Privacy Policy

Last updated: 1 September 2026

This Privacy Policy describes how Organigram ("we", "us", "our"), operated by Szaloczi Brothers AB (559596-6481), Registered office: Lomma, Sweden, collects, uses, discloses and protects personal data when you access or use the Organigram workforce-planning platform and related services available through organigram.se (the "Service").

We are committed to processing your personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national data protection law.


1. Who We Are

Data Controller (for account and subscriber data): Szaloczi Brothers AB Registered office: Lomma, Sweden Email: privacy@organigram.se

For customers using Organigram to manage workforce planning information, the customer organisation generally acts as the Data Controller, while Organigram acts as a Data Processor for Workspace Data. If you have questions about this Policy or how we handle your data, contact us at privacy@organigram.se.


2. Definitions

For the purposes of this Privacy Policy:

"Personal Data" means any information relating to an identified or identifiable natural person.

"Customer Data" means information uploaded, submitted, or generated by customers while using the Service, including workforce and organisational information.

"Workspace Data" means data contained within a customer's Organigram workspace, including organisational structures, employee information, and workforce planning scenarios.

"Controller" and "Processor" have the meanings given under the EU General Data Protection Regulation (GDPR).


3. Scope of This Policy

This Privacy Policy covers two main categories of personal data processed through the Service:

CategoryDescriptionOur role
Account dataPersonal data you provide when registering and using Organigram (your name, email, account activity)Data Controller
Workspace / workforce dataPersonal data you or your organisation upload into a workspace (employee names, titles, salaries, org-chart relationships, etc.)Data Processor

When we act as Data Processor for workspace data, the organisation that created the workspace is the Data Controller. Our obligations in that role are governed by our Data Processing Agreement (DPA). This Policy focuses on our role as Data Controller for account data. We process Workspace Data only according to the customer's documented instructions and do not use such data for our own independent purposes, including advertising, profiling, or unrelated product development.


4. Personal Data We Collect

4.1 Account data (collected directly from you)

DataPurpose
Full nameDisplay in the app; identify you to workspace collaborators
Email addressAuthentication, transactional notifications, account communications, and marketing emails (only with your explicit consent)
Marketing email consent preferenceRecording whether you have opted in to receive marketing emails; used solely to determine whether such emails are sent to you
Password (bcrypt-hashed and never stored in plain text)Authentication
Workspace membership and roleAccess control
Login timestamps and session activitySecurity, fraud detection, service improvement
IP addressRate-limiting and abuse prevention (not linked to a persistent profile)
Workspace access request messagesText you submit when requesting access to a workspace owned by another user; used to communicate your request to the workspace owner
Feedback and survey responsesOptional satisfaction rating, use-case description, feature gap notes, NPS score, and free-text comments you may submit via the in-app feedback prompt after using the export feature. Submission is always voluntary; skipping has no effect on your use of the Service

Our servers receive standard HTTP request data (such as your IP address and browser user agent) in the normal course of operating the Service. This information is used for security and stability purposes and is not stored in a persistent profile.

4.2 Workspace / workforce data (processed on your behalf)

When you import an org chart or build one manually, data stored in your workspace may include employee names, employee IDs, work email addresses, job titles, seniority levels, departments, reporting lines, salary information, FTE, cost-centre data, and other workforce-planning fields you choose to include. We do not use this data for our own purposes — we store and process it solely to deliver the Service as a Data Processor acting on your instructions.

Customers should not upload special categories of personal data as defined under Article 9 GDPR unless such processing is necessary for the customer's purposes and supported by an appropriate lawful basis under applicable data protection law.

Customers may choose to import workforce data from third-party services such as Google Sheets. Where such integrations are used, Organigram accesses the selected data solely to perform the requested import and does not retain ongoing access unless explicitly authorised by the customer.

