How Orca360 handles personal information across the OrcaComply website and software service.
Last updated: 30 August 2026
OrcaComply is an information security management and compliance software product operated by Orca360 Ltd. In this Privacy Policy, “OrcaComply”, “Orca360”, “we”, “us” and “our” refer to Orca360 Ltd as the organisation operating the OrcaComply website and software service.
Our registered office is Ennis Suite Unit 4, 419 Wick Lane, London, England, E3 2PW. Privacy enquiries can be made through our contact page or through Orca360.
This policy applies when you visit the OrcaComply website, request information or a demonstration, create or use an OrcaComply workspace, administer an account, manage ISMS records, risks, controls, policies, evidence, audits or related compliance information, receive service communications, or otherwise interact with OrcaComply in a business capacity.
Controller activities. Orca360 generally acts as controller for information used to run its own business and customer relationship, including website enquiries, trial and account administration, licensing, billing records, service communications, security records and support correspondence.
Processor activities. Where a customer places personal data into an OrcaComply workspace for its own ISMS, compliance or assurance activities, the customer will normally be the controller and Orca360 will act as processor on that customer's documented instructions.
Customers remain responsible for identifying the lawful basis for personal data they enter into OrcaComply and for giving any privacy information required to their employees, contractors, suppliers or other individuals.
Customers should avoid placing special-category data, criminal-offence data or other highly sensitive information into OrcaComply unless it is genuinely required, lawful and appropriately protected.
We may collect information directly from you, from your employer or organisation, from another authorised OrcaComply user, through the OrcaComply application, through support or account interactions, or automatically from systems used to provide and secure the service.
Where Orca360 processes personal data in a customer's workspace as processor, we use that information only to provide, secure, maintain and support OrcaComply and in accordance with the customer's documented instructions, unless the law requires otherwise.
The customer controls its ISMS content, risk and control records, evidence requirements, authorised users, retention decisions and export or deletion choices.
OrcaComply is hosted on virtual private server infrastructure supplied by Fasthosts Internet Limited, in the same hosting environment used for other Orca360 services. Orca360 develops and operates the software and restricts administrative access to authorised personnel. Fasthosts may have limited infrastructure or administrative access where necessary to provide, secure, maintain or support the hosting service, or where required by law.
To the extent Fasthosts processes personal data on our behalf, it acts as a processor or sub-processor.
We use service providers where necessary to operate OrcaComply. The principal infrastructure provider for hosted customer data is Fasthosts Internet Limited. Other providers may be used for business communications, support, billing or related services. Where a new processor or sub-processor is introduced for customer-controlled personal data, we will update our documentation and follow any applicable authorisation or notification requirements.
If personal data is transferred outside the United Kingdom, we will use a transfer mechanism recognised under UK data protection law where one is required, together with appropriate supplementary safeguards where necessary.
We keep personal data only for as long as reasonably required for the relevant purpose, to provide the service, meet legal or accounting obligations, resolve disputes and protect legal rights.
For customer-controlled ISMS and compliance records, the customer determines its retention period. Deletion from active systems may not immediately remove information from protected backups; backup copies are retained only for the applicable backup lifecycle and are then overwritten or deleted through normal rotation.
We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful loss, alteration, disclosure or access. Measures include access controls, account permissions, authentication controls, logging, server administration controls and software maintenance appropriate to the service.
No internet-based service can be guaranteed completely secure. Customers are responsible for maintaining secure user accounts, suitable permissions and appropriate organisational controls for their own users.
Where Orca360 acts as processor and becomes aware of a personal data breach affecting customer-controlled data, we will notify the relevant customer without undue delay and provide reasonable information and assistance to support the customer's own assessment and notification obligations.
Depending on the circumstances, individuals may have rights including access, rectification, erasure, restriction, objection, data portability and rights relating to solely automated decision-making. These rights are subject to legal conditions and exemptions.
If information is held in an OrcaComply customer workspace and the customer is the controller, we may direct the request to that customer or assist the customer in responding.
If you have concerns about how personal data is handled, please contact us first. You also have the right to complain to the Information Commissioner's Office (ICO), the UK supervisory authority for data protection.
The OrcaComply marketing website does not currently use analytics, advertising or behavioural tracking cookies. The authenticated OrcaComply application may use strictly necessary session or security technologies required to sign users in, maintain a secure session and provide requested functionality. Please see our Cookie Policy.
We may contact business users about OrcaComply where permitted by applicable law. You can ask us to stop direct marketing at any time. Service, billing, security and account messages are not marketing and may still be sent where necessary to provide the service.
We may update this policy to reflect changes in law, regulation, infrastructure or the OrcaComply service. The latest version will be published on this page with an updated date.