Legal

Privacy & Data Policy

Last updated: 18 June 2026  ·  Version 2.0  ·  UK GDPR

1. Who We Are

Automyx Ltd (trading as Orkestriq), a company registered in England and Wales (company number 17274298) with its registered office at 3 Avantgarde Place, London, E1 6GU ("Orkestriq", "we", "us", "our"), provides an event-management platform used by event organisers to register attendees, issue badges, manage check-in and agendas, generate visa-support and invitation letters, send event communications, and provide an AI event assistant. Orkestriq is a product of Automyx Ltd.
We are registered with the UK Information Commissioner's Office (ICO). Registration number: ZC177352.
We currently offer the platform to event organisers in the United Kingdom and in African markets. The Services are not directed at, or marketed to, organisers or attendees in the European Economic Area, and we do not knowingly onboard EEA-based organisers. If we begin offering the Services in the EEA, we will appoint a representative under Article 27 of the EU GDPR and update this policy before doing so.
Privacy enquiries and data-protection requests: privacy@automyx.io.

2. Our Two Roles

Orkestriq processes personal data in two distinct capacities. It is important to understand which applies to you.
We are the Controller
For data about our direct customers (event organisers and their administrator users), website visitors, billing contacts, and marketing recipients. This policy governs that data.
We are the Processor
For data about attendees/delegates that an organiser collects and manages through Orkestriq (registration details, passport and travel data, dietary needs, etc.). Here the event organiser is the Controller and decides why and how the data is used. We process it only on their instructions under our Data Processing Agreement.
If you are an attendee The organiser of the event you registered for is responsible for your data and for giving you a privacy notice. This policy explains how we handle that data on their behalf. To exercise your rights, contact the organiser; we will assist them. You may also contact us at privacy@automyx.io.

3. Data We Collect and Why

3.1 Customer & account data (we are Controller).
CategoryDataPurposeLawful Basis
Identity & contactName, work email, organisation, roleAccount creation, administration, communicationsContract (Art. 6(1)(b))
Usage & technicalFeature usage, session logs, device/browser info, IP addressOperating, securing and improving the serviceLegitimate interests (Art. 6(1)(f))
BillingBilling contact, invoice recordsInvoicing, accounting, taxContract / Legal obligation (Art. 6(1)(c))
SupportSupport messages, feedbackResponding to enquiriesLegitimate interests
MarketingWork emailProduct updates (opt-in / soft opt-in)Consent / Legitimate interests
3.2 Attendee data (we are Processor; the organiser is Controller). Organisers may, at their discretion, collect the following about attendees through Orkestriq. The lawful basis for this data is determined by the organiser.
CategoryDataPurpose (set by organiser)
Identity & contactFirst/last name, email, phone, organisation, job title, country/nationalityRegistration, badging, communications
Travel & identity documentsPassport number, passport expiry, date of birthGenerating visa-support / invitation letters
Dietary & accessibilityDietary requirements, free-text notesCatering and logistics (see §4)
AttendanceQR badge identifier, check-in records, session attendanceOn-site access and analytics
NetworkingConnection requests and messages between attendeesIn-event networking features
AI assistantQuestions submitted to the in-portal assistantAnswering attendee queries (see §5)
We do not collect payment card details from attendees. We do not currently take card payments from organisers in-platform; where billing applies, it is handled by invoice or a third-party payment provider under their own privacy policy.

4. Special Category Data

Dietary requirements, accessibility needs, and free-text notes can reveal information about a person's religious beliefs or health. This is "special category data" under Article 9 UK GDPR and is given extra protection.
Where an organiser chooses to collect this data through Orkestriq, the organiser (as Controller) is responsible for establishing a valid Article 9 condition (typically the attendee's explicit consent) and for telling attendees how it will be used. We process special category data only on the organiser's documented instructions and solely to deliver the catering and logistics functions of the service. We do not use it for any other purpose.

