Back
Open Org Workspace
Updated June 11, 2026Legal

Privacy Policy

See also:Terms of ServiceData Processing Agreement

Open Org Group Ltd

This Privacy Policy explains how Open Org Group Ltd ("Open Org", "we", "us", or "our"), a company incorporated in England and Wales, collects, uses, stores, shares, and protects your personal data when you use the Open Org Workspace platform at workspace.openorg.fyi and openorg.fyi (the "Platform").

The Platform is intended for business use only. It is provided to organisations (each a "Customer") and the individual users a Customer authorises to use it ("Authorised Users"). This Privacy Policy applies to personal data we process as an independent data controller - that is, data about you as an Authorised User of the Platform, such as your account, profile, and usage data. Where personal data about third parties (such as employees or candidates) is uploaded or input through the Platform, the Customer is the controller of that data and Open Org acts as a data processor on the Customer's behalf; that processing is governed by our Data Processing Agreement.

This Privacy Policy should be read alongside our Terms of Service and Data Processing Agreement. Capitalised terms not defined here have the meaning given to them in the Terms of Service.

1. Who We Are

Open Org Group Ltd is the data controller for the personal data described in this Privacy Policy.

CompanyOpen Org Group Ltd
RegisteredEngland and Wales
Websiteopenorg.fyi
Contacthello@openorg.fyi

We do not currently have a statutory obligation to appoint a Data Protection Officer. For any data protection queries, please contact us at hello@openorg.fyi.

2. What Personal Data We Collect

2.1 Data You Provide Directly

CategoryExamples
Account dataName, email address, password (hashed - we never store plaintext passwords)
Profile dataFirst name, last name, motivations, work context (company, tools, challenges, team structure), attribution (how you found us)
Onboarding dataLocation (country), company size, professional goals
PreferencesText size, theme, notification preferences
Chat and AI interactionsMessages you send to Open Org AI, files you upload, URLs you reference, feedback you provide on AI responses
Documents and ArtifactsFiles you upload, documents generated by the AI, code outputs, and their version history
Team and organisation dataTeam name, role within a team (owner, member)
Marketing preferencesWhether you have opted in to receive marketing emails

2.2 Data We Collect Automatically

CategoryExamples
Usage and analytics dataPages visited, features used, interaction events, timestamps, session duration
Device and technical dataBrowser type, operating system, screen resolution, IP address (collected by analytics and error monitoring services)
Error and performance dataError messages, stack traces, request metadata, performance metrics, session replays (on error)

2.3 Data We Receive from Third Parties

SourceData
Google (OAuth sign-in)Name, email address, profile picture URL (from your Google account)
StripePayment confirmation status, subscription status (we do not receive or store your payment card details)
Referral or invitation linksReferral code, inviter identity, team invitation details

3. How We Use Your Personal Data

PurposeLawful basis (UK GDPR)
Creating and managing your accountPerformance of contract (Article 6(1)(b))
Providing the Platform, including AI chat, Open Org Playbooks, and ArtifactsPerformance of contract
Processing payments and managing subscriptions via StripePerformance of contract
Sending transactional emails (account confirmations, team invitations, gift notifications, referral communications)Performance of contract
Providing customer supportPerformance of contract
Processing team invitations and managing team membershipPerformance of contract
Processing gift passes and referral rewardsPerformance of contract
Maintaining and improving the Platform - product analytics, feature usage tracking, performance monitoringLegitimate interests (improving the product and user experience)
Detecting and preventing errors, bugs, and security incidentsLegitimate interests (maintaining service reliability and security)
Sending marketing emails about product updates, tips, and Open Org newsConsent (you opt in during signup; you can withdraw at any time)
Recording and maintaining consent records (terms acceptance, marketing opt-in)Legal obligation (UK GDPR accountability requirements)
Complying with legal obligations, including tax and financial record-keepingLegal obligation

3.1 Legitimate Interests

Where we rely on legitimate interests, we have considered the balance between our interests and your rights. Our legitimate interests include:

  • Product improvement: Understanding how features are used so we can improve the Platform. We use PostHog (EU-hosted) for analytics, which collects pseudonymised usage events.
  • Error monitoring: Detecting and resolving bugs and performance issues promptly. We use Sentry (EU ingest) which may capture limited personal data in error context.
  • Security: Preventing misuse, fraud, and unauthorised access to the Platform.

You have the right to object to processing based on legitimate interests (see Section 8).

