OrangeCone Platform
Last Updated: February 16, 2026
This document outlines OrangeCone's compliance with the General Data Protection Regulation (GDPR) and demonstrates our commitment to protecting user privacy and data rights. Our platform has implemented comprehensive technical and organizational measures to ensure full compliance with GDPR requirements.
Processing necessary to provide our civic engagement services, including account management, report submission, and community features.
User consent obtained for optional features such as analytics cookies, marketing communications, and location tracking.
Platform security, fraud prevention, and service improvement based on our legitimate business interests.
| GDPR Right | Implementation | Status |
|---|---|---|
| Right to Access | Settings → Download My Data (JSON export) | ✓ Implemented |
| Right to Rectification | Settings → Profile editing functionality | ✓ Implemented |
| Right to Erasure | Settings → Delete Account (soft delete with 30-day grace period) | ✓ Implemented |
| Right to Data Portability | Machine-readable JSON export with 7-day download link | ✓ Implemented |
| Right to Restrict Processing | Contact privacy@orangecone.app for manual processing | ✓ Implemented |
| Right to Object | Settings → Notification preferences, marketing opt-out | ✓ Implemented |
| Right to Withdraw Consent | Cookie banner, notification settings, account deletion | ✓ Implemented |
OrangeCone collects only data necessary for platform functionality:
| Data Type | Retention Period | Reason |
|---|---|---|
| Active Account Data | While account is active | Service provision |
| Deleted Account Data | 30 days (grace period), then anonymized | Account recovery option |
| Public Reports | Indefinitely (anonymized after account deletion) | Community benefit |
| Analytics Data | 24 months | Platform improvement |
| Security Logs | 12 months | Security and fraud prevention |
OrangeCone uses the following third-party processors, all with GDPR-compliant Data Processing Agreements:
If data is transferred outside the EEA, we ensure appropriate safeguards through Standard Contractual Clauses (SCCs) approved by the European Commission, or by processing data only in countries with adequacy decisions.
As required by Article 30 GDPR, we maintain records of processing activities including:
In-App Tools:
Settings page provides direct access to data download, profile editing, and account deletion.
Email Contact:
privacy@orangecone.app - Responses within 30 days as required by GDPR
Identity Verification:
Users must be logged in or provide verification details to exercise rights
Users have the right to lodge a complaint with their local data protection authority. For more information, visit your country's data protection authority website.
OrangeCone conducts regular compliance reviews including:
GDPR Compliance Status: Fully Compliant
This documentation demonstrates OrangeCone's comprehensive compliance with GDPR requirements through technical implementations, organizational procedures, and transparent user communication.
Contact for Compliance Inquiries:
Email: privacy@orangecone.app
Data Protection Officer: dpo@orangecone.app