Privacy

Version 1.0 — Effective 3 September 2026

Onion runs commercial operations for its clients — prospection, enrichment, validation, scoring, deal management and meeting scheduling. That means we handle personal data in two very different capacities, and this policy is organised around that distinction.

Governing law: GDPR and LOPDGDD. Supervisory authority: Agencia Española de Protección de Datos.

1. Who we are

Onion is a commercial operating system: software plus the team that runs it. The service is operated by The Coding Company, S.L., a Spanish sociedad limitada with company number (CIF) B-44697217 and EU VAT number ESB44697217, registered at c/ Pompeu Fabra 3, 17320 Tossa de Mar, Girona, Spain. We trade as Onion. Datamorf is the same operation under its former name, and this policy covers personal data collected under either name on identical terms.

A note on our current status. We are incorporating Onion, S.L., a Spanish sociedad limitada to be registered in Barcelona, and the business will transfer to it. Until that transfer completes, The Coding Company, S.L. remains the controller of your personal data and is accountable for every commitment in this policy.

When the transfer takes effect, Onion, S.L. will become the controller and will assume those commitments in full. We will publish an updated version of this policy naming the new entity and its company number, and email account holders at least 30 days beforehand. Both companies are Spanish, so your supervisory authority and your rights are unchanged either way, and none of the practices described below change with it.

For anything to do with personal data — questions, requests, complaints — write to privacy@onionos.io. That inbox is monitored by our founders and is the fastest route to a person who can act.

We have not appointed a Data Protection Officer. Our processing does not meet the thresholds in Article 37 GDPR that would require one: we are not a public authority, our core activities do not involve large-scale systematic monitoring of individuals, and we do not process special categories of data on a large scale. If that changes, we will appoint a DPO and say so here.

2. What this policy covers

This policy applies to the Onion website at onionos.io, the Onion platform and browser extension, the booking pages our clients share with their prospects, and the commercial operations work we deliver for clients.

It does not cover what a client does with data after they export it from Onion, or what happens on third-party websites we link to. Where you reached an Onion booking page through a company you are dealing with, that company — not Onion — decides why your data is being collected.

3. Our two roles

Data protection law draws a hard line between deciding why personal data is processed (the controller) and processing it on someone else's instructions (the processor). Onion is sometimes one and sometimes the other, and your rights differ depending on which.

If you are a visitor to onionos.io — we are the controller. Governed by this policy.

If you are a user of the Onion platform — we are the controller. Governed by this policy and our Terms of Service.

If you are a prospect, lead or contact in a client's Onion workspace — we are the processor. Governed by our data processing agreement with that client, whose own privacy notice applies.

If you booked a meeting through a client's Onion booking page — we are the processor. Governed by the client's privacy notice, plus this policy for the technical logs we keep as controller.

If Onion contacted you about its own services — we are the controller. See section 8.

Where we act as a processor and you want your data corrected or deleted, the client is the right place to ask — but you can write to us and we will pass it on. Section 18 explains how.

Part A — Where Onion is the controller

4. Website visitors

When you visit onionos.io we process a small amount of data about the visit, and whatever you choose to send us through a form.

IP address, browser and device type, pages viewed, referring site. For serving the site, keeping it available and blocking abuse. Lawful basis: legitimate interests, Art. 6(1)(f).

Aggregated, cookieless page statistics. For understanding which pages are read so we can improve them. Lawful basis: legitimate interests, Art. 6(1)(f).

Name, work email, company, message. For answering your enquiry and, if it goes well, preparing a proposal. Lawful basis: steps prior to a contract and legitimate interests, Art. 6(1)(b) and 6(1)(f).

Email address for our mailing list. For sending you the updates you asked for. Lawful basis: consent, Art. 6(1)(a).

Where we rely on legitimate interests we have weighed them against your rights and concluded that running a secure, comprehensible website and replying to people who write to us does not override them. You can ask us for that assessment.

Nothing on our website obliges you to give us personal data. The fields marked required on a contact form are simply the minimum we need to reply — leave them blank and we cannot answer you, but no other consequence follows.

5. Cookies and analytics

We set only strictly necessary cookies: the ones that keep you logged in, protect against cross-site request forgery, balance load, and remember your cookie choices. Under Article 22.2 of Spanish Law 34/2002 (LSSI-CE), cookies that are strictly necessary to deliver a service you requested do not require consent, which is why you are not made to click through a banner to read this page.

We do not use Google Analytics. We do not run advertising or retargeting pixels from LinkedIn, Meta or Google Ads. We do not sell or share visitor data with data brokers, and we do not build cross-site profiles of the people who read our website.

