Skip to content
ORchestrate
  • Problem
  • Solution
  • How It Works
  • Matching
  • Founders
Start your free trial
ProblemSolutionHow It WorksMatchingFoundersStart your free trial

EEA & UK Privacy Notice

Effective date: September 19, 2026

This notice supplements the Privacy Policy of Orchestrate AI LLC, a Texas limited liability company ("Orchestrate," "we," "us"). It gives the information that Articles 13 and 14 of the EU General Data Protection Regulation and of the UK GDPR require a controller to give, and it describes the rights those regulations give you, if and to the extent either applies to our processing of your personal data. Read it together with the Privacy Policy, which describes our practices in full.

Like the Privacy Policy, this notice is not a contract. It describes our practices as of its effective date, creates no contractual or third-party-beneficiary rights, and does not modify any agreement between Orchestrate and a Customer. Where a Data Processing Agreement governs a particular processing activity, that agreement controls and this notice describes only what falls outside it.

1. Our Posture, Stated Plainly

Orchestrate is established in the United States and nowhere else. We have no establishment, office, subsidiary, or data centre in the European Economic Area or the United Kingdom. As Section 10 of the Privacy Policy says, our site and our application are operated from the United States and intended for United States users, and the personal data this notice covers is stored in Amazon Web Services' US East (N. Virginia) region.

We do not direct the site or the application at people in the EEA or the United Kingdom: we do not offer the application there, we do not price or present it in a member-state or UK currency or language, and we do not track visitors across other websites or build profiles of them (Sections 2.2 and 5.3 of the Privacy Policy). We have not appointed a representative in the Union or the United Kingdom under Article 27. If we begin to offer the site or the application to people in the EEA or the United Kingdom, we will appoint one and name them here before we do.

We also have not appointed a Data Protection Officer. Article 37 requires one where the controller is a public authority, where its core activities require regular and systematic monitoring of data subjects on a large scale, or where its core activities consist of large-scale processing of special categories of data — none of which describes what we do as a controller. Privacy questions go to the contact in Section 3.

Our site is reachable from anywhere. So if you visit it from the EEA or the United Kingdom, or if you are an individual whose personal data reaches us in one of the other ways described below, this notice tells you what Articles 13 and 14 would require us to tell you and what rights Articles 15 to 22 would give you. Where the GDPR does not apply to our processing, we will still handle a request under this notice as a matter of policy, and doing so does not mean the GDPR applies to us. Whether it applies to a particular processing activity is a question we do not decide for you in this document.

2. Controller or Processor — Which Role We Are In

The distinction decides who you should ask, and it is the single most important thing in this notice.

We are a processor for Customer Data. Schedules, staff rosters, provider names and credentials, shift and site information, and the case and procedure detail entered so cases can be staffed are processed on a Customer's behalf and on its documented instructions. The Customer — the anesthesia practice or provider organization that uses the application — is the controller within the meaning of Article 4(7), and Orchestrate is its processor within the meaning of Article 4(8). The Article 28 terms live in the Data Processing Agreement between us and that Customer, not in this notice.

If you are a clinician, an employee, or a contractor of a Customer and you want to exercise a right concerning data about you in the application, direct your request to that organization. We will refer to that Customer any request we receive about its data and support its response as the agreement requires; we will not act on it ourselves, because acting on it would mean processing outside the Customer's instructions, which Article 29 forbids.

We are a controller for our own business information. For the information described in Section 1.3 of the Privacy Policy — visitors to our marketing site, people who request a demo or a trial or write to us, Customer billing contacts, and our own operational, security, support, and billing use of application account information — Orchestrate decides the purposes and means itself, and is the controller. The rest of this notice is about that information.

One set of facts can fall on both sides of the line. An application user's log-in email is account-level administrative information we control for our own security and support purposes, and at the same time may be Personal Data we process on the Customer's behalf under a Data Processing Agreement. Where it is both, the Data Processing Agreement governs that processing, and this notice describes only our own operational, security, support, and billing use of it.

3. Controller Identity and Contact

Orchestrate AI LLC, a Texas limited liability company Attn: Privacy PO Box 9684, 770 Northcross Dr, Austin, TX 78766, United States Email: security@or.chestrate.com

Put "Privacy Request" in the subject line and we will route it accordingly.

