Privacy Policy
This Privacy Policy explains how we collect, use, store, and protect your personal data when you access the ORR Client Portal, Admin Portal, or any ORR-associated digital service.
INTRODUCTION
ORR Network ("ORR", "we", "us") operates a digital platform that provides strategic consultation services, personalised business workspaces, document generation, Data Structure (DS) modules, and associated administrative functions. This Privacy Policy explains how we collect, use, store, and protect your personal data when you access the ORR Client Portal, Admin Portal, or any ORR-associated digital service.
By using our platform, you acknowledge that you have read and understood this Privacy Policy.
WHO WE ARE
ORR Network is a consultancy and digital systems operator delivering:
- Online business consultations
- Personalised DS-driven workspaces
- Document vault and report generation
- Behaviour-based insights
- Subscription and retainer-based services
For all data processed directly through the platform, ORR is the Data Controller under the GDPR.
You may contact us at: privacy@orr.solutions
DATA WE COLLECT
We collect only the data required to provide our services. Depending on your engagement with the platform, ORR may process the following categories:
3.1 Account & Identity Data
- Full name
- Email address
- Phone number (optional)
- Country of residence / jurisdiction
- Preferred language
Used for: authentication, communication, and account identification.
3.2 Business & Profile Data
- Business name
- Sector and subsector
- Business stage
- Business description
- DS-required structured data fields
Used for: DS personalisation, consultations, workspace tools.
3.3 Consultation Data
- Meeting bookings
- Consultation notes
- Transcriptions (only with your consent or explicit initiation)
- Follow-up documentation
- Uploaded materials
Used for: generating consultation summaries, reports, and improvement recommendations.
3.4 Financial & Billing Data
- Wallet balance
- Transaction logs
- Deposit confirmations
- Subscription status
- Approvals of pro-data deductions
- Invoice records
Used for: billing, accounting, audit, and contractual obligations.
3.5 Behavioural Data
Collected only inside the ORR platform:
- Pages and modules visited
- Time spent in sections
- Tools accessed
- Workspace actions
- Browsing patterns that inform domain interests
Used for: personalisation, recommended tools, content surfacing, and UI optimisation.
We do not use third-party tracking (Google Ads, Facebook pixels, etc.).
3.6 System & Technical Data
- IP address
- Device/browser information
- Login timestamps
- Error logs
- System performance events
Used for: security, fraud prevention, and operational monitoring.
HOW WE COLLECT DATA
We collect data through:
- Direct user input (forms, uploads, metadata entry)
- Consultation interactions (notes, outputs, statements)
- System-generated data (logs, timestamps, billing events)
- Behavioural interpretation (within the portal only)
- Subscription and billing events
We do not buy external data. We do not scrape data from other platforms.
WHY WE PROCESS DATA (PURPOSES)
We process data only for legitimate and clearly defined purposes:
5.1 Service Delivery
- Account creation
- Consultations
- DS-powered workspace tools
- Report generation
- Document vault access
5.2 Personalisation
- Behaviour-driven recommendations
- Suggested tools and templates
- Contextual dashboard insights
5.3 Contractual Performance
- Retainer administration
- Meeting scheduling
- Report creation
- Subscription operations
5.4 Administrative Operations
- Billing and payment approvals
- Wallet management
- Support ticketing
- System notifications
5.5 Legal Compliance
- Tax and accounting requirements
- Security obligations
5.6 Legitimate Interests
- Service improvement
- Platform analytics
- Preventing fraud or misuse
LEGAL BASIS FOR PROCESSING
We rely on:
6.1 Contract Necessity
When processing is required to deliver the services you request.
6.2 Legitimate Interests
For:
- Platform optimisation
- Internal analytics
- Non-intrusive behaviour tracking
Always balanced with your privacy rights.
6.3 Consent
For:
- Cookies
- Optional behaviour-based personalisation
- Meeting recordings/transcriptions (if used)
6.4 Legal Obligation
For:
- Invoice retention
- Accounting compliance
- Security event logging
DATA RETENTION
Revised to align with GDPR minimisation principles.
| Data Category | Retention Period | Notes |
|---|---|---|
| Consultation Reports | 5 years | No fixed legal requirement; 5 years covers dispute windows. |
| Behavioural Data | 12 months | Longer storage unnecessary for personalisation. |
| System Logs | 12–18 months | Sufficient for operational and security audits. |
| Support Tickets | 3 years | Industry standard for SaaS operational records. |
| Uploaded Documents | 24 months of inactivity or on request | Unless required for financial/legal reasons. |
| Financial Records (Invoices) | 10 years | Mandatory EU accounting rule. |
You may request deletion of any data not subject to legal or contractual retention.
DATA SHARING
We share data only when necessary:
8.1 Internal Roles (Role-Based Access)
- Operators: client support & consultation processing
- Administrators: billing, DS assignment, system management
- Super Admin: platform governance
- Content Editors: content publishing only
Access is strictly limited to required operational scope.
8.2 External Processors (GDPR-Compliant)
- Payment processors
- Secure document storage
- Analytics tools (internal, non-marketing)
All third-party processors operate under a signed Data Processing Agreement (DPA).
8.3 Legal Authorities
Only when legally required.
We never sell personal data.
We never share behavioural data with advertisers.
SECURITY MEASURES
We implement:
- Role-based access control (RBAC)
- Encrypted storage
- Secure communication channels
- Audit logs
- System monitoring
- MFA (optional for clients, enforced for administrators)
- Regular access reviews
YOUR RIGHTS UNDER GDPR
You may exercise:
- Right of Access
- Right to Rectification
- Right to Erasure
- Right to Restrict Processing
- Right to Data Portability
- Right to Object
- Right to Withdraw Consent
Contact: privacy@orr.solutions
COOKIES & ONLINE IDENTIFIERS
We use:
- Essential cookies (required for login and security)
- Preference cookies
- Platform analytics cookies (internal only)
No advertising or cross-site tracking cookies are used.
Users may decline non-essential cookies.
AUTOMATED DECISION-MAKING
ORR does not use automated decision-making that produces legal or significant effects.
Behaviour-based insights in the dashboard are assistive only.
INTERNATIONAL DATA TRANSFERS
If data leaves the EEA, it is protected by:
- Adequacy decisions, or
- Standard Contractual Clauses (SCCs)
We ensure equivalent protection for all transfers.
UPDATES TO THIS POLICY
We may update this Privacy Policy to reflect:
- Legal changes
- Platform changes
- New DS modules
- New services
Major updates will be communicated within the portal.
CONTACT
ORR Network
Website: www.orr.solutions
Email: privacy@orr.solutions