Open Org Group Ltd
This Privacy Policy explains how Open Org Group Ltd ("Open Org", "we", "us", or "our"), a company incorporated in England and Wales, collects, uses, stores, shares, and protects your personal data when you use the Open Org Workspace platform at workspace.openorg.fyi and openorg.fyi (the "Platform").
The Platform is intended for business use only. It is provided to organisations (each a "Customer") and the individual users a Customer authorises to use it ("Authorised Users"). This Privacy Policy applies to personal data we process as an independent data controller - that is, data about you as an Authorised User of the Platform, such as your account, profile, and usage data. Where personal data about third parties (such as employees or candidates) is uploaded or input through the Platform, the Customer is the controller of that data and Open Org acts as a data processor on the Customer's behalf; that processing is governed by our Data Processing Agreement.
This Privacy Policy should be read alongside our Terms of Service and Data Processing Agreement. Capitalised terms not defined here have the meaning given to them in the Terms of Service.
1. Who We Are
Open Org Group Ltd is the data controller for the personal data described in this Privacy Policy.
| Company | Open Org Group Ltd |
| Registered | England and Wales |
| Website | openorg.fyi |
| Contact | hello@openorg.fyi |
We do not currently have a statutory obligation to appoint a Data Protection Officer. For any data protection queries, please contact us at hello@openorg.fyi.
2. What Personal Data We Collect
2.1 Data You Provide Directly
| Category | Examples |
|---|---|
| Account data | Name, email address, password (hashed - we never store plaintext passwords) |
| Profile data | First name, last name, motivations, work context (company, tools, challenges, team structure), attribution (how you found us) |
| Onboarding data | Location (country), company size, professional goals |
| Preferences | Text size, theme, notification preferences |
| Chat and AI interactions | Messages you send to Open Org AI, files you upload, URLs you reference, feedback you provide on AI responses |
| Documents and Artifacts | Files you upload, documents generated by the AI, code outputs, and their version history |
| Team and organisation data | Team name, role within a team (owner, member) |
| Marketing preferences | Whether you have opted in to receive marketing emails |
2.2 Data We Collect Automatically
| Category | Examples |
|---|---|
| Usage and analytics data | Pages visited, features used, interaction events, timestamps, session duration |
| Device and technical data | Browser type, operating system, screen resolution, IP address (collected by analytics and error monitoring services) |
| Error and performance data | Error messages, stack traces, request metadata, performance metrics, session replays (on error) |
2.3 Data We Receive from Third Parties
| Source | Data |
|---|---|
| Google (OAuth sign-in) | Name, email address, profile picture URL (from your Google account) |
| Stripe | Payment confirmation status, subscription status (we do not receive or store your payment card details) |
| Referral or invitation links | Referral code, inviter identity, team invitation details |
3. How We Use Your Personal Data
| Purpose | Lawful basis (UK GDPR) |
|---|---|
| Creating and managing your account | Performance of contract (Article 6(1)(b)) |
| Providing the Platform, including AI chat, Open Org Playbooks, and Artifacts | Performance of contract |
| Processing payments and managing subscriptions via Stripe | Performance of contract |
| Sending transactional emails (account confirmations, team invitations, gift notifications, referral communications) | Performance of contract |
| Providing customer support | Performance of contract |
| Processing team invitations and managing team membership | Performance of contract |
| Processing gift passes and referral rewards | Performance of contract |
| Maintaining and improving the Platform - product analytics, feature usage tracking, performance monitoring | Legitimate interests (improving the product and user experience) |
| Detecting and preventing errors, bugs, and security incidents | Legitimate interests (maintaining service reliability and security) |
| Sending marketing emails about product updates, tips, and Open Org news | Consent (you opt in during signup; you can withdraw at any time) |
| Recording and maintaining consent records (terms acceptance, marketing opt-in) | Legal obligation (UK GDPR accountability requirements) |
| Complying with legal obligations, including tax and financial record-keeping | Legal obligation |
3.1 Legitimate Interests
Where we rely on legitimate interests, we have considered the balance between our interests and your rights. Our legitimate interests include:
- Product improvement: Understanding how features are used so we can improve the Platform. We use PostHog (EU-hosted) for analytics, which collects pseudonymised usage events.
- Error monitoring: Detecting and resolving bugs and performance issues promptly. We use Sentry (EU ingest) which may capture limited personal data in error context.