Our website is built and hosted on Framer, and for traffic statistics we use Framer's built-in analytics and nothing else. It sets no cookies and creates no persistent identifiers: visitors are counted using a hashed IP address with an encryption key that rotates daily, so the same person returning tomorrow is simply a new count. It tells us that a page was read; it does not tell us who read it, and it cannot follow you to any other website.

Your browser lets you block or delete cookies. Blocking the strictly necessary ones will break parts of the platform, such as staying signed in. We honour Global Privacy Control signals where your browser sends them.

6. Client account users

If you work for an Onion client and have an account, we process your account data as controller — separately from the client data you handle inside that account, which is covered in Part B.

  • Identity and account: name, work email address, job title, workspace and role, and either a hashed password or the identifier issued by your single sign-on provider. We never store your password in a readable form.

  • Usage and security: sign-in times, IP addresses, browser and device, feature usage, and an audit trail of significant actions such as connecting or revoking a calendar.

  • Support: the emails, messages and call notes exchanged when you ask us for help.

  • Billing: the contact and company details needed to raise an invoice. Card details go directly to our payment provider; we never see or store them.

We process this to run the service you are contracted for (Art. 6(1)(b)), to keep it secure and to improve it in aggregate (Art. 6(1)(f)), and to meet our accounting and tax obligations (Art. 6(1)(c)).

Account data is a contractual requirement: we cannot give you a working account without a name, an email address and a credential, and billing details are required by law for us to invoice you. If you do not provide them we cannot open or maintain the account. Everything beyond that — a profile photo, a phone number, an optional field — is genuinely optional and nothing breaks if you leave it out.

7. Calendar connections

Onion includes a scheduler. To show a prospect when you are genuinely free, it needs to see your calendar — and this is the part of the product where we are most deliberate about what we do not ask for.

We never request read access to the contents of your calendar events. The permissions we ask Google and Microsoft for let us see that you are busy between 14:00 and 15:00. They do not let us see the title of that meeting, its description, its location, or who else is attending. We cannot leak what we cannot read, and we are happy to have that verified in a security questionnaire.

Concretely, we request the minimum scopes needed: the list of your calendars, free/busy information for the calendars you choose, and the ability to create and manage only the events Onion itself creates. Existing events remain closed to us.

Access tokens are encrypted with a key unique to your workspace, and every connect, refresh and revoke is written to an audit log. You can disconnect a calendar at any time from inside Onion, or revoke access directly in your Google or Microsoft account. Either way, availability calculation stops immediately and your booking pages stop offering slots rather than falling back to showing you as free all day.

8. Our own prospecting

We sell commercial operations, so it would be strange to pretend we do not do outbound ourselves. If we have contacted you about Onion, here is what sits behind that.

We process business contact data — name, work email, job title, employer, and publicly available information about your company — obtained from public web sources, licensed business data providers, or from you directly at an event or through our website. We rely on legitimate interests (Art. 6(1)(f)) to send business-to-business communications to people whose professional role plausibly relates to what we do, and we have documented that assessment.

You have an unconditional right to object. Reply to any message asking us to stop, or write to privacy@onionos.io, and we will remove you from all outbound. We keep a minimal suppression record — your email address and the fact that you objected — precisely so we do not contact you again; that record is not used for anything else.


Part B — Where Onion is a processor

9. Data we process for clients

Most of the personal data inside Onion does not belong to us. It belongs to our clients, who decide why it is there. We process it only on their documented instructions, under a data processing agreement that meets Article 28 GDPR.

The categories typically involved:

  • Business contact data: name, work email, work phone, job title, seniority, employer, and location at city or country level.

  • Company data: firmographics, technologies, funding stage, headcount and other attributes of the organisation rather than the person.

  • Relationship data: CRM records, deal stages, notes, email and meeting history, and pipeline activity synced from the client's own systems.

  • Derived attributes: validation results, enrichment output, fit and intent scores, segments, and routing decisions — described in section 11.

  • Meeting data: bookings made through Onion booking pages, including who booked, when, and which campaign or workflow the link was attributed to.

We do not process special categories of personal data under Article 9 — health, political opinions, religious beliefs, trade union membership, biometric or genetic data, sex life or sexual orientation — and our agreements prohibit clients from putting such data into Onion. We do not process criminal offence data.

10. Where lead data comes from

If you have never heard of Onion and find yourself in a client's workspace, this is the section that explains how. Article 14 GDPR requires it, and it is the part of a policy like ours that deserves the most candour. There are exactly three routes.

