Privacy policy

What we collect, why we need it, who else touches it and how to get it back. The short version: we collect what the work needs, we never sell it, and we don't follow you around the internet.

Last updated 2 October 2026

Who we are

This policy covers Orata Ltd ("Orata", "we", "us"), a company registered in England and Wales under company number 12019287. Our registered office is c/o Armstrongs Accountants, Alexandra House, Queen Street, Leek, Staffordshire, England, ST13 6LP.

It applies to this website, the Orata client portal at app.orata.io, our Chrome extension, and the work we do for clients. For the personal data described here we are the controller: we decide why and how it's used.

Questions, requests or complaints about your data go to [email protected]. A real person reads it, usually the founder.

What we collect and why

UK data protection law asks us to name a lawful basis for each use. Here they are in plain terms. "Contract" means we need it to do what you asked. "Legitimate interests" means it's a reasonable thing for a business like ours to do, and we've checked it doesn't override your interests. "Legal obligation" means the law makes us keep it.

When you book a call

Your name, email, phone number if you give it, your industry, your time zone and anything you write in the form. We use it to set up the meeting, send the invite and reminders, and get ready for the call. Basis: steps before a contract, and legitimate interests.

When you buy hours or pay an invoice

Your name, email, billing details and what you bought. Card payments are taken by Stripe; we never see or store your card number. Invoices are raised and tracked in Xero. Basis: contract, and legal obligation for our accounting records.

When you use the client portal

Your name, email, password (stored only as a salted hash), time zone, profile photo if you add one, and your two-factor settings. If you sign in with Google or Microsoft we receive your name, email and account ID from them. Then whatever you put into the portal: support tickets and their attachments, messages, task requests, approvals and comments. Basis: contract.

To keep accounts safe we also record sign-in activity: IP address, browser and device type, failed attempts, and devices you've chosen to trust. Basis: legitimate interests (security).

When we work together

Emails between us, meeting invites, notes, and the work records the portal shows you: projects, tasks, time logged and hours balances. If you're on a call with us, Google Meet may record it and produce a transcript, which we keep so nothing that was agreed gets lost. We'll say at the start of a call if it's being recorded. We also record short screen videos to show you work in progress. Basis: contract, and legitimate interests.

When you just visit this website

This site sets no cookies and runs no advertising or tracking scripts. Our hosting provider, Cloudflare, processes your IP address to deliver the pages and keep out attacks. If we turn on visitor statistics, we'll use a cookieless tool that counts visits without identifying you. Basis: legitimate interests.

Marketing

We don't run a mailing list. If you're a client or have asked us about our services, we may occasionally email you about something relevant. Every such email lets you opt out, and so does a one-line reply. Basis: legitimate interests, which the law now recognises for direct marketing.

Decisions made by software

We don't make decisions about you that have legal or similarly significant effects using automated processing alone. A person is involved in every decision that matters.

Data inside your systems

Most of our work happens inside a client's own systems: their Podio workspace, their CRM, their automations. Those systems hold data about the client's own customers and staff. For that data the client is the controller and we are their processor: we only use it to do the work they've asked for, on their instructions.

The rules for that are in the data processing terms in our terms of business. If you're one of our client's customers and want to use your rights over that data, contact the business you deal with directly. We'll help them answer.

How we use AI

We use AI tools, mainly Anthropic's Claude, to help us work faster. That includes tidying up call transcripts and screen recording captions, giving recordings a title, and helping us search and summarise our own records about your account.

  • We only use AI providers whose business terms say they don't train their models on our data.
  • A person reviews anything that goes to you or into your system.
  • AI tools never get passwords, card numbers or other credentials.
  • If you'd rather we didn't use AI on your data, tell us and we'll keep it out. It may make some work slower.

Who we share it with

We don't sell personal data, and we don't share it for anyone else's marketing. We use these service providers to run the business. Each one only gets what it needs and is bound by a data processing agreement.