5. The AI Event Assistant

The attendee portal includes an optional AI assistant that answers questions about the event (programme, logistics, visa and travel guidance). When an attendee sends a message, that message, together with the event's published programme and knowledge base, is transmitted to our AI sub-processor, OpenAI, to generate a reply.
OpenAI processes this data under its API terms and does not use data submitted via its API to train its models. We do not use attendee content to train any AI model. Attendees should avoid pasting sensitive personal data into the assistant; replies are AI-generated and may be inaccurate, so they should be verified for important decisions.

6. How We Use Data

Acting as Controller of customer and account data, we use it to:
  • Create, administer and secure organiser accounts
  • Provide, operate and improve the platform
  • Send transactional communications (account, service and security notices)
  • Send marketing communications where permitted (you can opt out at any time)
  • Detect and prevent fraud, abuse and security incidents
  • Comply with legal, accounting and regulatory obligations
  • Establish, exercise or defend legal claims
Acting as Processor of attendee data, we use it only to provide the service to the organiser, on their documented instructions.

7. How Long We Keep Data

Data typeRetention period
Organiser account dataDuration of the account + 2 years after closure
Attendee data (incl. registration, networking)For the duration set by the organiser; deleted or returned within 30 days of the organiser instructing us or closing the event, unless retention is required by law
Passport / date-of-birth / visa-letter dataDeleted promptly after the event (or once the visa-support purpose is fulfilled), on the organiser's instruction
Usage & security logs12 months
Billing & accounting records7 years (legal obligation)
Marketing consent recordsUntil withdrawn

8. Who We Share Data With

We share data only as necessary, with sub-processors acting under written data-protection terms:
  • Supabase: database, authentication and file storage
  • Vercel: application hosting and content delivery
  • OpenAI: the AI event assistant (see §5)
  • Resend: transactional and event email delivery
  • Legal and regulatory authorities: where required by law or court order
  • A successor: in a merger, acquisition or sale of the business, subject to this policy
We never sell personal data. Our current, full sub-processor list, including each provider's role and location, is at orkestriq.io/sub-processors.html.

9. International Transfers

Orkestriq serves organisers and attendees in the UK and Africa, our primary datastore is hosted in the EU, and some of our sub-processors are located in the United States. This means personal data may be transferred across borders.
Where we transfer personal data out of the UK or the EEA, we put appropriate safeguards in place, which may include:
  • The UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses;
  • The EU Standard Contractual Clauses (SCCs); and
  • Reliance on an adequacy decision where one applies.
Organisers in Africa and elsewhere remain responsible for compliance with the data-protection laws applicable to their attendees (for example Nigeria's NDPA, South Africa's POPIA, or Kenya's Data Protection Act).

10. Your Rights

Subject to applicable law, you have the right to:
Access
Obtain a copy of your personal data
Rectification
Correct inaccurate data
Erasure
Request deletion ("right to be forgotten")
Restriction
Limit how we process your data
Portability
Receive your data in a machine-readable format
Object
Object to processing based on legitimate interests or direct marketing
Withdraw consent
At any time where processing relies on consent
Automated decisions
Not be subject to solely automated decisions with legal effect
If you are an attendee, please direct rights requests to the event organiser (the Controller); we will help them respond. For account and customer data, contact privacy@automyx.io. We respond within one month.

11. Cookies

We use cookies and similar technologies for authentication, security and limited analytics. Non-essential cookies are used only with your consent. Full details, and how to manage your choices, are in our Cookie Policy.

12. Security

We implement appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS), encryption at rest, role-based access controls and tenant isolation, audit logging, and regular review of our security posture. Our measures are described in Schedule 1 of the Data Processing Agreement.

13. Complaints

If you are unhappy with how your data is handled, you may complain to the UK Information Commissioner's Office (ICO) at ico.org.uk or on 0303 123 1113. We would appreciate the chance to address your concerns first, so please contact privacy@automyx.io before you do.

