Effective date: [DATE]
Who we are: Orchid AI Advisors LLC, a Georgia limited liability company (“Orchid,” “we”), [ADDRESS].
Contact: contact@orchidaiadvisors.com
This policy explains what we collect, why, and what happens to it — on our public website and inside the Orchid platform (the client portal, AI interviews, forms, and related features).
1. The short version
- Platform accounts are created by invitation only — there is no open signup.
- For business customers, your organization controls its data; we process it on the organization's behalf under a Data Processing Addendum (“DPA”). For our website and our own operations (analytics, billing, consultation requests), we are the controller.
- Interviews are conducted by an AI system, and users are told so. Interview content is processed by our AI model provider with automated redaction designed to keep third-party personal names out of what the provider receives. Our provider agreements do not permit training foundation models on your data. [VERIFY provider terms at publication.]
- We do not sell or share personal information (as those terms are defined in the California Consumer Privacy Act), and we do not run advertising trackers. Our analytics are first-party. [VERIFY no third-party analytics scripts at publication.]
2. What we collect
On the public website:
- Page-view analytics — pages visited, timestamps, and technical request metadata, collected by our own first-party beacon into our own database. Retained approximately 14 months, then deleted.
- Consultation requests — name, contact details, and your message, so we can respond.
In the platform (invited users):
- Account data — name, email address, role, organization.
- Interview content — conversations with our AI interviewer, uploaded documents, form responses, and documents generated from them.
- Voice — if a user chooses voice features, audio is captured to transcribe the user's speech, and synthesized speech is generated for playback. The microphone stops automatically after a bounded period. [CONFIRM whether raw audio is stored or discarded after transcription — state whichever is true.]
- Support and discussion messages, including attachments.
- Activity logs — who did what (sign-ins, document actions), for security auditing and support.
- Error and security telemetry — application errors and browser content-security-policy reports.
Do not submit government identifiers, payment card numbers, or health records through the platform; the platform is not designed for them.
3. How we use it, and our legal bases
We use personal information to: provide and operate the Service; conduct and summarize AI-assisted interviews; generate requested documents; notify the right people (e.g., your organization's administrator) about activity; secure the Service, investigate abuse, and debug failures; invoice business customers; and meet legal obligations. We do not sell personal information and do not use it for third-party advertising.
Where GDPR or similar law applies, our legal bases are:
| Processing | Legal basis |
|---|---|
| Providing the platform to your organization | Performance of a contract; the organization's instructions under the DPA |
| Website analytics, service improvement | Legitimate interests (running and improving a business service) |
| Security, abuse prevention, audit logging | Legitimate interests (protecting the Service and its users); legal obligation |
| Billing and business records | Performance of a contract; legal obligation |
| Responding to consultation requests | Legitimate interests; steps prior to a contract |
We do not currently target the EU or UK. If we onboard EU/UK customers, we will put Standard Contractual Clauses in place under the DPA and make any required representative appointments before processing begins.
4. AI transparency
- You are interacting with an AI system. Platform interviews are conducted by an AI agent, identified as such, administered by Orchid personnel.
- What the AI provider receives. Interview conversations and related content are sent to our AI model provider (Anthropic) to generate responses and documents. Before sending, automated redaction replaces third-party personal names with neutral placeholders, restored only when content is displayed inside your organization's workspace. Text read aloud is sent to our speech provider (ElevenLabs) to synthesize audio.
- No foundation-model training. Our provider agreements do not permit training foundation models on your content. [VERIFY at publication.]
- Accuracy. Automated grounding checks review generated documents against their sources, and AI output can still contain errors; it is provided for your organization's review, and consequential decisions should be made by people.
- [DECISION REQUIRED — mirror of Terms §4.4: if de-identified cross-organization methodology learning is enabled for product customers, disclose it here in one plain sentence; if excluded, omit.] We will not attempt to re-identify de-identified information.