4. What We Process, Why, and on What Lawful Basis

Each row is one purpose, the personal data it uses, and the Article 6 basis we would rely on. Where the basis is legitimate interests under Article 6(1)(f), the last column states the interest, which is the balancing test's starting point — you can object to any of those under Article 21 and Section 10 below tells you how.

PurposePersonal data usedLawful basis (Article 6)The legitimate interest, where that is the basis
Responding to a demo, trial, or support request, and following up about itName, work email address, practice or group name, group size, number of sites, current scheduling setup, and any message you write.Article 6(1)(b), where you ask us to take steps before entering into a contract. Otherwise Article 6(1)(f).Marketing and developing a business-to-business service to the organization you represent, and answering someone who asked us for something.
Receiving and answering correspondenceYour contact details and the contents of your message.Article 6(1)(f).Answering the person who wrote to us.
Filtering automated submissions and investigating abuse of the formThe anti-spam signals described in Section 2.2 of the Privacy Policy, which filter submissions before anything is stored; and the IP address a submission came from, the user-agent string, and the time it was received, which we keep to investigate abuse.Article 6(1)(f).Keeping the form usable, and protecting our systems from automated abuse.
Attributing an enquiry to the campaign or referral that produced itThe referring page, the path of the page you submit the form from, and any campaign parameters or ad-click identifiers in its address, captured when you submit.Where the ePrivacy Directive or the UK PECR requires consent to store or read these values on your device, we do not yet ask for it, because the site is operated for United States users; we will ask before we offer the site in the EEA or the United Kingdom — see Section 11. Article 6(1)(f) for using them once we hold them.Understanding which campaign or referral produces enquiries, so that we spend on the ones that work.
Creating, authenticating, securing, and supporting application accountsLog-in email address, assigned application role, the Customer organization the account belongs to, and the second authentication factor where multi-factor authentication is enabled.Article 6(1)(b) where you are the person contracting with us. Article 6(1)(f) where the contract is with your organization rather than with you.Operating and securing the service the organization bought, and supporting the people who use it.
Billing, collecting payment, and administering the Customer relationshipBilling contact details, payment instructions, and invoice and payment history.Article 6(1)(b). Article 6(1)(c) for the tax and accounting records we are required to keep.—
Operating, securing, and monitoring the site and the application, and investigating incidentsInfrastructure, application, and security logs, which include IP addresses, request paths, and timestamps.Article 6(1)(f). Article 6(1)(c) where a legal or contractual security obligation applies.Keeping the service available, and protecting it and its users from fraud, abuse, and security threats.
Complying with law, responding to legal process, and establishing, exercising, or defending legal claimsWhatever is relevant to the obligation or the claim.Article 6(1)(c) where a legal obligation applies. Otherwise Article 6(1)(f).Establishing, exercising, or defending legal claims, and meeting obligations we are subject to.
A merger, financing, acquisition, or sale of assetsThe personal data described above, as part of the transaction and subject to the Privacy Policy.Article 6(1)(f).Being able to finance, transfer, or wind down the business.

We do not use your personal data for automated decision-making that produces legal or similarly significant effects about you — see Section 9.

5. Special Category Data and Health Data

As a controller, we do not process special categories of personal data within the meaning of Article 9. We do not ask for, and have no use for, data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, nor genetic data, biometric data used to identify someone, data concerning health, or data concerning sex life or sexual orientation.

As a processor, data concerning health may be present in Customer Data — for example, the pregnancy status a Customer may record for a member of its staff so that the allocation engine keeps them out of rooms using ionising radiation. Where it is, the Customer is the controller, the Customer is responsible for identifying its Article 9(2) condition and its Article 6 basis, and Orchestrate processes it only on that Customer's instructions under the Data Processing Agreement. Where that data is also protected health information under U.S. HIPAA, Orchestrate acts as the Customer's business associate under a Business Associate Agreement, as Section 1.2 of the Privacy Policy describes.

6. Where the Data Comes From, and Whether You Have to Give It

Most of the personal data in Section 4 comes from you — you type it into the request form, or you write to us — or from your browser and our infrastructure automatically, in the case of IP addresses, user-agent strings, log entries, and campaign parameters.

Some of it does not come from you, which is what Article 14 is about. Application account information — a log-in email address, an assigned role, and the organization an account belongs to — generally comes from the Customer organization that provisions the account, not from the person who will use it. Billing contact details generally come from the Customer on an order form.

