Privacy Policy

How Onoria handles your data.

Last updated: April 15, 2026

1. Introduction

Onoria Global operates onoriaglobal.com and the Onoria travel compliance platform. This policy explains what personal data we collect, why we collect it, how it is stored and protected, and what rights you have over your data. Onoria Global acts as the data controller under the General Data Protection Regulation (GDPR).

2. Data We Collect

We collect account data, including the name and email address you provide at registration. We collect travel compliance metadata entered by organisation administrators or members, which may include document types, expiry dates, issuing countries, nationality, and residency status. Where organisations choose to upload identity documents, we store those files — such as passports, visas, and residency permits — encrypted at rest using AES-256-CBC encryption.

We also collect usage and activity data: actions performed within the platform are logged for audit trail purposes. Authentication data, including session tokens and two-factor authentication records, is managed by our authentication system. Finally, we collect pseudonymous page visit data via Google Analytics to understand how the platform and marketing site are used. This is only collected with your consent.

3. Legal Basis for Processing

We process personal data on the following legal bases under GDPR:

  • Performance of a contract — Account data, travel compliance metadata, and travel documents are processed to deliver the platform service agreed with your organisation.
  • Legitimate interests — Security monitoring, fraud prevention, audit logging, and activity records are processed to protect the platform and its users.
  • Consent — Analytics cookies (Google Analytics) are only processed when you have explicitly accepted via the cookie banner. You may withdraw consent at any time using the Manage Cookies link in the footer.
  • Legal obligation — We may process or retain data where required by applicable law.

4. How We Use Your Data

We use collected data solely to provide, maintain, and improve the Onoria platform. We do not sell personal data to third parties. We do not use personal data for advertising purposes.

5. Data Storage and Security

All data is stored on servers located in France. Document files are encrypted at rest using AES-256-CBC encryption. Data in transit is protected using TLS. Access to personal data within the platform is controlled by role-based permissions. We maintain full audit logs of all document access and modifications.

6. Third-Party Services

We use Google Analytics for pseudonymous usage analytics, only when you have consented via our cookie banner. Google Analytics data is processed by Google LLC in the United States under Standard Contractual Clauses as the applicable transfer mechanism. You can review Google's privacy policy at policies.google.com/privacy. We use a third-party authentication service for session management. We use Stripe for payment processing and subscription billing. Stripe processes payment data under their own privacy policy and PCI-DSS compliance. Onoria Global does not store payment card details.

7. Data Retention

We retain account and organisational data for as long as your organisation's account is active.

Upon account deletion, your personal data — including your profile, email, and uploaded documents — is permanently deleted within 30 days. Anonymised event assignment records (with all personal identifiers removed) are retained for organisational audit integrity. Activity log entries are automatically deleted after 2 years.

Analytics data collected via Google Analytics is subject to Google's data retention settings, configured to 14 months.

8. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights:

  • Right of access — You may request a copy of the personal data we hold about you.
  • Right to rectification — You may request correction of inaccurate or incomplete data.
  • Right to erasure — You may request deletion of your personal data, subject to applicable legal obligations.
  • Right to restrict processing — You may request that we limit how we use your data in certain circumstances.
  • Right to object — You may object to processing based on legitimate interests.
  • Right to data portability — You may request a structured, machine-readable copy of your data.
  • Right to withdraw consent — Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, including requesting account deletion, contact us at [email protected]. We will respond within one month. You also have the right to lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL) at cnil.fr.

9. Cookies

We use essential cookies required for platform functionality and authentication. These are strictly necessary and do not require consent. We use Google Analytics cookies for pseudonymous usage measurement only if you accept analytics cookies via the consent banner shown on your first visit. You can withdraw your consent at any time using the Manage Cookies link in the footer of this site.

10. Automated Decision-Making

Onoria does not use automated decision-making or profiling that produces legal or similarly significant effects on individuals. Travel compliance readiness statuses are calculated algorithmically based on document data entered by your organisation, but all decisions and actions remain under human control.

11. Changes to This Policy

We may update this privacy policy from time to time. We will notify registered users of material changes by email. The date at the top of this policy reflects the most recent update.

12. Contact

For any privacy-related questions, requests, or to exercise your data protection rights, contact us at [email protected]. Onoria Global, Paris, France.

We use analytics cookies to understand how visitors use our site and improve it over time. Your session cookie is strictly necessary and always active. Privacy Policy.