1. Controller and processor roles
For the employee and organisational data you put into charts or submit for spreadsheet review, you are the data controller and Org Chart Studio is your data processor. We process that data only on your documented instructions (see our Terms and the Data Processing Agreement available to customers on request).
For your own account data (your name, email, sign-in, billing, and the analytics you consent to), we are the data controller. The legal bases below distinguish the two.
2. Legal bases (Art. 6)
| Processing | Lawful basis |
|---|---|
| Providing the service — creating your account, signing you in, storing and exporting your charts, collaboration | Art. 6(1)(b) — performance of our contract with you |
| Payments and billing records | Art. 6(1)(b) contract + Art. 6(1)(c) legal obligation (financial record-keeping) |
| Employee data in charts or submitted for spreadsheet review | Processed only on your documented instructions — you are the controller, we are the processor (Art. 28). We hold no independent basis for it. |
| Analytics, session replay, and marketing | Art. 6(1)(a) — your consent. Opt-in, granular per purpose, off by default, and withdrawable at any time. |
| Basic security/support telemetry (e.g. last-seen) and aggregate visitor counting | Art. 6(1)(f) — legitimate interest. Minimal, aggregate, and never used to track individuals. |
| Recording your consent choices | Art. 6(1)(c) — legal obligation (to be able to demonstrate consent) |
We do not ask you to submit special-category data (Art. 9) or children's data through the service. Org Chart Studio limits saved chart data to supported fields and custom fields you create, but it does not determine whether the content is sensitive. Do not use those fields for such data unless we have agreed to that processing in writing (see §5).
3. Your rights
You have the right to access, rectify, erase, restrict, and object to the processing of your personal data, to data portability, and to withdraw consent at any time. The Privacy Policy describes each in full. In practice, most rights are self-service:
- Erasure / account deletion: delete your account and the data held in it from account settings, with no email required. Chart drafts stored in other browsers or on offline devices must be cleared there.
- Portability — export your charts as CSV, PNG, PDF, or PowerPoint at any time.
- Withdraw consent — change analytics, session-replay, and marketing choices from the cookie settings in the footer; declining changes nothing about how the product works.
- Per-employee erasure: ask us to remove a named individual from every saved version of your charts.
For access, rectification, restriction, objection, or anything not covered above, contact us (§7) and we will respond within one month.
4. Where your data lives
Your consented behavioural event analytics is processed by Rybbit Cloud and Google Analytics. If you also accept marketing measurement, Google Tag Manager can coordinate optional advertising conversion tags. Rybbit states that its primary application and analytics infrastructure is hosted with Hetzner in Germany/EU; Google LLC processes analytics data in the United States under the EU-US Data Privacy Framework and SCCs. The first-party event payload contains pseudonymous identifiers and PII-scrubbed usage metadata — never your name, email, IP address, raw URL parameters, or org-chart employee data. Tinybird's Frankfurt workspace is retained temporarily as a legacy, read-only historical archive and rollback source.
Rybbit stores encrypted session-replay objects with Cloudflare R2 and its DPA permits processing outside the EEA subject to Standard Contractual Clauses or other recognized safeguards. We therefore do not claim that every replay byte remains exclusively in the EEA. Other sub-processors (including our current database, hosting, authentication, and payments) also process data in the United States. For applicable EU/EEA and UK transfers we rely on the EU-US Data Privacy Framework where the recipient is certified, and on Standard Contractual Clauses (EU SCCs 2021/914 + UK IDTA/Addendum) with a transfer impact assessment otherwise.
The full list — each sub-processor, what it processes, its region, and the transfer instrument — is on our Sub-processor List.
5. How privacy is enforced in the product
Rather than rely on policy alone, these protections are built into the code:
- Consent-gated by default. No analytics, session-replay, or marketing tool loads until you opt in, per purpose. Global Privacy Control (GPC) is honoured.
- Data-minimised analytics. Events carry pseudonymous IDs only — no names, emails, IP addresses, raw URL parameters, or employee data — and the primary Rybbit analytics infrastructure is in Germany (§4).
- Employee data is masked out of session recordings. Replay never runs on sign-in, verification, or checkout pages; input/editable fields are ignored and masked; employee details in chart nodes are replaced with neutral placeholder text in the recording (the real values are transformed in the browser and never transmitted); and surfaces listing employee data in full (people list, export previews, import comparisons) plus iframe content are blocked. The recorder does not capture our chart API request or response bodies.
- Saved chart data is limited. Only supported chart fields and custom fields you create are saved. Custom-field values are stored as supplied, so customers must not use them for special-category or children's data.
- Retention is enforced automatically by a scheduled purge, not manual cleanup, and erasure rotates the identifiers that could re-link anonymised records.
6. Retention
We keep personal data only as long as needed for the purpose it was collected, then delete or anonymise it. The specific windows (and the mechanisms that enforce them) are listed in the Privacy Policy.
7. Contact and complaints
For any data-protection question, or to exercise a right, contact us at hello@orgchartstudio.com.
If you are in the EU/EEA or the UK, you also have the right to lodge a complaint with your local data-protection supervisory authority.