Privacy
Collect less, expose less, retain only with a reason.
Ombudex separates private evidence from public facts and documents why each category of personal data is processed.
Last updated: 30 August 2026
Data categories
Account and team data support authentication and organization management. Review invitation data authenticates a customer relationship. Evidence and integration data support a requested verification.
Public profiles contain only information selected and approved for publication. Email addresses, tokens, credentials, and private documents are excluded.
Purposes and legal bases
Data is processed to provide the requested service, secure the platform, satisfy legal obligations, handle disputes, and where required record consent. The applicable basis depends on the workflow and jurisdiction.
Retention
Expired invitations, rejected files, raw monitoring checks, logs, and backups follow documented retention windows. Audit records may be minimized or pseudonymized where deletion would undermine integrity or legal obligations.
Your rights
Subject to applicable law, users may request access, correction, export, deletion, restriction, objection, or withdrawal of consent. An organization owner must transfer ownership before deleting an account that would leave no owner.
Recipients and transfers
Access is limited by role and purpose. Subprocessors, hosting regions, and transfer safeguards are documented before use. Ombudex does not add advertising trackers in the MVP.
Contact
Privacy requests are routed through the dedicated contact published in verified legal configuration. Identity may be checked proportionately before fulfilling a request.