Privacy Policy
Last updated: July 24, 2026
1. Introduction
This Privacy Policy describes how Orihost ("Orihost", "we", "us", or "our") collects, uses, discloses, and protects personal data in connection with Applico, including the website at applico.orihost.com, associated subdomains, applications, and APIs (collectively, the "Service"). It also explains the rights you may have over your personal data.
This Policy should be read together with our Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.
2. Roles: Controller vs. Processor
Two distinct processing relationships exist on the Service:
Orihost as controller. For account holders (organization owners and members) and visitors to our website, we act as the data controller of your account information, billing records, communications with us, and Service usage data.
Orihost as processor. When an organization uses the Service to publish forms and collect data from applicants, that organization is the data controller of the applicant data. We process applicant data only on the organization's behalf and documented instructions, as a data processor, to provide the Service. Our processor commitments are described in Section 9.
If you are an applicant: the organization whose form you completed decides how your data is used. Please direct questions and privacy requests about your application to that organization. We will refer any request we receive from you to the relevant organization, and will assist it in responding, but we cannot act on applicant data without its instruction except where required by law.
3. Personal Data We Collect
3.1 Account information
Name, email address, hashed password, and optionally a profile image. If you sign in via a third-party identity provider (e.g., Google), we receive basic profile information (name, email, avatar) from that provider.
3.2 Organization data
Organization name, logo, settings, customizations, member lists, roles, permissions, invitations, and audit log entries recording administrative actions.
3.3 Form and application data
Forms and their configurations, and all data submitted through published forms, including applicant names, email addresses, answers, uploaded files, and submission metadata such as timestamps and approximate location derived from IP address. The categories of applicant data collected are determined by the organization that designs the form.
3.4 Usage and technical data
Log data (IP address, browser type, pages accessed, timestamps), form view and submission counts, feature usage, and AI feature usage counts. We use this data for security, quota enforcement, and to operate and improve the Service. We do not use third-party advertising or analytics trackers.
3.5 Billing information
Subscription plan, status, billing period, and payment events. Payment card details are collected and processed directly by our payment providers; we never receive or store full card numbers.
3.6 Communications
Records of transactional emails sent through the Service (e.g., invitations, application confirmations, status notifications) and correspondence you send to us, including support requests.
4. Purposes and Legal Bases
Where we act as controller, we process personal data for the following purposes and, where the GDPR or similar laws apply, on the following legal bases:
- Providing the Service (account management, hosting your data, delivering features) — performance of a contract (Art. 6(1)(b) GDPR);
- Billing and subscription management — performance of a contract and compliance with legal obligations (tax and accounting laws) (Art. 6(1)(b), (c));
- Transactional communications (security alerts, service notices, application notifications) — performance of a contract and our legitimate interest in operating the Service (Art. 6(1)(b), (f));
- Security, fraud and abuse prevention (rate limiting, quota enforcement, investigating violations) — our legitimate interest in protecting the Service and its users (Art. 6(1)(f));
- Improving the Service using aggregated or de-identified usage statistics — our legitimate interest (Art. 6(1)(f));
- Legal compliance and defense — compliance with legal obligations and our legitimate interest in establishing, exercising, or defending legal claims (Art. 6(1)(c), (f)).
We do not sell personal data, use it for third-party advertising, or use customer or applicant data to train AI models.
5. AI Features
When an organization enables AI features (application screening, form generation, natural-language search), relevant data — such as form questions and application answers — is transmitted to third-party AI model providers acting as subprocessors, solely to generate the requested output. We contractually require that this data is not used to train their models and is not retained beyond what is necessary to provide the output.
AI outputs are assistive suggestions for the organization's human reviewers. The Service does not make automated decisions producing legal or similarly significant effects about applicants; organizations are contractually required to ensure meaningful human review of AI outputs before making any decision about an applicant.
6. Disclosure of Personal Data; Subprocessors
We disclose personal data only as follows:
- Service providers (subprocessors) — vendors that process data on our behalf to run the Service: cloud hosting and database infrastructure, object storage for uploaded files, email delivery (SMTP), payment processing, and AI model providers (only when AI features are used). All subprocessors are bound by contracts requiring confidentiality, security measures, and processing only on our instructions. A current list of subprocessors is available on request at [email protected];
- Within an organization — application data is visible to members of the organization that collected it, according to the roles and permissions its administrators configure;
- Legal requirements — where required by law, regulation, legal process, or enforceable governmental request, or where necessary to protect the rights, property, or safety of Orihost, our users, or the public. Where legally permitted, we will notify affected customers before disclosing their data;
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of the transaction, subject to this Policy or successor terms providing at least equivalent protection.
