orchestra_

Legal

Privacy policy

Last updated: 2026-10-05

This policy explains what personal data Orchestra handles, why, where it is kept and who else is involved. It describes what the software does today and is revised whenever that changes.

In short

1. Who we are

Orchestra is operated by Daniil Chuikin, a sole trader established in Spain, tax identification number (NIF) Z0986895Q, with address at:

Valencia, C/ Democracia 69, 46018

For anything concerning personal data, write to privacy@orchestrapm.io.

For the data described in sections 2 and 3 we are the data controller.

2. Visitors to this website

This website has no cookies, no analytics, no forms and no embedded third-party content. Our web server may record technical request data (IP address, time and the address requested) in short-lived logs kept for security and troubleshooting; we do not use them to identify or profile visitors. If you email us, we keep your message and address for as long as needed to answer and to follow up on the conversation. Our own mailboxes are provided by Google Workspace.

Legal basis: our legitimate interest in running a secure website and in answering people who contact us.

3. People who sign in to the console

The Orchestra console is used by the staff of our customers. When you sign in with Google we receive your name and email address, and use them only to identify you inside your organisation's workspace and to show who did what there. The console sets only strictly necessary cookies: one that keeps you signed in and a short-lived one used while you sign in. Neither is used for tracking.

Orchestra's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Legal basis: performing the agreement with your organisation, and our legitimate interest in keeping the service secure.

4. Our customers' business data

Customers use Orchestra to handle translation requests. To do that, Orchestra processes the content of the mailboxes a customer chooses to enrol, the attachments in them, the quotes prepared from them, and the client and linguist records synchronised from the customer's own systems. This data can include personal data of the customer's clients, linguists and correspondents.

For this data the customer is the data controller and Orchestra is a processor: we process it only on the customer's instructions and only to provide the service. Access to mailboxes is granted by the customer's own administrator, for a single Gmail permission scope, and that administrator can revoke it at any time. Orchestra reads only the mailboxes the customer has enrolled.

If your personal data appears in a message handled by one of our customers and you want to exercise your rights, please contact that customer first; we will assist them.

5. Who else processes the data

We use the following sub-processors:

A customer's own translation management system remains the customer's system; it is not a sub-processor of ours.

6. What we do not do

7. How long we keep data

Customer data is kept for as long as we provide the service to that customer. When the service ends, or earlier if the customer asks, we delete it from the live service within 30 days. Copies held in encrypted backups are not altered individually; they are overwritten as the backups rotate, within about three months. Sign-in details of console users are deleted together with their organisation's data, or earlier at the organisation's request.

8. Security

Data is encrypted in transit. Each customer's data is kept separate from every other customer's. Administrative access is restricted and backups are encrypted. No system is perfectly secure; if a breach affecting personal data occurs we will notify the affected customers and the authority as the law requires.

9. Your rights

Under the General Data Protection Regulation and the Spanish Organic Law 3/2018 (LOPDGDD) you have the right to access your personal data, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form. To exercise these rights write to privacy@orchestrapm.io; we answer within one month.

You also have the right to lodge a complaint with the Spanish supervisory authority, the Agencia Española de Protección de Datos (www.aepd.es).

10. Changes to this policy

We update this policy when the service changes. The date at the top shows the latest revision; customers are told in advance about any change that matters to them, including any new sub-processor.