Legal
Privacy Policy Superseded
This version has been superseded. It stays readable as an immutable record of what was in force at the time.
You are reading a superseded version
Version 2026-08 is no longer the privacy policy in force. It remains readable because orders placed while it was current are bound to this exact text.
Superseded
Current version 2026-09
Document control
Privacy Policy
Status
Superseded
Kept as a historical record
Version
2026-08
Immutable once published
Effective
Aug 1, 2026
Sat, 1 August 2026 00:00
Published
Aug 4, 2026
Tue, 4 August 2026 23:49
Superseded
Aug 5, 2026
Replaced by a newer version
At checkout
Acceptance required
Every order records acceptance of this policy
Length
1,250 words
About 7 minutes to read (estimate, 200 wpm)
Content fingerprint — SHA-256
0fb6d855ae3249872dbb46038456e3867d11167ec896fe5702fcfcca13fb65b5
Immutable
Policy text
1,250 wordsORUN PRIVACY POLICY
Version 2026-08
Effective 1 August 2026
This policy explains what personal data Orun holds about you, why, who else
sees it, and what you can do about it. It describes what the platform
actually does rather than what is customary.
The data controller is [LEGAL ENTITY NAME], a company registered in Ghana
with company number [COMPANY NUMBER], whose registered address is
[REGISTERED ADDRESS]. We process personal data in line with the Data
Protection Act, 2012 (Act 843).
1. WHAT WE COLLECT
1.1 Account details. Your name, email address, phone number if you give
one, and your password, which is stored only as a hash we cannot
reverse. If you enable two-factor authentication we store its secret
and your recovery codes, hashed.
1.2 Organisation details. The workspace name, its members and their roles.
1.3 Billing records. Orders, invoices, payments, refunds and ledger
entries, along with the billing details you enter.
1.4 Payment metadata — but never your card. Card payments happen on the
payment provider's own pages. Your card number never reaches Orun and
we cannot store it. We keep the transaction reference, amount,
currency, payment channel, fees and the time it was paid.
1.5 Consent evidence. When you accept a policy we record which version you
accepted, when, and the IP address you accepted it from.
1.6 Sign-in security data. Trusted devices you approve, including the IP
address and user agent they were approved from.
1.7 Support data. Your tickets and every message in them.
1.8 Activity records. An audit trail of significant actions taken in the
account, and who took them.
1.9 Infrastructure data. Details of the servers and buckets you order —
names, regions, sizes, images, and the SSH public keys you supply.
Where your servers run our monitoring agent we also receive the
metrics and log lines it sends.
1.10 Contact form enquiries. If you use the form on our site we receive
your name, email, optional phone number and message. That enquiry is
sent to us by email and is not stored in the platform database.
2. WHY WE HOLD IT
We hold this data to provide the services you order, to take payment and
keep proper financial records, to support you, to secure the platform and
investigate misuse, and to meet our legal obligations. Consent evidence
exists so that both of us can show what was agreed.
3. WHO ELSE RECEIVES IT
3.1 Paystack, our payment provider. When you pay we send the payment
reference, the amount, the currency and your email address. Your card
details go to Paystack directly and never through us.
3.2 Resend, our email provider. Every email we send you passes through
them — the recipient address and the full message. That includes
password resets, invoices, service notices and contact form enquiries.
3.3 DigitalOcean, our infrastructure provider. To create a server we send
the server name, region, size, image and the cloud-init configuration.
That configuration contains your SSH public keys, and where you chose
password access, a hash of the root password. Server names are derived
from your organisation's name.
3.4 DigitalOcean Spaces, our object storage. This holds your buckets and
their contents, and separately our own generated invoices, encrypted
data exports and encrypted database backups.
We do not sell personal data and we do not share it for advertising.
4. WHERE IT IS HELD
4.1 You choose the region for each service you order, from Amsterdam,
London, Frankfurt, New York and Singapore. Your server's contents and
your buckets live in the region you picked.
