Legal

Privacy Policy

Last updated: August 19, 2026

1. Who We Are

Ollegacy is a software platform that enables organisations and communities — including alumni associations, faith-based communities, nonprofits, schools, and professional networks — to build and manage private member portals. Ollegacy is operated by Transversal Group LLC, incorporated in the State of Florida, United States ("we", "our", "us").

For the purposes of applicable data protection law:

  • Ollegacy acts as a data controller for personal data it collects directly from Organisation Admins during account registration, billing, and platform support.
  • Ollegacy acts as a data processor on behalf of Organisations ("Tenants") for personal data belonging to Members of those Organisations' community portals. In that capacity, Ollegacy processes Member data strictly on the documented instructions of the Organisation (the data controller).

2. Data We Collect

A. Organisation Admin account data (we are controller):

  • Full name and email address (required for account creation)
  • Hashed password (bcrypt; we never store or transmit plaintext passwords)
  • Google or LinkedIn account identifier and profile name/email, if you choose OAuth sign-in
  • Organisation name, community URL slug, and plan selection
  • Billing metadata from Stripe: subscription status, last 4 card digits, card brand, billing email (we never store full card numbers)
  • IP address and user-agent string at login and account creation, retained for up to 90 days for security purposes
  • Account activity timestamps: account creation date, last login date, password change dates

B. Community Member data (we are processor on behalf of the Organisation):

  • Full name and email address (required for membership)
  • Hashed password (bcrypt), if the Member uses password-based login
  • Profile photo (stored on Backblaze B2 cloud storage)
  • City, state/province, and country of residence (optional, provided by Member)
  • Professional bio or personal story (optional, provided by Member)
  • Birthday month and day (not birth year; used for birthday wish feature) — collected only if Member provides it
  • Life stage or career stage labels (optional, selected by Member from Organisation-defined options)
  • "Open to" connection preferences (e.g., mentoring, collaboration) — optional, selected by Member
  • Member role within the community: member, moderator, or admin
  • Account status: pending, approved, or rejected
  • First login date (to personalise the first-time experience)
  • Membership source: invitation-based or self-submitted

C. Community activity data (we are processor):

  • Forum posts (threads and replies) created by Members, including post content, creation date, and edit history (within 10-minute edit window)
  • Event RSVPs: which events a Member has registered for and attendance status
  • Meeting RSVPs: which meetings a Member has registered for
  • Support wall posts: Member-authored posts including title, content, support category, and privacy setting (members-only or private)
  • Support solidarity reactions: records of which Members have expressed support for which support wall posts
  • Birthday wishes sent to and received from other Members
  • Fundraising pages created by Members for campaigns, including personal fundraising goals and amounts raised

D. Donation data (we are processor):

  • Donor name (as provided at checkout)
  • Donation amount and whether it is a pledge or a confirmed payment
  • Associated fundraising campaign and, where applicable, Member fundraising page
  • Stripe payment intent identifier (for reconciliation; no full card data stored by Ollegacy)
  • Donor's optional service tip amount paid to Ollegacy

E. Technical and operational data:

  • Server access logs: IP addresses, HTTP method, URL path, response code, and timestamp — retained for up to 90 days for security monitoring and debugging
  • Error and application logs: anonymised stack traces and error messages — retained for up to 30 days
  • Rate-limit counters: anonymous request counts per IP address, stored in Redis with a 1-minute rolling window, not associated with user identity

3. How We Use Your Data

We use personal data for the following purposes:

  • Service delivery: Creating and managing accounts, providing all platform features, and maintaining the community portal infrastructure
  • Transactional communications: Sending invitation emails, membership approval and rejection notifications, password reset emails, billing receipts, and subscription change confirmations via Resend
  • Birthday notifications: Sending automated birthday wish emails to Members whose birthday privacy settings allow it, on behalf of the Organisation
  • Payment processing: Processing subscription payments and facilitating donation transactions via Stripe
  • Security and fraud prevention: Monitoring for suspicious login activity, rate limiting, and detecting and responding to security incidents
  • Legal compliance: Maintaining financial records as required by law, responding to lawful requests from law enforcement or regulatory authorities
  • Platform improvement: Analysing aggregated, anonymised usage patterns to improve the Service. We do not build individual user profiles for this purpose.

