- UK GDPR
- ICO Registered
- EU hosted (Frankfurt)
- Last updated: August 2026
1. Roles and Scope
For Orca Time, your organisation is the data controller and OMG Center Limited (the publisher) is the data processor under UK GDPR Article 28. This is the reverse of the position for the Orca desktop app, where we hold no operational data at all; the two products have deliberately separate legal sets.
This agreement applies to all personal data processed in the course of providing Orca Time to your organisation, and forms part of the commercial agreement under which your licence is provisioned.
2. What Is Processed
The categories of data are narrow and fixed by the product's design:
- Data subjects: your organisation's admins and team members.
- Account data: name, email address, role, and team.
- Tracked time: frontmost application, window title, active browser tab URL and domain, idle state, and derived durations and attributions.
- Never processed: keystrokes, screenshots, or the content of any window, document, or page. The application has no capability to capture them.
Processing is limited to providing the Orca Time service: storing tracked time, applying your attribution rules, serving dashboards and reports, and enforcing retention and deletion settings. We do not use your data for any other purpose.
As part of the service and coaching relationship, the operator may share aggregate, organisation-level activity analytics with your organisation, containing no individual identifiers, window titles, URLs, domains, or content.
3. Hosting and Location
All Orca Time operational data is hosted in a Supabase project in the European Union, on AWS region eu-central-1 (Frankfurt). Data is not transferred outside that region for storage. Licence validation metadata (company name and admin email only) is held by Keygen; see the sub-processor list below.
4. Isolation Between Organisations
Each organisation's data is isolated by Postgres row-level security. Raw tracking tables are owner-only: each row is readable by the person it belongs to, and by nobody else directly. All cross-user access (admin team views, reports) goes through a security-definer read API that enforces the organisation boundary and the organisation's detail settings. Adversarial isolation tests covering cross-user access, cross-organisation access, seat cap enforcement, and operator redaction passed on 20 August 2026. The information security page describes the architecture in full.
5. Sub-processors
We use the following sub-processors to deliver Orca Time. We will give notice before adding or replacing a sub-processor that processes your personal data.
| Sub-processor | Purpose | Location | Data involved |
|---|---|---|---|
| Supabase | Database hosting | AWS eu-central-1, Frankfurt (EU) | All Orca Time operational data |
| Netlify | Hosting of the web dashboard | Global CDN (static assets only) | Serves the dashboard application; operational data flows from the browser to Supabase, not through Netlify |
| Keygen | Licence validation | United States | Company name and admin email only, held in licence metadata. No tracked time or personal tracking data. |
| Cloudflare | DNS and hosting of the app download | Global CDN | Serves the signed installer; no operational data |
6. Security
Technical and organisational measures are set out in the Orca Time information security document. In summary: owner-only row-level security on raw data, a security-definer read API as the sole cross-user path, structural redaction of the platform operator's view, EU hosting, a signed and notarised desktop client, and adversarial isolation testing.
7. Breach Notification
If we become aware of a personal data breach affecting your organisation's data, we will notify your admin contact without undue delay, and in any event within 72 hours of becoming aware, with the information available at that time: the nature of the breach, the data and data subjects affected so far as known, and the measures taken or proposed. We will cooperate with your own notification obligations to the ICO and to data subjects.
8. Data Subject Rights
The product is built so that most rights are exercisable directly: each person can see their own data in full, set their own retention period (1 to 3650 days, default 365, with automatic purge), delete their tracked data, and delete their account and full footprint. Where a data subject request reaches us instead, we will refer it to you as controller and assist as reasonably required.
9. Deletion and Return on Termination
On termination of your licence, we will, at your choice, return your organisation's data as a structured export (CSV) and then delete it, or delete it without return. Deletion covers all operational data for your organisation, subject only to short-lived backups which expire on their own cycle, and to records we must retain by law (commercial and financial records, not tracked time).
10. Contact
- Email: chris@simmance.ai
- Company: OMG Center Limited, Company No. 14169551
- Registered in England and Wales
Related Orca Time documents: privacy notice, information security, licence agreement. Plain-English guides live in the Orca Time docs.