This page represents our latest version, it can be downloaded here. Our previous version is archived here.

Controller: Orderlion GmbH, Himmelpfortgasse 17/7, 1010 Vienna, Austria ("Orderlion", "we").

Privacy contact: privacy@orderlion.com · Our internal data protection lead is Patrick Schubert (CTO), reachable via this address. We have not designated a formal data protection officer under Art 37 GDPR, as we are not legally required to; all requests are handled by our data protection lead.

1. The short version

We are a B2B company. We process personal data of website visitors, business contacts and leads, users of our customers (food and beverage suppliers), and their buyers' staff. For data inside the Orderlion platform, our customer (the supplier) usually decides the purposes; we process it on their behalf. We use AI to extract orders from emails; the AI providers do not train their models on this data. We do not sell personal data, and we make no automated decisions with legal effect on individuals.

2. Our two roles: controller and processor

For our website, marketing, sales, billing, support and our customers' user accounts, Orderlion is the controller.

For the data processed inside the platform on behalf of our customers, in particular data of buyer users (staff of restaurants and other businesses ordering from our customers: names, work email addresses, login data, orders, messages), the supplier is the controller and Orderlion is their processor under a Data Processing Agreement. If you are a buyer user and want to exercise data protection rights regarding your data on the platform, please contact your supplier; we support them in answering your request. Sections 3 to 6 below describe processing where we are controller; Section 7 explains the platform processing we perform for suppliers.

3. Website visitors

Hosting and logs. When you visit orderlion.com, our hosting provider processes technical data (IP address, browser and device information, referrer, pages visited, timestamps) in server logs, to deliver the website securely and defend against attacks. Legal basis: legitimate interest (Art 6(1)(f) GDPR). Log retention is set by our hosting provider and varies by log type, up to a maximum of twelve months.

Cookies and similar technologies. We use a consent management platform (cookie banner) that sorts every cookie and comparable technology, including browser local and session storage, into four categories: Essential, Analytics, Marketing and Personalisation. Everything other than Essential is blocked until you actively consent to that category. Nothing is pre-ticked, refusing is as easy as accepting, and you can change or withdraw your choices at any time through the cookie preferences link in the website footer. Your choice is stored in your own browser and expires automatically after six months, after which we ask you again. We also keep a record of the consent given, so that we can demonstrate it, as data protection law requires us to be able to do.

Essential technologies run without consent, on the basis of our legitimate interest and § 165(3) TKG 2021, because the website cannot be delivered securely without them. They cover bot protection and denial-of-service mitigation provided through our website host, and Google reCAPTCHA, which protects our contact and booking forms against automated abuse and processes technical and interaction data for that purpose.

Consent-based technologies run only with your consent (Art 6(1)(a) GDPR, § 165(3) TKG 2021):

  • Google Tag Manager and Google Analytics 4 (Google Ireland Ltd): reach and usage analytics. The analytics cookies last up to two years; the analytics data itself is retained for 14 months.
  • HubSpot (HubSpot Ireland): website analytics, forms and chat (see Section 4).
  • Microsoft Clarity (Microsoft Ireland Operations Limited): usage analytics, heatmaps and session analysis, to understand how the website is used. Microsoft acts as an independent controller for this data and retains the session data for up to 30 days. We have switched off the sharing of Clarity data with Microsoft for its own advertising purposes.
  • Meta advertising tools (Meta Platforms Ireland Ltd): advertising, conversion measurement and remarketing.

Embedded third-party content. Some pages embed video and scheduling content from third parties, currently Vimeo, Loom and Calendly. These embeds set their own cookies and storage entries and bring in their own analytics and error-monitoring providers, so they are loaded only after you consent. Until then you see a placeholder instead of the embedded content.

The full register. A complete, current list of every cookie and storage entry we set, with its provider, purpose, type and retention period, is available in the cookie preferences panel reachable from the website footer. We keep it there rather than in this document so that it stays accurate between policy updates.

Where these providers transfer personal data to the US or other third countries, this occurs under the EU-US Data Privacy Framework and/or EU Standard Contractual Clauses (see Section 9).

Contact and chat. If you contact us via forms, email or the website chat, we process your details and message to handle your request (Art 6(1)(b) or (f) GDPR). Requests are managed in HubSpot and, for support, Zendesk.

Calls, video meetings and SMS. If you call us or we call you, we process your telephone number and the details of the call. Calls and video meetings are recorded only with your consent, announced at the start of the call, and you can decline. Where a recording is made, it may be transcribed and summarised automatically to capture the substance of the conversation; no assessment of you as a person is made. Recordings, transcripts and summaries are deleted at the latest six months after the call. We also use SMS: for marketing purposes on the basis of your consent, and towards existing customers on the basis of our legitimate interest in the limits of § 174 TKG 2021. You can object at any time.

4. Leads, customers and marketing

CRM. We manage business contacts, leads and customer relationships in HubSpot (contact details, company, interaction history). Legal basis: performance of a contract or pre-contractual steps (Art 6(1)(b) GDPR) and our legitimate interest in managing B2B customer relationships (Art 6(1)(f) GDPR).

Newsletter and product communications. We send newsletters to subscribers with double opt-in consent (Art 6(1)(a) GDPR) and to existing customers for similar own products under § 174 TKG 2021 (Art 6(1)(f) GDPR). Newsletters contain open and click measurement (tracking pixels) to improve content; you can object or unsubscribe at any time via the link in every email.