4.3 Data we do not collect


5. How We Use Your Data and Our Legal Basis

PurposeLegal basis (GDPR Art. 6)
Providing the Service (account creation, login, workspace access)Contract — Art. 6(1)(b): necessary to perform the contract with you
Sending transactional emails (email verification, password reset, workspace invitations)Contract — Art. 6(1)(b)
Security monitoring, rate-limiting, fraud and abuse preventionLegitimate interests — Art. 6(1)(f): protecting the integrity of the Service and our users
Service improvement (diagnosing errors, improving reliability)Legitimate interests — Art. 6(1)(f)
Compliance with legal obligationsLegal obligation — Art. 6(1)(c)
Sending product-update and marketing emailsConsent — Art. 6(1)(a): only if you have explicitly opted in. You may withdraw consent at any time by clicking the unsubscribe link in any marketing email, or by emailing privacy@organigram.se. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
Collecting optional product feedback (post-export survey)Legitimate interests — Art. 6(1)(f): understanding how users experience the Service and prioritising product improvements. The feedback prompt is voluntary and skippable with no consequence to use of the Service

Where we rely on legitimate interests (Art. 6(1)(f)), we have assessed that our interest in securing and improving the Service is not outweighed by your privacy interests. The relevant processing is limited to transient operational data (such as IP-based rate limiting and server logs); it does not involve profiling, behavioural analysis, or any use beyond the specific technical purpose identified above.


6. Data Retention

Data categoryRetention period
Account data (name, email, password hash)For as long as your account is active, plus 30 days after deletion
Workspace dataUntil the workspace owner deletes it, or until your account is deleted (owned workspaces are deleted with the account)
Marketing email consent preferenceRetained for the lifetime of your account. Changing your preference in Account Settings or via an unsubscribe link takes effect immediately for future emails.
Security / access logsWorkspace audit trail records are retained for the lifetime of the workspace and are permanently deleted when the workspace or account is deleted.
Password reset tokensPassword reset tokens are single-use and time-limited (1 hour). Used or expired tokens are purged from operational systems in routine cleanup processes; residual copies in backups are purged within 30 days.
Deleted accountWhen you delete your account, your account data and owned workspace data are deleted immediately from our operational systems. Residual copies in backup systems are purged within 30 days.
Feedback / survey responsesRetained until your account is deleted. You may also request deletion at any time by emailing privacy@organigram.se.

Different retention periods may apply where we are required to retain information to comply with legal obligations, resolve disputes, enforce agreements, or protect our legitimate interests.

When your account is deleted, workspaces you own and associated Workspace Data are scheduled for deletion and permanently erased within 30 days, unless retention is required for legal or security purposes.

Deleting an individual user account does not automatically delete Workspace Data owned by another organisation or workspace owner.


7. Who We Share Your Data With

We do not sell, trade, or rent your personal data. We may share personal data with trusted third-party service providers ("Sub-processors") that support the operation, security, and delivery of the Service and are contractually bound to appropriate data protection safeguards:

Sub-processorRoleLocationSafeguard
Render (render.com)Backend API and frontend hostingUnited StatesEU Standard Contractual Clauses (SCCs)
Neon (neon.tech)Managed PostgreSQL databaseFrankfurt, Germany (EU)EU-located data storage
Resend (resend.com)Transactional email (verification, password reset, invitations)United StatesEU Standard Contractual Clauses (SCCs)
Stripe (stripe.com)Payment processing, subscription management and billingUnited States / EU (depending on services)SCCs and/or EU–US Data Privacy Framework, where applicable

We require our Sub-processors to process personal data only for agreed purposes and to implement appropriate confidentiality and security measures consistent with applicable data protection laws.

We do not use Customer Data contained within customer workspaces to train third-party general-purpose AI models or for advertising purposes.

We may disclose personal data if required by law, court order, or in connection with legal proceedings.


