1. Who we are
Oronzo LLP provides Trace, a multi-tenant work-management and knowledge platform. For privacy questions or requests, contact [email protected]. Your organization may also act as the controller of workspace content and user information it submits to Trace.
2. Information we process
We process account details such as name, email address, authentication records, organization membership, roles, device registration, and security events. We also process workspace content, including projects, tasks, defects, documents, comments, files, budgets, time entries, integrations, audit history, and configuration supplied by users.
Operational data may include IP address, request identifiers, browser and device information, timestamps, logs, queue status, and diagnostic events needed to secure and operate the service.
3. Why we use information
- Provide, authenticate, secure, and support Trace.
- Keep organizations and workspaces isolated.
- Send verification, invitation, operational, and security notifications.
- Maintain auditability, prevent abuse, diagnose failures, and improve reliability.
- Meet contractual, legal, accounting, and compliance obligations.
4. Service providers and international processing
Trace uses infrastructure and service providers that may process information in different countries. Current providers include Amazon Web Services for application infrastructure and storage, Cloudflare for main-domain edge delivery, Resend for transactional email, and Firebase Cloud Messaging for opted-in browser notifications. We limit access to what each provider needs and rely on their contractual and security protections.
5. Retention and deletion
We retain account and workspace information while the account or organization is active and for a limited period afterward where needed for recovery, security, dispute resolution, or legal obligations. Tenant-configured lifecycle policies may shorten retention for eligible records. Organization deletion uses a cooling-off period before operational completion; encrypted backups expire according to the applicable backup schedule.
6. Security
Trace uses encrypted transport, restricted AWS storage, tenant-scoped authorization, host-only session cookies, one-time verification records, rate limiting, audit trails, backups, monitoring, and least-privilege access controls. No service can guarantee absolute security, so customers should also protect credentials, devices, API keys, and integration secrets.
7. Your choices and rights
Depending on applicable law, you may request access, correction, export, restriction, objection, or deletion of personal information. Workspace content requests should normally be directed to the organization that controls the workspace. Contact us for account-level requests; we may verify identity before acting.
8. Children and changes
Trace is intended for business users and is not directed to children. We may update this policy as the service or legal requirements change. Material updates will be communicated through the service or an appropriate account contact.