1. Introduction
Orchestra ("we", "us", "our"), operated by AGENTIC DYNAMICS LLC, provides a platform for deploying and configuring AI agent teams at hiorchestra.com. This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights as a data subject under the EU General Data Protection Regulation (GDPR) and other applicable privacy laws.
By using the Service, you agree to the practices described in this Privacy Policy. For a technical overview of our security controls, see our Security & Data Protection statement at hiorchestra.com/legal/security.
Plain Language Summary
We host all of our infrastructure in the European Union (Amsterdam, Netherlands). Your account data, credentials, agent configuration, and each agent's working data are stored in the EU.
We do not sell your data, we do not use it to train our own models, we do not use advertising trackers, and we do not build advertising profiles of you.
Orchestra is an AI agent platform, so to do its job it forwards content at runtime to the AI model providers that power your agents and to the business tools you choose to connect (email, calendar, CRM, messaging). Some of these providers are located outside the EU. Where Orchestra supplies the key for a provider (for example, transcription, web search, or trial AI access), that provider is a sub-processor and is listed in Section 7. Where you supply your own AI provider API key, those calls are made directly under your own account and the provider's own terms.
For each integration you connect, you choose the access level, and Orchestra requests only the minimum permissions that level requires. You can revoke any integration at any time.
2. Data Controller and Data Processor
2.1 Data Controller — Orchestra is the data controller for personal data collected directly from users for the purpose of operating the Service, such as your email address and account information.
2.2 Data Processor — When you deploy Agents that access, process, or interact with personal data belonging to third parties (for example, reading emails from your Gmail, processing contacts, or interacting with external services on your behalf), Orchestra acts as a data processor. You, as the user, are the data controller for that data and are responsible for ensuring a lawful basis for its processing.
A Data Processing Agreement (DPA) is available at hiorchestra.com/legal/dpa for users who require it for GDPR compliance purposes. For a countersigned copy, contact legal@hiorchestra.com.
3. Legal Basis for Processing
We process your personal data under the following legal bases:
Performance of a contract (Article 6(1)(b) GDPR): Processing your account information and configuration data is necessary to provide the Service you have signed up for.
Legitimate interests (Article 6(1)(f) GDPR): We process basic, aggregate website analytics and security/abuse-prevention data to understand how the Service is used and to keep it secure. This does not involve tracking individual users across websites.
Consent (Article 6(1)(a) GDPR): Where you explicitly connect third-party accounts (Google, Slack, Telegram, and others), you provide consent for Orchestra to store the access tokens required to operate those integrations on your behalf. Marketing-site analytics cookies are also set only with your consent.
4. Information We Collect
4.1 Account Information — When you create an account, we collect your email address for authentication. We use a passwordless one-time-code (OTP) system. We do not store passwords.
4.2 Third-Party OAuth Tokens and Keys — If you connect third-party accounts (such as Google services, Slack, Telegram, or others), we store the OAuth refresh token or access credential required to maintain that integration. If you provide your own AI provider API keys, we store them in encrypted form. We do not store your passwords for any third-party service. You can revoke these at any time from the Channels or Settings pages.
4.3 Agent and Instance Configuration — We store your agent deployment settings, including channel configurations, agent definitions, workflows, scheduled tasks, and encrypted credentials. These are stored solely to operate the Service on your behalf.
4.4 Agent Working Data — Each customer runs a dedicated, isolated agent instance with its own storage volume, hosted in the EU. Files you upload to your agents and the working data your agents generate (including conversation context needed for the agent to function) are stored on that per-instance volume in the EU. This data is not stored in our shared central database.
4.5 Billing Data — We store subscription and billing metadata. Payment card details are handled directly by our payment processor, Stripe, and are not stored by Orchestra.
4.6 Automatically Collected Technical Data — When you access the Service, we automatically collect certain technical information, which may include: IP address (which may constitute personal data under GDPR), browser type and version, operating system and device type, referring URLs, pages visited, and timestamps. This is used for security monitoring, abuse prevention, and aggregate analytics. We do not use it to build individual advertising profiles.
4.7 What We Do Not Do — Orchestra does not sell your personal data, does not use your data or your agents' content to train our own models, and does not use cross-site advertising trackers. Our shared central systems do not retain the content of your agents' conversations; that working data lives on your dedicated EU instance. Note, however, that to deliver AI features that content is transmitted at runtime to the sub-processors listed in Section 7.
