Beta version. Orkora is in private beta, and these policies reflect the platform as it operates today. We may update them as the platform evolves; material changes will be announced at least 30 days in advance. Last updated 7 July 2026. Questions? hello@orkora.events

Privacy Policy

1. Who we are

Orkora Technologies Limited ("Orkora", "we", "us"), a wholly-owned subsidiary of VoltAfrica Technologies Limited, operates the Orkora event-management platform at orkora.events. Orkora Technologies Limited is a registered Nigerian company (RC 9697234) and is the data controller for the personal data described in Section 3 (account data) and a processor on behalf of the event organiser for the personal data described in Section 3 (attendance data). The controller for attendance data is the event organiser whose event you registered for. VoltAfrica Technologies Limited is the parent company; it does not process user data on its own behalf and is not a joint controller under this Policy.

Contact our Data Protection Officer at dpo@orkora.events.

2. Scope

This Policy applies when you:

  • Visit orkora.events (the marketing site)
  • Create an Orkora account
  • Register for an event hosted on Orkora
  • Receive an email from Orkora or from an organiser using Orkora
  • Use the Orkora mobile app or installable PWA

3. Personal data we collect

Account data (Orkora as controller).

  • Email address
  • Full name
  • Optional phone number
  • Hashed password (argon2id with per-account salt and a server-side pepper)
  • Verification status flags for email and phone
  • Locale and preferred currency
  • Platform role (default: none)
  • Timestamps for account creation and last login
  • Federated identifier from Google or Apple if you sign in via social login

Attendance data (event organiser as controller, Orkora as processor).

  • Full name of attendee
  • Email address of attendee
  • Optional phone number
  • Ticket tier and price paid
  • Order and payment reference, status, and timestamps
  • Check-in status and check-in timestamp
  • Chat messages, Q&A entries, and poll votes submitted during a session

Operational data (Orkora as controller).

  • Server logs (request IP, request method and path, response status, latency, request id)
  • Application logs (structured events related to your actions on the platform)
  • Error reports (stack traces, request context, breadcrumbs, captured in Sentry)
  • Refund-and-recovery audit log entries

Cookies and local storage (Orkora as controller).

See Section 9 for the complete list.

4. Sub-processors

We use the following sub-processors to operate the platform. Adding or removing a sub-processor requires 30 days' notice to controllers via an update to this Policy.

Sub-processorPurposeData locationCategories of data
RenderAPI hostingFrankfurt, GermanyAll categories
VercelWeb frontend hostingWorldwide CDN, primary in EuropeAll categories
NeonPostgreSQL databaseFrankfurt, EU-Central-1All categories
Cloudflare R2Object storage for banners, avatars, organiser logosWestern EuropeMedia uploads only
UpstashRedis queue + cacheFrankfurt, GermanyTransient processing data
PostmarkTransactional and campaign emailUnited States (EU region available, see §13)Email addresses and message content
TermiiSMS for OTPNigeriaPhone numbers and SMS message content
StripePayment processingIreland (EU), United StatesOrder metadata, attendee email; no card data ever transits Orkora
PaystackPayment processingNigeriaOrder metadata, attendee email
FlutterwavePayment processingNigeriaOrder metadata, attendee email
SentryError monitoringEUError stack traces and request context
Google CloudOptional Google sign-inWorldwideFederated identifier and email
AppleOptional Apple sign-inWorldwideFederated identifier and email

5. Why we process your data

PurposeLegal basis (GDPR)Legal basis (NDPR)
To create and maintain your accountContract (Art. 6(1)(b))Necessary for performance of a contract
To register you for an eventContractNecessary for performance of a contract
To process payments and refundsContract + legal obligationNecessary for performance of a contract
To send transactional emails (OTP, receipts, refund confirmations)ContractNecessary for performance of a contract
To send marketing campaigns from organisers to registered attendeesLegitimate interest (subject to opt-out)Consent (registration to the event implies opt-in to event-related communications)
To prevent fraud and platform abuseLegitimate interestLegitimate interest
To debug and improve the platformLegitimate interestLegitimate interest
To comply with tax, accounting, and other legal obligationsLegal obligationLegal obligation

6. Sharing of personal data

Your data is shared with:

  • The event organiser whose event you registered for (attendance data only).
  • The sub-processors listed in Section 4, strictly for the purposes listed.
  • Government bodies if compelled by valid legal process.
  • A successor entity in the event of a merger, acquisition, or sale of substantially all of our assets (with notice to you under Section 14).

