Effective Date: July 3, 2026
Business Name: Orivio
Contact: support@orivio.ai
Address: Suite RA01, 195-197 Wood Street, London, E17 3NU
Controller:
For UK GDPR purposes, Orivio is the controller of personal data processed in connection with the Orivio services.
Address: Suite RA01, 195-197 Wood Street, London, E17 3NU • Contact: support@orivio.ai
At Orivio, we respect your privacy and are committed to protecting the personal information that you share with us. This Privacy Policy explains in detail how we collect, use, disclose, and safeguard your information when you use our application and related services. We also describe your rights under UK data protection law, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using our services, you agree to the practices described in this Privacy Policy. If you do not agree, please discontinue use of our services.
We handle personal data in accordance with UK GDPR and apply industry-standard security controls, including encryption in transit and at rest.
1. Information We Collect
Account Information
Name, email address, login details, and contact information for account creation and management.
Email and Calendar Data
If you connect Gmail, Outlook, and/or your calendar, we access the data you choose to connect only to provide the features you use (e.g., tagging, draft creation, availability checks, event scheduling). Data is encrypted in transit and at rest. We do not sell your data or use it for advertising.
Live Chat and Knowledge Base Data
If you use Live Chat, we store chat messages between your team and customers to provide real-time support and conversation history. If you use the Knowledge Base, we store the articles your team creates to power help centre and AI-assisted answers. All chat messages and knowledge base content is application-encrypted (AES-256-GCM) at rest.
Payment Information
Subscription payments are securely processed by third-party providers (e.g., Stripe, PayPal). We do not store full card details but may retain billing identifiers and subscription records.
Technical Information
IP address, browser type, device identifiers, operating system, access times, log files, and crash reports.
Cookies
We use only essential cookies needed to run the service (for example, to keep you signed in and protect the service). We do not use analytics, advertising, or other non-essential cookies. Your browser may store limited settings (e.g., preferences) to improve your experience. You can clear cookies and storage in your browser, but this may sign you out. If we introduce non-essential cookies in the future, we will ask for your consent first.
2. How We Use Your Information
Service Delivery
Delivering and improving our services (email management, live chat, knowledge base, scheduling, tagging, draft generation).
Personalisation
Personalising features and understanding usage patterns.
Payment Processing
Processing subscription payments and maintaining billing records.
Support & Communication
Responding to support requests and communications.
Legal Compliance
Meeting legal and regulatory obligations.
Security
Preventing fraud, abuse, or unauthorised access. We do not use your data for purposes outside these without your consent.
2A. Google User Data (Gmail & Calendar)
Access to Google data is requested only after you connect Gmail and/or Google Calendar inside Orivio. You can disconnect at any time. Orivio's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2B. Microsoft User Data (Outlook & Calendar)
Access to Microsoft data is requested only after you connect Outlook and/or Microsoft Calendar inside Orivio. You can disconnect at any time. Orivio's use of information received from Microsoft Graph APIs will adhere to the Microsoft APIs Terms of Use and applicable data protection requirements.
2C. Meta User Data (WhatsApp, Messenger & Instagram)
What We Access
When you connect WhatsApp Business, Facebook Messenger, or Instagram Direct Messages inside Orivio, we receive incoming messages sent by your customers to your connected Facebook Page, WhatsApp Business number, or Instagram Business account. We also receive basic sender information (name, profile) provided by Meta's APIs to identify the customer in your inbox.
How We Use It
Message data is used solely to display conversations in your Orivio live chat inbox, enable your team to reply, and provide conversation history. We do not use Meta user data for advertising, profiling, or any purpose unrelated to delivering the Orivio service.
Storage and Encryption
All messages received via WhatsApp, Messenger, and Instagram are encrypted at rest (AES-256-GCM) in the same manner as other live chat data. Page access tokens are stored encrypted and are never exposed to end users or third parties.
Data Sharing
We do not sell, rent, or share Meta user data with third parties. Message content may be processed by AI services (e.g., for suggested replies) only if you enable AI features, subject to the same no-training guarantees described in Section 10.
Disconnection and Deletion
You can disconnect WhatsApp, Messenger, or Instagram at any time from Settings → Connected Apps. Upon disconnection, we revoke the stored access token and no new messages are received. Existing conversation history from the disconnected channel is retained in your account for continuity. To delete all Meta message data, delete your Orivio account via Settings → Account → Delete Account, or request deletion via support@orivio.ai.
Meta Platform Terms
Orivio's use of data received from Meta Platform APIs adheres to the Meta Platform Terms and Developer Policies, including data use restrictions and privacy requirements.
2D. Telegram User Data
What We Access
When you connect a Telegram Bot inside Orivio, we receive incoming messages sent by your customers to your Telegram bot. We also receive basic sender information (name, username) provided by the Telegram Bot API to identify the customer in your inbox.