We do not: sell personal data to third parties; use Member data for advertising; use personal data to train machine learning models; or share personal data with third parties except as described in Section 5.

4. Legal Basis for Processing (GDPR / UK GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, we process personal data under the following legal bases:

  • Contract performance (Art. 6(1)(b)): Processing necessary to create and manage your account, deliver the Service, and fulfil our contractual obligations to you
  • Legitimate interests (Art. 6(1)(f)): Security monitoring, fraud prevention, service integrity, and product improvement — where our interests are not overridden by your rights
  • Legal obligation (Art. 6(1)(c)): Compliance with applicable laws, including financial record retention requirements (7 years) and responding to lawful regulatory requests
  • Consent (Art. 6(1)(a)): For optional features such as birthday visibility and birthday wish reception, where we rely on Member consent. Consent may be withdrawn at any time through profile privacy settings without affecting the lawfulness of prior processing.

Where Ollegacy acts as a data processor, the lawful basis for processing Member data is established by the Organisation (the data controller) in accordance with its own privacy notice and member agreements.

5. Data Sharing & Sub-processors

We share personal data with the following third-party service providers ("sub-processors") strictly as necessary to operate the platform. Each sub-processor is bound by a Data Processing Agreement and is required to maintain appropriate technical and organisational security measures:

  • Stripe, Inc. (United States) — Payment processing for platform subscriptions and community donations. Stripe receives billing email, subscription details, and donation transaction data. Stripe Privacy Policy
  • Google LLC (United States) — OAuth2 authentication when you choose "Sign in with Google". We receive your name, email address, and Google account identifier. Google Privacy Policy
  • LinkedIn Ireland Unlimited Company (Ireland / United States) — OAuth2 authentication when you choose "Sign in with LinkedIn". We receive your name, email address, and LinkedIn account identifier. LinkedIn Privacy Policy
  • Resend, Inc. (United States) — Transactional email delivery. Resend receives recipient email addresses and email content (name, notification details) to deliver emails on our behalf.
  • Backblaze, Inc. (United States) — Cloud object storage for profile photos, media files, and broadcast images and file attachments uploaded by Organisation Admins or Members. Files are stored in Backblaze B2 and served via HTTPS. Broadcast header images, inline body images, and broadcast file attachments are stored as publicly accessible URLs — any person who obtains the URL can access the file without authentication. These files are intended for community communication purposes only; Organisation Admins must not upload files containing personal data of Members (such as membership lists or financial records) as broadcast attachments. Broadcast media files are subject to automatic deletion after 90 days via a bucket lifecycle rule (see Section 7).
  • Railway Technologies, Inc. (United States) — Cloud infrastructure and hosting for the Ollegacy API server and PostgreSQL database. All personal data stored in our database resides on Railway servers.
  • Vercel, Inc. (United States) — Frontend hosting, CDN, and edge delivery for the Ollegacy web application.

We do not share personal data with any other third parties except: (a) as required by applicable law, regulation, or lawful government request; (b) to protect the rights, property, or safety of Ollegacy, our users, or others; or (c) in connection with a merger, acquisition, or sale of assets (in which case we will provide notice and, where required, seek consent).

6. International Data Transfers

Ollegacy is incorporated in the United States and our sub-processors operate primarily in the United States. If you are located in the EEA, UK, or another jurisdiction with data transfer restrictions, your personal data will be transferred to and processed in the United States.

We rely on the following safeguards to legitimise international transfers:

  • EU Standard Contractual Clauses (SCCs): For transfers from the EEA to the United States, we rely on the European Commission's approved Standard Contractual Clauses (2021/914/EU) incorporated into our Data Processing Agreements with sub-processors.
  • UK International Data Transfer Agreements (IDTAs): For transfers from the United Kingdom, we rely on the UK IDTA or the UK Addendum to the EU SCCs.
  • Adequacy decisions: Where the European Commission or UK Information Commissioner's Office has issued an adequacy decision for the recipient country, we rely on that decision.

You may request a copy of the transfer mechanism documentation by contacting privacy@ollegacy.com.

7. Data Retention

We retain personal data only as long as necessary for the purposes for which it was collected, subject to any legal retention obligations.

