// LEGAL

Privacy Policy

LAST UPDATED — 1 SEPTEMBER 2026

// 01

Who we are and how to reach us

ORiON is a workforce and operations intelligence platform operated by AthLink Networking Inc., a corporation incorporated in Delaware with its registered office at 26 Sweetpea Court, Danville, California 94506, United States. In this policy, "ORiON", "we" and "us" refer to that entity, and "the platform" refers to the ORiON application and this website.

This policy explains what personal data we handle, why, on what legal basis, who else is involved, and what rights you have. It applies to visitors to this website, to people who hold ORiON accounts, and to personal data we process on behalf of our customers.

For any privacy question, or to exercise the rights described in section 11, contact us at legal@orionworkforce.ai or write to the address above. We have not appointed a Data Protection Officer, and we are not currently required to do so.

// 02

Controller and processor roles

ORiON handles personal data in two distinct capacities, and the distinction determines who you should approach about it.

As controller. For personal data about website visitors, people who contact us, and individuals who hold ORiON accounts, we decide why and how that data is processed. We are the controller, and this policy governs it.

As processor. When a customer connects their own systems — an ERP, CRM, payroll platform, mailbox or bank — ORiON reads data from those systems on that customer's instructions. That data frequently concerns the customer's own employees, contacts and counterparties. For it, the customer is the controller and we act as processor on their behalf, governed by the data processing terms of our agreement with that customer rather than by this policy alone.

If you are an employee, customer or contact of an organization that uses ORiON and you want to exercise rights over data held in that organization's systems, your request should go to that organization. We will support them in responding, but we cannot act on their data without their instruction.

// 03

What we collect

As controller, we collect the following categories of personal data.

  • Account and identity data. Name, work email address, and the authentication identifier from your sign-in provider. We do not receive or store your password for a third-party sign-in provider.
  • Organization and role data. Which organization you belong to, your role within it, and your permissions.
  • Connection data. Which systems your organization has connected, who connected each one, when, the scope granted, and the access credentials or tokens for those connections — stored encrypted.
  • Usage and product data. Dashboards and widgets you create, questions you ask, agents you configure, actions you approve or reject, and the record of when each occurred.
  • Technical data. IP address, browser and device information, and application logs generated when you use the platform.
  • Correspondence. Messages you send us through the contact form, by email, or in the course of support and sales conversations.
  • Website analytics. Pages visited and interactions on this website, as described in section 12.

We do not seek special category data, and the platform is not intended for it. Personal data reached inside connected systems is dealt with separately in section 05.

// 04

Why we process it, and the legal basis

We sell into the United States today. We are below the applicable thresholds of the California Consumer Privacy Act as amended, and we do not sell personal data or share it for cross-context behavioural advertising. Where the GDPR or UK GDPR applies to a customer or individual, we rely on the following bases.

CONTRACT

Creating and administering accounts, providing the platform, maintaining connections, running agents you configure, and providing support.

LEGITIMATE INTERESTS

Securing the platform and investigating misuse; diagnosing faults; understanding aggregate product usage to improve the service; and responding to business enquiries. We balance these against your interests and rights, and you may object as described in section 11.

CONSENT

Non-essential cookies and analytics where consent is required, and marketing email where you have opted in. You can withdraw consent at any time without affecting processing already carried out.

LEGAL OBLIGATION

Meeting accounting, tax and other statutory requirements, and responding to lawful requests from competent authorities.

// 05

Data from your connected systems

ORiON only reaches a system after someone in your organization explicitly connects it. What we can see is bounded by the permissions of the account used to make that connection — where a system supports per-user authorization, ORiON inherits that person's access and nothing beyond it.

Depending on which systems you connect, that data may include records about your employees, customers, suppliers and other individuals — for example roster and payroll information, contacts and deal records, correspondence, calendar entries, documents, transactions, tickets and call activity. We process it to answer questions you ask, populate the dashboards you build, and carry out the agent tasks you configure.

Writes back into a connected system are gated. An agent assembles a proposed action and holds it until a person in your organization approves it; only then is the change made. Rejected proposals are not executed. We keep a record of what was proposed, who decided, and the outcome.