B2B outreach. We contact potential business customers whose roles indicate relevance to our products, based on our legitimate interest in B2B direct marketing (Art 6(1)(f) GDPR, Recital 47). You can object at any time, effective for the future.

Billing. Customer billing runs through our billing provider (Chargebee) and payment/banking providers; invoice data is retained for 7 years under Austrian tax law (§ 132 BAO; Art 6(1)(c) GDPR).

5. Supplier user accounts

For staff of our customers using the platform (name, work email, role, login data, settings, activity), we process data to provide the contracted service (Art 6(1)(b) GDPR), for platform security and abuse prevention (Art 6(1)(f) GDPR), and for product analytics (Mixpanel; Art 6(1)(f) GDPR), where the data is automatically deleted or anonymised at the latest 2 years after collection. Since August 2026 we transmit only a pseudonymous user identifier together with feature usage and device information to our analytics provider; names, company names, job titles, telephone numbers and email addresses are not sent. Error and performance diagnostics use Datadog (Art 6(1)(f) GDPR). Account data is retained while the customer's account with us is active, and an individual user record is deleted at the latest one year after that user's last activity.

6. Job applicants

Application data is processed to run the recruitment process (Art 6(1)(b) GDPR analogously; § 96 ArbVG considerations apply to internal use). If no employment results, we delete application documents at the latest 7 months after completion of the process (limitation period for claims under the Austrian Equal Treatment Act), unless you consent to a longer retention in our talent pool.

7. The Orderlion platform: processing for our customers

As processor for our supplier customers we process, on their documented instructions: buyer user account data, order and transaction data, in-platform messages, and, for the Inbox feature, the content of order emails forwarded by the supplier (metadata, text, attachments).

AI-supported order extraction (Inbox). To convert order emails into structured orders, email content is processed by large language models accessed via API from OpenAI and Anthropic. Voice messages (e.g. voicemail orders) are transcribed using Microsoft Azure's Whisper service on EU infrastructure before extraction; Microsoft retains a sample of audio and transcriptions for up to 30 days for abuse monitoring before deleting it. Platform data is stored on AWS in Frankfurt, Germany; the AI providers process the content transmitted to them for extraction only and do not use it to train their models. Transfers to these providers outside the EU are safeguarded by EU Standard Contractual Clauses and, where applicable, the EU-US Data Privacy Framework. Suppliers choose between a mode where their staff review each extracted order and an automatic mode with system-side flagging of uncertain orders.

EU-hosted AI models on request. Customers may request that AI processing for their account is performed exclusively on infrastructure located in the EU. For those accounts, order extraction runs on Anthropic Claude models provided via AWS Bedrock in Frankfurt, and OpenAI is not used. This must be requested in writing during setup and confirmed by Orderlion.

AI transparency. Our AI assistant identifies itself as AI. AI features on the platform make no decisions with legal or similarly significant effect on natural persons; they extract, summarise and recommend, and humans decide.

The supplier controls purposes, retention and disclosure of platform data; details are set out in our Data Processing Agreement and subprocessor list.

8. Recipients

We disclose personal data to: our subprocessors and service providers (hosting, email delivery, AI model providers, analytics, support, CRM, billing, communication tools) under data processing agreements; our tax and legal advisors; banks and payment providers for settlement; debt collection service providers where invoices remain unpaid after reminders, limited to the necessary contact and claim data (Art 6(1)(f) GDPR); and authorities where legally required. Where a customer was referred to us by a sales partner, we share information about that customer with the partner at company level only, for commission settlement; personal contact details of customer staff are not disclosed. A current list of the subprocessors used for platform data is published at www.orderlion.com/subprocessors.

9. International transfers

Where recipients are located outside the EU/EEA (in particular US-based providers), we rely on adequacy decisions (including the EU-US Data Privacy Framework for certified recipients) and/or EU Standard Contractual Clauses with supplementary measures where needed. Copies of the relevant safeguards can be requested via our privacy contact.

10. Retention

We keep personal data only as long as needed for the purposes above or as legally required: contract and billing data up to 7 years (tax law); contractual documentation up to 3 years after contract end (limitation periods); marketing data until objection or, for prospects who never become customers, at the latest 24 months after the last interaction; application data 7 months; website analytics data 14 months, with the underlying cookies expiring after at most 2 years; your cookie preferences 6 months, stored in your own browser, and the corresponding consent record 24 months; pseudonymised product analytics data up to 2 years after collection, after which it is deleted or anonymised automatically; platform data per the supplier's instructions and our DPA. Where periods are still being finalised in our internal records, the shorter of the stated periods applies.

11. Your rights

You have the right to access, rectification, erasure, restriction, data portability, and to object to processing based on legitimate interest, including direct marketing (Art 15-21 GDPR). Where processing is based on consent, you can withdraw it at any time with effect for the future. Contact: privacy@orderlion.com. You also have the right to lodge a complaint with the Austrian Data Protection Authority (Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, dsb.gv.at) or your local supervisory authority.

12. No automated decision-making

We do not carry out automated decision-making within the meaning of Art 22 GDPR, i.e. no decisions based solely on automated processing that produce legal effects on you or similarly significantly affect you.

13. Changes

We update this policy when our processing, tools or the law change. The current version is published on this page with its version date; material changes affecting customers are additionally communicated per our contractual notice terms.