Privacy Policy | ORIAI

Privacy Policy

We value your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, and safeguard your data when you use our services.

Last Updated: May 26, 2025

1. Overview

At ORIAI ("we", "our", or "us"), we respect your privacy and are committed to protecting it through our compliance with this policy.

This Privacy Policy describes the types of information we may collect from you or that you may provide when you visit our website at https://oriai.ai (our "Website") or use our AI services and products, and our practices for collecting, using, maintaining, protecting, and disclosing that information.

By accessing or using our Website and services, you agree to this Privacy Policy. If you do not agree with our policies and practices, your choice is not to use our Website or services.

2. Information We Collect

We collect several types of information from and about users of our Website and services, including:

Personal Information

Personal information that can be used to identify you as an individual, such as:

  • Name, email address, phone number, and billing information
  • Business information (company name, job title, etc.)
  • Account login credentials
  • Information you provide when you contact us or request support

Content and Brand Voice Data

When you use our Brand GPT creation services, we collect:

  • Content samples you provide for brand voice extraction
  • Business knowledge information you input for your Custom Brand GPT
  • Communications between you and your Brand GPT

Usage Data

We collect information about your interactions with our Website and services:

  • Access times, pages viewed, and interactions
  • IP address, browser type, device type, and operating system
  • Referring websites or applications
  • Features and tools you use within our services

Payment Information

When you make a purchase, we collect payment information necessary to process your transaction. We do not store full credit card details on our servers. Payment processing is handled by trusted third-party payment processors who comply with PCI-DSS standards.

3. How We Use Your Information

We use the information we collect about you or that you provide to us for the following purposes:

To Provide Our Services

Creating and operating your Custom Brand GPT; processing transactions; providing customer service and support; communicating with you about your account or services.

To Improve Our Services

Analyzing usage patterns; understanding how users interact with our services; debugging issues; developing new features and improvements.

For Marketing and Communication

Sending promotional communications (if you've opted in); providing relevant content; measuring marketing effectiveness.

To Protect Our Services and Users

Detecting and preventing fraud, security incidents, and abuse; enforcing our Terms of Service; protecting our rights and property.

For Legal Compliance

Complying with applicable laws, regulations, legal processes, or governmental requests.

4. Information Sharing and Disclosure

We may disclose personal information that we collect or you provide as described in this Privacy Policy:

Service Providers

We share information with third-party vendors, service providers, and contractors who perform services on our behalf, such as payment processing, data analysis, email delivery, hosting services, and customer service. These service providers have access to your personal information only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Business Transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, your information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

Legal Requirements

We may disclose personal information if required to do so by law or in response to valid requests by public authorities (e.g., a court or a government agency), to protect our rights, privacy, safety or property, or to protect the rights, privacy, safety or property of others.

With Your Consent

We may share your information in any other circumstances where we have your explicit consent.

We do not sell or rent your personal information to third parties for their marketing purposes without your explicit consent.

5. Data Security

We have implemented appropriate technical and organizational measures designed to secure your personal information from accidental loss and from unauthorized access, use, alteration, and disclosure.

These security measures include:

  • Encryption of sensitive data both in transit and at rest
  • Secure access controls and authentication mechanisms
  • Regular security assessments and audits
  • Employee training on data protection and security practices
  • Physical security controls for our facilities

Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal information, we cannot guarantee the security of your information transmitted to our Website. Any transmission of personal information is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Website.

In the event of a data breach involving your personal information, we will notify you and relevant authorities in accordance with applicable laws.

6. Data Retention and Minimization

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide services to you
  • Our legal obligations under applicable laws
  • The existence of any legal claims or liability obligations
  • Whether retention is advisable based on our legal position (such as for statutes of limitations, litigation, or regulatory investigations)

We implement data minimization principles, collecting only the personal information that is necessary for the purposes specified in this Privacy Policy. We regularly review our data collection, storage, and processing practices to ensure we only collect and retain personal information that is necessary.

When we no longer need personal information for the purposes for which it was collected, we will securely delete or anonymize it. If this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.

7. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our Website and store certain information. Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device.

Types of Cookies We Use

Essential Cookies

These cookies are necessary for the Website to function properly and cannot be switched off in our systems. They are usually set in response to actions made by you, such as setting your privacy preferences, logging in, or filling in forms.

Performance and Analytics Cookies

These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site.

Functionality Cookies

These cookies enable the website to provide enhanced functionality and personalization. They may be set by us or by third-party providers whose services we have added to our pages.

Marketing Cookies

These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant advertisements on other sites.