  • From the client. They upload a list, connect their CRM (such as Attio, Pipedrive or HubSpot), forward an inbound enquiry, or enter a contact by hand. The client is responsible for having a lawful basis for the data they give us.

  • From public web sources. Our extractor collects business information from company websites, public business registries and other publicly accessible pages — company details, role-based contact addresses, and publicly stated job titles. We respect robots.txt and rate limits, and we collect information about people in their professional capacity only.

  • From licensed business data providers. We use third-party B2B data vendors for enrichment. Our contracts require them to warrant that they collected the data lawfully and have discharged their own transparency obligations to the people in it.

We do not scrape personal social media profiles, and we do not buy consumer data. Everything we handle concerns a person acting in a professional role at an organisation.

Where the client is the controller, the duty to tell you about this processing sits with them, and their privacy notice should describe it. Where notifying every individual directly would involve disproportionate effort within the meaning of Article 14(5)(b), this public section is the safeguard: it names the categories of source, and you can always ask us or the client which one applied to you.

11. Enrichment, validation, scoring and routing

These four words describe most of what Onion does to a record.

  • Validation checks whether an email address is deliverable and whether a company still exists, and flags records that are stale or wrong.

  • Enrichment adds missing business attributes from the sources in section 10 — a job title, a company size, a technology in use.

  • Scoring ranks a record against the client's definition of a good fit, so their team knows which conversations to have first.

  • Routing sends a record to the right person, sequence or market based on those attributes and scores.

Scoring and routing are automated, and we want to be precise about what that does and does not mean. They determine which sales conversations a client's team prioritises. They do not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR: no decision is made here about your employment, credit, insurance, housing, education or access to any service. A low score means a salesperson calls someone else first.

You still have the right to object to this processing under Article 21. Contact the client, or write to us and we will route it to them.

12. AI and language models

Parts of Onion use large language models — to classify a company, summarise public information about an account, draft a message for a human to review, or normalise messy data into a consistent shape. We use Anthropic and OpenAI through their business APIs. We do not send client data to consumer chat products.

Client data is never used to train third-party AI models. Our AI vendors are engaged on enterprise or API terms that contractually exclude training on submitted content, and we use zero- or limited-retention configurations wherever the vendor offers them. We do not train our own models on one client's data to benefit another.

AI does not make final decisions about a person in Onion. Its output is a suggestion — a draft, a classification, a score component — that a human reviews before it reaches a prospect.

Where the EU AI Act's transparency rules in Article 50 apply, which have been in force since 2 August 2026, we comply: people interacting with an AI system are told so, and AI-generated content that is published without substantive human editorial review is disclosed as such.

13. If you booked a meeting through Onion

You did not sign up for anything, so this section is written for you directly.

When you pick a slot on an Onion booking page we collect your name, email address, timezone, the answers to any questions the host asked, and the time you chose. We use it to create the meeting, invite you to it, send you a confirmation with a link to reschedule or cancel, and record for the host which campaign or link brought you there.

The company you are meeting is the controller of that data; we process it for them. Their privacy notice tells you how long they keep it and what else they do with it.

Two things worth knowing. First, the availability you see is computed from free/busy information only — arranging a meeting through Onion does not expose the host's other appointments to you, or yours to them. Second, your reschedule and cancel links are signed and expire; they are not guessable URLs, which is why you should not forward one to anybody you would not want rescheduling your meeting.

Part C — Common to both roles

14. Sub-processors

We use a small number of vendors to run Onion. Each is bound by a written contract with confidentiality, security and data protection terms at least as strict as our own commitments, and each processes data only on our instructions.

Google Cloud EMEA Limited (Ireland) — hosting for the Onion application, database and backups. All categories of data. Stored in Google Cloud's European Union regions.

Google Ireland Limited — Google Calendar API, for reading free/busy windows and creating the events Onion books. Free/busy windows, meeting records, account identifiers. EU, with transfers to the United States.

Microsoft Ireland Operations Limited — Microsoft Graph API, for the same purpose on Microsoft calendars. Free/busy windows, meeting records, account identifiers. EU, with transfers to the United States.

Framer B.V. (Netherlands) — hosting and analytics for the onionos.io website. Page requests and cookieless, non-identifying visit statistics. EU.

Anthropic, PBC and OpenAI, L.L.C. (United States) — classification, enrichment and drafting, through their business APIs under terms that exclude training on our data. Text containing business contact and company data.

Slack Technologies Limited (Ireland, part of Salesforce) — internal communication and operational alerts. Limited operational data. EU, with transfers to the United States.

Mailjet (Sinch) (France) — delivery of booking confirmations, service notifications and mailing list messages. Name, email address and meeting details. EU.