Disconnecting a system revokes our access to it, and content cached from that system is purged. Because ORiON is a layer over your systems rather than a system of record, your data remains in the source platform throughout, so there is nothing to migrate back when you disconnect or leave. Technical and security logs are retained for the period given in section 10.

// 06

AI models and your data

ORiON uses large language models to interpret questions, analyze data and plan agent actions. To do that, relevant content from your connected systems is sent to Anthropic, which we access directly through its API, for processing.

Customer data is not used to train Anthropic’s models. Data sent for inference is retained by Anthropic only for the period necessary to return a result and to meet its abuse-monitoring obligations, under commercial terms that prohibit further use.

Separately, we will not use your data to develop or improve ORiON itself except where you have given us written permission to do so. Because model-generated output can be incorrect or incomplete, ORiON records the sources behind an answer so that any figure can be traced back to the records it came from.

// 07

Google user data

This section is specific to data ORiON reads from Google Workspace accounts. It applies in addition to everything above, and where it is more specific, it governs.

What Google user data we access

ORiON requests these permissions when a person connects their Google account, and only these:

  • Gmail messages and settings, read only, so ORiON can answer questions about correspondence and triage an inbox.
  • Sending mail as the signed-in person, so a drafted reply they approve can actually go out.
  • Google Drive files, read only, so ORiON can search a person's Drive and read the contents of a document they ask about.
  • Google Sheets, Docs and Slides, read and write, so ORiON can build a spreadsheet, append rows, edit a document or assemble a deck when asked.
  • Calendar events, read and write, so ORiON can answer questions about a schedule and create an event a person approves.
  • Google Contacts, including other contacts, read only, so a person named in a request resolves to the right email address instead of a guess.

ORiON reads this data only while carrying out a request from the person whose account it is, or a scheduled task that person set up. It does not crawl an account in the background, and it does not read the account of anyone who has not connected one.

How we use it

Google user data is used for one purpose: to provide the features the person asked for. That means answering their questions, populating the dashboards they build, and preparing the actions they approve. Content from Google is held for the length of the request and to keep a conversation coherent, and it is not used to build profiles, to target advertising, for lending or credit decisions, or for any purpose the person did not ask for.

Who we share it with

We do not sell Google user data and we do not transfer it to data brokers, advertisers or any other third party for their own purposes. Two providers process it on our behalf, both under contracts that limit them to our instructions:

  • Supabase, which hosts the database and runs the server-side code, in the United States.
  • Anthropic, whose models interpret the request, in the United States. Only the content relevant to the request in front of ORiON is sent.

We may disclose data where the law requires it. We would notify the affected customer unless we were prohibited from doing so.

How we protect it

Google tokens are stored encrypted, are never sent to the browser, and every call to a Google API is made from our servers. Each organization's records are separated at the database level by row-level policies rather than by application logic, so a query that loses its scope returns nothing. Data is encrypted in transit and at rest. Administrative rights are held separately from ordinary membership, and any change ORiON proposes to a connected system waits for a person to approve it.

How long we keep it and how it is deleted

  • Google tokens are deleted immediately when a person disconnects Google or closes their account.
  • Content read from Google is purged when Google is disconnected or the account is closed.
  • A person can disconnect Google at any time from Settings in the platform, which revokes our access and triggers that purge. They can also revoke it directly at myaccount.google.com/permissions.
  • Anything else tied to the account, such as saved dashboards and approval records, is deleted 30 days after the account closes.
  • Anyone can ask us to delete their data sooner by writing to legal@orionworkforce.ai.

AI models and Google user data

ORiON sends Google content to Anthropic's models to interpret a request. That data is not used to develop, improve or train any AI or machine learning model, including Anthropic's and our own. Anthropic's commercial terms prohibit training on customer content, and we do not train on it either.

ORiON's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

// 08

Sub-processors and third parties

We keep our supply chain deliberately short. Two providers are involved in running the platform, and one more sees traffic on this marketing website and nothing else. Each is bound by contract to process personal data only on our instructions and to maintain appropriate security.

  • Supabase — hosting, database, authentication and transactional email. Processed in the United States.
  • Anthropic — model inference for questions, analysis and agent planning. Processed in the United States.
  • Snitcher — visitor analytics on this marketing website only. It never touches the platform or any data from a connected system. Processed in the European Union.

