Your data,
protected.
How Orispace Studio SAS collects, uses and protects your personal data across orispace.co, viewer.orispace.co and venue.orispace.co.
LAST UPDATED — June 24, 2026Orispace Studio SAS(“Orispace”, “we”, “us”, or “our”) is committed to protecting your personal data. This Privacy Policy explains what data we collect, why we collect it, how we use it, and what rights you have over it.
It applies to all services accessible via orispace.co, viewer.orispace.co and venue.orispace.co (collectively, the “Service”).
Who is responsible.
The data controller responsible for your personal data is:
What we collect.
| Category | Data | Source |
|---|---|---|
| Account | Email address, display name | Provided by you at registration |
| Content | Uploaded 3D model files, texture files | Provided by you when using the viewer |
| Technical | Authentication token (stored in browser localStorage), IP address (not stored) | Generated automatically at login |
| Billing | Billing email, transaction ID | Provided by you at checkout (processed by (No setup yet)) |
We do not collect sensitive data (health data, political opinions, biometric data, etc.).
Why we process it.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and managing your account | Performance of a contract (Art. 6.1.b) |
| Storing and displaying your 3D models | Performance of a contract (Art. 6.1.b) |
| Processing payments | Performance of a contract (Art. 6.1.b) |
| Responding to support requests | Legitimate interest (Art. 6.1.f) |
| Complying with legal obligations (e.g. accounting records) | Legal obligation (Art. 6.1.c) |
How long we keep it.
| Data | Retention period |
|---|---|
| Account data (email, display name) | Duration of the account + 30 days after deletion |
| Uploaded files (3D models, textures) | Deleted immediately upon account deletion |
| Billing records | 10 years (French legal accounting obligation) |
| Support correspondence | 3 years from last contact |
You can permanently delete your account and all associated data at any time from your account settings (Danger zone).
Who we work with.
We use the following sub-processors to operate the Service. Each acts solely on our instructions and is bound by a data processing agreement.
| Provider | Role | Location | Transfer mechanism |
|---|---|---|---|
| Supabase Inc. | Authentication & database | United States | Standard Contractual Clauses (SCCs) |
| Cloudflare Inc. | File storage (R2) | United States | EU-US Data Privacy Framework |
| Vercel Inc. | Hosting & CDN | United States | EU-US Data Privacy Framework |
| (No setup yet) | Payment processing | ... to be determined ... | ... to be determined ... |
We do not sell your data to any third party. Your files are never shared with third parties outside the providers listed above.
Data outside the EU.
Some of our sub-processors are based in the United States. These transfers are governed by either the EU-US Data Privacy Framework (an adequacy decision by the European Commission) or Standard Contractual Clauses (SCCs) approved by the European Commission, ensuring a level of data protection equivalent to that in the European Union.
What you can do.
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15) — obtain a copy of the data we hold about you
- Right to rectification (Art. 16) — correct inaccurate or incomplete data
- Right to erasure (Art. 17) — request deletion of your data (“right to be forgotten”)
- Right to restriction (Art. 18) — request that we limit processing of your data
- Right to data portability (Art. 20) — receive your data in a structured, machine-readable format
- Right to object (Art. 21) — object to processing based on legitimate interest
- Right to withdraw consent (Art. 7) — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
To exercise any of these rights, contact us at contact@orispace.co. We will respond within 30 days.
You also have the right to lodge a complaint with the French data protection authority — CNIL(Commission Nationale de l’Informatique et des Libertés), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr.
We don't use them.
We do notuse HTTP cookies. Authentication sessions are maintained through the browser’s localStorage, which is local to your device and never transmitted to third parties. This token expires when you log out or clear your browser storage.
We do not use advertising, tracking, or analytics cookies. No consent banner is required or displayed.
How we protect it.
We implement appropriate technical and organisational measures to protect your data against unauthorised access, disclosure, alteration or destruction. These include encryption in transit (TLS), encryption at rest, and access controls on all data stores.
In the event of a data breach likely to affect your rights and freedoms, we will notify you and the CNIL within the timeframes required by law.
Age requirement.
The Service is not directed at children under the age of 16. We do not knowingly collect personal data from minors. If you believe a minor has provided us with personal data, please contact us at contact@orispace.co and we will delete it promptly.
Updates to this policy.
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated” date at the top of this page and, where changes are significant, notify you by email or via the Service.
Your continued use of the Service after any changes constitutes acceptance of the updated policy.
Get in touch.
For any questions about this Privacy Policy or your personal data: