orun
Legal

Privacy Policy Superseded

This version has been superseded. It stays readable as an immutable record of what was in force at the time.

Privacy Policy Version 2026-08 Effective 1 August 2026 Published 4 August 2026 Superseded 5 August 2026
You are reading a superseded version

Version 2026-08 is no longer the privacy policy in force. It remains readable because orders placed while it was current are bound to this exact text.

Effective 1 Aug 2026 Superseded 5 Aug 2026 0fb6d855ae324987…

Document control

Privacy Policy
Status Superseded
Kept as a historical record
Version 2026-08
Immutable once published
Effective Aug 1, 2026
Sat, 1 August 2026 00:00
Published Aug 4, 2026
Tue, 4 August 2026 23:49
Superseded Aug 5, 2026
Replaced by a newer version
At checkout Acceptance required
Every order records acceptance of this policy
Length 1,250 words
About 7 minutes to read (estimate, 200 wpm)
Content fingerprint — SHA-256 0fb6d855ae3249872dbb46038456e3867d11167ec896fe5702fcfcca13fb65b5
Immutable

Policy text

1,250 words
ORUN PRIVACY POLICY Version 2026-08 Effective 1 August 2026 This policy explains what personal data Orun holds about you, why, who else sees it, and what you can do about it. It describes what the platform actually does rather than what is customary. The data controller is [LEGAL ENTITY NAME], a company registered in Ghana with company number [COMPANY NUMBER], whose registered address is [REGISTERED ADDRESS]. We process personal data in line with the Data Protection Act, 2012 (Act 843). 1. WHAT WE COLLECT 1.1 Account details. Your name, email address, phone number if you give one, and your password, which is stored only as a hash we cannot reverse. If you enable two-factor authentication we store its secret and your recovery codes, hashed. 1.2 Organisation details. The workspace name, its members and their roles. 1.3 Billing records. Orders, invoices, payments, refunds and ledger entries, along with the billing details you enter. 1.4 Payment metadata — but never your card. Card payments happen on the payment provider's own pages. Your card number never reaches Orun and we cannot store it. We keep the transaction reference, amount, currency, payment channel, fees and the time it was paid. 1.5 Consent evidence. When you accept a policy we record which version you accepted, when, and the IP address you accepted it from. 1.6 Sign-in security data. Trusted devices you approve, including the IP address and user agent they were approved from. 1.7 Support data. Your tickets and every message in them. 1.8 Activity records. An audit trail of significant actions taken in the account, and who took them. 1.9 Infrastructure data. Details of the servers and buckets you order — names, regions, sizes, images, and the SSH public keys you supply. Where your servers run our monitoring agent we also receive the metrics and log lines it sends. 1.10 Contact form enquiries. If you use the form on our site we receive your name, email, optional phone number and message. That enquiry is sent to us by email and is not stored in the platform database. 2. WHY WE HOLD IT We hold this data to provide the services you order, to take payment and keep proper financial records, to support you, to secure the platform and investigate misuse, and to meet our legal obligations. Consent evidence exists so that both of us can show what was agreed. 3. WHO ELSE RECEIVES IT 3.1 Paystack, our payment provider. When you pay we send the payment reference, the amount, the currency and your email address. Your card details go to Paystack directly and never through us. 3.2 Resend, our email provider. Every email we send you passes through them — the recipient address and the full message. That includes password resets, invoices, service notices and contact form enquiries. 3.3 DigitalOcean, our infrastructure provider. To create a server we send the server name, region, size, image and the cloud-init configuration. That configuration contains your SSH public keys, and where you chose password access, a hash of the root password. Server names are derived from your organisation's name. 3.4 DigitalOcean Spaces, our object storage. This holds your buckets and their contents, and separately our own generated invoices, encrypted data exports and encrypted database backups. We do not sell personal data and we do not share it for advertising. 4. WHERE IT IS HELD 4.1 You choose the region for each service you order, from Amsterdam, London, Frankfurt, New York and Singapore. Your server's contents and your buckets live in the region you picked. 4.2 The Orun platform itself — the application and its database — runs in Amsterdam, the Netherlands. 