GDPR · EU AI Act 2024 · Effective
Last Updated · 2026-04-18

Privacyfor clientsand projects

Onravetoni is an operating partner for growing businesses: audit, systems implementation, and growth support. This policy explains what we collect during engagements, how we protect it, and how to exercise your rights under GDPR and the EU AI Act.

Zero RetentionEU HostingNo Model Training30-Day Deletion
01 ──

Operating Principles

Four principles for how we handle client data during audit, implementation, and ongoing support.

01

Zero Retention

Project materials are not kept longer than needed for delivery unless the client enables separate history in the workspace.

02

No Model Training

Client data is not used to train third-party models; zero-retention modes are used where supported.

03

Data minimization

We collect only what is required for authentication, billing, communication, and project delivery.

04

EU Hosting

Primary infrastructure is in the EU. Data does not leave the region without explicit client consent.

02 ──

What We Collect

A complete inventory of the data flowing through Onravetoni, grouped by purpose. If it is not listed here, it is not collected.

Account Data

  • Email address
  • Hashed password
  • Workspace metadata
  • JWT rotation log
RetentionUntil account deletion

Project & tool data

  • Audit and implementation materials (with consent)
  • Working notes and client-facing reports
  • Technical execution metadata (minimal PII)
  • Aggregated service usage metrics
RetentionZero Retention

Telemetry

  • Endpoint latency
  • Error codes
  • Anonymized request counts
  • Region of origin
Retention30-Day Deletion

Billing

  • Stripe customer ID
  • Invoice history
  • Plan tier
  • VAT / TAX region
Retention7 years (tax law)
03 ──

Third-Party Sharing

Sub-processors and partners who receive your data as part of delivering the service. We contract each to GDPR-equivalent standards.

Stripe
Payment Processing
PCI-DSS Level 1

Billing identity, payment method tokens, invoice history

US / EU
Anthropic / OpenAI / Google / DeepSeek
AI sub-processors (when needed for delivery)
SOC 2 Type II

Limited project fragments for analytics and automation; no model training

US / EU
Amazon Web Services
Cloud Infrastructure
ISO 27001 / SOC 2

Encrypted payload processing, storage of encrypted backups

EU-West (Frankfurt / Dublin)
Vercel / Cloudflare
CDN & Edge Delivery
SOC 2 Type II

Anonymized IP, request metadata for WAF and rate limiting

EU PoPs prioritised
Nodemailer / SMTP Provider
Transactional Email
GDPR DPA in place

Email address, notification content

EU
Internal Analytics (anonymized)
Product Telemetry
No third-party sharing

Anonymized usage events — no PII, no session replay

EU
Note:We never sell personal data to third parties. Every sub-processor listed above operates under a signed Data Processing Agreement (DPA) that limits use to the specified purpose only. A full list of sub-processors is available on request at dpo@onravetoni.com.
04 ──

Cookie Policy

A breakdown of every cookie we set, its purpose, and how to control it. We keep this minimal by design.

Essential

Required for the platform to function. Cannot be disabled.

next-auth.session-token
Authenticated session JWT
Session / 30 daysRequired
next-auth.csrf-token
CSRF protection on auth routes
SessionRequired
__Secure-next-auth.callback-url
Post-login redirect URL
SessionRequired
Functional

Enhance your experience. Disabled by default on first visit until consent is given.

onrv_theme
Stores UI theme preference
1 yearOptional
onrv_workspace
Remembers last active workspace
30 daysOptional
Analytics

Anonymized usage data. No personal identifiers are sent to any external service.

onrv_anon_id
Anonymous session identifier for internal product analytics only
6 monthsOptional
Marketing

We do not run marketing cookies. No advertising networks, no retargeting pixels.

No cookies set in this category.
05 ──

Your Rights

Six rights granted by GDPR Articles 15–22. Each is exercisable through your dashboard or by a signed request to our DPO.

Access

Export every record we hold tied to your account in machine-readable JSON.

Rectification

Correct inaccurate identifiers, contact info, or workspace metadata on request.

Erasure

Permanent deletion within 30 days, including encrypted backups on next rotation.

Portability

Receive structured, commonly-used exports suitable for migration to another provider.

Restriction

Freeze processing while disputes or investigations are being resolved.

Objection

Opt out of any optional analytics, product telemetry, or marketing signals.

06 ──

Data Protection Officer

All privacy requests, complaints, and regulatory inquiries route to a single authenticated address.

Direct Channel

Contact Our
Data Protection Officer

Every request receives a response within 72 hours. Fulfilment within 30 days, as mandated by GDPR Art. 12.

dpo@onravetoni.com
Privacy Policy | Onravetoni