Privacy Policy

Effective: 2 April 2026

1. Who we are

Ordestra is operated by Daliah Group B.V., a company registered in the Netherlands. We are the data controller for the personal data described in this policy.

Contact: hello@ordestra.com

2. What Ordestra does

Ordestra converts evidence-based scientific publications (PDFs) into compliance-constrained audio summaries with citation-anchored transcripts. It serves professionals in medical affairs, academia, policy research, and other evidence-based domains.

3. Personal data we collect

Account data

Usage data

Payment data

Technical data

Uploaded content

4. Why we process your data and our legal basis

PurposeLegal basis (GDPR)
Providing the service (account management, PDF processing, audio generation)Performance of contract (Art. 6(1)(b))
Processing payments and managing subscriptionsPerformance of contract (Art. 6(1)(b))
Maintaining audit logs for compliance and evidence traceabilityLegitimate interest (Art. 6(1)(f)) — regulatory accountability and evidence integrity
Error monitoring and service reliabilityLegitimate interest (Art. 6(1)(f)) — ensuring service stability
Sending transactional emails (account confirmations, password resets, billing receipts)Performance of contract (Art. 6(1)(b))
Sending marketing communications (only with your explicit opt-in)Consent (Art. 6(1)(a))

We do not sell your personal data. We do not use profiling or automated decision-making that produces legal effects or similarly significant effects on you.

5. Who we share data with

We use the following third-party processors to deliver the service. Each operates under a data processing agreement.

ProcessorPurposeData regionWhat is shared
SupabaseAuthentication, database, file storageEU (Frankfurt)Account data, papers metadata, generated outputs, uploaded PDFs
Anthropic (Claude API)Text extraction and script generationEUExtracted text content from uploaded PDFs (no account data). Anthropic does not train on data sent via the API.
ElevenLabsVoice synthesisZero Retention Mode enabled (see Section 6)Generated script text only. No personal data is sent to ElevenLabs.
StripePayment processingEUBilling name, payment method, subscription status
SentryError monitoringEUError logs and performance data (no personally identifiable information)
CloudflareHosting and edge deliveryGlobal edge networkHTTP requests are routed through Cloudflare's network. No application data is persisted by Cloudflare.

6. International data transfers

We store and process all persistent data within the European Union. Our database, authentication, and storage infrastructure is hosted in the EU (Frankfurt).

ElevenLabs (voice synthesis): We use ElevenLabs with Zero Retention Mode enabled, meaning ElevenLabs does not store input or output data after delivery. Only generated script text (which contains no personal data) is sent for synthesis. Processing may transiently route through non-EU infrastructure, but no data is persisted outside the EU.

Cloudflare: As an edge network, Cloudflare routes HTTP requests through the nearest point of presence globally. This is standard for web delivery and does not involve persisting personal data outside the EU.

Where any processing occurs outside the EU/EEA, it is covered by appropriate safeguards including Standard Contractual Clauses (SCCs) or adequacy decisions under the GDPR.

7. How long we keep your data

Retention periods depend on your subscription tier and the type of data:

TierAudioTranscriptUploaded PDFAudit logs
FreeNot storedNot storedDeleted after generation3 years
Starter30 days30 daysDeleted after generation3 years
Plus / Pro90 days90 daysDeleted after generation3 years
Team1 year1 yearDeleted after generation3 years

Account data is retained for the duration of your account. If you delete your account, we erase your personal data within 30 days, except where we are legally required to retain records (e.g., audit logs for regulatory compliance).

Audit logs are retained for 3 years for all tiers. These are append-only records that ensure evidence traceability and regulatory accountability. They do not contain the content of your papers or audio outputs.

8. Your rights under the GDPR

As a data subject, you have the following rights:

To exercise any of these rights, email hello@ordestra.com. We will respond within 30 days.

9. Right to complain

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Dutch Data Protection Authority:

Autoriteit Persoonsgegevens
Website: autoriteitpersoonsgegevens.nl
Phone: +31 (0)70 888 85 00

10. Cookies

Ordestra uses only essential cookies required for the service to function:

We do not use tracking cookies, advertising cookies, or third-party analytics cookies. We do not use cookie consent banners because we do not use any cookies that require consent.

11. Children

Ordestra is not directed at individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child under 16 has provided us with personal data, please contact us at hello@ordestra.com and we will delete it promptly.

12. Changes to this policy

We may update this policy to reflect changes in our practices or legal requirements. When we make material changes, we will notify you by email or by a prominent notice on the service before the changes take effect. The "Effective" date at the top of this page indicates when the policy was last updated.

This policy will be reviewed by qualified legal counsel before launch.