14. Changes to This Policy

We will notify organisers of material changes by email or in-app notice at least 30 days in advance. The current version is always at orkestriq.io/privacy.html.
This Data Processing Agreement (DPA) applies to event organisers (Business Users) and is incorporated into the Orkestriq Terms and Conditions. It governs our processing of attendee personal data on your behalf. Last updated: 18 June 2026 | Version 2.0

1. Definitions

"Controller": the event organiser (you), who determines the purposes and means of processing attendee Personal Data.
"Processor": Automyx Ltd (trading as Orkestriq), acting on the Controller's instructions.
"Data Protection Laws": the UK GDPR, the Data Protection Act 2018, and any other data-protection law applicable to the processing.
"Personal Data", "Data Subject", "Processing", "Special Category Data": as defined in the Data Protection Laws.
"Sub-processor": any third party engaged by Orkestriq to process Personal Data on behalf of the Controller.

2. Scope

This DPA applies where Orkestriq processes Personal Data on your behalf in providing the Services. It supplements and forms part of the Terms and Conditions.

3. Controller Obligations

You warrant and represent that:
  • you have a valid lawful basis (and, for Special Category Data such as dietary requirements, a valid Article 9 condition) for all Personal Data you collect through the Services;
  • you have provided all required privacy notices to attendees, including in respect of passport/travel data and the AI assistant;
  • you will not instruct Orkestriq to process Personal Data in a way that breaches Data Protection Laws.

4. Orkestriq's Obligations as Processor

Orkestriq shall:
  • process Personal Data only on your documented instructions and not for any other purpose;
  • ensure personnel with access to Personal Data are bound by confidentiality obligations;
  • implement and maintain the technical and organisational security measures in Schedule 1;
  • not transfer Personal Data outside the UK/EEA without appropriate safeguards (IDTA, UK Addendum or SCCs);
  • notify you without undue delay (and in any event within 48 hours) on becoming aware of a Personal Data breach affecting your data, with sufficient information to meet your own notification duties;
  • assist you, taking account of the nature of processing, in responding to Data Subject rights requests;
  • assist you with Data Protection Impact Assessments (DPIAs) and prior consultations where required;
  • delete or return all Personal Data on termination, as you elect, within 30 days, and delete existing copies unless retention is required by law.

5. Sub-Processors

5.1 You grant Orkestriq general written authorisation to engage the Sub-processors listed at orkestriq.io/sub-processors.html.
5.2 We will give at least 10 days' notice of any intended addition or replacement of a Sub-processor.
5.3 If you reasonably object on data-protection grounds within 10 days of notice, you may terminate the affected Services with a pro-rata refund.
5.4 We impose data-protection obligations on Sub-processors equivalent to those in this DPA and remain liable to you for their compliance.

6. Audit Rights

No more than once per year, and on at least 30 days' written notice, you may audit our compliance with this DPA or request written evidence of compliance (such as certifications, audit reports or security-questionnaire responses). Audit costs are borne by you unless non-compliance is found.

Schedule 1: Technical and Organisational Measures

AreaMeasure
EncryptionTLS 1.2+ in transit; AES-256 at rest
Access controlRole-based access; per-tenant data isolation (row-level security); two-factor authentication (2FA) available for privileged (organiser) accounts
MonitoringAudit logging; rate limiting; anomaly review
Vulnerability managementSecret management, dependency and patch management, periodic security review
Incident responseDocumented breach-response procedure with controller notification
StaffConfidentiality obligations and data-protection awareness
HostingReputable cloud infrastructure (no own data centres)

Schedule 2: Processing Details

ElementDetails
Subject matter & natureEvent-management services: registration, badging, check-in, agenda, communications, visa-letter generation, networking, AI assistant
PurposeProviding the Orkestriq platform as described in the Terms and instructed by the organiser
DurationThe term of the Services agreement
Types of Personal DataName, email, phone, organisation, job title, country/nationality; passport number and expiry, date of birth; dietary requirements and notes (Special Category Data); attendance, networking and AI-assistant content
Categories of Data SubjectsThe organiser's event attendees/delegates and its staff users
This Acceptable Use Policy governs what you may and may not do with Orkestriq. It supplements the Terms and Conditions. Violations may result in suspension or termination, and may be referred to law enforcement. Last updated: 18 June 2026 | Version 2.0