4. AI Functionality and Your Data

The Platform includes AI Functionality (Open Org AI, Playbooks, Artifacts, and Code Interpreter). When you use these features:

(a) Your messages, uploaded files, referenced URLs, conversation history, and work context are sent to our AI sub-processors (Anthropic and OpenAI) to generate responses.

(b) Your data is not used to train AI models. Anthropic's Commercial Terms (Section B) and Data Processing Addendum contractually prohibit Anthropic from training models on commercial API customer content. OpenAI's Enterprise Privacy Policy and Data Processing Addendum confirm that API data is not used for model training by default, and Open Org has not opted in to any data sharing programme. Open Org does not use your data to train AI models. Open Org may use your data to maintain and improve the Platform (including the AI Functionality) only as permitted by our Terms of Service, which govern this use, but not to train AI models.

(c) AI inputs and outputs are retained by Anthropic and OpenAI for up to 30 days for abuse and safety monitoring, after which they are deleted.

(d) Text content you index in the Platform is converted into vector embeddings using OpenAI's embedding model. Embeddings are stored in our Supabase database (UK) for semantic search functionality.

(e) When you reference external URLs in chat, the content at those URLs may be fetched via Jina AI (Germany/Global) to provide context to the AI.

(f) AI-generated outputs (Artifacts) and their version history are stored in our database.

For full details of how AI sub-processors handle your data, see the Data Processing Agreement.

5. Who We Share Your Data With

We share your personal data only with the third-party service providers ("sub-processors") necessary to operate the Platform. We do not sell your personal data to anyone.

Service providerPurposeData sharedLocationTerms
Supabase (Supabase Inc.)Database, authentication, and file storageAll account and service dataUnited Kingdom (London)DPA
Anthropic (Anthropic PBC)AI chat responses, document generation, and document processing (primary AI provider)Messages, files (including PDFs), contextUnited StatesDPA · Terms
OpenAI (OpenAI LLC)AI chat responses, text embeddings, Code Interpreter (secondary AI provider)Messages, files, contextUnited StatesDPA · Privacy
Stripe (Stripe Inc.)Payment processing and subscription billingUser ID, email, subscription metadataUnited StatesDPA
Vercel (Vercel Inc.)Application hosting and serverless APIData in transit via HTTP requestsUnited States / GlobalDPA
Mailchimp (Rocket Science Group LLC)Marketing emails (only if you opt in)Email, name, subscription status, tagsUnited StatesDPA
Loops (Loops Inc.)Transactional emailsEmail, gift/referral/invitation metadataUnited StatesDPA
PostHog (PostHog Inc.)Product analyticsPseudonymised user ID, usage events, page viewsEuropean Union (Frankfurt)DPA · Privacy
Sentry (Functional Software Inc.)Error monitoring and performance trackingError data, stack traces, request metadataEuropean Union (ingest)DPA
Jina AI (Jina AI GmbH)URL content extractionURL content fetched at your requestGermany / GlobalTerms · Privacy

We may also disclose your personal data if required to do so by law, regulation, or court order.

6. International Data Transfers

Your primary data is stored in the United Kingdom (Supabase, London region).

Where we transfer personal data outside the UK to sub-processors in the United States and other countries, we ensure appropriate safeguards are in place:

(a) UK transfers: We rely on the transfer mechanisms included in our sub-processors' standard data processing terms, which typically incorporate the UK Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement (IDTA).

(b) EEA transfers: Where applicable, our sub-processors' terms incorporate the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor).

(c) We review the data processing terms of each sub-processor to confirm that appropriate transfer safeguards are in place.

If you would like further information about the safeguards in place, please contact us at hello@openorg.fyi.

7. How Long We Keep Your Data

Data categoryRetention period
Account and profile dataWhile your account exists
Chat history, Artifacts, and uploaded filesWhile your account exists (including any free Subscription), then deleted or returned within 30 days of the end of your Subscription Term
Usage analytics (PostHog)Per our configured retention period (currently 12 months of event data)
Error monitoring data (Sentry)90 days
Marketing data (Mailchimp)Until you unsubscribe or request deletion
Payment records (Stripe)As required by Stripe's policies and applicable tax/financial regulations
AI provider logs (Anthropic, OpenAI)Up to 30 days for abuse monitoring, then deleted
Transactional email logs (Loops)Per Loops' standard retention policies

After your account is deleted:

  • We provide a 30-day window to export your data before permanent deletion.
  • Data is removed from primary systems after the export window.
  • Backup copies are purged in accordance with our hosting provider's backup rotation schedule (currently 7-day daily backup retention on Supabase).