You are under no statutory or contractual obligation to give us any of it. But we cannot answer a request without an email address to answer to, we cannot give someone an application account without an identifier to authenticate them with, and we cannot invoice a Customer without billing details. If you would rather not provide something, tell us and we will tell you what we can still do.

7. How Long We Keep It

Section 6 of the Privacy Policy states our retention practice, and Section 5 of the U.S. State Privacy Notice sets it out record by record. Those periods apply here. In short: demo and trial records and correspondence are reviewed at least quarterly and we aim to delete them within twenty-four (24) months of our last contact with you; account information lasts the life of the Customer relationship plus any post-termination period the customer agreement sets; billing records last as long as our tax and accounting obligations require; access logs for the application's API are deleted automatically after 400 days, and other logs are reviewed periodically rather than deleted on a fixed schedule; and values stored in your own browser stay there until they are replaced or you clear them.

8. Recipients and Sub-processors

Section 4 of the Privacy Policy names who receives personal data and why: Amazon Web Services for hosting, storage, logging, transactional email, and authentication; Purelymail, which hosts our mailboxes and therefore receives every message sent to us; Stripe for card and subscription billing; our professional advisors; and the recipients of a legally compelled disclosure or of a business transfer. No advertising or analytics platform receives anything, because no such tag is active.

Where we act as a processor, sub-processors are engaged under Article 28(2) and 28(4) with the Customer's authorization and on the terms of the Data Processing Agreement, and the sub-processor annex to the Data Processing Agreement is the authoritative list. We can make it available to a Customer, or to a prospective Customer under a confidentiality agreement, on request.

9. Automated Decision-Making, Including the Allocation Engine

We do not make decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you, within the meaning of Article 22, in any of the processing described in Section 4. Nobody's access to our service, price, or treatment is decided by an algorithm.

The allocation engine deserves a direct answer, because it is what our application does. It proposes staffing assignments for a Customer's own personnel — which room, which shift, which site. Three things are true about it and all three matter. The data it runs on is Customer Data, so Orchestrate is the processor and the Customer is the controller (Section 2). Its output is a proposal that a person must review before it is used: our Terms of Use state that every proposed assignment is a suggestion requiring human review, and that scheduling decisions must be reviewed and approved by a qualified person. And any Article 22 analysis of a staffing decision made with its help belongs to the Customer as controller, not to Orchestrate — if you are a Customer's clinician or employee, that is another reason to direct a question about it to your organization.

10. Your Rights

If and to the extent the GDPR or UK GDPR applies to our processing, you have the rights below. Where it does not apply, we will still consider a request under them as a matter of policy.

  • Access (Article 15). Ask us to confirm whether we process personal data about you, and to give you a copy of it along with the information in this notice.
  • Rectification (Article 16). Ask us to correct inaccurate personal data, or to complete data that is incomplete.
  • Erasure (Article 17). Ask us to delete personal data, where one of the grounds in Article 17(1) applies — for example where it is no longer necessary for the purpose we collected it for, or where you successfully object and no overriding legitimate ground remains.
  • Restriction (Article 18). Ask us to restrict processing while we check an accuracy dispute or an objection, or instead of erasure where you need the data for a legal claim.
  • Portability (Article 20). Where we process personal data you gave us by automated means, on the basis of consent or of a contract, ask us to give it to you in a structured, commonly used, machine-readable format, or to transmit it to another controller where that is technically feasible.
  • Objection (Article 21). Object at any time, on grounds relating to your particular situation, to processing we base on legitimate interests — the rows in Section 4 that name Article 6(1)(f). We will stop unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or unless we need the data for a legal claim. An objection to direct marketing is absolute: if you tell us to stop contacting you for marketing purposes, we stop, with no balancing test. (Section 3 of the Privacy Policy records that we run no marketing campaigns, newsletters, or drip sequences at all.)
  • Automated decisions (Article 22). Not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — see Section 9.
  • Withdraw consent (Article 7(3)). Where we rely on consent, withdraw it at any time. Withdrawing it does not affect the lawfulness of what we did before you withdrew it.
  • Notification (Article 19). Where we rectify, erase, or restrict personal data, we will tell each recipient we disclosed it to, unless that proves impossible or involves disproportionate effort, and we will tell you who they are if you ask.
  • Complain (Article 77). Lodge a complaint with a supervisory authority — see Section 12.

