Privacy policy
Last updated: 18 August 2026.
This page explains what personal data Orora processes when you visit orora-group.eu, write to us, request an audit, book a call, subscribe to our newsletter or buy an ebook. For each processing activity you will find the data involved, the purpose, the legal basis under article 6 GDPR and how long we keep it.
Who is responsible for your data
The controller is ORORA SRL, Rue des Bons-Enfants 111, 4500 Huy, Belgium (enterprise number 1013.027.913, VAT BE 1013.027.913).
We are not required to appoint a data protection officer, so your questions and requests reach us directly at info@orora-group.eu.
What we process, and why
Contact form
- Data: your first name, last name, email address, phone number if you give one, and the message you write.
- Purpose: to answer your enquiry and, if it leads to working together, to prepare that. A copy of your message arrives in our inbox and you receive a confirmation email.
- Legal basis: our legitimate interest in replying to people who approach us (art. 6(1)(f)). Once your enquiry concerns a quote or a proposal, steps taken at your request before entering into a contract (art. 6(1)(b)).
- Retention: no later than 24 months after our last exchange on the subject. If it turns into an engagement, the file follows that engagement and the accounting period below.
Audit request
- Data: your name, your company name, your email address, the market you are targeting, the audit scope and deep dives you select, and any free text you add.
- Purpose: to prepare and send you the audit proposal you asked for. The configuration you assemble is emailed to us together with your request.
- Legal basis: steps taken at your request before entering into a contract (art. 6(1)(b)).
- Retention: no later than 24 months after our last exchange on the subject.
Booking a call
- Data: your name, email address, phone number and the slot you choose.
- Purpose: to hold the slot, put the appointment in the work calendar of the Orora colleague who will meet you, and send you the confirmation. The availability shown comes from that calendar; nothing about you is read from it.
- Legal basis: steps taken at your request before entering into a contract (art. 6(1)(b)).
- Retention: the booking and the calendar entry are deleted no later than 24 months after the appointment date.
Newsletter
- Data: your email address.
- Purpose: to send you our newsletter.
- Legal basis: your consent (art. 6(1)(a)), given by submitting the sign-up form. You can withdraw it at any time, through the unsubscribe link in every mailing or by writing to us.
- Retention: until you unsubscribe, at which point your address is removed from the mailing list.
Buying an ebook
- Data: your name, your email address, and the order itself: the product, the amount and the payment status.
- Purpose: to record the order, have Mollie collect the payment, deliver the file to you through a personal download link, and produce the accounting record. Your card or bank account details are entered on Mollie's own secure payment page and never reach this site or our servers.
- Legal basis: performance of the contract you enter into (art. 6(1)(b)). For the invoice and the accounting entry, our legal obligation under Belgian accounting and tax law (art. 6(1)(c)).
- Retention: the download link we send you expires after 30 days. The payment and its associated data are kept by Mollie and in our accounts for 7 years from the end of the financial year concerned, the Belgian statutory retention period.
This site keeps no order database: the payment recorded at Mollie is the record of the sale.
Analytics and marketing tools
- Data: the pages you view, your clicks and interactions with the page, the page you arrived from, your device and browser, an approximate location derived from your IP address, JavaScript errors encountered, and, where session recording is active, a replay of your visit. Your IP address is not anonymised. What you type into a form is masked before it leaves your browser, and no passwords are recorded.
- Purpose: to understand how the site is used so we can improve it (PostHog), to load our measurement tags (Google Tag Manager) and to recognise the companies visiting the site (Leadinfo).
- Legal basis: your consent (art. 6(1)(a)), given in the cookie banner. None of these tools loads and no corresponding cookie is set before you accept the relevant category, and you can change your mind at any time.
- Retention: session recordings are kept for at most 30 days. Analytics events are kept by PostHog according to our project's retention setting, and for at most 7 years.
Server logs, rate limiting and errors
- Data: your IP address, the time of the request, the page requested and your user agent.
- Purpose: to keep the site available and secure, and to stop a bot from flooding our forms. The rate limiter holds your IP address in the server's memory only for as long as it takes to count your requests; it is never written to a database. Uncaught server errors are reported to us so we can fix them; they contain no identifier relating to you.
- Legal basis: our legitimate interest in the security, availability and correct operation of the site (art. 6(1)(f)).
- Retention: hosting logs are kept by our host for at most 30 days. The rate limiter's counter disappears within minutes, and at the latest when the server instance stops.
