Coorde

LEGAL

Privacy Policy

Effective date: 1 September 2026 · Last updated: 1 September 2026

This Privacy Policy explains how Coorde Tech s.r.o. (“Coorde”, “we”, “us”) collects and uses personal data when you visit our website, sign up for an account, or use the Coorde service. We are committed to handling your data lawfully, transparently and in line with the General Data Protection Regulation (GDPR).

CONTENTS

1. Who we are · 2. Our role · 3. What data we collect · 4. Where we get it · 5. Legal bases · 6. AI processing · 7. Product improvement · 8. Marketing · 9. Cookies · 10. Sharing · 11. Transfers · 12. Retention · 13. Security · 14. Your rights · 15. Children · 16. Changes · 17. Contact

1. Who we are

The controller responsible for your personal data is Coorde Tech s.r.o., IČO 29639981, VAT ID CZ29639981, Nové sady 988/2, 602 00 Brno, Czech Republic. Privacy contact: privacy@coorde.ai. We have not appointed a Data Protection Officer, as we are not required to. You can reach us about any privacy matter at the address above.

2. Our role: controller and processor

We act in two different roles depending on the data. For visitors, account holders and our own marketing, we are the data controller. When a customer adds team members to a workspace, we process those people’s personal data on the customer’s behalf. For that data we act as a data processor, and our business customer is the controller. We offer a Data Processing Agreement to our business customers.

3. What data we collect

We collect account data: your name, email address, workspace name and login details. Calendar data: events from the Google Calendar you connect, which we read and write to plan and schedule work. Work data: tasks, processes, deadlines and the team members you set up. Team member data: names and contact handles of people you add. Messages exchanged through Coorde on WhatsApp, Slack or the web app. Usage, technical and support data. Billing data handled by Paddle; we receive limited information such as your plan, billing status and invoice records, but do not store full card details. Marketing data: your email address and preferences if you join our list or waitlist.

4. Where we get it

Most data comes directly from you when you sign up and use Coorde. Some comes from services you connect, such as your Google Calendar. Team member data is provided to us by the customer who adds those people to a workspace. Billing data comes from our payment provider.

5. Why we use it and our legal bases

We process account, calendar, task and messaging data to provide and operate Coorde on the basis of performance of a contract under Article 6(1)(b). We provide support on the basis of contract and our legitimate interest in helping users under Article 6(1)(b) and (f). We keep the service secure and prevent abuse on the basis of legitimate interest under Article 6(1)(f). We use anonymized data for product improvement; once anonymized, it is no longer personal data. We send marketing emails only with consent under Article 6(1)(a). We keep accounting and tax records to meet legal obligations under Article 6(1)(c).

6. AI processing

Coorde uses OpenAI models through their API to understand your goals and coordinate work. Under OpenAI’s API terms, your inputs are not used to train OpenAI’s models. OpenAI may retain API data briefly to monitor for abuse and then deletes it. Our architecture allows us to change AI providers if needed. Coorde’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular, we do not use Google Workspace data, such as Google Calendar data, or data derived from it, to develop, improve or train generalized or foundational artificial-intelligence or machine-learning models. The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.

7. Product improvement

We study how teams use Coorde to make it better. For this we use anonymized data only: data that can no longer be linked to you, your team or your business. We do not train AI models on your data, and we never sell identifiable data or use it for third-party advertising.

8. Marketing emails

We only send marketing emails to people who have opted in, and we use double opt-in confirmation. Every email has an unsubscribe link, and we honour unsubscribes promptly. Your consent stays valid until you withdraw it; we periodically remove contacts who have been inactive for around 2–3 years.

9. Cookies and analytics

We aim to keep tracking to a minimum. We use Plausible, a privacy-friendly analytics service that does not use cookies and does not collect personal data. Where any non-essential cookies are used, we ask for your consent first. For full details, see our Cookie Policy.

10. Who we share data with

We share data only with the service providers and subprocessors that help us run Coorde, and only as needed. We keep data processing agreements in place with each of them. The current list, with what each does and where it is located, is on our Security & Data page. We do not sell your personal data.

11. International transfers

Coorde’s application and data are hosted in the United States via Convex, and some of our providers are also based there. When we transfer personal data outside the European Economic Area, we rely on Standard Contractual Clauses and appropriate safeguards to protect it.

12. How long we keep data

We keep account and content data while your subscription is active; after cancellation we keep it for 30 days, then delete or anonymize it. Anonymized insights are kept indefinitely, as they are no longer personal data. Support conversations are kept for up to 2 years. Invoices and accounting records are kept for 10 years as required by Czech law. Backups are taken daily and retained for 7 days. Marketing contacts are kept until you unsubscribe, and we prune inactive contacts after around 2–3 years.

13. How we protect data

Data is encrypted in transit using TLS and at rest. Access to customer data is limited to authorized staff who need it to run the service or provide support, and everyone on the team is bound by confidentiality.

14. Your rights

Under the GDPR you have the right to access the personal data we hold about you; correct inaccurate data; ask us to delete your data; restrict or object to certain processing; receive your data in a portable format; and withdraw consent at any time where processing is based on consent. To exercise any of these rights, email privacy@coorde.ai. If you are a team member added by a customer, we may direct your request to that customer, who is the controller of your data. You also have the right to lodge a complaint with a supervisory authority. In the Czech Republic this is the Office for Personal Data Protection, Úřad pro ochranu osobních údajů, Pplk. Sochora 727/27, 170 00 Prague 7, uoou.gov.cz.

15. Children

Coorde is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.

16. Changes to this policy

We may update this policy from time to time. When we make material changes, we will update the date at the top and, where appropriate, let you know by email or in the app.

17. How to contact us

Coorde Tech s.r.o. · IČO 29639981 · VAT ID CZ29639981 · Nové sady 988/2, 602 00 Brno, Czech Republic. Privacy and data requests: privacy@coorde.ai. General support: support@coorde.ai.