- Security: Preventing misuse, fraud, and unauthorised access to the Platform.
You have the right to object to processing based on legitimate interests (see Section 8).
4. AI Functionality and Your Data
The Platform includes AI Functionality (Open Org AI, Playbooks, Artifacts, and Code Interpreter). When you use these features:
(a) Your messages, uploaded files, referenced URLs, conversation history, and work context are sent to our AI sub-processors (Anthropic and OpenAI) to generate responses.
(b) Your data is not used to train AI models. Anthropic's Commercial Terms (Section B) and Data Processing Addendum contractually prohibit Anthropic from training models on commercial API customer content. OpenAI's Enterprise Privacy Policy and Data Processing Addendum confirm that API data is not used for model training by default, and Open Org has not opted in to any data sharing programme. Open Org does not use your data to train AI models. Open Org may use your data to maintain and improve the Platform (including the AI Functionality) only as permitted by our Terms of Service, which govern this use, but not to train AI models.
(c) AI inputs and outputs are retained by Anthropic and OpenAI for up to 30 days for abuse and safety monitoring, after which they are deleted.
(d) Text content you index in the Platform is converted into vector embeddings using OpenAI's embedding model. Embeddings are stored in our Supabase database (UK) for semantic search functionality.
(e) When you reference external URLs in chat, the content at those URLs may be fetched via Jina AI (Germany/Global) to provide context to the AI.
(f) AI-generated outputs (Artifacts) and their version history are stored in our database.
For full details of how AI sub-processors handle your data, see the Data Processing Agreement.
5. Who We Share Your Data With
We share your personal data only with the third-party service providers ("sub-processors") necessary to operate the Platform. We do not sell your personal data to anyone.
| Service provider | Purpose | Data shared | Location | Terms |
|---|---|---|---|---|
| Supabase (Supabase Inc.) | Database, authentication, and file storage | All account and service data | United Kingdom (London) | DPA |
| Anthropic (Anthropic PBC) | AI chat responses, document generation, and document processing (primary AI provider) | Messages, files (including PDFs), context | United States | DPA · Terms |
| OpenAI (OpenAI LLC) | AI chat responses, text embeddings, Code Interpreter (secondary AI provider) | Messages, files, context | United States | DPA · Privacy |
| Stripe (Stripe Inc.) | Payment processing and subscription billing | User ID, email, subscription metadata | United States | DPA |
| Vercel (Vercel Inc.) | Application hosting and serverless API | Data in transit via HTTP requests | United States / Global | DPA |
| Mailchimp (Rocket Science Group LLC) | Marketing emails (only if you opt in) | Email, name, subscription status, tags | United States | DPA |
| Loops (Loops Inc.) | Transactional emails | Email, gift/referral/invitation metadata | United States | DPA |
| PostHog (PostHog Inc.) | Product analytics | Pseudonymised user ID, usage events, page views | European Union (Frankfurt) | DPA · Privacy |
| Sentry (Functional Software Inc.) | Error monitoring and performance tracking | Error data, stack traces, request metadata | European Union (ingest) | DPA |
| Jina AI (Jina AI GmbH) | URL content extraction | URL content fetched at your request | Germany / Global | Terms · Privacy |
We may also disclose your personal data if required to do so by law, regulation, or court order.
6. International Data Transfers
Your primary data is stored in the United Kingdom (Supabase, London region).
Where we transfer personal data outside the UK to sub-processors in the United States and other countries, we ensure appropriate safeguards are in place:
(a) UK transfers: We rely on the transfer mechanisms included in our sub-processors' standard data processing terms, which typically incorporate the UK Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement (IDTA).
(b) EEA transfers: Where applicable, our sub-processors' terms incorporate the European Commission's Standard Contractual Clauses (Module Two: Controller to Processor).
(c) We review the data processing terms of each sub-processor to confirm that appropriate transfer safeguards are in place.
If you would like further information about the safeguards in place, please contact us at hello@openorg.fyi.