8. International Data Transfers

Our primary database is located in Frankfurt, Germany (EU). Some of our Sub-processors may process personal data outside the European Economic Area (EEA). Where such transfers occur, we implement appropriate safeguards in accordance with applicable data protection law, including Standard Contractual Clauses approved by the European Commission, adequacy decisions, or other lawful transfer mechanisms. Where applicable, we may also rely on the EU–US Data Privacy Framework.


9. Your Rights Under GDPR

As a data subject, you have the following rights:

RightWhat it means
Access (Art. 15)Request a copy of the personal data we hold about you
Rectification (Art. 16)Request correction of inaccurate or incomplete data
Erasure (Art. 17)Request deletion of your personal data — you can also do this directly via Account Settings → Delete Account
Restriction (Art. 18)Request that we restrict processing of your data in certain circumstances
Portability (Art. 20)Request a machine-readable copy of the personal data you provided to us — you can also do this directly via Account Settings → Export my data
Objection (Art. 21)Object to processing based on legitimate interests
Withdraw consentWhere processing is based on consent (e.g. marketing emails), withdraw at any time by: (a) using the Communications toggle in Account Settings (avatar menu → What's New → Communications section), (b) clicking the unsubscribe link in any such email, or (c) contacting privacy@organigram.se. Withdrawal does not affect prior processing.

To exercise any of these rights, use the self-service options in Account Settings where available, or email privacy@organigram.se. We will respond without undue delay and generally within one month of receiving your request. Where permitted by GDPR, this period may be extended, and we will inform you if an extension is required. We may also ask you to verify your identity.

You have the right to lodge a complaint with your national supervisory authority. In Sweden, that is the Integritetsskyddsmyndigheten (IMY): imy.se. In other EEA states, contact your local authority.

If you are an employee whose personal data has been added to an Organigram workspace by your employer, your rights regarding that data should be exercised with your employer as the Data Controller.


10. Cookies and Local Storage

Organigram uses cookies and similar technologies that are necessary for providing and securing the Service.

MechanismPurposeDuration
Essential authentication cookiesUsed to securely authenticate users and maintain logged-in sessions. Session validity may expire earlier due to server-side security controls.up to 7 days
Local storageUsed to store user preferences and application settingsUntil deleted by the user

These technologies are required for the operation of the Service and are not used for advertising, cross-site tracking, or behavioural profiling.

We use PostHog analytics cookies to understand product usage (e.g. which features are used, session flow). These only load after you explicitly accept cookies via the banner below. We do not use advertising cookies or cross-site tracking cookies.

A session identifier is generated in your browser and included in requests to the Service for the duration of your browser session. It is not linked to your account and is cleared when you close your browser tab.


11. Security and Protection of Personal Data

We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, disclosure, alteration, loss, or destruction.

If you believe your account has been compromised, contact us immediately at privacy@organigram.se.


12. Security Incidents

If we become aware of a personal data breach affecting personal data processed through the Service, we will investigate the incident, take appropriate mitigation measures, and notify affected customers without undue delay where required by applicable law.

Where Organigram acts as a Data Processor, we will provide customers with information reasonably necessary to enable them to fulfil their own obligations under applicable data protection law.


13. Children

Organigram is a B2B tool intended for business professionals. We do not knowingly collect data from individuals under 16 years of age. If we become aware that we have inadvertently done so, we will delete it promptly.


14. Changes to This Policy

We may update this Policy from time to time. For material changes, we will notify registered users by email or a prominent in-app notice at least 14 days before the change takes effect. The "Last updated" date at the top reflects the most recent revision. Your continued use of the Service after the updated Policy becomes effective means that you acknowledge the revised Policy. Where required by applicable law, we will obtain consent or provide additional notice before changes take effect.


15. No Automated Decisions

Organigram provides workforce planning, organisational modelling, and reporting capabilities. The Service does not make automated decisions about individuals that produce legal or similarly significant effects, including decisions relating to employment, hiring, promotion, termination, compensation, or eligibility.


16. Contact

Privacy enquiries: privacy@organigram.se

General: organigram.se

Postal address: Lomma, Sweden