- UK GDPR
- ICO Registered
- EU hosted (Frankfurt)
- Last updated: August 2026
1. Who We Are
Orca Time is published by OMG Center Limited (Company No. 14169551, registered in England and Wales), the publisher of Orca. Your employer (or the organisation that invited you) licenses Orca Time and decides to deploy it; the publisher hosts and processes the data on that organisation's behalf. The data processing agreement sets out that relationship formally.
2. What Is Collected
- The frontmost application
- The title of the active window
- The URL and domain of the active browser tab
- Idle state
- Account details: name, email address, role, and team
Never collected: keystrokes, screenshots, or the content of any window, page, or document. This is a structural property of the app, which has no capture capability for any of them, not a configuration choice.
3. The Paused and Blocked Honesty Model
You can pause tracking at any time, and you (and your organisation) can blocklist apps and sites. Both hide what you did, never how long: paused and blocked periods appear as labelled durations with no titles, URLs, or app names. Incognito and private browsing is treated this way by default. Window title and URL capture can each be switched off outright.
4. Lawful Basis
Your organisation deploys Orca Time under its contract with the publisher, and relies on performance of its employment or engagement contract with you and its legitimate interest in recording and billing working time. Independently of that, the app presents a consent screen before tracking starts: nothing is recorded until you have seen what will be collected and agreed to it. You can pause or stop tracking at any time.
5. Who Sees What
- You: your own data in full, always.
- Your organisation's admins: the team's time at the detail level your organisation has set. Granular mode shows window titles; holistic mode shows rollups only, with no titles or URLs.
- The platform operator: customer organisation names and aggregate activity totals, to support the service and the coaching relationship. The operator can never see individual people, window titles, URLs, domains, or content. This individual-level redaction is enforced structurally in the database read path, not by policy.
6. Where Your Data Is Held
All operational data is stored in a Supabase project in the EU (AWS eu-central-1, Frankfurt), with per-organisation isolation enforced by Postgres row-level security. The dashboard is served by Netlify, the app download by Cloudflare, and licence validation by Keygen, which holds only your organisation's company name and admin email. See the DPA for the full sub-processor list.
7. Retention and Deletion
You choose your own retention period, from 1 to 3650 days (default 365); older data is purged automatically. In the product you can delete your tracked data at any time, or delete your account and full footprint. On termination of your organisation's licence, data is returned and deleted as set out in the DPA.
8. Your Rights
Under UK GDPR you have rights of access, rectification, erasure, restriction, portability, and objection. Most are exercisable directly in the product: your dashboard shows everything held about you, and deletion and export are self-service. For anything else, contact your organisation's admin as controller, or email chris@simmance.ai. You may also complain to the Information Commissioner's Office at ico.org.uk.
9. Contact
- Email: chris@simmance.ai
- Company: OMG Center Limited, Company No. 14169551
Plain-English guides: what Orca Time records, getting started for team members.