LEGAL / PRIVACY

Privacy Policy

How Oronzo LLP collects, uses, protects, and shares personal information when you use Trace.

Effective 22 July 2026

1. Who we are

Oronzo LLP provides Trace, a multi-tenant work-management and knowledge platform. For privacy questions or requests, contact [email protected]. Your organization may also act as the controller of workspace content and user information it submits to Trace.

2. Information we process

We process account details such as name, email address, authentication records, organization membership, roles, device registration, and security events. We also process workspace content, including projects, tasks, defects, documents, comments, files, budgets, time entries, integrations, audit history, and configuration supplied by users.

Operational data may include IP address, request identifiers, browser and device information, timestamps, logs, queue status, and diagnostic events needed to secure and operate the service.

3. Why we use information

  • Provide, authenticate, secure, and support Trace.
  • Keep organizations and workspaces isolated.
  • Send verification, invitation, operational, and security notifications.
  • Maintain auditability, prevent abuse, diagnose failures, and improve reliability.
  • Meet contractual, legal, accounting, and compliance obligations.

4. Service providers and international processing

Trace uses infrastructure and service providers that may process information in different countries. Current providers include Amazon Web Services for application infrastructure and storage, Cloudflare for main-domain edge delivery, Resend for transactional email, and Firebase Cloud Messaging for opted-in browser notifications. We limit access to what each provider needs and rely on their contractual and security protections.

5. Retention and deletion

We retain account and workspace information while the account or organization is active and for a limited period afterward where needed for recovery, security, dispute resolution, or legal obligations. Tenant-configured lifecycle policies may shorten retention for eligible records. Organization deletion uses a cooling-off period before operational completion; encrypted backups expire according to the applicable backup schedule.

6. Security

Trace uses encrypted transport, restricted AWS storage, tenant-scoped authorization, host-only session cookies, one-time verification records, rate limiting, audit trails, backups, monitoring, and least-privilege access controls. No service can guarantee absolute security, so customers should also protect credentials, devices, API keys, and integration secrets.

7. Your choices and rights

Depending on applicable law, you may request access, correction, export, restriction, objection, or deletion of personal information. Workspace content requests should normally be directed to the organization that controls the workspace. Contact us for account-level requests; we may verify identity before acting.

8. Children and changes

Trace is intended for business users and is not directed to children. We may update this policy as the service or legal requirements change. Material updates will be communicated through the service or an appropriate account contact.