5. AI Model Providers and Runtime Processing
Orchestra is an AI agent platform. To function, your agents send content at runtime to AI model providers and to the tools you connect. There are two distinct paths, and they are treated differently under this Policy:
5.1 Your own keys (direct) — When you provide your own AI provider API key (for example, your own Anthropic, OpenAI, Google AI, Mistral, xAI, or Alibaba key), calls made with that key go to that provider under your own account and their own terms of service and privacy policy. This is functionally similar to using that provider directly. You are responsible for reviewing and accepting the terms of the providers whose keys you supply.
5.2 Orchestra-supplied providers (sub-processors) — For certain features, Orchestra supplies the credential and routes your content on your behalf. This currently includes audio transcription, text-to-speech, web search, trial/managed AI model access, model routing, and session utilities. In these cases the provider is a sub-processor of Orchestra and is listed in Section 7. These transfers are governed by Data Processing Agreements and appropriate safeguards (see Sections 7 and 14).
In all cases, Orchestra does not use the content of these requests for advertising or to train its own models.
6. Data Storage and Security
All Orchestra infrastructure — the web application, the backend API, the shared database, and each customer's dedicated agent instance and storage volume — is hosted on Railway in the European Union (Amsterdam, Netherlands). Customer data at rest is stored within the EU.
Each customer's agent runs in its own isolated instance with its own dedicated storage volume; customer environments are isolated from one another. We do not use any external database or external object/file storage — all stored data resides on our EU infrastructure.
All connections use HTTPS/TLS encryption in transit. Sensitive credentials (third-party API keys, OAuth tokens) are encrypted at rest at the application layer using AES-256. Platform sub-processor keys are held server-side and are not exposed to customer instances.
We follow industry-standard security practices to protect your data from unauthorised access, disclosure, or destruction. No method of transmission or storage is completely secure, and we do not guarantee absolute security.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify affected users and, where required, the competent supervisory authority without undue delay and in any case within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
7. Sub-Processors
To provide the Service, we engage the following sub-processors. We distinguish between (A) platform sub-processors, where Orchestra supplies the credentials and routes data on your behalf, and (B) customer-connected integrations, which process data only when you connect the relevant account and instruct your agent to use it.
(A) Platform sub-processors:
Railway — cloud hosting, database, and storage — EU data region (provider is US-incorporated) — DPA + Standard Contractual Clauses (SCCs).
Stripe — subscription billing and payment processing — EU (Stripe Payments Europe) / US — DPA + SCCs; PCI-DSS.
Resend — transactional and verification email (including one-time login codes) — US — DPA + SCCs.
Anthropic — AI model inference — US — DPA + SCCs.
OpenAI — AI model inference and image generation — US — DPA + SCCs.
Google (Gemini / Cloud AI) — AI model inference — US — DPA + SCCs.
OpenRouter — AI model routing, trial model access, and session utilities — US — DPA + SCCs.
Groq — audio transcription — US — DPA + SCCs.
ElevenLabs — text-to-speech — US — DPA + SCCs.
Composio — connected-tool and automation gateway (brokers many of the integrations in category B) — US — DPA + SCCs.
Brave Search — web search for agents — US — DPA + SCCs.
Google Analytics — marketing-website analytics only (not the application), set only with your consent via our cookie banner — US.
(B) Customer-connected integrations (activated by you, using your own account or credentials):
Google Workspace (Gmail, Calendar, Drive, Docs, Sheets, Contacts) — productivity — US.
Slack — messaging — US.
Telegram — messaging — UK / UAE.
Twilio (SMS, voice, WhatsApp) — messaging — US.
WhatsApp / Discord (Meta) — messaging — US.
Business tools such as HubSpot, Shopify, Linear, Zendesk, Intercom, ActiveCampaign, Jira, and GitHub — mainly US.
Mistral AI (optional, your key) — AI model — EU (France).
Other AI models such as xAI or Alibaba Qwen (optional, your key) — US / Asia.
For each integration you connect, you choose the access level (for example, read-only versus read and write), and Orchestra requests only the minimum permissions that level requires; the third-party provider enforces those permissions. A current, itemised sub-processor list and corresponding DPAs are available on request and as part of contract documentation. We will give notice of material changes to our sub-processor list to customers who have entered into a DPA with us.
8. Data Retention
We retain your data for as long as your account is active. Specific retention periods by data type:
Account email address: Retained for the duration of your account. Deleted within 30 days of an account deletion request.
