GDPR & UK-GDPR Compliance
How OrionHQ aligns with European data protection regulations.
1. Data Subject Access Rights (DSAR)
Under the General Data Protection Regulation (GDPR) and UK-GDPR, users within the European Union (EU) and United Kingdom (UK) are entitled to exercise their legal rights. OrionHQ provides built-in tools to support these rights:
- Right to be Informed: Transparent explanations of how your data is processed.
- Right of Access: Request a complete download of your personal data history.
- Right to Rectification: Request correction of inaccurate profile data.
- Right to Erasure: Self-service request to erase all your personal records.
- Right to Object: Toggle cookie preferences to disable analytics/marketing scripts instantly.
2. Consent Manager & Cookies Gating
Our cookie consent banner is fully compliant with European guidelines: analytics and marketing scripts do not execute before explicit opt-in. All client-side tags are routed through server-side GTM client container gating, and GA4 events are sent via GTM Server rather than directly from your browser.
3. Data Security & Storage Isolation
All data processed by OrionHQ is saved in Google Cloud Firestore. We enforce strict database security rules denying all client-side browser writes to compliance collections. This prevents data injection and unauthorized modifications.
4. Incident Response
In the event of a security incident or data breach, OrionHQ will notify affected users and the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33.