Kortex
snapshot · 2026-09-06

Data protection

This page is Orkora Limited's data-protection statement for the Kortex platform, and serves as the public transparency notice under Articles 13 and 14 UK/EU GDPR for personal data we did not collect from the individuals concerned. Plain statements, no claims of absence where the honest answer is "some".

Who is responsible

Orkora Limited (registered in England and Wales, company no. 16555987; registered office Wsm, Connect House, 133-137 Alexandra Road, Wimbledon, London SW19 7JY) is the controller for the personal data described on this page. Contact for all data-protection matters: kortex@orkora.com. Orkora Limited is the UK operating company of the Orkora Inc. group; the group parent is not a controller of platform data.

Three kinds of data, three positions

1 · Personal data inside the product

The graph is infrastructure and corporate-entity records: power plants, substations, grids, legal entities, jurisdictions. Within the corporate layer, some records are personal data even though they arise in a business context:

Lawful basis: legitimate interests (Article 6(1)(f)): enabling evidence-based screening of corporate counterparties and infrastructure ownership using records that statutory regimes publish precisely so that the public can know who controls what. The data is limited to what the registers publish (names, roles, appointments, control relationships), is not enriched with private-life information, and concerns individuals in their corporate capacity, where the privacy expectation over register-published facts is at its lowest. We rely on Article 14(5)(b): individually notifying every officer named in public registers would be disproportionate, and this page is the public notice instead.

2 · Customer account data

Contact details, hashed API keys, and usage records, processed to operate the service (Article 6(1)(b), contract) and to secure it (legitimate interests). Retained for the life of the account plus statutory record-keeping periods.

3 · Customer candidate data (your shortlists and counterparties)

When you run a screen, your candidate coordinates or counterparty identifiers are archived inside your receipt so the answer stays retrievable and auditable. Counterparty identifiers can include personal data where a counterparty is an individual officer-rich small company. For this data you are the controller and Orkora Limited processes it on your instructions: receipts are private to your organisation by default, shareable and deletable only by you. Data-processing terms covering this processing are part of every pilot agreement; our standard draft is available to your DPO on request while it completes external counsel review.

Subprocessors, by name

ProviderRoleLocation
Hetzner Online GmbHHosting and offsite encrypted backupsGermany (EU)
Resend, Inc.Transactional email (alerts, sign-in links)United States

That is the complete list. The Resend transfer is limited to email address and message content and is safeguarded by standard contractual clauses per Resend's data-processing terms. Platform databases and backups do not leave the EU.

Your rights

Individuals whose data appears in the product, and users of the platform, have the UK/EU GDPR rights of access, rectification, erasure, restriction and objection. Write to kortex@orkora.com; we respond within one calendar month. Where a record mirrors a statutory register, correction at the register is the durable fix and we will point you to it as well as reflecting the register's correction on our next refresh. You may complain to the Information Commissioner's Office (ico.org.uk) or your local supervisory authority.

Stated plainly. This page was rewritten after an external vendor-risk review correctly called out that our earlier wording, "no personal data in the product", was overstated: register-published officer records are personal data in law. The position above is the honest one. This statement is maintained by the operators of the platform and reviewed as sources change; material changes are noted on the /changelog.