Legal

Privacy Policy

How we collect, use, share, and protect personal data across the Orcastrator marketing site and product.

Last updated: 12 July 2026

Who this policy covers

This Privacy Policy describes how Orcastrator handles personal data when you use:

It does not cover third-party sites we link to (for example documentation hosts, status pages, or Calendly) beyond describing that those services may process data under their own policies.

Controller and contact

For personal data collected through the marketing site (demo requests, support inquiries, and related emails), Orcastrator is the controller.

For customer account, workspace, and product usage data inside Orcastrator, the organisation that contracted for the service is typically the controller, and Orcastrator processes that data on their instructions. See our Data Processing Addendum for processor terms.

Privacy questions: privacy@orcastrator.qa.

Data we collect on the marketing site

When you submit a demo or contact form, we collect:

  • Name and work email
  • Company and job title
  • Phone number (optional)
  • Use case, timeline, and free-text message (optional)

We use this information to respond to your inquiry, schedule demos, and follow up about Orcastrator. Messages are sent through our email provider (Resend) from an Orcastrator address (for example info@notify.orcastrator.qa) to our sales inbox, with an acknowledgement to you.

If you book time through Calendly, Calendly processes scheduling data under its own privacy policy.

Data processed in the product

Depending on how your organisation uses Orcastrator, we may process:

  • Account and identity data — names, emails, roles, and authentication details (including Microsoft Entra ID SSO where configured, with JIT/SCIM provisioning)
  • Workspace content — projects, blueprints, specs, test cases, suites, orchestrations, run results, evidence (such as step output and screenshots), and Pulse risk metrics
  • AI authoring context — prompts and suggestions from Sonar AI grounded in your project data, subject to your organisation’s configuration and review workflows
  • Billing data — plan, invoices, and subscription status. Card payments are handled by our payment processor (Stripe); we do not store full card numbers on Orcastrator systems
  • Operational logs — security, access, and diagnostic events needed to run and secure the service

Hybrid or on-premises agents may run in your infrastructure while still reporting status and results to Orcastrator. Your organisation remains responsible for data that stays in its own environment.

How we use personal data

We use personal data to:

  • Provide, secure, and improve the website and product
  • Respond to sales, support, and security inquiries
  • Authenticate users and enforce role-based access
  • Process subscriptions, trials, and invoices
  • Send service-related notices (for example billing or incidents)
  • Comply with law and enforce our Terms

We do not sell personal data. We do not use marketing-site form submissions for unrelated advertising lists without a lawful basis and clear notice.

Processors and sharing

We share personal data with subprocessors only as needed to operate Orcastrator. On the marketing site that currently includes:

  • Resend — transactional email delivery for contact and acknowledgement messages
  • Calendly — demo scheduling when you use that flow
  • Azure — hosting for the marketing site (Azure Static Web Apps) and related API functions
  • PostHog — product and marketing analytics (page views, button clicks, and similar engagement events) for the marketing site, hosted in the EU

The product additionally relies on cloud infrastructure, identity (including Microsoft Entra ID when enabled), payment processing (Stripe), and other operational vendors. A fuller customer-facing subprocessor list is available on request for enterprise agreements.

We may also disclose data if required by law, or to protect the rights, safety, and security of Orcastrator, our customers, or the public.

Retention

Marketing inquiries are retained as long as needed to complete the sales or support conversation and for ordinary business record-keeping, unless a longer period is required by law.

Product data retention follows your organisation’s plan limits (as marketed: Hobby 14 days, Professional 30 days, Business 90 days, Enterprise 365 days for applicable product data). Administrators should confirm exact scopes in-product and in their agreement.

When an account is closed, we delete or anonymise personal data within a reasonable period, except where we must retain records for legal, security, or financial compliance.

Security

We apply administrative, technical, and organisational measures appropriate to the risk. See our Security page for practices such as encryption in transit, access control, and deployment options. No method of transmission or storage is perfectly secure; please use strong credentials and report suspected incidents promptly.

Your rights

Depending on where you live (including the UK GDPR / EU GDPR and similar laws), you may have rights to access, correct, delete, restrict, or port personal data, and to object to certain processing. You may also have the right to lodge a complaint with a supervisory authority.

To exercise rights related to marketing-site data, email privacy@orcastrator.qa. For product workspace data, contact your organisation’s Orcastrator administrator first; we will assist controllers as described in the DPA.

Cookies and similar technologies

Our sites use cookies or similar technologies that are necessary for them to function, plus analytics cookies (PostHog) by default so we can understand how they are used. This covers both the marketing site at orcastrator.qa and the product application at app.orcastrator.qa.

We use a single analytics project across both so we can understand the journey from a first visit through to creating an account — for example, how many people who read the pricing page go on to sign up. To make that possible, the analytics identifier and your cookie choice are stored on the shared orcastrator.qa domain, so one decision applies to both sites rather than each asking you separately.

You can limit this anytime with Necessary only on the cookie card (or Cookie settings in the footer); we then stop storing PostHog cookies across both sites and may still measure traffic in a cookieless way if that mode is enabled in our analytics project. Third-party embeds such as Calendly may use their own cookies when those features load. You can also control cookies in your browser.

International transfers

Orcastrator and its processors may process data in countries other than where you or your organisation are located. Where required, we use appropriate safeguards (such as standard contractual clauses) for restricted transfers. Deployment options (public cloud, private cloud, or on-premises agents) can affect where product workloads and evidence reside — discuss residency requirements with sales for enterprise needs.

Children

Orcastrator is a business service and is not directed at children. We do not knowingly collect personal data from children under 16.

Changes

We may update this policy from time to time. The “Last updated” date at the top will change when we do. Material changes will be highlighted on this page or communicated through the product or email where appropriate.

Questions about this document? Contact support (support@orcastrator.qa) or privacy (privacy@orcastrator.qa).