How to exercise them, and when to expect an answer. Write to the contact in Section 3. We will respond within one month of receiving the request. We may extend that by up to two further months where the request is complex or where you have made several, and if we do we will tell you within the first month and explain why. There is no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act, and we will tell you which and why.

Verification. We will take reasonable steps to confirm who you are before acting, because acting on an unverified request is itself a disclosure to the wrong person. Section 10 of the U.S. State Privacy Notice describes how we do that; the same approach applies here. Where we have reasonable doubts, Article 12(6) lets us ask for additional information to confirm your identity.

Where we decline. We will tell you why, and tell you that you may complain to a supervisory authority and seek a judicial remedy. You may also ask us to reconsider by replying to our response.

11. Cookies, Local Storage, and the ePrivacy Rules

The site sets no advertising or analytics cookies, because no analytics or advertising tags are active on it (Section 2.2 of the Privacy Policy).

When you submit the demo or trial request form, it stores campaign-attribution values in your browser's local storage — the referring page, the path of the page you submitted from, and any campaign parameters in its address. Storing or reading information on your device is governed by Article 5(3) of the ePrivacy Directive as implemented in each member state, and in the United Kingdom by regulation 6 of PECR, which require consent for storage that is not strictly necessary to provide the service you asked for. Attribution is not strictly necessary in that sense. The site does not currently present a consent interface, because it is built and operated for United States users (Section 10 of the Privacy Policy). Before we offer the site to visitors in the EEA or the United Kingdom, we will ask for consent before storing these values.

You can clear local storage at any time through your browser's settings, and doing so removes these values. Nothing else the site stores in your browser is used for advertising or for tracking you across sites.

12. Complaints to a Supervisory Authority

If you think our processing of your personal data infringes the GDPR or the UK GDPR, you may lodge a complaint with a supervisory authority — in the EEA, the authority in the member state where you live, where you work, or where the alleged infringement took place, and in the United Kingdom, the Information Commissioner's Office.

  • EEA supervisory authorities are listed by the European Data Protection Board at edpb.europa.eu.
  • The UK Information Commissioner's Office is at ico.org.uk.

You may also seek a judicial remedy. We would rather hear from you first — write to the contact in Section 3 — but nothing in this notice requires you to, and nothing in it limits any right you have under applicable law.

13. International Transfers

Orchestrate processes the personal data covered by this notice in the United States, in Amazon Web Services' US East (N. Virginia) region. The email and payment providers named in Section 8 hold what they receive on their own infrastructure and under their own terms. Static site content is distributed through a global content-delivery network, so a page you load may be served from an edge location outside the United States.

Where you give personal data to us directly — by filling in our form or writing to us from the EEA or the United Kingdom — the European Data Protection Board's guidance on the interplay between Article 3 and Chapter V treats that as a direct disclosure by you rather than as a "transfer" requiring a Chapter V mechanism, because there is no exporter subject to the GDPR sending it. That is guidance, not a statute, and it is the position we describe rather than a legal conclusion we ask you to accept.

Where a Chapter V transfer does occur — for example where a Customer established in the EEA or the United Kingdom instructs us as its processor — the transfer mechanism is agreed in the Data Processing Agreement between us and that Customer, and that agreement, not this notice, governs it. As of the effective date of this notice we have no Customer established in the EEA or the United Kingdom.

We do not participate in the EU-U.S. Data Privacy Framework, the UK Extension to it, or the Swiss-U.S. Data Privacy Framework, and we make no claim to be certified under any of them.

14. Changes, and Contact

We may update this notice. We will post the updated version here with a new effective date, and the Privacy Policy's change process in its Section 10 applies to this notice as well.

Orchestrate AI LLC Attn: Privacy PO Box 9684, 770 Northcross Dr, Austin, TX 78766, United States Email: security@or.chestrate.com

See also the Privacy Policy, the U.S. State Privacy Notice, and our Terms of Use.

Effective September 19, 2026. This notice supplements our Privacy Policy.

ORchestrate

Intelligent Anesthesia Scheduling Platform. Your entire group staffed in one click. Built by a chief CRNA and the engineer who solved it. Austin, TX.

As heard onAtomic Anesthesia podcast

Explore

  • Problem
  • Solution
  • How It Works
  • Matching
  • Founders

Get a demo

  • Start your free trial
  • Email us directly
© 2026 ORchestrate. All rights reserved.Built by a chief CRNA and the engineer who solved it.
Privacy PolicyTerms of UseU.S. State PrivacyEEA & UK Privacy