Privacy Policy
Effective date: · legal-2026-09-10.v3
1. Who we are and scope
Orchestri, LLC provides business software. This Privacy Policy covers our website, customer administrators and Authorized Users, support interactions, mobile features and connected Integrations. Orchestri determines how information is processed for account administration, the website and business operations. When processing Customer Data to deliver a Customer’s requested workflows, we act on that Customer’s instructions as a processor or service provider. Requests involving that data may require the workspace owner’s direction.
2. Information and sources
We receive account and profile details, workspace names and configuration, CRM and relationship records, imported files and support messages from Customers, their administrators and Authorized Users. Connected services provide only data accessible under authorized features and permissions, including email and calendar data and contact identities appearing in those records. The personal Calendar connection is read-only; email intelligence is separately authorized, and Gmail draft capability is optional.
When Customers enable supported meeting features or upload media, we process recordings, audio, transcripts and derived meeting information. AI features process prompts, relevant workspace context and outputs. Product availability and permissions determine which of these features a user can invoke; this list does not mean every Customer provides every category.
We receive billing contacts and transaction references from Customers and Stripe, and device/browser details, diagnostics, security logs and operational events from product use and our infrastructure. Optional website analytics follow the cookie controls below. Customer-directed imports, authorized providers and enabled business-enrichment features may supply publicly available business information. If we offer a referral program, its terms and notices will describe the information needed to administer it.
3. Purposes and sensitive information
We use these records to authenticate users, administer workspaces, provide relationship intelligence, organize email/calendar activity, generate requested drafts, transcribe or analyze authorized meetings, process billing, support customers, diagnose faults, maintain reliability, prevent abuse and comply with legal obligations. We send service and account communications and, where permitted and subject to opt-out, product communications. Optional website analytics help understand site use only after consent.
Communications and recordings may contain sensitive personal information. Do not submit categories that your workspace is not authorized to process. Customer is responsible for lawful instructions and required participant or sensitive-data consent. We do not use this material to infer protected characteristics for advertising or lending. Requests for additional sensitive-data uses require separate assessment and any legally required consent.
4. AI, ownership and Google Workspace data
Customer Data includes customer-specific AI outputs and remains owned by the Customer. Orchestri does not use Customer Data to create, train or improve generalized or foundational AI/ML models. Authorized AI providers process only the context needed for requested features under applicable access, purpose and data-use controls. Orchestri’s ownership of its preexisting software, models, methods and analytics does not include Customer Data, and service improvement does not authorize generalized model training with Customer Data.
Orchestri’s use and transfer of information received from Google Workspace APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google Workspace data is accessed only with user authorization and appropriate scopes for visible, user-benefiting features. We do not sell it, use it for advertising or creditworthiness/lending decisions, or use it to create, train or improve generalized or foundational AI/ML models. These protections also apply to data derived or transformed from Google data. Transfers to providers are limited to what is necessary to deliver authorized features under appropriate controls. Human access is restricted to specific consent, security or abuse investigation, legal compliance or another policy-permitted exception. Provider terms do not override these commitments. Users can disconnect Google and use available deletion controls or contact support@orchestri.ai for help with prior imports.
5. Recipients and providers
We share necessary information with hosting/database and authentication providers, authorized AI processors, email delivery services, payment processors, monitoring/security services and Integrations selected by the Customer. Recipients process information for the functions they provide. Payment providers may also process information to meet their own legal, security and fraud-prevention obligations. Customer-selected Integrations are governed by the Customer’s relationship with the connected provider as well as Orchestri’s obligations for its own processing.
We may disclose information to professional advisers under confidentiality obligations, to authorities when legally required, to protect rights and security, or as part of a corporate transaction subject to appropriate safeguards and continued privacy obligations. We do not sell personal information or share it for cross-context behavioral advertising or targeted advertising. We do not treat deidentification as permission to evade Google Limited Use, and we do not reidentify deidentified Usage Data.
