Privacy Policy

How orthogonal supersystems GmbH collects, processes, stores, discloses, and protects personal data across the ODE platform.

Last Updated: 30 August 2026

orthogonal supersystems GmbH (referred to as "Company", "we", "our", or "us") operates ODE (the "Service"). This Privacy Policy outlines the framework under which we collect, process, store, disclose, and protect personal data associated with your access to and use of our Service. This Privacy Policy applies to all users of the ODE platform, including account holders and visitors to our website. By accessing or using ODE, you agree to the practices described in this policy.

1. Information We Collect and Receive

We collect personal data directly from you, automatically through your interactions with the Service, and from authorized third-party sources.

1.1 Data Provided Directly by You

  • Account & Profile Data: Full name, business email address, job title, phone number, company/organization name, and authentication credentials created during registration.
  • Payment & Financial Records: Payment transactions are handled directly by PCI-DSS compliant third-party payment processors (e.g., Stripe). We do not store raw payment card numbers or authentication codes. We retain transaction history, billing addresses, tax identifiers (e.g., VAT IDs), and payment confirmation references strictly required for accounting, tax, and auditing compliance.
  • Customer Content & Prompts: Text, files, configurations, code, digital assets, and natural language prompts submitted, uploaded, or transmitted by users through our Service interface or AI entry point.
  • Support & Communication Records: Information provided when submitting support requests, responding to communications, or interacting with our support and sales teams. This includes call or video conference recordings conducted with prior consent for quality control and documentation purposes.

1.2 Data Collected Automatically

  • System & Technical Logs: Internet Protocol (IP) address, operating system, browser configuration, device identifiers, time-stamped access logs, error logs, and resource utilization metrics required for session authentication, rate limiting, and infrastructure security.
  • Essential Operation Tokens: We deploy strictly necessary session tokens and operational cookies required to manage user sessions, maintain system state, and secure platform operations. We do not employ third-party advertising trackers or cross-site behavioral analytics frameworks on our front-end interfaces.

1.3 Data from Other Sources

  • Enterprise Provisioning: If you access the Service under an organizational subscription or corporate domain, designated administrators may provide your business contact information to provision your user profile.

2. Processing in AI Entry Point & Backend Systems

2.1 Operational Purpose of AI Entry Point: Inputs and prompts submitted via the AI Entry Point are processed in real time solely to parse user instructions, map operational intent, and execute corresponding deterministic logic within our backend systems.

2.2 Prohibition on Model Training: Customer Content, business inputs, and prompt logs are NOT used by the Company or any third-party infrastructure vendor to train, retrain, evaluate, or improve public or commercial machine learning models.

2.3 Third-Party Infrastructure Safeguards: Where third-party model infrastructure or hosted APIs are utilized for language processing, all transfers take place strictly under binding Data Processing Agreements (DPAs) and European Commission Standard Contractual Clauses (SCCs). These agreements strictly prohibit third-party vendors from retaining, persisting, or utilizing Customer Content for secondary purposes beyond immediate instruction execution.

3. Purposes and Legal Bases for Processing

We process personal data strictly pursuant to valid legal bases defined under the GDPR:

  • Performance of a Contract: Managing user accounts, executing backend computations, processing subscription fees, providing technical support, and fulfilling contractual commitments.
  • Legitimate Interests: Maintaining infrastructure security, preventing fraudulent activity, enforcing system rate limits, and defending against technical abuse or unauthorized access.
  • Legal Compliance: Fulfilling statutory record-keeping, accounting, commercial, and tax obligations under applicable German and European law.

4. Disclosure and Sharing of Personal Data

We do not sell, rent, or commercialize personal data. Disclosures are restricted to the following operational scenarios:

  • Enterprise Workspace Administration: If your account is registered under a corporate domain or managed by an organization, designated administrators may access account profile data, usage logs, and administrative settings associated with accounts within that domain.
  • Vetted Sub-processors: We engage specialized service providers for cloud hosting, database management, billing infrastructure, and system monitoring. All sub-processors are bound by written DPAs requiring data protection standards fully compliant with GDPR.
  • Statutory and Official Requirements: We may disclose personal data where required by enforceable legal processes, judicial mandates, or valid governmental orders. In the event of a legal restructuring, merger, or acquisition, personal data will be transferred subject to ongoing confidentiality and data protection obligations.

5. Cross-Border Data Transfers

Personal data is primarily stored and processed within the European Union (EU) and European Economic Area (EEA). Where personal data is transferred to or accessed from jurisdictions outside the EEA that have not received an official adequacy decision, such transfers are governed by European Commission Standard Contractual Clauses (SCCs), supplemented by appropriate technical and organizational safeguards.

6. Security Architecture and Breach Protocol

6.1 Technical and Organizational Safeguards: We maintain technical and organizational security measures to protect personal data against unauthorized access, loss, destruction, or alteration. These measures include administrative access controls, secure network architecture, encryption mechanisms for data in transit and at rest, and regular system vulnerability management.

6.2 Data Breach Notification Protocol: In the event of a security incident resulting in a personal data breach that presents a risk to the rights and freedoms of natural persons, we will notify the competent supervisory authority and affected users within the mandatory statutory timeframes mandated by law.

7. Statutory Data Subject Rights

Under applicable European data protection legislation, you possess the following legal rights regarding your personal data:

  • Right of Access: Request confirmation as to whether your personal data is processed and obtain a copy of such data.
  • Right to Rectification: Request the rectification of inaccurate or incomplete personal data.
  • Right to Erasure: Request the deletion of your personal data where statutory grounds are met, subject to legal retention duties.
  • Right to Restriction of Processing: Request the restriction of data processing under defined statutory circumstances.
  • Right to Data Portability: Request the provision of your data in a structured, standard, machine-readable format.
  • Right to Object: Object to data processing based on legitimate interests on grounds relating to your particular situation.

To exercise your statutory rights, please direct your communication to info@orthogonal.dev. You also reserve the right to lodge a complaint with a competent Data Protection Supervisory Authority.

8. Policy Updates

We may update this Privacy Policy from time to time to reflect changes in legal, regulatory, technical, or operational requirements. Updated versions will be published on our website with a revised "Last Updated" date. Continued access to or use of the Service after any update constitutes acknowledgement of the revised Privacy Policy.

9. Data Controller and Contact Information

  • Data Controller: orthogonal supersystems GmbH
  • Legal Address: Lichtenbergstraße 8, 85748 Garching b. Munich, Germany
  • Contact: info@orthogonal.dev