Legal

Privacy Policy

What data we hold, why, for how long, and how to get it back or have it erased. Twelve articles, all linked from the table of contents.

Last updated 13 September 2026

This English version is provided for your convenience. The French version is the legally binding text and prevails in case of any discrepancy. Read the French version

This policy explains how oReel (“we”, available at oreel.me) collects, uses and protects your personal data when you use our online portfolio creation service or visit our website. We apply the General Data Protection Regulation (GDPR).

Controller

The controller is Wedey OÜ, a company registered in Estonia under number 17153535, with its registered office at Sepapaja tn 6, 15551 Tallinn, Estonia. For any question about your data, write to [email protected].

For the data of people who visit a customer's portfolio (messages, appointments, subscribers, conversations with the assistant), the controller is that customer, and we act as processor under the Data Processing Agreement.

1. Data we collect

  • Account: e-mail address and password hash (never the password in plain text). Optionally your name and an avatar.
  • Sign-in with Google: if you choose this method, Google sends us your e-mail address, your name and your profile picture. We receive no access to your Google account.
  • Portfolio data: all content you publish — text, images, videos, social links, testimonials, prices, booking slots.
  • CV or LinkedIn profile import: when you request it, we read the document you upload or the public profile page whose address you provide, and we extract fields from it that are offered to you as suggestions. The document and the page are not kept; the text of a CV is sent to our artificial intelligence provider for extraction.
  • Google Calendar: if you connect your calendar, we read your busy times to hide unavailable slots and we create an event when you confirm an appointment. The access token is encrypted; you can disconnect the calendar at any time.
  • Audience measurement of the oReel website: our servers record the requested page, the referring site, campaign parameters, the country, and the device and browser type. No IP address is recorded: a visit is linked to a fingerprint recalculated every day, which does not make it possible to recognise you from one day to the next. This measurement does not set any cookie.
  • Product analytics events: after you accept analytics cookies, page views, clicks, performance measurements and errors encountered in your browser, together with your IP address (from which we derive a country and a city). Once you are signed in, these events are linked to your account so that we can handle a support request. No data is sold or matched with any advertiser.
  • Session recording: after you accept analytics cookies, the course of your visit (navigation, clicks, input) in order to reproduce a malfunction. Password fields are masked; no card data passes through our pages. You can withdraw your consent via “Manage cookies”.
  • Portfolio statistics: the owner of a portfolio sees the COUNTRY each view comes from — never the city or the IP address, which are not kept for this purpose.
  • Data of portfolio visitors: name, e-mail and message of people who write or book a slot; e-mail of newsletter subscribers; questions asked to the assistant (without IP address).
  • Payments: Stripe handles the entire payment. We receive the country and, where applicable, the VAT number needed to calculate tax, but no card data.

2. Purposes of processing

  • Providing the oReel service (creating, editing, hosting and publishing your portfolio).
  • Invoicing, calculating the taxes due and keeping the accounts.
  • Essential communications (security, billing, appointments, messages received).
  • Customer support when you contact us.
  • Audience measurement and product improvement.
  • Preventing fraud and abuse, limiting the number of requests.

3. Legal basis

  • Performance of the contract — account, hosting of your content, imports you request, connection of your calendar, payment.
  • Consent — analytics cookies and session recording, newsletter sign-up (can be withdrawn at any time).
  • Legitimate interest — security, fraud prevention, error logs, audience measurement without cookies or IP addresses.
  • Legal obligation — retention of accounting and tax records.

4. Retention period

  • Account and portfolio data: for as long as your account is active.
  • After deletion of your account (via Settings > Danger zone): all your data and files are erased immediately — or at the end of the 30-day suspension if you chose to suspend first. Backup copies follow within the periods below.
  • Backups: one daily copy, kept for 14 days; a file deleted from the service is removed from the copy within 30 days.
  • Error logs: 90 days.
  • Audience measurement and analytics events: 13 months maximum.
  • Accounting records: the period required by applicable law (up to 10 years).

5. Processors

We work with selected processors, bound by a GDPR-compliant data processing agreement:

  • Supabase — authentication, database and file storage. Place of processing: European Union (eu-central-1).
  • Stripe — payment, subscription and tax processing. Place of processing: Ireland and United States (standard contractual clauses).
  • Brevo — sending transactional e-mails. Place of processing: France — French company, data in the European Union.
  • DeepSeek — artificial intelligence features (bio writing, visitor chatbot, CV extraction); requests are not used to train models. Place of processing: outside the European Union (standard contractual clauses).
  • Contabo GmbH — hosting of the application on a dedicated server. Place of processing: Lauterbourg, France.
  • Cloudflare — content delivery network, attack protection and bot verification (Turnstile); sees the IP address of every request. Place of processing: global network, US company (standard contractual clauses).
  • Upstash — request rate limiting against abuse; keeps the IP address or account identifier for a few minutes. Place of processing: Frankfurt, Germany (EU region).
  • Sentry — collection of technical errors for diagnosis. Place of processing: European Union (EU region).
  • PostHog — product analytics, session recording and browser error tracking. Place of processing: European Union (EU region).

Google acts as a separate controller when you sign in with your Google account or connect your calendar; its own privacy policy applies.

6. Your rights

You have the following rights over your data. Most of them can be exercised directly from your dashboard.

  • Access and portability — export all your data in JSON format via Settings > Danger zone.
  • Rectification — edit your profile in Settings > Profile.
  • Erasure — permanently delete your account via Settings > Danger zone.
  • Objection and withdrawal of consent — refuse analytics cookies via “Manage cookies” in the footer.
  • Restriction of processing — write to us.
  • The right to lodge a complaint with the supervisory authority of your country, or with the Estonian data protection authority (Andmekaitse Inspektsioon).

If you are a visitor to a portfolio, first address your request to its owner; we will help them respond to it.

7. Cookies

oReel uses a minimal number of cookies:

  • Technical cookies — sign-in session, chosen language, memory of your cookie choice, and referral link (30 days). They are necessary for the service and do not require consent.
  • Analytics cookies — only after your explicit consent. No advertising cookies, ever.

8. International transfers

The application is hosted on a dedicated server from Contabo GmbH located in Lauterbourg (France), and the database in the European Union. Some processors listed in article 5 process data outside the European Union, in particular in the United States.

These transfers are governed by an adequacy decision of the European Commission (including the EU–US Data Privacy Framework where the recipient participates in it) or by standard contractual clauses. You can disable the artificial intelligence features by not using them.

9. Security

  • TLS encryption of all communications.
  • Data isolation at database level (Row Level Security): each customer can access only their own data.
  • Passwords hashed by our authentication provider.
  • Request rate limiting and bot verification on public forms.
  • Audit log of administrative actions.
  • Daily backup of data and files, with automatic restore testing.

10. Contact

For any question or to exercise your rights, write to [email protected]. We reply within one month at the latest.

11. Changes

This policy may change along with the service or the regulations. The date at the top of the page shows the latest update. In the event of a significant change, we will notify you by e-mail before it takes effect.