GDPR & UK-GDPR Compliance

How OrionHQ aligns with European data protection regulations.

Last Updated: June 21, 2026

1. Data Subject Access Rights (DSAR)

Under the General Data Protection Regulation (GDPR) and UK-GDPR, users within the European Union (EU) and United Kingdom (UK) are entitled to exercise their legal rights. OrionHQ provides built-in tools to support these rights:

  • Right to be Informed: Transparent explanations of how your data is processed.
  • Right of Access: Request a complete download of your personal data history.
  • Right to Rectification: Request correction of inaccurate profile data.
  • Right to Erasure: Self-service request to erase all your personal records.
  • Right to Object: Toggle cookie preferences to disable analytics/marketing scripts instantly.

2. Consent Manager & Cookies Gating

Our cookie consent banner is fully compliant with European guidelines: analytics and marketing scripts do not execute before explicit opt-in. All client-side tags are routed through server-side GTM client container gating, and GA4 events are sent via GTM Server rather than directly from your browser.

3. Data Security & Storage Isolation

All data processed by OrionHQ is saved in Google Cloud Firestore. We enforce strict database security rules denying all client-side browser writes to compliance collections. This prevents data injection and unauthorized modifications.

4. Incident Response

In the event of a security incident or data breach, OrionHQ will notify affected users and the relevant supervisory authority within 72 hours of becoming aware of the breach, in accordance with GDPR Article 33.

GDPR Compliance | OrionHQ