Legal
Privacy Policy
How we collect, use, share, and protect personal data across the Orcastrator marketing site and product.
Last updated: 12 July 2026
Who this policy covers
This Privacy Policy describes how Orcastrator handles personal data when you use:
- Our marketing website at orcastrator.qa (including demo and support forms)
- The Orcastrator product at app.orcastrator.qa
It does not cover third-party sites we link to (for example documentation hosts, status pages, or Calendly) beyond describing that those services may process data under their own policies.
Controller and contact
For personal data collected through the marketing site (demo requests, support inquiries, and related emails), Orcastrator is the controller.
For customer account, workspace, and product usage data inside Orcastrator, the organisation that contracted for the service is typically the controller, and Orcastrator processes that data on their instructions. See our Data Processing Addendum for processor terms.
Privacy questions: privacy@orcastrator.qa.
Data we collect on the marketing site
When you submit a demo or contact form, we collect:
- Name and work email
- Company and job title
- Phone number (optional)
- Use case, timeline, and free-text message (optional)
We use this information to respond to your inquiry, schedule demos, and follow up about Orcastrator. Messages are sent through our email provider (Resend) from an Orcastrator address (for example info@notify.orcastrator.qa) to our sales inbox, with an acknowledgement to you.
If you book time through Calendly, Calendly processes scheduling data under its own privacy policy.
Data processed in the product
Depending on how your organisation uses Orcastrator, we may process:
- Account and identity data — names, emails, roles, and authentication details (including Microsoft Entra ID SSO where configured, with JIT/SCIM provisioning)
- Workspace content — projects, blueprints, specs, test cases, suites, orchestrations, run results, evidence (such as step output and screenshots), and Pulse risk metrics
- AI authoring context — prompts and suggestions from Sonar AI grounded in your project data, subject to your organisation’s configuration and review workflows
- Billing data — plan, invoices, and subscription status. Card payments are handled by our payment processor (Stripe); we do not store full card numbers on Orcastrator systems
- Operational logs — security, access, and diagnostic events needed to run and secure the service
Hybrid or on-premises agents may run in your infrastructure while still reporting status and results to Orcastrator. Your organisation remains responsible for data that stays in its own environment.
How we use personal data
We use personal data to:
- Provide, secure, and improve the website and product
- Respond to sales, support, and security inquiries
- Authenticate users and enforce role-based access
- Process subscriptions, trials, and invoices
- Send service-related notices (for example billing or incidents)
- Comply with law and enforce our Terms
We do not sell personal data. We do not use marketing-site form submissions for unrelated advertising lists without a lawful basis and clear notice.
Retention
Marketing inquiries are retained as long as needed to complete the sales or support conversation and for ordinary business record-keeping, unless a longer period is required by law.
Product data retention follows your organisation’s plan limits (as marketed: Hobby 14 days, Professional 30 days, Business 90 days, Enterprise 365 days for applicable product data). Administrators should confirm exact scopes in-product and in their agreement.
When an account is closed, we delete or anonymise personal data within a reasonable period, except where we must retain records for legal, security, or financial compliance.
Security
We apply administrative, technical, and organisational measures appropriate to the risk. See our Security page for practices such as encryption in transit, access control, and deployment options. No method of transmission or storage is perfectly secure; please use strong credentials and report suspected incidents promptly.
Your rights
Depending on where you live (including the UK GDPR / EU GDPR and similar laws), you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing. You may also have the right to lodge a complaint with a supervisory authority.
To exercise rights related to marketing-site data, email privacy@orcastrator.qa. For product workspace data, contact your organisation’s Orcastrator administrator first; we will assist controllers as described in the DPA.
International transfers
Orcastrator and its processors may process data in countries other than where you or your organisation are located. Where required, we use appropriate safeguards (such as standard contractual clauses) for restricted transfers. Deployment options (public cloud, private cloud, or on-premises agents) can affect where product workloads and evidence reside — discuss residency requirements with sales for enterprise needs.
Children
Orcastrator is a business service and is not directed at children. We do not knowingly collect personal data from children under 16.
Changes
We may update this policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be highlighted on this page or communicated through the product or email where appropriate.
Questions about this document? Contact support (support@orcastrator.qa) or privacy (privacy@orcastrator.qa).