Orq AI B.V. ("the Company," "we," "us," or "our") (Blaak 40, Floor 8, 3011 AA Rotterdam, Netherlands) is the data controller for personal data processed through getorqai.com. This policy explains what we process, why, and what rights you have under the General Data Protection Regulation (GDPR) and the Dutch UAVG implementation. For any data-protection matter, including to exercise your rights, contact us at [email protected].
Orq AI is an AI agent observability platform. Platform engineers instrument their agent code with the Orq SDK, which captures execution traces and spans. Those traces contain LLM prompts and completions, tool-call arguments and results, latency and token metrics, and eval run scores. This data is submitted by customers who operate their own products using our infrastructure.
1. Two Roles: Controller and Processor
Orq AI operates in two distinct data-protection roles depending on whose data is involved:
- Data controller - for account holder data (names, work email addresses, org memberships, login records, billing information, support correspondence) that customers provide directly to Orq AI to create and manage their accounts.
- Data processor - for trace content submitted by customers through the SDK. This includes execution spans, LLM prompt and completion payloads, tool-call arguments, eval suite definitions, and scored eval run data. The customer is the data controller for this content. Orq AI processes it solely on the customer's instructions, under the terms of our data-processing agreement, to provide the tracing and evaluation service.
The remainder of this section describes our processing as data controller. For processing where you are a customer acting as controller, the data-processing agreement governs.
2. Personal Data We Process as Controller
When you create an account, use the platform, or contact us, we process:
- Account data: name, work email address, organisation membership, role within your team;
- Authentication and audit records: login timestamps, session identifiers, API key identifiers (not the key values themselves);
- Billing data: payment method and transaction records handled via our payment processor;
- Support and correspondence: messages, requests, and responses exchanged with our team;
- Technical and usage data collected automatically: IP address, browser type, operating system, pages visited on getorqai.com, and (with your consent) analytics data on how the dashboard is used.
3. Trace Content and Third-Party Personal Data
Agent traces submitted to Orq AI through the SDK may contain whatever content a customer's own end users provide to that customer's product. For example, if a customer's agent processes user messages, those messages - and any personal data they contain - may appear in the prompt or completion payload captured in a trace.
Orq AI processes this trace content strictly as a data processor on the customer's behalf. We do not read, analyse, or make use of trace payloads for any purpose other than storing and displaying them to the authorised users of the customer's Orq AI account. We do not use prompt or completion content from customer traces to train or improve Orq AI's own models, to provide services to other customers, or for any purpose beyond operating the tracing service for that specific customer.
Customers can limit the personal data reaching Orq AI by redacting or omitting sensitive fields at instrumentation time before the SDK submits a span. Orq AI's SDK documentation describes how to filter or mask payload fields.
Trace data is subject to tier-dependent retention: Free plan traces are retained for 7 days, Pro plan traces for 30 days, and Scale plan customers may negotiate a custom retention period. After the applicable retention window, trace data is deleted from active storage.
4. Purposes and Legal Bases (Article 6 GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the tracing, eval, and release-gating service to account holders | Performance of contract (Art. 6(1)(b)) |
| Responding to inquiries and support requests | Pre-contract steps / legitimate interest (Art. 6(1)(b)/(f)) |
| Operating, securing, and improving the platform | Legitimate interest (Art. 6(1)(f)) |
| Billing and payment processing | Performance of contract (Art. 6(1)(b)) |
| Legal compliance and fraud prevention | Legal obligation (Art. 6(1)(c)) / legitimate interest (Art. 6(1)(f)) |
| Analytics cookies and usage measurement | Consent (ePrivacy Directive + Art. 6(1)(a)) |
5. Recipients and International Transfers
Personal data is shared only with processors acting on our behalf under Article 28 GDPR data-processing agreements. These processors fall into functional categories: cloud infrastructure hosting (servers located in the EU/EEA), transactional email delivery, payment processing, and, with consent, analytics. We do not sell personal data to third parties and do not share it with advertisers.
Where data is transferred outside the EU/EEA - for example, where a processor operates infrastructure in a third country - we rely on Standard Contractual Clauses (Art. 46 GDPR) and assess the need for supplementary measures in light of the Schrems II ruling.
6. Retention
Account holder data is retained for the duration of the account and for up to 36 months after closure, to the extent required for legal or contractual obligations. Support correspondence is retained for 24 months after the inquiry is closed. Server access logs are retained for 90 days. Trace and eval data follows the tier-dependent retention periods described in Section 3.
7. Your GDPR Rights
- Right of access (Art. 15) - confirm whether we process your personal data and obtain a copy;
- Right to rectification (Art. 16) - correct inaccurate or incomplete data;
- Right to erasure / "right to be forgotten" (Art. 17) - request deletion, subject to limited exceptions for legal obligations;
- Right to restriction of processing (Art. 18) - request that we limit how we use your data while a dispute is resolved;
- Right to data portability (Art. 20) - receive account data in a structured, machine-readable format;
- Right to object (Art. 21) - object to processing based on legitimate interest, including direct marketing without further conditions;
- Right not to be subject to automated decision-making (Art. 22) - we do not engage in automated decision-making with legal or similarly significant effects on individuals.
To exercise any right, email [email protected]. We will respond within one calendar month, extendable by two further months for complex or numerous requests.
8. Right to Lodge a Complaint
You have the right to lodge a complaint with your national supervisory authority. For users in the Netherlands, the competent authority is the Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl). A full list of EU/EEA supervisory authorities is available at edpb.europa.eu.
9. Cookies
See our Cookie Policy. Non-essential cookies - including analytics cookies - are not set until you give prior consent through our cookie banner, in line with the ePrivacy Directive as implemented in Dutch law (Telecommunicatiewet).
10. Security
We implement technical and organisational measures appropriate to the risk, including TLS encryption in transit, encrypted storage, access controls limited to personnel who need the data to perform their role, and periodic review of our security practices.
11. Changes to This Policy
Material changes will be reflected by an updated "Last updated" date at the top of this page. Where required under GDPR, we will seek renewed consent before processing personal data in a new way.
12. Contact
Orq AI B.V.Blaak 40, Floor 8
3011 AA Rotterdam
Netherlands
Email: [email protected]
Phone: +31 10 340 7120