislation.

7.2.3 What the DPA Governs

The DPA and its Annexes are the complete statement of both parties' data protection obligations: Orgo's obligations as Processor, your obligations as Controller, subprocessors, international transfers, breach notification, audit rights, and deletion on termination. Where this Section 7 summarises the DPA, the DPA prevails (Section 14.1.1).

7.3 Subprocessors

Our core subprocessors are AWS Frankfurt (hosting), Stripe (payments), Cloudflare (CDN for static assets only, not Member Data) and Plausible Analytics. The complete, current list is at orgo.space/subprocessors.

We notify you at least 30 days before adding or replacing a subprocessor, and you may object on reasonable data protection grounds. See DPA Section 7 and Annex 3.

7.4 Data Security

7.4.1 Orgo's Security Measures

The measures Orgo actually operates are described, control by control, in DPA Annex 2. In summary:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Access controls and multi-factor authentication on administrative access
  • A web application firewall with rate-based rules at the API entry point
  • Management-plane audit logging (AWS CloudTrail), multi-region, with alarms routed to a notification channel
  • All Member Data hosted in AWS Frankfurt, Germany (EU)

Scope. Alarms are evaluated continuously and notifications are triaged under our incident response process. ISO/IEC 27001 preparation is underway; Orgo does not claim certification and publishes no target date.

Annex 2 states the scope of each control precisely, and Orgo does not claim a control it cannot evidence. If your procurement process needs more than the Annex covers — a completed security questionnaire, our Statement of Applicability, or control-level detail — write to security@orgo.space and we will provide it under NDA (Section 14.1.3).

7.4.2 Your Security Responsibilities

You are responsible for:

  • Securing Administrator accounts (strong passwords, enabling MFA)
  • Controlling access to Member Data within your organization
  • Educating Administrators and End Users about security
  • Reporting suspected security incidents to security@orgo.space

7.4.3 Detailed Security Measures

See DPA Annex 2 for detailed technical and organizational security measures.

7.5 Data Breaches

7.5.1 Orgo's Notification to You

If we become aware of a security breach affecting Member Data, we will notify you within 72 hours via email.

7.5.2 Your Notification Obligations

As Data Controller, you are responsible for:

  • Determining whether to notify data protection authorities and/or affected Members
  • Providing such notifications within legal timeframes (GDPR: 72 hours to authority; CCPA: without unreasonable delay)
  • We will assist you in preparing breach notifications (see DPA Section 10)

7.6 International Data Transfers

All Member Data is hosted in AWS Frankfurt, Germany (EU). Where data is transferred outside the EEA — for example to a subprocessor in the United States — Orgo relies on the European Commission's Standard Contractual Clauses together with supplementary technical measures, and carries out transfer impact assessments. See DPA Section 11 and Annex 4.

7.7 Data Retention and Deletion

We retain Member Data while your Account is active, or as you configure where your plan provides retention settings.

On termination we retain Member Data for 90 days so you can export it, then delete it, except where law requires us to keep specific records. You may request immediate deletion at privacy@orgo.space. See DPA Section 13.

7.8 Data Portability

You may export Member Data at any time — through self-service export in Account Settings, through the API, or by asking us at privacy@orgo.space. Exports are provided in CSV, JSON, Excel or SQL. See DPA Section 14 for the EU Data Act switching process.

7.9 Privacy Policy

Our Privacy Policy explains what personal data Orgo collects and how it is used.

It does not discharge your own obligation. As Controller, you must give your Members a privacy notice covering how your organization uses their data. Orgo's Privacy Policy does not replace it.

7.10 Children's Data

If your organization serves children under 13 (US - COPPA) or under 16 (EU - GDPR):

(a) You must implement verifiable parental consent mechanisms before collecting children's data.

(b) You must comply with COPPA, GDPR Article 8, and other applicable children's privacy laws.

(c) You must ensure Administrators with access to children's data have appropriate background checks and safeguarding training (Section 5.5.11.3).

(d) See DPA Annex 5 for detailed requirements for processing children's data.

7.11 Special Categories of Personal Data

If your organization processes Special Categories of Personal Data (GDPR Article 9: health data, biometric data, racial/ethnic origin, political opinions, religious beliefs, etc.):

(a) You must have a lawful basis under GDPR Article 9 (explicit consent, legal claims, medical purposes, etc.).

(b) You must implement enhanced safeguards (Section 5.5.11.8).