  • Active accounts: Data is retained for as long as your account remains active and your Subscription is in good standing.
  • Deleted/terminated accounts: Upon account deletion or termination, personal data is permanently and irreversibly deleted within 30 days, except as noted below.
  • Financial records: Billing records, subscription invoices, and donation transaction records are retained for 7 years from the transaction date as required by applicable tax and accounting law, even after account deletion. These records are held in aggregate form with minimal personal data.
  • Server logs: Access and security logs are retained for up to 90 days.
  • Error logs: Application error logs are retained for up to 30 days.
  • Backup retention: Encrypted database backups may contain personal data and are retained for up to 30 days before being permanently overwritten.
  • Member data: Community Member data is controlled by the Organisation. Members should contact their community administrator to request deletion or modification of their profile data. Organisations that delete their Ollegacy account will cause all associated Member data to be deleted within 30 days.
  • Broadcast images: Header images uploaded by Organisation Admins for community broadcast messages are stored in Backblaze B2 under a dedicated prefix and are automatically and permanently deleted after 90 days via a bucket lifecycle rule. This deletion is irreversible and does not require any action from the Organisation. The broadcast text and subject line are retained in the database for as long as the Organisation account remains active.
  • Broadcast file attachments: File attachments (e.g. PDF, DOCX, XLSX) uploaded by Organisation Admins for community broadcast emails are stored in Backblaze B2 under a dedicated prefix and are automatically and permanently deleted after 90 days via the same bucket lifecycle rule. These files are publicly accessible URLs — Organisation Admins should not attach files that contain Member personal data. The broadcast record in the database retains only the filename and file size (not the file content) and is retained for as long as the Organisation account remains active.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data. To exercise any right, contact us at privacy@ollegacy.com. We will respond within 30 days (EEA/UK: within 1 calendar month as required by GDPR).

  • Right of access (Art. 15 GDPR): Request a copy of the personal data we hold about you and information on how it is processed.
  • Right to rectification (Art. 16 GDPR): Request correction of inaccurate or incomplete personal data.
  • Right to erasure / "right to be forgotten" (Art. 17 GDPR): Request deletion of your personal data where: (a) it is no longer necessary for the purposes for which it was collected; (b) you withdraw consent and there is no other legal basis; (c) you object to processing and there are no overriding legitimate grounds; or (d) the data has been unlawfully processed. Note: Erasure may be limited where we are required to retain data by law.
  • Right to data portability (Art. 20 GDPR): Request your personal data in a structured, commonly used, machine-readable format (JSON or CSV) for transfer to another service, where processing is based on consent or contract.
  • Right to object (Art. 21 GDPR): Object to processing based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds that override your rights.
  • Right to restriction (Art. 18 GDPR): Request restriction of processing in certain circumstances, for example while the accuracy of data is contested.
  • Right to withdraw consent: Where we rely on consent, withdraw it at any time (e.g., via birthday privacy settings in your profile) without affecting the lawfulness of prior processing.
  • California residents (CCPA/CPRA): You have the right to know, delete, and opt-out of the sale of personal information. Ollegacy does not sell personal information. To submit a verifiable consumer request, contact privacy@ollegacy.com.

Note for Members: If you are a Member of an Organisation's community portal (not an Organisation Admin), Ollegacy processes your data as a processor on behalf of your Organisation. For requests related to your Member profile, forum posts, or community activity, you should contact your Organisation's admin directly. Ollegacy will forward requests to the appropriate controller if you contact us.

Google Sign-In users: Revoke Ollegacy's access at Google Account Permissions. This does not automatically delete your Ollegacy account.

LinkedIn Sign-In users: Revoke Ollegacy's access via LinkedIn Settings → Security → Permitted Services. This does not automatically delete your Ollegacy account.

9. Cookies & Client-Side Storage

Ollegacy uses the following cookies and client-side storage mechanisms:

Authentication cookies (strictly necessary — cannot be disabled):

  • ol_person_rt — HttpOnly, Secure, SameSite=Lax. Session refresh token for all Person accounts (Organisation Admins and community Members). Expires after session end or 30 days.
  • ol_platform_refresh — HttpOnly, Secure, SameSite=Lax. Session refresh token for Ollegacy internal staff accounts.