OAuth tokens and API keys: Retained until you disconnect the relevant integration or delete your account. Revocable at any time.
Agent configuration, workflows, uploaded files, and agent working data: Stored on your dedicated EU instance for the duration of your account. When your account or instance is deleted, the instance and its storage volume are decommissioned and the associated data is deleted within 30 days.
Website analytics: Aggregated and anonymised.
You may request deletion of your account and all associated data at any time by contacting legal@hiorchestra.com. We will process deletion requests within 30 days, subject to any legal retention obligations.
9. Your Rights Under GDPR
If you are located in the European Union or European Economic Area, you have the following rights:
Right of access: You may request a copy of the personal data we hold about you.
Right to rectification: You may request correction of inaccurate or incomplete data.
Right to erasure: You may request deletion of your personal data, subject to legal retention obligations.
Right to restriction: You may request that we restrict processing of your data in certain circumstances.
Right to data portability: You may request your data in a structured, machine-readable format.
Right to object: You may object to processing based on legitimate interests.
Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at legal@hiorchestra.com. We will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority (in Spain, the Agencia Española de Protección de Datos, www.aepd.es).
10. Third-Party Services
The Service integrates with third-party platforms at your explicit request. Each integration is governed by the third party's own privacy policy. Orchestra requests only the scopes required for the access level you choose and does not share user data with third parties for marketing or advertising purposes.
You are responsible for reviewing and accepting the terms and privacy policies of each service you connect to Orchestra. A current list of supported integrations is maintained in Section 7 and in your account.
11. Cookies and Tracking
The Orchestra application does not use advertising cookies or cross-site tracking technologies. Our marketing website uses analytics (Google Analytics) that is loaded only after you consent via our cookie banner; you can decline or withdraw consent at any time. No cookies that identify individual users for advertising are set.
12. Minimum Age and Children's Data
The Service is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors under 18. If you are under 18 years of age, you may not use the Service.
If we become aware that personal data has been collected from a user under 18 without verifiable parental or guardian consent, we will take all reasonable steps to delete such information as promptly as possible. If you believe a minor has provided us with personal data, please notify us at legal@hiorchestra.com.
13. Communications and Opt-Out
Orchestra may send you the following communications by email: (a) transactional emails necessary to operate the Service, such as one-time login codes, account confirmations, and security alerts — these cannot be opted out of while your account is active; (b) product updates and announcements about material changes to the Service or these policies; and (c) optional service communications such as tips, feature releases, or newsletters, which you may opt out of at any time.
To opt out of non-transactional communications, click the "unsubscribe" link included in any such email, or contact us at legal@hiorchestra.com. Opting out of marketing emails does not affect delivery of transactional communications.
14. International Data Transfers
Our infrastructure and stored customer data are located in the European Union. Because Orchestra is an AI agent platform, certain processing transfers occur at runtime where AI inference or a customer-connected tool is provided by a non-EU sub-processor (see Section 7).
For such transfers of personal data from the EU to third countries, we rely on appropriate safeguards under GDPR Chapter V, including the European Commission's Standard Contractual Clauses (SCCs), the EU–US Data Privacy Framework where the sub-processor is certified, adequacy decisions, and the sub-processors' Data Processing Agreements.
For customers whose policies require that no personal data is processed outside the EU, Orchestra can provide an EU-only processing configuration (for example, routing AI inference to EU-based model providers and disabling non-EU speech and search services). This is offered as an enterprise configuration and is scoped per customer.
15. No Third Party Beneficiaries
This Privacy Policy does not create rights enforceable by third parties. It is intended solely for the benefit of Orchestra and its users.
16. Relationship to Terms and Conditions
This Privacy Policy is incorporated by reference into Orchestra's Terms and Conditions of Use. By using the Service, you agree to both documents. In the event of any conflict between this Privacy Policy and the Terms, this Privacy Policy shall govern with respect to privacy and personal data matters.
17. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify registered users of material changes via email at least 15 days before the changes take effect. The current version will always be available at hiorchestra.com/legal/privacy.
18. Contact and Data Protection Inquiries
For any questions, requests, or complaints regarding this Privacy Policy or our data practices, contact us at: legal@hiorchestra.com
For GDPR-specific requests including DPA inquiries, data subject rights requests, or breach notifications, please use the same address with the subject line "GDPR Request". For security-specific matters, see hiorchestra.com/legal/security.