(c) You should conduct a Data Protection Impact Assessment (DPIA) as required by GDPR Article 35.

(d) We recommend the Scale plan for additional security and compliance support.

7.12 Your Members' Privacy Rights

Your Members (End Users) have rights under GDPR, CCPA, and other privacy laws, including:

  • Right to access their data
  • Right to correct inaccurate data
  • Right to delete their data
  • Right to data portability
  • Right to object to processing
  • Right to opt-out of marketing

As Data Controller, YOU are responsible for responding to Members' rights requests. Orgo will assist you as specified in DPA Section 8.

7.13 GDPR Representative

For EU data protection matters, our GDPR representative is:

  • Name: Vasile Varzariu-Darie
  • Email: privacy@orgo.space
  • Address: S.C. ORGO INFORMATICS SRL, Str. Gheorghe Grigore Cantacuzino nr 14, etaj PARTER, ap 1, Ploiești, județul Prahova, Romania

8. INTELLECTUAL PROPERTY

8.1 Ownership of Service

The Service, including all software, technology, content, trademarks, and intellectual property, is owned by Orgo and is protected by copyright, trademark, patent, trade secret, and other intellectual property laws.

8.2 Ownership of Customer Data

You retain all ownership rights to Customer Data and Member Data. By uploading Customer Data to the Service, you grant Orgo a limited license to:

(a) Process Customer Data solely to provide the Service to you (as specified in the DPA).

(b) Create aggregated, anonymized, and de-identified data for analytics and service improvement (Section 8.3).

(c) Display Customer Data to Administrators and Members as necessary to provide the Service.

8.3 Use of Anonymized Data

8.3.1 What Is Anonymized Data?

"Anonymized Data" means data that:

  • Cannot reasonably identify you or your organization
  • Cannot reasonably identify individual Members
  • Has been aggregated and de-identified in accordance with GDPR, CCPA, and industry standards

8.3.2 Our Rights to Anonymized Data

We may use Anonymized Data for:

  • Analytics and research
  • Improving the Service
  • Developing new features
  • Benchmarking and industry reports
  • Marketing and promotional materials

8.3.3 Examples of Anonymized Data

  • "Organizations with 100-500 members have an average event attendance rate of 35%"
  • "Email open rates for newsletters sent on Tuesdays are 5% higher than Fridays"
  • "Communities using gamification features see 20% higher engagement"

8.3.4 No Re-Identification

We will not attempt to re-identify Anonymized Data to link it back to you or your Members.

8.4 Feedback and Suggestions

If you provide us with feedback, suggestions, or ideas about the Service:

(a) You grant us a perpetual, irrevocable, royalty-free, worldwide license to use, implement, and commercialize your feedback.

(b) You waive any rights to compensation or attribution for your feedback.

(c) This helps us improve the Service for all customers.

8.5 Restrictions

You may not:

(a) Reverse engineer, decompile, or disassemble the Service.

(b) Remove or alter any copyright, trademark, or proprietary notices.

(c) Use the Service to build a competing product or service.

(d) Copy, reproduce, or distribute any part of the Service.

(e) Use the Service for any purpose other than as expressly permitted in these Terms.


9. WARRANTIES & DISCLAIMERS

9.1 Your Warranties

You represent and warrant that:

(a) You have the authority to bind your organization to these Terms.

(b) Your use of the Service complies with all applicable laws.

(c) Customer Data does not violate third-party rights or applicable laws.

(d) You have obtained all necessary consents from Members for processing their personal data.

9.2 Orgo's Limited Warranty

We warrant that the Service will perform substantially in accordance with our documentation available at orgo.space/docs during your subscription term.

9.3 DISCLAIMER OF WARRANTIES

EXCEPT AS EXPRESSLY PROVIDED IN SECTION 9.2, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTIES OF ANY KIND, EITHER EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO:

(a) Implied warranties of merchantability, fitness for a particular purpose, title, or non-infringement.

(b) No guarantee that the Service will be uninterrupted, error-free, secure, or free from viruses.

(c) No guarantee of results, outcomes, or specific performance.

(d) Non-GA Features (Section 3.4) are provided "AS IS" without any warranties.

SOME JURISDICTIONS DO NOT ALLOW THE EXCLUSION OF IMPLIED WARRANTIES, SO THE ABOVE EXCLUSIONS MAY NOT APPLY TO YOU. IN SUCH JURISDICTIONS, OUR WARRANTIES ARE LIMITED TO THE MAXIMUM EXTENT PERMITTED BY LAW.