OAuth security cookies (short-lived, strictly necessary):

  • ol_google_oauth_state — HttpOnly, Secure, SameSite=Lax. CSRF protection token for Google OAuth flows. Expires after 10 minutes.
  • ol_linkedin_oauth_state — HttpOnly, Secure, SameSite=Lax. CSRF protection token for LinkedIn OAuth flows. Expires after 10 minutes.
  • ol_google_pending — Non-HttpOnly, Secure, SameSite=Lax. Short-lived token for new Google sign-up continuation. Expires after 15 minutes. Contains only the pending registration state; no persistent personal data.
  • ol_linkedin_pending — Non-HttpOnly, Secure, SameSite=Lax. Short-lived token for new LinkedIn sign-up continuation. Expires after 15 minutes.

Browser localStorage (strictly necessary):

  • ol_access_token — Short-lived access token (JWT, 15-minute expiry) for all Person sessions (admin and member). Stored in localStorage for use by the frontend application. Cleared on logout.
  • ol_person_profile — Cached person profile (name, email, role). Cleared on logout.
  • ol_platform_token — Short-lived access token for Ollegacy internal staff sessions. Cleared on logout.
  • ol_platform_profile — Cached staff profile. Cleared on logout.

We do not use: tracking cookies, advertising cookies, cross-site tracking, third-party analytics cookies, or any persistent identifiers beyond authentication and security purposes described above.

All authentication cookies are strictly necessary for the Service to function. You may block or delete cookies in your browser settings, but doing so will prevent you from logging into or using the Service.

10. Security Measures

We take technical and organisational security seriously. Our measures include:

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS 1.2 or higher. All API communication is over HTTPS.
  • Encryption at rest: Database storage is encrypted at rest on Railway's infrastructure. File storage on Backblaze B2 is encrypted at rest.
  • Password hashing: All passwords are hashed using bcrypt with a cost factor of 12 before storage. We never store or log plaintext passwords.
  • Password policy: Passwords must be at least 12 characters and cannot be a commonly known password.
  • Authentication tokens: Access tokens expire after 15 minutes. Refresh tokens are stored HttpOnly and rotated on each use.
  • OAuth CSRF protection: Google and LinkedIn OAuth flows use cryptographically random, single-use CSRF state tokens to prevent cross-site request forgery and account hijacking.
  • Rate limiting: All API endpoints are protected by distributed rate limiting backed by Redis to prevent brute-force and credential-stuffing attacks.
  • Access control: Multi-tenancy isolation ensures that Organisation data is strictly segregated. Platform staff access to tenant data is logged and restricted to authorised personnel with a legitimate support need.
  • Dependency monitoring: Dependencies are reviewed for known vulnerabilities before deployment.

For a full description of our security practices, see our Security page.

Despite our measures, no internet-based service can guarantee absolute security. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and (where required) the relevant supervisory authority in accordance with applicable law.

11. Children

Ollegacy is not directed at children under the age of 13 (or the applicable minimum age in your jurisdiction). We do not knowingly collect personal data from children under 13. If you are a parent or guardian and believe your child has provided personal data to us, please contact us at privacy@ollegacy.com and we will promptly delete it.

Organisations operating in the European Union must apply the applicable national minimum age for digital consent (16 in most EU member states, or 13 with verifiable parental consent in some) and are responsible for obtaining any required parental consent before admitting Members below that age threshold to their community portal.

12. Automated Decision-Making

Ollegacy does not use automated decision-making or profiling that produces legal or similarly significant effects on individuals, as described in Article 22 of the GDPR. Membership approval or rejection decisions made through the platform are made by Organisation Admins, not by automated systems.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the law, our data practices, or the Service. We will notify active Organisation Admins of material changes via email and/or in-platform notice at least 14 days before the change takes effect. For changes required by law, we may update immediately.

The date of the most recent revision appears at the top of this page. Continued use of the Service after the effective date of an updated Privacy Policy constitutes your acceptance of the changes.

14. Contact & Supervisory Authority

For privacy-related questions, to exercise your data rights, or to raise a privacy concern, contact us at:

Transversal Group LLC (operating as Ollegacy)

State of Florida, United States

Privacy: privacy@ollegacy.com

EEA/UK residents: If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority. In the EU, you may contact the supervisory authority in the member state of your habitual residence, place of work, or place of the alleged infringement. In the UK, you may contact the Information Commissioner's Office (ICO) at ico.org.uk.