Do Not Track

Some browsers have a "Do Not Track" feature that signals to websites that you visit that you do not want to have your online activity tracked. Our Website does respond to "Do Not Track" signals. You can disable cookies through your browser settings.

Your Cookie Choices

You can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies. You do this through your browser settings. Since each browser is a little different, look at your browser's Help Menu to learn the correct way to modify your cookies.

If you disable cookies, some features may be disabled. It won't affect the core functionality of the service, but it may affect your user experience.

8. Your Rights and Choices

Depending on your location, you may have certain rights regarding your personal information. These may include:

Access and Portability

You have the right to request a copy of the personal information we hold about you and to receive it in a structured, commonly used format.

Correction

You have the right to have inaccurate personal information corrected, or incomplete information completed.

Deletion

You have the right to request that we delete your personal information in certain circumstances.

Restriction

You have the right to request that we restrict the processing of your personal information in certain circumstances.

Objection

You have the right to object to the processing of your personal information in certain circumstances.

Withdraw Consent

Where we process data based on consent, you have the right to withdraw that consent at any time.

Automated Decision-Making and Profiling

In certain circumstances, you have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal or similarly significant effects. While our AI services automate certain processes, we implement appropriate safeguards and ensure there is always human oversight in decisions that might significantly affect you.

To exercise any of these rights, please contact us using the information provided in the "Contact Us" section below. We will respond to your request within a reasonable timeframe and in accordance with applicable data protection laws.

Please note that these rights are not absolute, and in some instances, we may be entitled to refuse your request where exceptions apply.

9. GDPR Compliance

For users in the European Economic Area (EEA), the United Kingdom, and Switzerland, we process your personal information in accordance with the General Data Protection Regulation (GDPR) and applicable local laws.

Legal Basis for Processing

We process your personal information based on one or more of the following legal grounds:

  • Performance of a Contract: Processing necessary for the performance of a contract with you or to take steps at your request before entering into a contract.
  • Legitimate Interests: Processing necessary for our legitimate interests, provided those interests are not overridden by your rights and freedoms.
  • Consent: Where you have given us consent to process your personal information for specific purposes.
  • Legal Obligation: Processing necessary for compliance with a legal obligation to which we are subject.

International Data Transfers

We may transfer your personal information to countries outside the EEA, UK, or Switzerland that may not have data protection laws as comprehensive as those in your jurisdiction. When we transfer your personal information internationally, we implement appropriate safeguards in accordance with the GDPR and applicable data protection laws.

These safeguards may include:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Binding Corporate Rules (BCRs)
  • Adequacy decisions issued by the European Commission
  • Derogations for specific situations as set out in Article 49 of the GDPR

If you have any questions about our GDPR compliance or wish to exercise your GDPR rights, please contact our Data Protection Officer using the contact information provided at the end of this Privacy Policy.

10. CCPA Compliance

The California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide California residents with specific rights regarding their personal information. This section describes your CCPA/CPRA rights and explains how to exercise those rights.

Your Rights Under the CCPA/CPRA

Right to Know

You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past 12 months, including the categories of personal information we collected, the sources of that information, our business purpose for collecting it, and the categories of third parties with whom we share it.

Right to Delete

You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions for legitimate business purposes.

Right to Correct

You have the right to request that we correct inaccurate personal information that we maintain about you.

Right to Opt-Out of Sale or Sharing

ORIAI does not sell personal information as defined in the CCPA/CPRA. However, if you feel that your information is being sold or shared for cross-context behavioral advertising, you have the right to opt-out.

Right to Limit Use of Sensitive Personal Information

You have the right to limit our use and disclosure of sensitive personal information to certain business purposes.

Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA/CPRA rights. We will not deny you goods or services, charge you different prices or rates, provide a different level of service or quality, or suggest you will receive a different price or quality level.

Exercising Your CCPA/CPRA Rights

To exercise your rights described above, you can submit a verifiable consumer request to us by contacting us using the information in the "Contact Us" section. Only you, or a person registered with the California Secretary of State that you authorize to act on your behalf, may make a request related to your personal information.

We will respond to your request within 45 days. If we require more time, we will inform you of the reason and extension period in writing.

11. Children's Privacy

Our Website and services are not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and you believe we might have collected information from your child, please contact us immediately using the information in the "Contact Us" section, and we will take appropriate steps to remove that information from our systems.

In certain jurisdictions, collection and use of children's data may be subject to additional requirements or limitations under applicable laws. We comply with these requirements in our data processing activities.

12. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

If we make material changes to this Privacy Policy, we will notify you either through the email address you have provided us or by placing a prominent notice on our Website.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

ORIAI

For data protection inquiries specifically, you can contact our Data Protection Officer at [email protected].