Skip to main content

Privacy

Collect less, expose less, retain only with a reason.

Ombudex separates private evidence from public facts and documents why each category of personal data is processed.

Last updated: 30 August 2026

Data categories

Account and team data support authentication and organization management. Review invitation data authenticates a customer relationship. Evidence and integration data support a requested verification.

Public profiles contain only information selected and approved for publication. Email addresses, tokens, credentials, and private documents are excluded.

Purposes and legal bases

Data is processed to provide the requested service, secure the platform, satisfy legal obligations, handle disputes, and where required record consent. The applicable basis depends on the workflow and jurisdiction.

Retention

Expired invitations, rejected files, raw monitoring checks, logs, and backups follow documented retention windows. Audit records may be minimized or pseudonymized where deletion would undermine integrity or legal obligations.

Your rights

Subject to applicable law, users may request access, correction, export, deletion, restriction, objection, or withdrawal of consent. An organization owner must transfer ownership before deleting an account that would leave no owner.

Recipients and transfers

Access is limited by role and purpose. Subprocessors, hosting regions, and transfer safeguards are documented before use. Ombudex does not add advertising trackers in the MVP.

Contact

Privacy requests are routed through the dedicated contact published in verified legal configuration. Identity may be checked proportionately before fulfilling a request.