4.2 The Orun platform itself — the application and its database — runs in
Amsterdam, the Netherlands.
4.3 This means personal data is transferred outside Ghana. Where you are
in the European Economic Area or the United Kingdom, data you place in
the Amsterdam, London or Frankfurt regions stays within it.
5. HOW LONG WE KEEP IT
We are specific here because vague retention promises are unverifiable.
5.1 Data exports you request are deleted 24 hours after they are
generated. An export that failed is cleared after 7 days.
5.2 Log lines shipped by the monitoring agent are deleted after 14 days.
5.3 When you cancel a service, access ends after 7 days and the underlying
resources and contents are deleted 14 days after that.
5.4 Account and organisation records are kept while your account is open.
5.5 Billing records — orders, invoices, payments, refunds and ledger
entries — are kept after an account closes, because we are required to
keep financial records and because they evidence transactions that
actually happened.
5.6 Consent evidence, support tickets and the activity audit trail are
retained. We are working towards defined limits for these; until we
publish one, treat them as retained indefinitely rather than assume a
period we do not enforce.
6. YOUR RIGHTS
6.1 Access and portability. You can request a copy of your personal data
from your profile page. We generate an encrypted JSON export and give
you a private download link. The link expires after 24 hours and the
file is then deleted. You may request up to three exports an hour.
6.2 Erasure. You can request erasure from your profile page. You must
confirm it and give a reason. The request is reviewed by a person —
you cannot erase your own account unilaterally, which protects
accounts against a compromised session doing it for you. You may
cancel the request while it is pending.
6.3 What erasure actually does, stated plainly. We delete your API tokens,
trusted devices, SSH keys, preferences, two-factor settings and
notifications, and we remove you from every organisation and role. We
then pseudonymise your user record: your name becomes "Deleted user",
your email is replaced with an address that cannot receive mail, and
the account is deactivated.
6.4 What erasure does not do. It does not delete your billing records,
your consent evidence including the IP address you accepted from, your
support messages, or the audit trail. We keep those for the reasons in
clause 5.5, and because deleting them would destroy the record of
transactions and agreements that both parties may need to rely on. If
that distinction matters to you, please ask us before requesting
erasure.
6.5 Correction. You can change your account details from your profile at
any time. For anything you cannot edit yourself, email us.
6.6 Complaints. You may complain to us at [email protected], and to the
Data Protection Commission of Ghana.
7. IP ADDRESSES AND COOKIES
7.1 We record IP addresses when you accept a policy and when you approve a
trusted device. We say so explicitly because it is easy to assume
otherwise.
7.2 We use cookies that are necessary for the site to work — keeping you
signed in and protecting forms against cross-site request forgery.
Session cookies are encrypted. We do not use advertising cookies.
8. SECURITY
8.1 Traffic to orunhq.com is encrypted in transit. The connection to our
database is encrypted and its certificate is verified.
8.2 Passwords are stored as hashes. Provider credentials and two-factor
secrets are encrypted at rest. Data exports and database backups are
encrypted.
8.3 No system is perfectly secure. If a breach affects your personal data
we will tell you and the Data Protection Commission as the Act
requires.
9. CHANGES
We may publish a new version of this policy. The version in force is always
at orunhq.com/legal/privacy, and published versions are never edited — each
is kept at its own address.
10. CONTACT
Privacy questions and requests [email protected]
Postal [REGISTERED ADDRESS]
Version history
2 versionsPolicy set
3 of 5 in force
Terms of Service
Version 2026-09 · effective 5 Aug 2026
Checkout In force
Privacy Policy
You are reading version 2026-08 · version 2026-09 is the one in force
Checkout This page
Refund Policy
Version 2026-09 · effective 5 Aug 2026
Checkout In force
Acceptable Use Policy
No version has been published yet
Not published
Service Level Agreement
No version has been published yet
Not published
Related actions
Orun · Privacy Policy version 2026-08 · 0fb6d855ae3249872dbb46038456e3867d11167ec896fe5702fcfcca13fb65b5