Licensed B2B data providers — enrichment source data. Business contact and company data.

We do not use a third-party CRM to hold client or prospect data; it lives in Onion itself.

A current, named list of every sub-processor — including the licensed data providers listed by category above — is available on request from privacy@onionos.io. Clients are notified at least 30 days before we add or replace a sub-processor and may object on reasonable data protection grounds.

15. International transfers

Onion's application, database and backups are hosted in the European Union. Some of our vendors are established in the United States, so certain data leaves the European Economic Area.

Where it does, we rely on the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914), backed by a transfer impact assessment and supplementary technical measures including encryption in transit and at rest.

Several of our US vendors are also certified under the EU–US Data Privacy Framework. That framework was upheld by the EU General Court in September 2025 but is under appeal before the Court of Justice, and the US surveillance law underpinning it has been in flux. We therefore do not rely on it as our only safeguard: Standard Contractual Clauses are in place with every US vendor regardless of their certification status, so a change in the framework's validity would not leave transfers unprotected.

You can ask us for a copy of the safeguards applying to a specific transfer at privacy@onionos.io.

16. Security

The measures below are the ones we consider material enough to state publicly, in line with Article 32 GDPR.

  • All traffic encrypted in transit with TLS 1.2 or above; data encrypted at rest.

  • Calendar and integration credentials protected by envelope encryption with a data key unique to each client workspace.

  • Tenant isolation enforced in the database itself through row-level security, not only in application code.

  • Least-privilege access, multi-factor authentication on administrative accounts, and audit logging of privileged and integration events.

  • Encrypted, regularly tested backups.

  • An incident response process under which we notify affected clients without undue delay, and supervisory authorities within 72 hours where Article 33 requires it.

No system is perfectly secure, and we will not claim otherwise. If you believe you have found a vulnerability, tell us at privacy@onionos.io and we will work with you on it.

17. How long we keep data

Website server logs — 90 days.

Aggregated website statistics — retained indefinitely in aggregate, non-identifying form.

Enquiries and correspondence — 24 months from last contact.

Mailing list subscription — until you unsubscribe.

Opt-out and suppression records — kept indefinitely, solely so we do not contact you again.

Client account data — duration of the contract, then 90 days.

Client-controlled data (leads, bookings, pipeline records) — as the client instructs; returned or deleted within 30 days of contract termination.

Raw synced calendar payloads — 7 days. We discard the raw sync data and keep only the derived booking record.

Security and audit logs — 12 months.

Invoices and accounting records — six years, as required by Article 30 of the Spanish Commercial Code.

When a retention period ends we delete the data or irreversibly anonymise it. Anonymised, aggregated statistics that can no longer identify anyone may be kept indefinitely.

18. Your rights

Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or send it to another provider in a machine-readable format. You can object to processing based on legitimate interests, and you can object to direct marketing at any time with no justification required — that one is absolute and we will always honour it. Where we rely on consent, you can withdraw it, which does not affect processing already carried out.

How to exercise them

Write to privacy@onionos.io. We reply within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. There is no charge. We may ask for information to confirm your identity, and we will ask for no more than we need.

If we hold your data for a client

We cannot decide on your behalf what happens to data a client controls. We will identify the client, forward your request to them within five business days, and assist them in answering it — as our processing agreements require. If you already know which company it is, going to them directly will be faster.

Complaints

If you are unhappy with how we have handled your data, please tell us first — most things are fixable. You also have the right to complain to a supervisory authority. Ours is the Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid (aepd.es), and it stays the AEPD after the transfer to Onion, S.L. You may also complain to the authority in your own country of residence or workplace instead — in Norway, for example, that is Datatilsynet.

19. Children

Onion is a business tool sold to businesses. It is not directed at children and we do not knowingly process the personal data of anyone under 18. If you believe a child's data has reached us, write to privacy@onionos.io and we will delete it.

20. Changes to this policy

We update this policy when our processing changes. Every version carries a number and an effective date at the top of the page. For material changes we email account holders at least 30 days before the new version takes effect, and we keep superseded versions available on request so you can see what changed.

Version 1.0 — 3 September 2026 — first published version.

Data protection contact: privacy@onionos.io The Coding Company, S.L., trading as Onion — c/ Pompeu Fabra 3, 17320 Tossa de Mar, Girona, Spain — CIF B-44697217

Supervisory authority: Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid — aepd.es

FREE REVIEW

Get a free review of your commercial setup

A short review of your current commercial setup, how your strategy, systems and execution work together, and where the gaps are. We’ll then show you how Onion could fit into your existing process and help build a more repeatable commercial operating model.