10. LIMITATION OF LIABILITY

10.1 Cap on Liability

10.1.1 General Cap

ORGO'S TOTAL AGGREGATE LIABILITY TO YOU FOR ALL CLAIMS ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICE SHALL NOT EXCEED THE AMOUNT OF FEES YOU PAID TO ORGO DURING THE 12 MONTHS PRECEDING THE DATE THE CLAIM AROSE.

10.1.2 Free Plan

If you are on a free plan, Orgo's total aggregate liability shall not exceed €100.

10.2 Exclusion of Indirect Damages

TO THE MAXIMUM EXTENT PERMITTED BY LAW, ORGO SHALL NOT BE LIABLE FOR ANY:

  • Indirect damages
  • Incidental damages
  • Consequential damages
  • Special damages
  • Punitive damages
  • Loss of profits, revenue, data, goodwill, or business opportunities
  • Cost of substitute services
  • Business interruption

EVEN IF ORGO HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

10.3 Exceptions

The limitations in Sections 10.1 and 10.2 do not apply to:

(a) Your indemnification obligations (Section 11).

(b) Your payment obligations (Fees, late payment interest).

(c) Your violations of Section 2.3 (third-party monetization restrictions) or Section 5.5 (data protection obligations).

(d) Our gross negligence or willful misconduct.

(e) Personal injury or death caused by our negligence.

(f) Fraud or fraudulent misrepresentation.

(g) Liability that cannot be excluded or limited under applicable law (e.g., GDPR data protection violations as required by GDPR Article 82).

10.4 Essential Purpose

YOU AGREE THAT THE LIMITATIONS OF LIABILITY IN THIS SECTION 10 ARE FUNDAMENTAL ELEMENTS OF THE AGREEMENT BETWEEN YOU AND ORGO. ORGO WOULD NOT PROVIDE THE SERVICE WITHOUT THESE LIMITATIONS. IF ANY LIMITATION IS FOUND TO BE INVALID, THE REMAINDER OF THIS SECTION 10 SHALL REMAIN IN FULL FORCE AND EFFECT.

10.5 Basis of the Bargain

The Service is offered at the price specified in your Subscription Plan based on these limitations of liability. If you require higher liability limits, contact sales@orgo.space — a higher cap can be agreed in an Order Form under Section 14.1.2.


11. INDEMNIFICATION

11.1 Your Indemnification of Orgo

You agree to indemnify, defend, and hold harmless Orgo, its officers, directors, employees, agents, and subprocessors from and against any and all claims, losses, damages, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from or relating to:

(a) Your use of the Service in violation of these Terms or applicable law.

(b) Customer Data you upload, including claims that Customer Data infringes third-party intellectual property rights or violates privacy laws.

(c) Your Members' conduct, including claims arising from Member-generated content (except to the extent caused by our breach of these Terms).

(d) Your violation of data protection laws (GDPR, CCPA, COPPA, etc.) in your capacity as Data Controller.

(e) Your breach of Section 5 (Your Responsibilities), including:

  • Failure to obtain required consents from Members
  • Misuse of Member Contact Lists
  • Failure to implement administrator confidentiality or background checks
  • Data breaches caused by your administrators

(f) Your violation of Section 2.3(c) (third-party monetization restrictions), including unauthorized reselling or white-labeling of the Service.

(g) Claims by third parties (sponsors, partners, vendors) arising from your use of the Service or your relationship with them.

(h) Your Administrators' conduct, including unauthorized access, data misuse, or security breaches caused by your Administrators.

11.2 Indemnification Procedure

(a) Orgo will promptly notify you in writing of any claim subject to indemnification.

(b) You will have sole control of the defense and settlement, provided you:

  • Do not admit liability on Orgo's behalf
  • Do not agree to any settlement that imposes obligations on Orgo or requires Orgo to pay money or admit wrongdoing
  • Keep Orgo reasonably informed of the status

(c) Orgo may participate in the defense with its own counsel at its own expense.

(d) You will pay all judgments, settlements, and reasonable costs (including attorneys' fees) arising from indemnified claims.

11.3 Orgo's Indemnification of You (Limited to certain claims)

Orgo will indemnify, defend, and hold you harmless from third-party claims that:

(a) The Service infringes a third party's valid copyright, trademark, or patent (registered in the EU or US).