1. Prohibited Content and Conduct

You must not use the Services to collect, store, process, distribute or facilitate content or activity that:
1.1 Is illegal
  • Violates any applicable law or regulation
  • Infringes copyright, trade marks, patents or other intellectual property rights
  • Constitutes defamation, harassment or unlawful discrimination
  • Facilitates fraud, identity theft or financial crime
1.2 Is harmful
  • Promotes or facilitates violence, terrorism or extremism
  • Contains child sexual abuse material (CSAM) or any sexualisation of minors
  • Facilitates self-harm or suicide
  • Constitutes non-consensual intimate imagery
1.3 Misuses attendee data
  • Collecting attendee data (including passport, date-of-birth or dietary data) without a valid lawful basis and notice
  • Using attendee data for purposes the attendee was not told about, or selling it
  • Sending unlawful or unsolicited marketing through the platform

2. Prohibited Technical Activities

You must not:
  • reverse engineer, decompile or disassemble the Services;
  • probe, scan or test the vulnerability of the Services without prior written authorisation;
  • circumvent or interfere with security controls, authentication, tenant isolation or rate limits;
  • use bots, scrapers or crawlers to access the Services beyond what our documentation permits;
  • introduce malware or any malicious code;
  • conduct denial-of-service attacks against the Services or any third party via the Services;
  • access another organiser's or attendee's data without authorisation.

3. Prohibited Business Activities

You must not:
  • resell, sublicense or white-label the Services without a separate written agreement with Orkestriq;
  • use the Services to build a directly competing product without our prior written consent;
  • use the AI assistant as a substitute for qualified immigration, legal, medical or financial advice.

4. Responsible Use of the AI Assistant

The AI assistant produces automated responses that may be inaccurate. We ask that you:
  • Verify AI output before relying on it for visa, travel or other consequential decisions
  • Avoid placing sensitive personal data in the knowledge base or assistant
  • Make clear to attendees that responses are AI-generated

5. Reporting and Enforcement

Report suspected violations to legal@automyx.io. We may remove offending content, suspend or terminate accounts, report illegal activity to authorities, and pursue available remedies.
This SLA applies to paid event organisers. Last updated: 18 June 2026 | Version 2.0

1. Uptime Commitment

Orkestriq targets a monthly uptime of 99.5% for the core platform, measured as:
Uptime % = ((Total minutes in month − Downtime minutes) / Total minutes in month) × 100
"Downtime" means a period during which the core Services are completely unavailable to you, excluding Excluded Downtime (scheduled maintenance, emergency maintenance, force majeure, your own acts or omissions, third-party provider failures, and Beta/Preview features).

2. Service Credits

If monthly uptime falls below the commitment, you are eligible for service credits:
Monthly UptimeService Credit
99.0% – 99.49%10% of monthly fee
95.0% – 98.99%25% of monthly fee
Below 95.0%50% of monthly fee
Submit credit requests to support@automyx.io within 30 days of the affected month. Credits apply to your next invoice and are non-transferable and non-refundable as cash.

3. Support Tiers

FeatureStarterGrowthEnterprise
Email supportYesYesYes
Live chatNoYesYes
Dedicated Customer Success ManagerNoNoYes
Response (business hours)24 hours8 hours2 hours
Response (critical incidents)8 hours4 hours1 hour
Onboarding supportDocumentationGuidedCustom
Business hours: 09:00–18:00 Monday–Friday, UK time, excluding UK public holidays.

4. Incident Severity Levels

SeverityDefinitionTarget Response
P1 · CriticalComplete service unavailability or data loss1 hr (Enterprise), 4 hrs (Growth)
P2 · HighMajor feature impairment with no workaround4 hrs (Enterprise), 8 hrs (Growth)
P3 · MediumFeature impairment with workaround availableNext business day
P4 · LowGeneral questions, minor issues, feature requests2 business days

5. Contact