Security and data

Security and data at Orkestriq

Updated 14 September 2026

Your delegate list is the most sensitive file a conference holds. This page says where Orkestriq keeps it, who can see it, how you get it back and how it is deleted. Every statement here is backed by our Privacy Policy, the Data Processing Agreement you sign before any data is loaded, and the sub-processor list.

Where your data is held

Delegate records, event data and uploaded files are stored in our primary datastore, which is hosted in the European Union. The application itself is served through a global edge network, and email delivery and the AI delegate assistant run through providers in the United States under standard contractual clauses and the UK Addendum. Each provider, what it processes and where, is listed on the sub-processors page.

Who can see it

You are the data controller. Orkestriq is your processor and acts only on your documented instructions. A Data Processing Agreement is signed before any delegate data is loaded.

How delegates sign in

Delegates use a web portal that needs no app and no password. They sign in with a six-digit code sent to the email address on their registration. Portal access closes automatically 7 days after each event ends, so a link that was shared during the conference stops working on its own. Delegates registered for another event with the same organiser move straight to it without signing in again.

Getting your data back

You can export your full delegate list from the dashboard at any time, during the event or after it, as a spreadsheet. There is no lock-in and nothing to request from us. When a contract ends, you choose whether we return the data or delete it, and we do so within 30 days.

Deleting it

When you ask us to remove your delegate data, we delete it permanently and confirm in writing. On termination it is deleted within 30 days unless you elect a return first, and existing copies are removed unless the law requires us to keep them. Residual copies in backups are overwritten in the ordinary backup rotation.

Security measures

Sub-processors

We use a small number of providers to run the service. Each is bound by written data-protection terms and processes data only on our documented instructions. The current list, with the purpose, the data involved, the location and the transfer safeguard for each, is maintained at orkestriq.io/sub-processors. Our AI provider does not use data sent through its API to train its models.

The company

Orkestriq is a product of Automyx Ltd, a company registered in England and Wales, company number 17274298, registered office 3 Avantgarde Place, London E1 6GU. Automyx Ltd is registered with the UK Information Commissioner's Office under number ZC177352.

Contact

Data-protection requests and questions about this page: privacy@automyx.io. For a copy of the Data Processing Agreement before you sign, or to complete a security questionnaire, write to orkestriq@automyx.io.