(b) Provided such claims are not caused by:

  • Your modification of the Service
  • Your combination of the Service with third-party products
  • Your use of the Service in violation of these Terms
  • Customer Data you uploaded

11.4 Orgo's Remedies for IP Claims

If we reasonably believe the Service infringes, or if we receive an infringement claim, we may (at our option):

(a) Obtain the right to continue providing the Service.

(b) Replace or modify the Service to make it non-infringing.

(c) Terminate the affected portion of the Service and refund prepaid Fees on a pro-rata basis.

11.5 Exclusive Remedy

This Section 11 states Orgo's sole and exclusive liability and your sole and exclusive remedy for third-party IP infringement claims related to the Service.


12. TERM & TERMINATION

12.1 Term

These Terms commence on the date you accept them (by creating an Account or clicking "I Agree") and continue until terminated in accordance with this Section 12.

12.2 Termination by You

You may terminate these Terms and your Account:

(a) At any time, in accordance with Section 4.5 (Cancellation).

(b) Termination takes effect at the end of your current billing cycle.

(c) Upon termination:

  • You lose access to the Service
  • We retain your Customer Data for 90 days (Section 7.7) for data export
  • After 90 days, we delete your Customer Data (except as required by law)

12.3 Termination by Orgo

We may terminate these Terms and your Account:

(a) For Cause (immediate or with 15 days' notice to cure):

  • You materially breach these Terms (e.g., violations of Section 2.3(c), 5.5, or non-payment per Section 4.6)
  • Your Account poses a security or legal risk
  • You engage in fraud, abuse, or illegal activity

(b) For Convenience (with 30 days' notice):

  • We discontinue the Service (unlikely, but we'll refund unused prepaid Fees on a pro-rata basis)

(c) Immediate Termination Without Notice:

  • You violate Section 2.3(c) (reselling/white-labeling)
  • You violate Section 5.5.10 (breach of Member trust, spam, data misuse)
  • Required by law or court order

12.4 Effect of Termination

Upon termination:

(a) Your Access: You and your Members immediately lose access to the Service.

(b) Data Retention: We retain Customer Data for 90 days (you may request export during this period).

(c) Data Deletion: After 90 days, we delete Customer Data in accordance with DPA Section 13.

(d) Payment Obligations: You remain responsible for all Fees incurred up to the termination date. No refunds for prepaid Fees (except as specified in Section 12.3(b) for our convenience termination).

(e) Survival: The following Sections survive termination:

  • Section 4.6 (Late Payment Interest)
  • Section 7 (Data Protection - for ongoing obligations)
  • Section 8 (Intellectual Property - ownership provisions)
  • Section 9.3 (Disclaimer)
  • Section 10 (Limitation of Liability)
  • Section 11 (Indemnification)
  • Section 12.4 (Effect of Termination)
  • Section 14 (General Provisions)

12.5 No Refunds Upon Termination for Cause

If we terminate your Account for your breach of these Terms (Section 12.3(a) or (c)), you are not entitled to any refund of prepaid Fees.


13. DISPUTE RESOLUTION & GOVERNING LAW

13.1 Governing Law

These Terms shall be governed by and construed in accordance with the laws of Romania, without regard to conflict of laws principles.

13.2 Jurisdiction

Any disputes arising out of or relating to these Terms shall be subject to the exclusive jurisdiction of the courts of Ploiești, Romania (or the courts of Bucharest, Romania, if Ploiești courts decline jurisdiction).

13.3 GDPR and Data Protection Disputes

For disputes related to data protection (GDPR, CCPA, DPA), the governing law and jurisdiction provisions in our Data Processing Agreement (DPA) shall apply, which may differ from this Section 13 to comply with GDPR requirements.

13.4 Informal Resolution

Before filing a lawsuit, you agree to first attempt to resolve the dispute informally by contacting us at legal@orgo.space. We will attempt to resolve the dispute within 30 days.

13.5 Time Limit for Claims

You must bring any claim arising out of these Terms within one (1) year after the claim arose, or the claim is permanently barred.


14. GENERAL PROVISIONS

14.1 Entire Agreement

These Terms, together with the Privacy Policy, Data Processing Agreement (including its Annexes), AI Addendum, and User Terms of Service, constitute the entire agreement between you and Orgo regarding the Service and supersede all prior agreements, representations, or understandings.