Your cookie choice itself
- Data: the optional categories you accepted or refused, the date of your decision, the banner version, and a random identifier specific to this site.
- Purpose: to remember your choice so we do not ask again on every page, and to be able to tie a later withdrawal to the acceptance it revokes.
- Legal basis: our obligation to be able to demonstrate consent (art. 6(1)(c), read with art. 7(1)).
- Retention: this record stays in your own browser and is not sent anywhere. We stop acting on it after 12 months and ask again. You can delete it yourself by clearing your browser's local storage.
Do you have to give us this data
No. Nothing on this site asks for data you are legally obliged to give us. But the forms only work with what they ask for: without an email address we cannot answer your enquiry, confirm your booking, or deliver what you bought. The optional cookies really are optional: refusing them costs you no functionality on this site.
Who else sees your data
We do not sell your data and we do not share it for third-party marketing. We do rely on the following providers, who process it on our instructions under a data processing agreement:
- Vercel Inc. (United States): hosts and serves this website.
- Sanity AS (Norway): manages the site's editorial content. No visitor data is stored there.
- Resend, Inc. (United States): delivers the contact, confirmation and delivery emails, and hosts the newsletter mailing list.
- Mollie B.V. (Netherlands): collects the payment on its own secure page and holds the payment data.
- Devly Solutions BV (Belgium): builds and maintains this site, and operates the call-booking service it uses.
- Microsoft Ireland Operations Ltd (Ireland): Microsoft 365, the inbox your message arrives in and the calendar a meeting is written into.
- PostHog, Inc. (United States): analytics, session recording and error tracking. We use PostHog's European cloud, so the data stays in the European Union. Only with your "Analytics" consent.
- Google Ireland Ltd (Ireland): Google Tag Manager, which loads our tags. Only with your "Marketing" consent.
- Leadinfo B.V. (Netherlands): identifies the company behind a business visit. Only with your "Marketing" consent.
Beyond these providers, an order reaches our accountant and the tax authorities, because an accounting record has to be booked and filed. We disclose data to any other public authority or court only where the law requires it.
Transfers outside the European Economic Area
Vercel, Resend and PostHog are established in the United States, and Sanity in Norway (an EEA country covered by the GDPR). Where personal data is transferred outside the EEA, the transfer is covered by the European Commission's standard contractual clauses, which form part of our data processing agreement with that provider, supplemented by additional measures where needed. Write to info@orora-group.eu for a copy.
Security
The site is served over HTTPS only. Ebook download links are cryptographically signed and expire, so a link can neither be guessed nor reused indefinitely. The forms are protected against automated submissions. We limit access to data to the people who need it.
Automated decision-making
We do not make decisions about you based solely on automated processing, and we do not profile you in a way that produces legal effects or similarly significant effects. Leadinfo tells us which company a visit came from; it decides nothing about you.
Minors
This site is aimed at professionals. It is not directed at minors and we do not knowingly collect data from anyone under 16.
Your rights
Under the GDPR you have the following rights over the personal data we hold about you:
- Access (art. 15): find out what we hold about you and receive a copy.
- Rectification (art. 16): have anything inaccurate or incomplete corrected.
- Erasure (art. 17): have your data deleted, except where we must keep it, an accounting record for example.
- Restriction (art. 18): have a processing activity suspended while a dispute is resolved.
- Portability (art. 20): receive the data you provided to us in a structured, machine-readable format, or ask us to pass it to a third party.
- Objection (art. 21): object to processing based on our legitimate interest, and object at any time and without giving a reason where the data is used for direct marketing.
- Withdrawal of consent (art. 7(3)): withdraw a consent you gave, at any time and as easily as you gave it: via "Manage cookies" at the foot of every page for trackers, via the unsubscribe link for the newsletter. Withdrawal does not affect the lawfulness of what was done beforehand.
To exercise any of these rights, write to info@orora-group.eu. We answer within one month. Exercising these rights is free, and we may ask you to confirm your identity before we disclose data about you.
Complaints
If you think we are handling your data badly, tell us first at info@orora-group.eu. You can also lodge a complaint with the Belgian Data Protection Authority, Rue de la Presse 35, 1000 Brussels (contact@apd-gba.be, dataprotectionauthority.be), or with the supervisory authority of the EU member state where you live or work.
Changes
We update this policy whenever the site starts or stops doing something with personal data. The last-updated date at the top of this page reflects the version in force.