5. Who we share it with (subprocessors and other recipients)
We use a small set of service providers, each processing data only to provide its service to us:
| Provider | What it does | Data it touches |
|---|---|---|
| Supabase | Database, authentication, file storage, server functions | All platform data |
| Netlify | Website hosting, CDN, DNS | Web traffic |
| Anthropic | AI language model for interviews and documents | Redacted interview content |
| ElevenLabs | Text-to-speech for voice features | Text being read aloud |
| Resend | Transactional email (invitations, notifications) | Names, email addresses, notification content |
| CloudConvert | Document format conversion | Documents being converted |
| Google Fonts | Font delivery on web pages | IP address of the browser request |
| [Zoho Mail] | [Business email for contact@ correspondence] | [Email you send us] |
| [Twilio] | [SMS alerts — currently inactive; include only if activated] | [Phone numbers, alert text] |
[VERIFY this table against live configuration at publication; confirm the inbound email provider for reply-by-email features.]
Data is hosted in [REGION — confirm the Supabase project region; if processing occurs outside the customer's country, say so here and address transfers in the DPA].
We may also disclose information: if required by law or legal process (see the DPA for how we handle government requests for customer data); to professional advisors under confidentiality; or in a merger, acquisition, or sale of assets, in which case this policy continues to apply to previously collected data.
6. How long we keep it
| Data | Retention |
|---|---|
| Website page-view analytics | ~14 months |
| Client documents and generated files | Up to 7 years, then automatically purged (organizations can archive or purge earlier through the document lifecycle tools) |
| Support conversations | 3 years (records are immutable during that period) |
| Interview conversations and form responses | Duration of the engagement plus [PERIOD — decide, e.g., 90 days], then deleted per the DPA termination schedule |
| Account data | Life of the account; removing a user preserves organizational contributions but revokes access; a full purge option erases them |
| Activity, error, and security logs | [PERIOD — confirm; recommend 12–24 months] |
| Voice audio | [Discarded after transcription / retained — CONFIRM and state] |
7. Your privacy rights
Platform users: for data we process on your organization's behalf, route requests (access, correction, export, deletion) through your organization's administrator; we support the organization per the DPA. For data we control (website analytics, consultation requests, billing), contact contact@orchidaiadvisors.com.
U.S. state privacy laws (California, Colorado, Connecticut, Virginia, and others): depending on your state, you may have rights to access, correct, delete, and obtain a copy of personal information, and to opt out of sale, sharing, and targeted advertising. We do not sell or share personal information and do not engage in targeted advertising, so there is nothing to opt out of; we honor browser Global Privacy Control signals for any future processing to which they would apply. We will not discriminate against you for exercising rights. You may appeal a refusal by replying to our decision, and we will re-review. [Counsel: Georgia currently has no comprehensive consumer privacy statute — believed correct as of drafting; confirm, and confirm whether CPRA thresholds are even met before formal CCPA notices are added.]
EU/UK (if applicable): rights of access, rectification, erasure, restriction, portability, and objection; complaints may go to your supervisory authority. See §3 for our posture on EU/UK processing.
We respond within the time required by applicable law.
8. Security
We maintain organization-level tenant isolation enforced in the database, encryption in transit, role-based access, invitation-only accounts, per-organization spending limits on AI processing, security headers including an enforced content-security policy with violation reporting, activity audit logging, and monitored error telemetry. No internet service can promise perfect security; if we learn of a breach affecting your data, we will notify affected customers as described in the DPA and as required by law.
9. Cookies and local storage
The platform uses cookies and local storage for sign-in sessions and product functionality only — not for advertising or cross-site tracking. [VERIFY at publication whether any non-essential cookies exist; if none, keep this plain statement — it is a selling point.]
10. Children
The Service is for business use and is not directed to children under 16.
11. Changes
We will post changes here with a new effective date and notify business customers of material changes as the DPA requires.