4.3 This means personal data is transferred outside Ghana. Where you are in the European Economic Area or the United Kingdom, data you place in the Amsterdam, London or Frankfurt regions stays within it. 5. HOW LONG WE KEEP IT We are specific here because vague retention promises are unverifiable. 5.1 Data exports you request are deleted 24 hours after they are generated. An export that failed is cleared after 7 days. 5.2 Log lines shipped by the monitoring agent are deleted after 14 days. 5.3 When you cancel a service, access ends after 7 days and the underlying resources and contents are deleted 14 days after that. 5.4 Account and organisation records are kept while your account is open. 5.5 Billing records — orders, invoices, payments, refunds and ledger entries — are kept after an account closes, because we are required to keep financial records and because they evidence transactions that actually happened. 5.6 Consent evidence, support tickets and the activity audit trail are retained. We are working towards defined limits for these; until we publish one, treat them as retained indefinitely rather than assume a period we do not enforce. 6. YOUR RIGHTS 6.1 Access and portability. You can request a copy of your personal data from your profile page. We generate an encrypted JSON export and give you a private download link. The link expires after 24 hours and the file is then deleted. You may request up to three exports an hour. 6.2 Erasure. You can request erasure from your profile page. You must confirm it and give a reason. The request is reviewed by a person — you cannot erase your own account unilaterally, which protects accounts against a compromised session doing it for you. You may cancel the request while it is pending. 6.3 What erasure actually does, stated plainly. We delete your API tokens, trusted devices, SSH keys, preferences, two-factor settings and notifications, and we remove you from every organisation and role. We then pseudonymise your user record: your name becomes "Deleted user", your email is replaced with an address that cannot receive mail, and the account is deactivated. 6.4 What erasure does not do. It does not delete your billing records, your consent evidence including the IP address you accepted from, your support messages, or the audit trail. We keep those for the reasons in clause 5.5, and because deleting them would destroy the record of transactions and agreements that both parties may need to rely on. If that distinction matters to you, please ask us before requesting erasure. 6.5 Correction. You can change your account details from your profile at any time. For anything you cannot edit yourself, email us. 6.6 Complaints. You may complain to us at [email protected], and to the Data Protection Commission of Ghana. 7. IP ADDRESSES AND COOKIES 7.1 We record IP addresses when you accept a policy and when you approve a trusted device. We say so explicitly because it is easy to assume otherwise. 7.2 We use cookies that are necessary for the site to work — keeping you signed in and protecting forms against cross-site request forgery. Session cookies are encrypted. We do not use advertising cookies. 8. SECURITY 8.1 Traffic to orunhq.com is encrypted in transit. The connection to our database is encrypted and its certificate is verified. 8.2 Passwords are stored as hashes. Provider credentials and two-factor secrets are encrypted at rest. Data exports and database backups are encrypted. 8.3 No system is perfectly secure. If a breach affects your personal data we will tell you and the Data Protection Commission as the Act requires. 9. CHANGES We may publish a new version of this policy. The version in force is always at orunhq.com/legal/privacy, and published versions are never edited — each is kept at its own address. 10. CONTACT Privacy questions and requests [email protected] Postal [REGISTERED ADDRESS]

Version history

2 versions
Version Status Effective Published Superseded Fingerprint Actions
Version 2026-09 Privacy Policy In force Checkout 5 Aug 2026 5 Aug 2026 3b7425169f9e…
Version 2026-08 You are reading this Superseded Checkout 1 Aug 2026 4 Aug 2026 5 Aug 2026 0fb6d855ae32…

Policy set

3 of 5 in force
Terms of Service Version 2026-09 · effective 5 Aug 2026
Checkout In force
Privacy Policy You are reading version 2026-08 · version 2026-09 is the one in force
Checkout This page
Refund Policy Version 2026-09 · effective 5 Aug 2026
Checkout In force
Acceptable Use Policy No version has been published yet
Not published
Service Level Agreement No version has been published yet
Not published

Related actions

Sign in See which version of this policy your account accepted, and when
Create an account Acceptance is captured at checkout against this exact text

Orun · Privacy Policy version 2026-08 · 0fb6d855ae3249872dbb46038456e3867d11167ec896fe5702fcfcca13fb65b5