7. How Long We Keep Your Data
| Data category | Retention period |
|---|---|
| Account and profile data | While your account exists |
| Chat history, Artifacts, and uploaded files | While your account exists (including any free Subscription), then deleted or returned within 30 days of the end of your Subscription Term |
| Usage analytics (PostHog) | Per our configured retention period (currently 12 months of event data) |
| Error monitoring data (Sentry) | 90 days |
| Marketing data (Mailchimp) | Until you unsubscribe or request deletion |
| Payment records (Stripe) | As required by Stripe's policies and applicable tax/financial regulations |
| AI provider logs (Anthropic, OpenAI) | Up to 30 days for abuse monitoring, then deleted |
| Transactional email logs (Loops) | Per Loops' standard retention policies |
After your account is deleted:
- We provide a 30-day window to export your data before permanent deletion.
- Data is removed from primary systems after the export window.
- Backup copies are purged in accordance with our hosting provider's backup rotation schedule (currently 7-day daily backup retention on Supabase).
We may retain certain data for longer where required by law (for example, financial records for tax purposes).
8. Your Rights
Under the UK GDPR, you have the following rights in relation to your personal data:
| Right | Description |
|---|---|
| Access | Request a copy of the personal data we hold about you |
| Rectification | Request correction of inaccurate or incomplete data |
| Erasure | Request deletion of your personal data (subject to legal retention requirements) |
| Restriction | Request that we restrict processing of your data in certain circumstances |
| Portability | Receive your data in a structured, commonly used, machine-readable format |
| Objection | Object to processing based on legitimate interests or for direct marketing |
| Withdraw consent | Where processing is based on consent (e.g., marketing emails), you can withdraw at any time without affecting the lawfulness of processing before withdrawal |
How to Exercise Your Rights
- Email: hello@openorg.fyi
- Account settings: You can update your profile, manage preferences, and request data export through the Platform
- Marketing opt-out: Use the unsubscribe link in any marketing email, or update your preferences in your account
We will respond to your request within one month. If your request is complex, we may extend this by a further two months, and we will inform you if this is the case.
We will not charge a fee for handling your request unless it is manifestly unfounded or excessive.
9. Right to Complain
If you are not satisfied with how we handle your personal data or your rights request, you have the right to lodge a complaint with the Information Commissioner's Office (ICO):
| Website | ico.org.uk |
| Phone | 0303 123 1113 |
| Post | Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF |
We would appreciate the opportunity to address your concerns before you approach the ICO. Please contact us at hello@openorg.fyi in the first instance.
10. Cookies and Tracking Technologies
10.1 What We Use
We do not use traditional advertising or third-party tracking cookies. The Platform uses the following technologies:
| Technology | Type | Purpose | Duration |
|---|---|---|---|
| Supabase auth token | localStorage | Keeps you signed in between sessions | Until you sign out or the session expires |
| PostHog analytics | First-party cookies / localStorage | Pseudonymised product analytics (page views, feature usage) | Session / 12 months |
| Sentry error monitoring | First-party | Captures error context and session replay data when errors occur | Session |
| Functional localStorage values | localStorage | Stores UI preferences (text size, theme), invitation tokens, referral codes, and checkout state | Varies (session to persistent) |
10.2 Managing Cookies and Storage
You can manage or clear cookies and localStorage through your browser settings. Note that clearing authentication storage will sign you out of the Platform.
11. Automated Decision-Making
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects on you.
The AI Functionality in the Platform generates responses based on your inputs, but these are tools you choose to use - they do not make decisions about you.
12. Children's Data
The Platform is intended for business and professional use and is not directed at individuals under the age of 18. We do not knowingly collect personal data from children under 18.
If you believe we have inadvertently collected data from a person under 18, please contact us at hello@openorg.fyi and we will promptly delete that data.
13. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption in transit (TLS/HTTPS) and at rest (provided by Supabase infrastructure)
- Row-level security policies on our database, ensuring users can only access their own data
- Secure authentication via Supabase Auth with bcrypt password hashing
- Environment-separated API keys and secrets
- Regular access reviews and least-privilege access controls
- Sub-processor security assessments before onboarding
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach, we will notify affected users and the ICO as required by law.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes:
(a) We will update the "Last updated" date at the top of this page.
(b) For material changes, we will notify you by email or through a notice within the Platform.
(c) Your continued use of the Platform after the changes take effect constitutes your acceptance of the updated Privacy Policy.
We encourage you to review this Privacy Policy periodically.
15. How to Contact Us
If you have any questions about this Privacy Policy or how we handle your personal data:
| hello@openorg.fyi | |
| Company | Open Org Group Ltd |
| Website | openorg.fyi |
Open Org Group Ltd · Registered in England and Wales · openorg.fyi