14.1.1 Order of Precedence

Where two of these documents conflict, the following order applies, from highest to lowest:

  1. A signed Order Form or written agreement between you and Orgo, but only in respect of the specific terms it expressly varies (see Section 14.1.2)
  2. The Data Processing Agreement and its Annexes, in respect of the processing of personal data
  3. The AI Addendum, in respect of the AI Features
  4. These Organization Terms of Service
  5. Any other document referenced in these Terms

14.1.2 Order Forms and Negotiated Terms

These Terms are designed to govern the relationship in full, without a separately negotiated contract, for organizations of any size. Acceptance under Section 14.7 is sufficient to form a binding agreement.

Where you and Orgo sign an Order Form, that Order Form may vary specific terms of this Agreement — including subscription scope, pricing, payment method and terms, subscription term, uptime and support commitments, the limitation of liability in Section 10, and any additional security or compliance obligations agreed between us.

The following conditions apply:

(a) An Order Form varies these Terms only in respect of the terms it expressly addresses. All other provisions of this Agreement continue to apply unchanged.

(b) An Order Form must be in writing and signed by authorized representatives of both parties. Electronic signature is sufficient.

(c) An Order Form cannot reduce either party's obligations under applicable data protection law, and cannot vary the Data Processing Agreement except by a written amendment to the DPA itself.

(d) In the absence of a signed Order Form, these Terms apply in full, as published at the time of your acceptance.

14.1.3 Additional Documentation on Request

Orgo maintains supplementary documentation describing its security and compliance posture in greater detail than the summary published in Annex 2 of the DPA. This documentation is made available to Customers and to prospective Customers conducting due diligence, on request and subject to a confidentiality agreement. Requests should be directed to security@orgo.space.

14.2 Amendments

14.2.1 Our Right to Amend

We may amend these Terms from time to time to:

  • Comply with legal or regulatory requirements
  • Reflect changes to the Service
  • Clarify ambiguous terms
  • Make other reasonable changes

14.2.2 Notice of Amendments

We will provide you with at least 30 days' advance notice of material amendments via:

  • Email to your account email address
  • In-app notification
  • Posting updated Terms at orgo.space/terms/ with the "Last Updated" date changed

14.2.3 Your Right to Object

If you object to a material amendment that adversely affects your rights:

  • Notify us in writing at legal@orgo.space within 30 days
  • If we cannot reach a mutually acceptable resolution, you may terminate your Account in accordance with Section 12.2
  • Your continued use of the Service after the effective date of an amendment constitutes acceptance

14.2.4 Immediate Amendments

Amendments required by law (e.g., new regulations, court orders) shall take effect immediately upon notice, without the 30-day notice period.

14.3 Severability

If any provision of these Terms is held to be invalid, illegal, or unenforceable:

  • The provision shall be modified to the minimum extent necessary to make it valid and enforceable
  • If modification is not possible, the provision shall be severed
  • The remaining provisions shall remain in full force and effect

14.4 Waiver

No waiver of any provision of these Terms shall be effective unless in writing. No waiver of any breach or default shall constitute a waiver of any other breach or default.

14.5 Assignment

14.5.1 Your Assignment

You may not assign or transfer these Terms or your Account without our prior written consent, except:

  • To an affiliate or successor entity in connection with a merger, acquisition, or sale of assets
  • Provided the successor entity agrees to be bound by these Terms

14.5.2 Our Assignment

We may assign or transfer these Terms or the Service:

  • To an affiliate or successor entity
  • In connection with a merger, acquisition, reorganization, or sale of our business
  • To a third party, provided we notify you and your rights under these Terms are not materially diminished

14.6 No Third-Party Beneficiaries

These Terms are solely for the benefit of you and Orgo and do not create any rights in favor of third parties, except:

  • Data Subjects (your Members) who are third-party beneficiaries of our Data Processing Agreement as required by GDPR

14.7 Independent Contractors

You and Orgo are independent contractors. These Terms do not create a partnership, joint venture, agency, employment, or fiduciary relationship.

14.8 Force Majeure

Neither party shall be liable for any failure or delay in performing its obligations (other than payment obligations) due to events beyond its reasonable control, including:

  • Acts of God (natural disasters, pandemics)
  • War, terrorism, civil unrest
  • Government actions, laws, or regulations
  • Utility failures, internet outages
  • Cyberattacks by third parties (provided we have implemented appropriate security measures)

The affected party shall:

  • Notify the other party promptly
  • Use commercially reasonable efforts to mitigate the impact
  • Resume performance as soon as reasonably practicable

If a force majeure event continues for more than 60 consecutive days, either party may terminate these Terms upon written notice.