We may retain certain data for longer where required by law (for example, financial records for tax purposes).

8. Your Rights

Under the UK GDPR, you have the following rights in relation to your personal data:

RightDescription
AccessRequest a copy of the personal data we hold about you
RectificationRequest correction of inaccurate or incomplete data
ErasureRequest deletion of your personal data (subject to legal retention requirements)
RestrictionRequest that we restrict processing of your data in certain circumstances
PortabilityReceive your data in a structured, commonly used, machine-readable format
ObjectionObject to processing based on legitimate interests or for direct marketing
Withdraw consentWhere processing is based on consent (e.g., marketing emails), you can withdraw at any time without affecting the lawfulness of processing before withdrawal

How to Exercise Your Rights

  • Email: hello@openorg.fyi
  • Account settings: You can update your profile, manage preferences, and request data export through the Platform
  • Marketing opt-out: Use the unsubscribe link in any marketing email, or update your preferences in your account

We will respond to your request within one month. If your request is complex, we may extend this by a further two months, and we will inform you if this is the case.

We will not charge a fee for handling your request unless it is manifestly unfounded or excessive.

9. Right to Complain

If you are not satisfied with how we handle your personal data or your rights request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):

Websiteico.org.uk
Phone0303 123 1113
PostInformation Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF

We would appreciate the opportunity to address your concerns before you approach the ICO. Please contact us at hello@openorg.fyi in the first instance.

10. Cookies and Tracking Technologies

10.1 What We Use

We do not use traditional advertising or third-party tracking cookies. The Platform uses the following technologies:

TechnologyTypePurposeDuration
Supabase auth tokenlocalStorageKeeps you signed in between sessionsUntil you sign out or the session expires
PostHog analyticsFirst-party cookies / localStoragePseudonymised product analytics (page views, feature usage)Session / 12 months
Sentry error monitoringFirst-partyCaptures error context and session replay data when errors occurSession
Functional localStorage valueslocalStorageStores UI preferences (text size, theme), invitation tokens, referral codes, and checkout stateVaries (session to persistent)

10.2 Managing Cookies and Storage

You can manage or clear cookies and localStorage through your browser settings. Note that clearing authentication storage will sign you out of the Platform.

11. Automated Decision-Making

We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you.

The AI Functionality in the Platform generates responses based on your inputs, but these are tools you choose to use - they do not make decisions about you.

12. Children's Data

The Platform is intended for business and professional use and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children under 18.

If you believe we have inadvertently collected data from a person under 18, please contact us at hello@openorg.fyi and we will promptly delete that data.

13. Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • Encryption in transit (TLS/HTTPS) and at rest (provided by Supabase infrastructure)
  • Row-level security policies on our database, ensuring users can only access their own data
  • Secure authentication via Supabase Auth with bcrypt password hashing
  • Environment-separated API keys and secrets
  • Regular access reviews and least-privilege access controls
  • Sub-processor security assessments before onboarding

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach, we will notify affected users and the ICO as required by law.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make changes:

(a) We will update the "Last updated" date at the top of this page.

(b) For material changes, we will notify you by email or through a notice within the Platform.

(c) Your continued use of the Platform after the changes take effect constitutes your acceptance of the updated Privacy Policy.

We encourage you to review this Privacy Policy periodically.

15. How to Contact Us

If you have any questions about this Privacy Policy or how we handle your personal data:

Emailhello@openorg.fyi
CompanyOpen Org Group Ltd
Websiteopenorg.fyi

Open Org Group Ltd · Registered in England and Wales · openorg.fyi

Contents

  • 1. Who We Are
  • 2. What Personal Data We Collect
  • 3. How We Use Your Personal Data
  • 4. AI Functionality and Your Data
  • 5. Who We Share Your Data With
  • 6. International Data Transfers
  • 7. How Long We Keep Your Data
  • 8. Your Rights
  • 9. Right to Complain
  • 10. Cookies and Tracking Technologies
  • 11. Automated Decision-Making
  • 12. Children's Data
  • 13. Data Security
  • 14. Changes to This Privacy Policy
  • 15. How to Contact Us

About

Open Org Workspace is a platform for planning, building and shipping your People team projects, faster.

Subscribe to our newsletter

Quick Links

Terms of ServicePrivacy PolicyData Processing AgreementDocumentationLinkedIn

Open Org Ecosystem

Culture SupportOpenverseCommunity
©2026Open Org Group Ltd
Built with ♥️ by John & Adam