ProviderWhat forWhere
NeonOur main databaseLondon, UK
CloudflareHosting, file storage, video, bot protection, error logsGlobal network, US company
GoogleEmail, calendar, Meet calls, transcripts, Google sign-inUS and EU
MicrosoftMicrosoft sign-in, if you choose itUS and EU
ResendSending and receiving portal and ticket emailsUS
StripeCard payments for hour packsUK, EU and US
XeroInvoicing and accountsUS, UK company
AnthropicAI tools (see above)US
SentryError monitoring, set not to collect personal detailsUS

We also share data with our accountants, bank, insurers and legal advisers when we need to, and with authorities when the law requires it. If Orata is ever sold or merged, the data would move with the business under the same protections, and we'd tell you first.

Data outside the UK

Our main database is in London, but several providers above are based in the US. When personal data leaves the UK we rely on one of the safeguards UK law allows: a UK adequacy decision (including the UK Extension to the EU-US Data Privacy Framework, where the provider is certified), or the UK International Data Transfer Agreement or Addendum. Ask us and we'll tell you which applies to a given provider.

How long we keep it

DataHow long
Portal accountUntil you delete it. After that you have 30 days to change your mind by signing in again, then your name, email, password, photo and sign-in details are erased.
Invoices, payments and accounting records6 years after the end of the financial year, because tax law requires it
Tickets, messages, recordings, transcripts and work recordsWhile we work together, then up to 6 years so we can answer questions about past work
Call bookings that didn't lead to workUp to 2 years
Sign-in sessions and one-time codesDeleted automatically when they expire

When you delete your portal account, tickets and work records stay with your company's account, because they're your business's records. They just stop showing your name.

Cookies and storage

This website sets no cookies. The client portal only uses what it needs to work, so there's no cookie banner:

NameWhat it doesHow long
sessionIdKeeps you signed inUp to 7 days, or until you sign out
Two-factor cookieRemembers you're midway through a two-factor sign-inA few minutes
trusted_deviceSkips two-factor on a device you've chosen to trust30 days
Cloudflare TurnstileChecks you're not a bot on the sign-in and sign-up pagesOnly during the check

The portal also keeps a copy of the pages you've loaded and your display preferences in your browser's storage, so it opens quickly. It's cleared when you sign out, or you can clear it in your browser settings at any time.

Our Chrome extension

The Orata Chrome extension is a tool for Orata staff. It tracks time against client work and records the screen, tab or window the user picks, with their microphone if they turn it on. It only records when the user presses record. It checks the current tab's address only to see whether it can show its controls there, and never stores or sends it. It doesn't read page content, collect browsing history, or run any advertising or analytics.

Recordings and time entries go to the Orata portal over an encrypted connection and are stored with Cloudflare. They're used only to share work with the client it belongs to and to bill time accurately. The extension's use of data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. Nothing it collects is sold, used for advertising, or used to decide anyone's creditworthiness.

Keeping it safe

Everything is encrypted in transit and at rest. Passwords are hashed, two-factor sign-in is available on every account, and access to client data is limited to the people doing the work. Third-party credentials are stored encrypted. If something goes wrong with your data, we'll tell you and, where the law requires, the Information Commissioner's Office.

Your rights

You can ask us to:

  • give you a copy of the personal data we hold about you
  • correct anything that's wrong
  • delete it, where we don't need to keep it
  • limit how we use it, or stop using it for a particular purpose
  • send it to you or someone else in a format a computer can read
  • stop sending you marketing emails, at any time

Email [email protected]. We may ask you to confirm who you are first. We'll reply within one month. If a request is complex we can take up to two more months, and we'll tell you if we need to. If we need more detail to find what you're asking about, the clock pauses until you send it. We'll search properly, in proportion to what you've asked for. You can delete your portal account yourself from your account settings.

Complaints

If you're unhappy with how we've handled your data, tell us first at [email protected]. We'll confirm we've got your complaint within 30 days, look into it properly, and tell you what we found and what we've done about it.

You can also complain to the Information Commissioner's Office at any time, at ico.org.uk/make-a-complaint or on 0303 123 1113.

Changes to this policy

We'll update this page when what we do changes, and change the date at the top. If a change matters to how we use your data, we'll email clients and portal users before it takes effect.