Last Updated: October 2026 · Complies with Regulation (EU) 2016/679 (GDPR) and UK GDPR
1.1 "Customer" (or "Data Controller") refers to the individual creator, studio, brand, or entity maintaining an active Orgemy CRM workspace.
1.2 "Platform" (or "Data Processor") refers to Orgemy, a Netdrix company, providing creator audience management, link-in-bio services, social automation, and deal tracking software.
1.3 "Customer Personal Data" refers to any personal data submitted by Customer or collected via Customer's published link-in-bio pages, lead capture forms, or social channels (such as names, email addresses, phone numbers, and social handles).
Orgemy processes Customer Personal Data solely on behalf of and in accordance with Customer's documented instructions, as necessary to provide the Services, and in compliance with applicable Data Protection Legislation.
Orgemy shall not sell, retain, use, or disclose Customer Personal Data for any purpose other than for the specific business purposes of operating, maintaining, and supporting the Customer's workspace.
Orgemy implements and maintains appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
Customer grants general written authorization for Orgemy to engage the subprocessors listed on our Authorized Subprocessors Directory. Orgemy imposes contractual data protection obligations upon each subprocessor no less protective than those set forth in this DPA.
In the event of a confirmed Personal Data Breach affecting Customer Personal Data, Orgemy shall notify Customer without undue delay and, in any event, within seventy-two (72) hours of becoming aware of the breach, providing relevant details to assist Customer in meeting their regulatory obligations.
Orgemy provides self-serve capabilities within the Platform to enable Customer to fulfill requests from data subjects to access, rectify, export, or erase their personal data (GDPR Articles 15–20). Upon termination of the Services, Orgemy shall, at Customer's election, delete or return all Customer Personal Data within thirty (30) days.