Privacy and data processing
Last updated: 3 October 2026
Here we explain who is responsible for each piece of data. There are two different situations: the data of people who visit this site, and the data a customer processes with the platform, for which the customer itself is the controller.
Who is behind this site
This site is operated by the Orkestfy project. The company that will back it is being set up. Until it exists, the controller of the data processed on this site is the project promoter, who you can write to at info@orkestfy.ai.
As soon as the company is incorporated we will state its name, tax ID and address here.
Data of people who visit this site (we are the controller)
We process the minimum data needed for three things:
- Measuring visits. We use a European, cookieless analytics tool (Plausible) that counts page views and actions such as booking a demo, without storing IP addresses or personal identifiers and without following anyone across sites. It tells us which pages are useful. Legal basis: legitimate interest (Art. 6.1(f) GDPR), with minimal impact on your privacy.
- Answering your email. If you write to info@orkestfy.ai we use your message and address only to reply. Legal basis: your request (pre-contractual steps) and, where applicable, your consent. We keep it while the conversation lasts and afterwards for as long as the law requires.
- Booking a demo. The booking link takes you to Microsoft (Bookings), where you enter your name, email and company. Microsoft processes them as a provider under its own privacy statement; we use them only to arrange the meeting with you.
No cookies
This site does not use cookies. It only stores in your browser three technical items that depend on you, do not identify you and are not sent to any server: the light or dark theme (ofy_theme), the language you pick with the switch (ofy_lang_choice) and a mark that you have already seen the opening animation during this session (ofy_intro). They are needed for the site to work the way you ask, so no cookie notice is required.
Data our customers process with the platform (we are the processor)
When a company, association or firm uses Orkestfy, all the personal data it uploads or that its agents process (about employees, customers, suppliers, members…) is the responsibility of that organisation: it decides what the data is used for and how. Orkestfy acts as data processor (Art. 28 GDPR).
This is formalised in a data processing agreement, signed before the service starts. Among other things it provides that:
- We process data only on the customer’s documented instructions and to deliver the service.
- Data and AI run in European Union data centres. If a customer chooses a model or tool provider that processes data outside the EU, this is agreed and documented with them beforehand.
- Each department, location, country or client stays in its own isolated space, and every agent action is logged so it can be audited.
- Orkestfy staff access data only when needed to provide support, under a duty of confidentiality.
- Sub-processors (the infrastructure and model providers involved in the service) are disclosed to the customer, along with any change.
- We help the customer respond to data subjects’ rights. If someone writes to us about data we process on behalf of a customer, we refer them to that customer.
- We notify the customer without undue delay if we detect a security breach affecting their data.
- When the service ends we return or delete the data, as the customer decides.
Associations and their members
When an association offers Orkestfy to its members, each winery is responsible for the data in its own space (products, labels, orders, customers), which is isolated from other wineries and from the association itself. The shared knowledge (regulations, calendar, guides) is decided and maintained by the association.
Your rights
Where we process your data as controller, you can ask us for access, rectification, erasure, restriction, portability and object to the processing by writing to info@orkestfy.ai. If you think we have not handled your request properly you can complain to the Spanish Data Protection Agency (www.aepd.es) or to the supervisory authority of your country.
Changes
We will update this page when something important changes, and the date above will reflect it.