14.9 Notices

14.9.1 How to Send Notices

All notices under these Terms must be in writing and sent to:

To Orgo:

  • Email: legal@orgo.space (for legal matters), privacy@orgo.space (for data protection), support@orgo.space (for support), security@orgo.space (for security incidents)
  • Mail: S.C. ORGO INFORMATICS SRL, Str. Gheorghe Grigore Cantacuzino nr 14, etaj PARTER, ap 1, Ploiești, județul Prahova, Romania

To You:

  • The email address associated with your Account
  • The billing address provided during registration

14.9.2 When Notices Are Deemed Given

Notices are deemed given:

  • Upon personal delivery
  • Upon email confirmation (if sent during business hours; otherwise, next business day)
  • Three (3) business days after sending by registered mail

14.9.3 Updating Contact Information

You must keep your contact information current in your account settings. We are not responsible for notices sent to outdated contact information.

14.10 Language

These Terms are executed in English. If translated into another language, the English version shall prevail in the event of any conflict.

14.11 Electronic Signatures

You agree that your electronic acceptance of these Terms (by clicking "I Agree" or creating an Account) constitutes your legally binding electronic signature.

14.12 Relationship to User Terms

Important: These Organization Terms govern the relationship between Orgo and your organization. Your Members (End Users) must separately accept our User Terms of Service, which govern their use of the Service and conduct within your Orgo space.

14.13 Headings

Section headings are for convenience only and do not affect interpretation of these Terms.


15. CONTACT INFORMATION

For general questions: Email: contact@orgo.space Website: orgo.space Documentation: orgo.space/docs

For support: Email: support@orgo.space

For data protection and privacy matters: Privacy Contact: privacy@orgo.space

For security issues: Email: security@orgo.space

For legal matters: Email: legal@orgo.space

For sales and Scale plans: Email: sales@orgo.space

Mailing address: S.C. ORGO INFORMATICS SRL Str. Gheorghe Grigore Cantacuzino nr 14, etaj PARTER, ap 1 Ploiești, județul Prahova, Romania Registration: J29/2796/2019 Fiscal Code: RO41650396


16. RELATED DOCUMENTS

Please also review these related documents:

  • User Terms of Service - Terms for individual Members using your Orgo space
  • Privacy Policy - How we collect and use personal data
  • Data Processing Agreement (DPA) - GDPR-compliant data processing terms
  • Subprocessors List - Third parties we use to provide the Service

ACCEPTANCE

By clicking "I Agree," creating an organization account, or accessing the Service, you acknowledge that you have read, understood, and agree to be bound by these Organization Terms of Service on behalf of your organization.


END OF ORGANIZATION TERMS OF SERVICE

Last Updated: August 1, 2026

Table of Contents

    orgo community
    • Platform
    • Features
    • Branded App
    • Trust & Security
    • iOS app↗
    • Android app↗
    • Company
    • About us
    • Contact
    • Get a demo
    • Resources
    • Documentation↗
    • Changelog↗
    • API reference↗
    • Blog
    • Alternatives
    • Comparisons
    • Delete your account
    • Guides
    • Sitemap
    • Use Cases
    • NGOs
    • Scouts
    • Associations
    • Federations
    • Trade Associations
    • Political Parties
    • Fundraising Campaign
    🇬🇧 English
    🇩🇪 Deutsch 🇫🇷 Français 🇮🇹 Italiano 🇪🇸 Español 🇵🇱 Polski 🇷🇴 Română 🇨🇿 Čeština 🇸🇰 Slovenčina
    © 2026 Orgo Informatics.
    Terms User Terms Privacy Cookies DPA Subprocessors AI Addendum

    Before you go — got 2 minutes?

    No newsletters. No 10 follow-up calls. We just want to see if Orgo is the right fit for you. A 20-min demo, calendar open right now.

    Please complete this required field.

    Please complete this required field.

    Please enter a valid email address.

    Please complete this required field.

    By submitting, I acknowledge I have read and understand Orgo's Privacy Notice.

    Dear ,

    Your meeting is booked! We look forward to learning about your organization and showing you how Orgo can help.