We do not sell your personal data. We do not share your data with advertisers. We do not run third-party analytics on the marketing site or in the product.

7. How long we keep your data

CategoryRetention
Account dataFor as long as your account is active. 90 days after account closure, then deleted.
Attendance dataControlled by the organiser; their retention policy applies. Orkora deletes attendance data 12 months after the event end date unless the organiser instructs us to retain it longer (in which case the organiser is responsible for compliance).
Financial records (orders, payments, refunds, audit log)6 years from the end of the financial year, per Nigerian Companies Income Tax Act s.55.
Server logs30 days.
Sentry error reports90 days.
Email send logs (Postmark)45 days for raw logs, longer for aggregate counts.
Backups (Neon PITR)7 days for branch-level point-in-time recovery; longer for compliance snapshots.

8. Your rights

Depending on the law that applies to you, you have the right to:

  • Access the personal data we hold about you.
  • Rectify inaccurate or incomplete personal data.
  • Erase personal data, subject to the financial retention requirement in Section 7.
  • Restrict or object to certain processing.
  • Data portability: receive a copy of your data in a structured, machine-readable format.
  • Withdraw consent at any time where processing is based on consent.
  • Lodge a complaint with your data protection authority (in Nigeria, the Nigeria Data Protection Commission; in the EU, your local supervisory authority; in the UK, the Information Commissioner's Office).

Exercise any of these rights by emailing dpo@orkora.events. We will respond within 30 days. If we cannot honour a request (because of a legal obligation or because we cannot verify your identity), we will tell you why.

9. Cookies and local storage

Orkora uses the smallest set of cookies and storage entries necessary to operate the platform. We do not use cookies for advertising or third-party analytics.

NameTypePurposeLifetime
orkora_rthttpOnly cookieRefresh token for keeping you signed in30 days
orkora_csrfnon-httpOnly cookieCSRF double-submit token30 days
access_tokensessionStorageShort-lived access tokentab session
orkora_pending_signupsessionStorageHolds signup fields between password entry and OTP verificationtab session, wiped on success or failure
Service-worker cachebrowser cache storageOffline access to ticket QR codes7 days

We do not require a cookie banner because we do not run non-essential cookies. If we add non-essential cookies (analytics, advertising) we will publish a banner and obtain consent before they fire.

10. Security

Technical and organisational measures we maintain:

  • TLS 1.3 in transit for all client-API traffic.
  • HSTS with a 6-month max-age on orkora.events.
  • Strict Content Security Policy with per-request nonces.
  • Argon2id password hashing with a server-side pepper.
  • Refresh-token rotation with reuse detection; a stolen-and-replayed token revokes the entire token family.
  • Per-account exponential backoff on failed login.
  • RS256-signed access tokens with kid-based key rotation.
  • Cross-site request forgery double-submit token on the refresh endpoint.
  • Per-org tenancy isolation enforced server-side and tested on every push.
  • Continuous security audit pipeline (see SECURITY_AUDIT.md): dependency CVE scan, secrets scan, web bundle leak scan, transport posture check, API authorization abuse tests, OWASP ZAP baseline.
  • Centralised error monitoring via Sentry with 90-day retention.
  • Audit log on every privileged action (refund, role change, admin action).

No system is perfectly secure. If you discover a vulnerability please report it to security@orkora.events.

11. Children

Orkora is not intended for use by anyone under 16. We do not knowingly collect personal data from children under 16. If you become aware that a child has provided us with personal data, contact dpo@orkora.events and we will delete it.

12. International transfers

Some of our sub-processors are located outside Nigeria and the EU. Where personal data crosses a border for processing, we rely on the recipient sub-processor's standard contractual clauses (SCCs) under the EU's 2021 SCC framework, plus an adequacy assessment for the recipient country. For UK transfers we rely on the UK International Data Transfer Addendum.

13. Data Protection Officer

Email: dpo@orkora.events. Postal address: as registered with the Nigeria Data Protection Commission (NDPC).

14. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified to the email on your account at least 30 days before they take effect. The "Last updated" date at the top of this Policy reflects the most recent change.

15. Contact