Skip to content
OnTrackio

Privacy Policy

What personal data we handle, why, and the rights you have over it. Written to be read, not to hide behind.

Effective 25 June 2026 · Controller: OnTrackio ITAM UAB (Lithuania) · Contact privacy@ontrackio.com

1. Who we are and the two roles we play

This policy explains how OnTrackio ITAM UAB ("OnTrackio", "we", "us") handles personal data. We wear two hats:

  • Controller for data about our own prospects, customers, partners, and website visitors: the accounts, billing contacts, and email addresses we use to run the business.
  • Processor for the data our customers put into the platform about their own people. We handle that strictly on the customer's documented instructions under our Data Processing Agreement (DPA), which is requested and signed separately.

Sections 2 to 7 below describe the controller side. Section 8 summarises the processor side; the DPA governs it in full.

2. What we collect as controller, and why

Account and sign-up data. Your name, work email, workspace name, a hashed password, any MFA secrets or passkey credentials you enrol, and the IP address and browser user-agent of your sessions. We use this to provision and secure your workspace, contact you about your account, and detect fraud. Legal basis: performance of a contract (GDPR Article 6(1)(b)). Kept for the life of the account. After cancellation there is a 30-day grace period, after which the isolated per-tenant database is permanently dropped.

Billing data. Your billing email, subscription status, and invoice references. Full card data is held by Stripe and never reaches our systems; we do not see or store card numbers. We use this to manage your subscription and show your billing history. Legal basis: performance of a contract.

Email-delivery events. When we send a transactional email, we record the address plus bounce and complaint metadata so we stop emailing addresses that fail and comply with anti-spam rules. Legal basis: legitimate interest (Article 6(1)(f)). Kept for up to 180 days, then aggregate-only.

Website usage. This site sets no tracking or advertising cookies. To see how many people visit and which pages help, we use Cloudflare Web Analytics, a privacy-first, cookieless tool that counts visits without cookies, without cross-site tracking, and without building a profile of you. It records only aggregate signals such as page path, referrer, approximate country, and device type. Cloudflare, Inc. (US) processes this as our processor under its data-processing agreement and EU Standard Contractual Clauses. The site is served through AWS CloudFront for TLS and EU edge delivery, so a request also reaches our infrastructure with the usual transport metadata (your IP address and user-agent), used only for security and operations. Fonts are served from an EU-hosted, cookie-free provider. Legal basis for analytics and operations: legitimate interest (Article 6(1)(f)). We do not build a profile of you for marketing.

3. Where your data lives

All core platform data is stored in the workspace's home region: EU workspaces in AWS eu-central-1 (Frankfurt, Germany), US workspaces in AWS us-east-1 (N. Virginia, USA). The platform itself does not replicate a workspace's data across regions.

4. International transfers

A few narrow flows can leave the EU, each under EU Standard Contractual Clauses with supplementary measures:

  • Billing. Payment processing involves Stripe; billing contact details may be processed by Stripe under its Article 28 terms.
  • AI features (opt-in only). If you turn on an AI feature, the input you choose to send is processed by Anthropic (US). You can supply your own Anthropic key so the contract is directly yours, and Anthropic's API terms exclude that content from model training. AI features are off unless you enable them.
  • Website analytics. Cookieless visitor metrics from this website are processed by Cloudflare (US). No cookies, no cross-site tracking, no profile.

5. Sub-processors

We keep the current list of sub-processors, their purpose, and their region on our Security page. We give 30 days' notice before a material change so you can object, as set out in our DPA.

6. Your rights

Under the GDPR (Articles 12 to 22) you can ask us to give you access to your personal data, correct it, erase it, restrict or object to its processing, or hand it to you in a portable format. To exercise any of these:

  • Email your request to privacy@ontrackio.com, or
  • if you have a workspace account, export your own records in-app from your profile.

We respond within 30 days (Article 12(3)). If we process data your employer put into the platform, we'll route your request to them as the controller. You also have the right to complain to your local supervisory authority. In Lithuania, that is the State Data Protection Inspectorate (VDAI).

7. How long we keep things, and security

Retention in short: account and billing data for the life of the account; email-delivery events for up to 180 days, then aggregate-only; and the in-app audit log for your configured retention (365-day default, 30-day floor, configurable higher). Customer (tenant) data is kept for as long as the subscription is live. On cancellation, your workspace becomes read-only for a 30-day grace period during which you can export, after which the isolated per-tenant database is dropped, unless the law requires us to keep specific records.

Security measures include encryption at rest (AWS KMS) and in transit (TLS 1.2+), database-per-tenant isolation, role-based access control, enforced MFA, and an audit log on every change. More detail is on the Security page.

8. Data we process on your behalf

When you use the platform, you are the controller of your own people's records (employee and asset data, endpoint-agent telemetry, and anything you put into an AI feature), and we are your processor under the DPA. We minimise where we can: the endpoint agent does not collect browsing history, domains, or URLs, and AI features are off unless you enable them. Request the DPA from privacy@ontrackio.com.

9. Changes to this policy

We review this notice at least annually and when our data flows change materially. We'll post the updated version here with a new effective date. Questions go to privacy@ontrackio.com.