Legal

Privacy Policy

Last updated 15 August 2026. Effective 15 August 2026.

This policy is written to be read, not to be survived. It says what Ordelume collects, why, who else touches it, where it lives, and how you get it back or deleted.

1. Who we are

Ordelume is operated by Olha Horobets, an individual entrepreneur registered in Ukraine (registration number to be added).

Contact for anything in this policy, including access and deletion requests: olha@ordelume.com. We answer within 30 days, usually much sooner.

2. Two different roles

Which rules apply depends on whose data it is.

3. What we collect as controller

DataWhyLegal basis
Name, email, password (stored only as a PBKDF2 hash, never in plain text)To create and secure your accountContract
Organisation and workspace nameTo build your workspace and keep it separate from every other oneContract
Waitlist entry: name, email, company, noteTo decide who gets access during private beta and to reply to youConsent
Session records: a session identifier, expiry, last-seen timeTo keep you signed in and to end sessions when you reset your passwordContract
Emails we send you: verification, password reset, invitationsTo operate the accountContract
Server logsTo keep the service running and to investigate faults and abuseLegitimate interest

We do not run advertising or analytics trackers. There is no Google Analytics, no advertising pixel, and no third-party tracking script on this site. The only cookie we set is the one that keeps you signed in, plus a short-lived one if a private-beta access code is in use. Both are strictly necessary, which is why you do not get a consent banner: there is nothing to consent to.

4. What we hold as processor

Whatever you or your team put into the workspace. In practice that includes:

We do not sell any of it, we do not share it with other customers, and we do not use it to build or improve anyone else's workspace. Each workspace is isolated: the API resolves every request against the workspaces your account actually belongs to, and a request for another company's workspace is refused.

5. AI processing

Ordelume sends parts of your workspace data to an AI provider when you ask for something that needs it: an agent answer, a message draft, a campaign plan, a report. What travels is the relevant records for that request, not your whole workspace.

6. Connected accounts

If you connect Google or Microsoft, we ask only for the scopes the feature needs, we store the tokens encrypted, and we use them only to do the thing you switched on: read recent mail to draft a reply, send a message you approved, read calendar availability. You can disconnect at any time in Integrations, which invalidates our copy of the tokens. Ordelume's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. The browser extension and LinkedIn

The Ordelume extension runs in your own browser, under your own LinkedIn session, at a human pace. It reads pages you open and saves what you choose into your workspace. It does not run on our servers and it does not use your LinkedIn credentials: we never see them.

Two honest points. Automated collection of LinkedIn data can conflict with LinkedIn's terms of service, and you are the one accountable for that. And once a person's details are in your CRM, you are the controller of that data: telling them, and honouring their requests, is your obligation, not ours. We give you the tools to find, export, and delete any record.

8. Who else processes data

We use a short list of subprocessors, each for one job. The current list, with what they do and where they are, is at ordelume.com/subprocessors. We tell customers before adding a new one.

9. Where data is stored

The application and database run in Frankfurt, Germany (EU). Uploaded files sit on a disk in the same region. Backups stay with the database provider in the same region.

We operate from Ukraine, so administering the service involves access from outside the EEA. Where that transfer needs a legal basis, it is covered by the European Commission's Standard Contractual Clauses, which are included in our DPA.

10. How long we keep it

11. Security

What is actually in place, not what sounds good: HTTPS everywhere with HSTS; passwords stored as PBKDF2-SHA256 with 240,000 iterations and a per-password salt; API keys and OAuth tokens encrypted at rest; session cookies that JavaScript cannot read; per-workspace isolation enforced on the server for every request; role-based module visibility inside a workspace; an audit log; EU-hosted managed Postgres with provider backups.

What we do not claim: we hold no SOC 2 or ISO 27001 certification, and we do not pretend to. If your procurement needs one, tell us before you buy.

12. Your rights

If you are in the EEA or the UK you can ask for access, correction, deletion, a portable copy, restriction, or object to processing. Write to olha@ordelume.com. Inside the product you can already export any module to CSV yourself, and request full deletion of a workspace by email. You can also complain to your data protection authority; in Ukraine that is the Ukrainian Parliament Commissioner for Human Rights.

If your request is about data held in a customer's workspace rather than your own account, we pass it to that customer, who is the controller, and help them answer it.

13. Children

Ordelume is a business tool and is not for anyone under 16. We do not knowingly collect their data.

14. Changes

If we change this policy in a way that matters, we email account holders before it takes effect and update the date at the top. Older versions are available on request.