We use no error-monitoring or advertising providers, and no analytics provider has any access to the platform or to data from a connected system. If that changes we will update this list and notify account holders before the new provider begins processing.

We do not sell personal data, and we do not share it for cross-context behavioural advertising. We may disclose personal data where required by law, to establish or defend legal claims, or in connection with a merger or acquisition — in which case we will notify affected customers.

// 09

International transfers

The platform is hosted on Supabase in a United States region, and model inference is carried out by Anthropic in the United States. All processing therefore takes place in the United States. Where personal data reaches us from the European Economic Area or the United Kingdom, we rely on the Standard Contractual Clauses, together with the UK Addendum where applicable and supplementary measures where appropriate.

We do not currently offer a guarantee that data will be stored and processed exclusively within a nominated region. If regional residency is a requirement for your organization, raise it before contracting so we can tell you honestly whether we can meet it.

// 10

Retention

We keep personal data only as long as needed for the purpose it was collected for, or as long as the law requires.

  • Account and organization data — for the life of the account, then deleted 30 days after closure.
  • Connection credentials — deleted immediately on disconnection or account closure.
  • Content read from connected systems — purged when the system is disconnected or the account is closed.
  • Dashboards, agent configurations and approval records — for the life of the account, then deleted 30 days after closure.
  • Technical and security logs — 90 days.
  • Correspondence and enquiries — 24 months from the last exchange.
  • Billing and accounting records — as required by United States federal and California state law.
// 11

Your rights

Subject to the law that applies to you, you have the right to request access to your personal data; to have inaccurate data corrected; to have data erased; to restrict or object to processing; to receive your data in a portable format; and to withdraw consent where processing relies on it. Where US state privacy laws apply, you may also have rights to know, delete, correct and opt out, and not to be discriminated against for exercising them.

To make a request, contact legal@orionworkforce.ai. We will respond within one month, extendable by a further two months for complex requests, and we may need to verify your identity first. There is no charge unless a request is manifestly unfounded or excessive.

One important limit: where your data sits inside a customer's connected system and we process it as their processor, we must refer your request to that organization rather than act on it ourselves. We will tell you promptly if that is the case, and support them in responding.

// 12

Cookies and website analytics

Inside the platform we use strictly necessary cookies only. They keep you signed in and keep the service working, and they cannot be switched off because the service does not work without them. We run no advertising cookies anywhere, and we run no analytics inside the platform.

On this marketing website, and not in the platform, we use Snitcher. It identifies the organization an anonymous visitor is browsing from by looking up their IP address, and it records pages visited and interactions on the site. We use it to understand which companies are interested in ORiON. It is not used to build a profile of you as an individual, and it does not run on any page you reach after signing in. You can opt out using any standard tracker blocker, or by writing to legal@orionworkforce.ai. No Google user data is involved in this at any point. If we add advertising or marketing cookies, this section will be updated and a consent mechanism put in place before those cookies are set.

// 13

Security

Each organization's data is isolated at the database level through row-level security policies rather than by conditional logic in application code, so a query that loses its organization scope returns nothing rather than another customer's records. Integration credentials are stored encrypted and are never sent to the browser; all calls to your systems are made server-side. Data is encrypted in transit, and at rest by our hosting provider. Administrative rights are separated from ordinary membership, and every write an agent proposes requires human approval before it executes.

Our Security & Architecture page describes this in more detail. No system is perfectly secure, and we do not represent that ours is. We do not hold a third-party security certification, and we make no claim to one.

// 14

Breaches, complaints and changes

If a personal data breach occurs, we will notify affected customers without undue delay and in any event within 72 hours of becoming aware of it, so that they can meet their own obligations. We will notify regulators and affected individuals where the law requires.

If you are unhappy with how we have handled your personal data, contact us first at legal@orionworkforce.ai and we will try to resolve it. California residents may also contact the California Privacy Protection Agency or the California Attorney General. Individuals in the EEA or UK have the right to complain to their local supervisory authority.

We may update this policy as the platform changes. The date at the top records the current version. Where a change materially affects how we handle your personal data, we will notify account holders directly rather than relying on you noticing the new date.

// PRIVACY ENQUIRIES

Ask us about
data handling.

SEND A MESSAGE Security & architecture →