Privacy Policy
DRAFT — not legally binding
DRAFT — pending legal counsel review. Do not rely on this as legal advice.
Last updated: June 2026 · Effective: pending counsel sign-off
This Privacy Policy describes how Orqelo ("we", "us", "our") collects, uses, and protects personal data when you use the Orqelo AI chatbot platform (the "Service"). Please read it carefully.
1. Who we are
Orqelo is operated by Ibrahim Chehab. For privacy enquiries, contact: privacy@orqelo.com.
For Enterprise customers with an active Data Processing Agreement (DPA), we act as a data processor for the personal data of your end users. For account-level data (your team's user accounts, billing data), we act as a data controller.
2. Data we collect
2.1 Account data
When you register or manage a tenant account, we collect:
- Name and email address of account holders and invited team members
- Billing information (processed by Stripe; we store only the last 4 digits of the card, card type, and billing address)
- Authentication tokens (stored in HttpOnly cookies — not accessible to JavaScript)
- Multi-factor authentication secrets (stored encrypted)
2.2 Conversation data
The Service stores:
- Chat messages sent to and received from your chatbot (including any data your end users submit)
- Knowledge base documents you upload for RAG (Retrieval-Augmented Generation)
- Conversation metadata (timestamps, session IDs, resolution status)
Conversation data is isolated per tenant via Postgres Row-Level Security. No query can access another tenant's conversation data.
2.3 Usage and telemetry
We collect:
- API call counts, token consumption, and feature usage metrics — used for billing and quota enforcement
- Error logs and performance traces — used for debugging and reliability (personal data minimised)
- Aggregated analytics on page and feature usage within the tenant dashboard
2.4 Data we do not collect
We do not:
- Use advertising cookies or third-party ad tracking pixels
- Sell personal data to third parties
- Access the content of your conversations for purposes other than service operation, quality improvement (opt-in), and legal compliance
3. How we use your data
- Service operation: Account management, authentication, billing, and delivering the chatbot infrastructure you pay for.
- AI model improvement: We may use anonymised conversation data to improve model quality. You can opt out at any time in workspace settings → Privacy. Opt-out is honoured for all future processing; historical anonymised aggregates may be retained.
- Security and fraud prevention: Audit log, rate limiting, and abuse detection.
- Legal compliance: Responding to lawful requests from authorities, enforcing our Terms, resolving disputes.
- Product communications: Service announcements, billing notifications, and (with your consent) product updates. You can unsubscribe from marketing emails at any time.
4. Data storage and security
4.1 Default storage
Data is stored on AWS infrastructure. The primary region for all plans is EU (eu-west-1). A disaster-recovery replica resides in AWS us-east-1. Database data is encrypted at rest using AES-256 with per-tenant Data Encryption Keys (DEKs) managed via AWS KMS.
4.2 Enterprise data residency
Enterprise customers may select MENA (me-south-1) residency or request a single-region eu-west-1 configuration with no replication outside the EEA at account provisioning. Regional selection is enforced at the infrastructure layer.
4.3 Security measures
- Postgres Row-Level Security (RLS) enforcing per-tenant isolation at the database engine
- AES-256 encryption at rest, per-tenant DEK + KMS
- JWT authentication stored in HttpOnly, SameSite=Strict cookies
- MFA (TOTP) available and encouraged
- Cryptographic audit log (tamper-evident hash chain)
- BYOK available on Enterprise (Bring Your Own Key via AWS KMS CMK)
5. Retention periods
- Active account data: Retained for the duration of your subscription.
- Conversation data: Retained per the retention window configured in your workspace settings (default: 180 days; configurable to 30–365 days on paid plans; unlimited on Enterprise).
- Billing records: Retained for 7 years for tax and accounting compliance.
- Audit logs: Retained for 12 months by default; Enterprise can extend to 7 years.
- Deleted accounts: All personal data deleted within 90 days of account deletion, except where retention is required by law.
6. Sub-processors
We share data with sub-processors to deliver the Service. A full list is available at /legal/subprocessors. Key sub-processors: AWS (infrastructure), Stripe (billing), OpenAI and Anthropic (AI inference), Twilio (optional voice/SMS), LiveKit (optional WebRTC).
7. Your GDPR rights
If you are located in the European Economic Area (EEA) or the UK, you have the following rights under GDPR / UK GDPR:
- Right of access: Request a copy of the personal data we hold about you or your workspace.
- Right to erasure ("right to be forgotten"): Request deletion of your personal data. Automated DSAR tooling is available in the tenant dashboard under Settings → Privacy → Delete my data.
- Right to data portability: Export your conversation data and account data in JSON or CSV format from the dashboard.
- Right to rectification: Correct inaccurate personal data held about you.
- Right to restriction of processing: Request that we limit processing of your data in certain circumstances.
- Right to object: Object to processing for legitimate interests or direct marketing.
To exercise any of these rights, use the in-product DSAR tool or email privacy@orqelo.com. We will respond within 30 days. These controls are implemented in our product today; compliance posture is oriented pending full legal counsel review.
8. Your CCPA rights (California residents)
Under the California Consumer Privacy Act (CCPA), California residents have the right to:
- Know what personal information is collected and how it is used;
- Delete personal information (subject to certain exceptions);
- Opt out of the sale of personal information — we do not sell personal information;
- Non-discrimination for exercising CCPA rights.
To submit a CCPA request, email privacy@orqelo.com with the subject line "CCPA Request".
9. Cookies
We use essential cookies only. Full details in our Cookie Policy. No advertising cookies are set.
10. Children's privacy
The Service is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us at privacy@orqelo.com and we will delete it.
11. Changes to this policy
We will notify you of material changes via email or in-product notification at least 14 days before the change takes effect for existing users.
12. Contact
Privacy enquiries: privacy@orqelo.com