BlueOcean Orbit

Technical and organisational measures

Under Art. 32 GDPR. This page describes what is actually implemented in BlueOcean Orbit — not what we intend to do. As of 19 August 2026.

Art. 32 GDPR requires measures appropriate to the risk. We describe them openly so that you, as the controller, can assess whether they are sufficient for your purpose. Where something is not implemented, that is stated here too.

1. Confidentiality

Access control (who gets into the system)

Access control (who sees what)

Encryption

Separation of processing

2. Integrity

3. Availability and resilience

4. Review and evaluation

5. Processors

We use the following for operations:

Data processing agreements under Art. 28 GDPR are being concluded. Please ask us for the current status before productive use with personal data.

6. Jurisdiction and requests from authorities

Technical measures are only one half. The other is the question of who can compel us to do what. We answer it here as precisely as the rest of this page.

Set out in full and in plain language under Which law applies to us — and which does not.

7. Your role

When using BlueOcean Orbit, you are generally the controller under the GDPR and we are the processor. You decide what data you enter. We provide the measures described above.

This page is a technical description, not a certification and not legal advice. No provider can declare "GDPR compliant" on your behalf — compliance depends on how you use the tool.

8. Questions and reports

Please report security issues and privacy questions to [email protected]. We respond within 72 hours.

How your iPhone protects your messages · To the privacy policy · To the terms of service