6. Cookies and choice
Essential cookies or browser storage support authentication, security and saved preferences. Optional website analytics are off until a visitor affirmatively accepts analytics cookies. Declining or making no choice leaves analytics off. Cookie Preferences lets a visitor decline or reset a prior choice; resetting returns the consent state to unknown. Essential service functions continue.
We do not sell personal information or use it for targeted advertising. You may contact support@orchestri.ai to exercise applicable privacy rights or object to processing. Declining optional analytics leaves essential service functions available.
7. Retention and deletion
Orchestri retains Customer Data for the period needed to provide the Services and fulfill the Customer relationship. Following a verified deletion request or termination, Orchestri deletes or deidentifies eligible Customer Data within a commercially reasonable period, subject to protected backup cycles and records retained for legal, security, accounting, fraud-prevention or dispute-resolution purposes.
Account and workspace content, imported communications, recordings, transcripts, prompts and derived information are retained for the requested Services and handled through the applicable deletion process. We verify identity and authority, identify the scope of the request, and explain any records that cannot be deleted and the reason for retaining them. Protected backup copies may remain until overwritten through ordinary backup cycles; retained data remains restricted to its permitted purpose.
OAuth credentials are removed from active use when a connection is disconnected, and provider revocation is attempted where supported. Disconnecting does not automatically delete previously imported or derived records. Users may preview and delete eligible imported Google data through the available controls or contact support for broader deletion assistance. These actions do not delete the original information held by Google or Microsoft.
Billing records are retained for accounting, payment administration and legal obligations. Support records, security logs and fraud/dispute records are retained for resolving requests, protecting the Services and meeting applicable obligations. Export and import artifacts are retained while needed for their processing or delivery and applicable recordkeeping purposes. Deidentified Usage Data is retained for its permitted operational purpose, is not reidentified and remains subject to applicable source-data restrictions.
8. Access, correction, deletion, export and appeals
For access, correction, deletion or export requests, email support@orchestri.ai with your account email, workspace and requested action. Do not send passwords or full payment details. We verify identity and authority using account or administrator confirmation and may request proportionate additional information. For Customer-controlled data, we coordinate with the authorized workspace owner. If a request is denied or limited, we explain the reason and available review steps.
You may update supported profile fields and use available export tools subject to workspace permissions. Contact support for other available exports or account deletion. Deleting an individual account is different from deleting a workspace and does not authorize deletion of other users’ data. Workspace owners should arrange ownership transfer, required exports and approval of the workspace deletion request.
Disconnect Google or Microsoft in Profile Integrations to stop future access through that connection. You may also revoke Orchestri’s access in the provider’s account permissions. To delete prior imports, use the available Google deletion controls or contact support for assistance with Google, Microsoft or other data. Disconnecting or revoking access is not the same as deleting previously imported information.
You may unsubscribe from marketing messages using their unsubscribe controls or by contacting support. Necessary account and service notices continue. Where applicable, you may object to or opt out of processing and appeal a privacy decision by emailing support@orchestri.ai with “Privacy appeal” in the subject. We review appeals and explain our response and any available regulator complaint route within applicable legal periods.
9. Security and international processing
We use reasonable administrative, technical and organizational safeguards, including access controls, encrypted transport, protection of stored OAuth credentials and hosted storage encryption at rest. Customers must protect their accounts and devices and use appropriate permissions. No system is absolutely secure.
Our infrastructure and authorized providers may process information in the United States and other countries where they operate. Additional data-processing terms and applicable international-transfer safeguards may be agreed where appropriate. This policy does not itself create a data-residency commitment or a Data Processing Addendum.
10. Business audience, changes and contact
The Services are intended for business users who are at least 18 years old. If you believe a child has supplied personal information to Orchestri, contact support@orchestri.ai so we can investigate and address it.
We will identify the effective version and give advance notice of material changes through the website or relevant account contact. New processing that requires consent will not begin merely because a policy page changed. Historical acceptance evidence remains associated with the text accepted at the time.
Contact Orchestri, LLC at support@orchestri.ai for support, privacy requests and appeals, billing or cancellation assistance, security notifications, and legal-notice routing.