Privacy Policy & GDPR / CCPA Compliance
Last Updated: September 30, 2026 · Effective Date: January 1, 2026
1. Overview and System Boundaries
Orgemy (“Platform”, “we”, “our”) respects your privacy and is committed to protecting your personal data and the data of your audience contacts. This Privacy Policy explains how we collect, process, store, and safeguard information when you use Orgemy.
Data Ownership: You (the creator or brand workspace owner) maintain 100% legal ownership of your contacts, customer lists, notes, and deal history. Orgemy acts strictly as a Data Processor regarding your audience contacts, while acting as a Data Controller regarding your platform account credentials and billing records.
2. Categories of Data Collected
We process information categorized into distinct data classifications:
- Account Credentials: Name, email address, password hashes (salted SHA-256 / bcrypt), workspace slugs, and billing customer references.
- Audience Contacts: First name, last name, email addresses, phone numbers, social handles (Instagram, YouTube, Skool), and explicit consent preferences.
- Commerce Data: Store order numbers, purchased items, total minor unit spend, and webhook reference IDs from connected commerce systems. Cardholder payment details are processed directly by PCI-DSS compliant providers (Stripe, PayPal) and are never stored in CRM databases.
- Telemetry & Audit Logs: Cryptographic session tokens, IP addresses, browser user agents, and mutation timestamps.
3. Lawful Basis for Processing (GDPR Article 6)
We process personal data under the following lawful bases:
- Contract Performance: Providing core CRM, workflow automations, and brand deal tracking services.
- Consent: Sending email campaigns, SMS alerts, and marketing broadcasts only when contacts have granted explicit opt-in consent (
consentEmail: true). - Legitimate Interests: Enforcing platform fraud detection, preventing abusive message velocities, and protecting system security.
4. Data Subject Rights (Portability & Erasure)
In accordance with GDPR (Articles 15–22) and the California Consumer Privacy Act (CCPA), you and your contacts possess guaranteed data rights:
Export complete structured JSON archives of your contacts, timeline events, and brand deals via Privacy Settings or POST /api/v1/privacy/export.
Trigger irreversible cryptographic anonymization of contact PII across all databases via POST /api/v1/privacy/erase while preserving immutable financial audit requirements.
5. Security Operations & Encryption
All integration credentials (OAuth tokens, API secrets) are encrypted at rest using industry-standard AES-256-GCM. Outbound webhooks are cryptographically signed using HMAC-SHA256 signatures (X-Orgemy-Signature) to ensure data authenticity and tamper prevention.
6. Contact Data Protection Officer (DPO)
For legal inquiries, privacy concerns, or verification audits, contact our Data Protection Office at:
Email: privacy@orgemy.com
Entity: Netdrix Cloud Services