We do not share, sell, or rent personal data to third parties for their own marketing purposes.
7. International Data Transfers
Personal data may be processed in countries other than your country of residence, including countries that may not provide the same level of data protection. Where personal data subject to the GDPR is transferred outside the EU/EEA, we rely on appropriate safeguards, such as adequacy decisions of the European Commission or the European Commission's Standard Contractual Clauses, supplemented where necessary by additional technical and organizational measures. You may request more information about transfer safeguards via the contact details in Section 14.
8. Security
We implement technical and organizational measures appropriate to the risk, including encryption in transit (TLS/HTTPS), secure password hashing, role-based access controls, signed time-limited URLs for file access, environment segregation, and audit logging of administrative actions. Access to production data is restricted to personnel who need it to operate the Service.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach affecting data we control, we will notify the competent supervisory authority and affected individuals where required by law; if the breach affects data we process on behalf of an organization, we will notify that organization without undue delay.
9. Our Commitments as a Processor
With respect to applicant data we process on behalf of organizations, we commit to:
- process the data only on the organization's documented instructions, including as configured through the Service, unless required otherwise by law (in which case we will inform the organization unless legally prohibited);
- ensure that personnel authorized to process the data are bound by confidentiality obligations;
- implement the security measures described in Section 8;
- engage subprocessors only under a written contract imposing data protection obligations equivalent to ours, and remain responsible for their performance;
- taking into account the nature of the processing, assist the organization in responding to data subject requests and in meeting its obligations regarding security, breach notification, and data protection impact assessments;
- at the organization's choice, delete or return the data at the end of the provision of services, and delete existing copies unless retention is required by law; and
- make available information reasonably necessary to demonstrate compliance with these obligations.
Organizations requiring a signed data processing agreement (DPA) for their compliance records may contact us at [email protected].
10. Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy:
- Account data — for the life of your account. If you delete your account, we delete or anonymize your personal data within 30 days, except where longer retention is required by law (e.g., billing records retained for statutory tax and accounting periods);
- Organization and application data — for as long as the organization exists. Organization owners can delete individual applications, forms, or the entire organization at any time, which removes the associated data;
- Backups — deleted data may persist in encrypted backups for a limited period before being overwritten in the ordinary backup cycle;
- Logs — technical and security logs are retained for a limited period proportionate to their security purpose.
11. Your Rights
Depending on your jurisdiction, you may have the right to: access the personal data we hold about you; have inaccurate data corrected; have your data erased; restrict or object to certain processing (including processing based on legitimate interests); receive your data in a structured, commonly used, machine-readable format (portability); and withdraw consent at any time where processing is based on consent (without affecting the lawfulness of processing before withdrawal).
To exercise these rights, contact us at [email protected]. We will respond within the timeframe required by applicable law (one month under the GDPR, extendable where permitted). We may need to verify your identity before acting on a request. If we act as processor for the data concerned, we will refer your request to the controlling organization and assist it in responding.
If you are in the EU/EEA or UK, you also have the right to lodge a complaint with your local data protection supervisory authority. We would appreciate the opportunity to address your concerns first.
12. Cookies and Local Storage
The Service uses strictly necessary cookies for authentication, session management, and security (e.g., CSRF protection). We use browser local storage for functional preferences such as theme selection. Because we use only strictly necessary and functional storage, no consent banner is required; we do not use tracking, advertising, or third-party analytics cookies. You can configure your browser to reject cookies, but the Service will not function without the strictly necessary ones.
13. Children
The Service is not directed at children under 16, and we do not knowingly collect personal data from them as controller. If you believe a child under 16 has provided us personal data, contact us and we will delete it promptly. Organizations that direct forms at minors are responsible for complying with all laws applicable to children's data, including obtaining any required parental consent.
14. Contact and Complaints
Orihost is the entity responsible for personal data processed as described in this Policy. For privacy questions, requests, or complaints, contact us at [email protected].
15. Changes to This Policy
We may update this Policy from time to time. For material changes, we will provide reasonable advance notice by email or an in-product notice before the changes take effect. The "Last updated" date above reflects the current version. Your continued use of the Service after changes take effect constitutes acknowledgment of the updated Policy; where a change requires your consent under applicable law, we will request it.