1. Who we are and what this policy covers
Orcinta is a US technology company. This policy explains how we handle personal information when you visit our website, contact us, apply for a role, or interact with our services.
We determine how information is used for our own website, business communications, recruitment, and account administration. When we process connected-source or workspace information for a customer, we generally act on that organization’s instructions under its service and data-processing arrangements. The customer determines the purposes of that processing and the sources it authorizes.
If your question concerns information in an employer’s or another organization’s workspace, contact that organization first. You can also submit a privacy request, and we will help identify the appropriate path.
2. Information we collect
Information you provide
- Inquiries and demo requests: your name, email, company name where requested, selected topic, and message.
- Job applications: your name, email, the role you apply for, résumé file or link, and any location, profile, portfolio, or additional information you choose to provide.
- Accounts and workspaces: identity and contact details, authentication information, memberships, roles, preferences, and connection settings.
- Conversations and support: questions, responses, conversation context, support messages, and information you share while using text or voice features.
- Commercial information: business contacts, agreements, subscription and usage information, and billing or payment-related metadata where applicable.
Information from authorized sources
When an organization or member connects a source, we process documents, messages, business records, source metadata, and other information within the authorized scope. This information may concern employees, customers, suppliers, and other people mentioned in those sources. Agent and action records can also include the identity of an actor, responsible person, approval, or policy.
Information generated through use
Web requests and service activity can generate technical information such as IP addresses, browser and device information, request times, language preferences, access events, errors, and usage or security records. Hosting and service providers may process this information to deliver and protect the service. We also generate extracted intelligence and provenance from authorized source material.
3. How we use information
We use personal information as needed to:
- Respond to inquiries, arrange demonstrations, discuss commercial requirements, and review applications.
- Provide accounts and workspaces, authenticate users, manage access, and support customers.
- Process authorized sources, connect organizational context, answer questions, and support configured governance and review workflows.
- Maintain security, detect abuse, investigate errors, and preserve required activity records.
- Administer agreements, usage, billing, legal obligations, and disputes.
- Understand and improve the reliability and usability of our services.
Where applicable law requires a legal basis, we rely on the following. Responding to inquiries, arranging demonstrations, and discussing commercial requirements: steps taken at your request before a contract, and our legitimate interest in operating our business. Providing accounts, workspaces, and support: performance of the agreement with your organization. Security, abuse detection, error investigation, and required activity records: our legitimate interests in protecting the service and our legal obligations. Reviewing job applications: steps taken at your request and our legitimate interest in recruitment. Optional website preferences and translation: your consent, which you can withdraw at any time through Cookie settings. Administering agreements, billing, and disputes: performance of a contract and legal obligations. For customer-controlled workspace processing, the customer is responsible for identifying the appropriate legal basis.
4. Source content, retained intelligence, and AI
Raw connected documents and messages are temporary by default. They are processed to extract signals, claims, summaries, source references, and provenance, rather than kept as a permanent document archive. Authorized evidence may be fetched again when needed.
This does not mean that no information is stored. Extracted intelligence can include personal or sensitive information. Account data, conversations, preferences, audit records, receipts, and source metadata have their own storage and retention lifecycles. Private member-vault information is kept separate from shared organizational intelligence unless explicitly contributed.
Organizational learning uses context, retrieval, and recorded outcomes. It is distinct from training a model on workspace conversations. Where external AI services are configured, relevant request content and context may be sent to them for processing. Provider selection, retention, training restrictions, and deployment-specific terms should be confirmed in the applicable service arrangements; this policy does not assert a universal provider configuration.
See Trust & security for more detail about data boundaries and the limits of the security claims we make.
7. How long information is kept
Retention depends on why the information is held, the applicable agreement, organization settings, legal obligations, and the need to resolve disputes or maintain security.
- Inquiries remain in the receiving mailbox while the conversation or a related commercial relationship is active and are then removed in routine mailbox cleanup. Application materials are kept for up to twelve months after the role closes so the team can consider you for similar openings, unless you ask for earlier deletion. Neither is erased automatically when the website form closes.
- Raw connected-source bodies are temporary by default, while extracted intelligence and provenance follow the workspace’s retention and deletion rules.
- Conversation history has no default automatic expiration. It remains available until explicitly deleted, unless an installation applies a configured retention window.
- Account, billing, audit, and receipt records may have separate retention requirements. Privacy workflows can remove or restrict eligible content while preserving required event-history integrity.
- Backups and records subject to a legal hold may remain for their applicable retention periods.
Disconnecting a source does not necessarily erase information already extracted from it. Contact the workspace administrator or submit a privacy request to discuss deletion of specific information.
8. Security and access
We use technical and organizational measures designed to limit unauthorized access and protect information. Supported controls include permission checks, organization-scoped access, protection of sensitive credentials, and activity records. The controls available to an organization depend on its deployment and configuration.
No service or method of transmission can guarantee absolute security. Protect your credentials, review access permissions, and avoid sharing secrets through public forms. Report suspected vulnerabilities through the contact information on our Trust & security page.
9. International processing
Information may be processed in the United States or other locations used by the service providers involved in delivering your service. Those locations may have data-protection laws that differ from your jurisdiction.
For website inquiries and job applications, our hosting and email providers process information in the United States under their data-processing terms, which include standard contractual clauses or an equivalent recognized transfer mechanism where the law requires one. For contracted services, hosting location, residency requirements, and applicable transfer safeguards are addressed through the relevant service and data-processing arrangements. Contact our team to confirm those arrangements for your organization. A general reference to a deployment option does not guarantee that all information remains in a particular country.
10. Your rights and choices
Depending on your location and the law that applies, you may have rights to access or receive a copy of your personal information, correct it, request deletion, restrict or object to processing, obtain portability, or withdraw consent where processing is based on consent. Some laws also provide rights concerning targeted advertising, the sale or sharing of information, and certain automated decisions. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
To exercise a right, submit a privacy request. Identify the information or account involved and the action you are requesting. We may need to verify your identity and authority before acting, and may direct workspace-related requests to the responsible customer. Do not send passwords or unnecessary identity documents with an initial request.
Rights are subject to applicable exceptions, including legal obligations and the rights of others. We will respond according to applicable law. Where available, you may use an authorized agent, appeal a request decision, or complain to a relevant data-protection authority. We will not discriminate against you for exercising applicable privacy rights.
You can also manage account preferences, request workspace changes through your administrator, stop providing optional information, or ask us to stop optional communications. Necessary service and security messages may still be required.
11. Children’s information
Our website and services are intended for business and professional use and are not directed to children under 13. We do not knowingly seek personal information from children under 13. If you believe a child has provided information to us, submit a privacy request so we can review and address it.
12. Updates and how to reach us
We may update this policy to reflect changes in our practices, services, or legal requirements. The date above identifies the latest revision. We will provide additional notice or seek consent where required by law.
For privacy questions or requests, use our privacy request form or email admin@orcinta.com. For other questions, contact our team. Please include enough context for the team to understand your request without sending unnecessary sensitive information.