Privacyfor clientsand projects
Onravetoni is an operating partner for growing businesses: audit, systems implementation, and growth support. This policy explains what we collect during engagements, how we protect it, and how to exercise your rights under GDPR and the EU AI Act.
Operating Principles
Four principles for how we handle client data during audit, implementation, and ongoing support.
Zero Retention
Project materials are not kept longer than needed for delivery unless the client enables separate history in the workspace.
No Model Training
Client data is not used to train third-party models; zero-retention modes are used where supported.
Data minimization
We collect only what is required for authentication, billing, communication, and project delivery.
EU Hosting
Primary infrastructure is in the EU. Data does not leave the region without explicit client consent.
What We Collect
A complete inventory of the data flowing through Onravetoni, grouped by purpose. If it is not listed here, it is not collected.
Account Data
- ▹Email address
- ▹Hashed password
- ▹Workspace metadata
- ▹JWT rotation log
Project & tool data
- ▹Audit and implementation materials (with consent)
- ▹Working notes and client-facing reports
- ▹Technical execution metadata (minimal PII)
- ▹Aggregated service usage metrics
Telemetry
- ▹Endpoint latency
- ▹Error codes
- ▹Anonymized request counts
- ▹Region of origin
Billing
- ▹Stripe customer ID
- ▹Invoice history
- ▹Plan tier
- ▹VAT / TAX region
Third-Party Sharing
Sub-processors and partners who receive your data as part of delivering the service. We contract each to GDPR-equivalent standards.
Billing identity, payment method tokens, invoice history
Limited project fragments for analytics and automation; no model training
Encrypted payload processing, storage of encrypted backups
Anonymized IP, request metadata for WAF and rate limiting
Email address, notification content
Anonymized usage events — no PII, no session replay
Cookie Policy
A breakdown of every cookie we set, its purpose, and how to control it. We keep this minimal by design.
Required for the platform to function. Cannot be disabled.
Enhance your experience. Disabled by default on first visit until consent is given.
Anonymized usage data. No personal identifiers are sent to any external service.
We do not run marketing cookies. No advertising networks, no retargeting pixels.
Your Rights
Six rights granted by GDPR Articles 15–22. Each is exercisable through your dashboard or by a signed request to our DPO.
Access
Export every record we hold tied to your account in machine-readable JSON.
Rectification
Correct inaccurate identifiers, contact info, or workspace metadata on request.
Erasure
Permanent deletion within 30 days, including encrypted backups on next rotation.
Portability
Receive structured, commonly-used exports suitable for migration to another provider.
Restriction
Freeze processing while disputes or investigations are being resolved.
Objection
Opt out of any optional analytics, product telemetry, or marketing signals.
Data Protection Officer
All privacy requests, complaints, and regulatory inquiries route to a single authenticated address.
Contact Our
Data Protection Officer
Every request receives a response within 72 hours. Fulfilment within 30 days, as mandated by GDPR Art. 12.
dpo@onravetoni.com