How We Use It
Message data is used solely to display conversations in your Orivio live chat inbox, enable your team to reply, and provide conversation history. We do not use Telegram user data for advertising, profiling, or any purpose unrelated to delivering the Orivio service.
Storage and Encryption
All messages received via Telegram are encrypted at rest (AES-256-GCM) in the same manner as other live chat data. Bot tokens are stored encrypted and are never exposed to end users or third parties.
Data Sharing
We do not sell, rent, or share Telegram user data with third parties. Message content may be processed by AI services (e.g., for suggested replies) only if you enable AI features, subject to the same no-training guarantees described in Section 10.
Disconnection and Deletion
You can disconnect Telegram at any time from Settings → Connected Apps. Upon disconnection, the stored bot token is removed and no new messages are received. Existing conversation history from Telegram is retained in your account for continuity. To delete all Telegram message data, delete your Orivio account via Settings → Account → Delete Account, or request deletion via support@orivio.ai.
2E. Twilio SMS Data
What We Access
When you connect a Twilio SMS number inside Orivio, we receive incoming SMS messages sent by your customers to your connected phone number. We also receive the sender's phone number to identify the customer in your inbox.
How We Use It
SMS message data is used solely to display conversations in your Orivio live chat inbox, enable your team to reply via SMS, and provide conversation history. We do not use SMS data for advertising, profiling, or any purpose unrelated to delivering the Orivio service.
Storage and Encryption
All SMS messages are encrypted at rest (AES-256-GCM) in the same manner as other live chat data. Twilio credentials are stored encrypted and are never exposed to end users or third parties.
Data Sharing
We do not sell, rent, or share SMS data with third parties. Message content may be processed by AI services (e.g., for suggested replies) only if you enable AI features, subject to the same no-training guarantees described in Section 10.
Disconnection and Deletion
You can disconnect Twilio SMS at any time from Settings → Connected Apps. Upon disconnection, stored credentials are removed and no new messages are received. Existing SMS conversation history is retained in your account for continuity. To delete all SMS data, delete your Orivio account via Settings → Account → Delete Account, or request deletion via support@orivio.ai.
2F. Stripe Data
What We Access
When you connect Stripe inside Orivio (via API key or OAuth), we access customer billing information such as subscription status, payment history, and customer details from your Stripe account. This data is displayed in the conversation sidebar to give your support team billing context.
How We Use It
Stripe data is used solely to display relevant billing information alongside customer conversations in your Orivio inbox. We do not use Stripe data for advertising, profiling, or any purpose unrelated to delivering the Orivio service.
Storage and Encryption
Stripe API keys and OAuth tokens are stored encrypted (AES-256-GCM). Billing data is fetched in real-time from Stripe and is not permanently stored in Orivio.
Disconnection and Deletion
You can disconnect Stripe at any time from Settings → Connected Apps. Upon disconnection, stored credentials are removed and no further Stripe data is accessed.
2G. Geolocation Data (MaxMind GeoLite2)
What We Access
Orivio uses the MaxMind GeoLite2 database to approximate a visitor's location (country, region, and city) from their IP address. This is used for visitor analytics in your live chat inbox, location-aware routing, and security features such as IP-based blocking.
Attribution
This product includes GeoLite2 data created by MaxMind, available from https://www.maxmind.com.
2H. CRM Integrations (HubSpot & Salesforce)
What We Access
If you choose to connect a CRM, we access contact records in that CRM in order to link them to the corresponding contacts in Orivio. Linking is performed using an email address or a telephone number only. Once a contact is linked, a limited set of basic contact details is kept aligned between the two systems. We do not access or synchronise notes, tags, deals, tickets, attachments, or any other records held in your CRM.
How We Use It
CRM data is used solely to keep the same contact details consistent in Orivio and in your CRM, so that your team sees the same information wherever they work. We do not use CRM data for advertising, profiling, or any purpose unrelated to delivering the Orivio service.
Storage and Encryption
CRM access tokens are stored encrypted (AES-256-GCM) and are never exposed to end users or third parties. Contact details received from your CRM are stored in the same manner as other contact data in your account.
Data Sharing
Because synchronisation operates in both directions, contact details held in Orivio may be written to your CRM at your instruction. Your CRM provider remains an independent controller of its own service, and its handling of that data is governed by your agreement with them rather than by this policy. We do not share CRM data with any other third party.
Disconnection and Deletion
You can disconnect your CRM at any time from Settings → Connected Apps. Upon disconnection the stored access token is removed and no further synchronisation takes place. Contact details already written to your CRM remain in your CRM and must be deleted there; deleting your Orivio account does not remove them. To delete the data held in Orivio, delete your account via Settings → Account → Delete Account, or request deletion via support@orivio.ai.
2I. Connected Online Stores (WooCommerce, Shopify & Wix)
What We Access
If you choose to connect an online store, we read product information from that store so the chat assistant can answer questions about what you sell. Where you enable order lookup, we can also retrieve details of a specific order — but only after the person asking has confirmed control of the email address on that order by entering a one-time code sent to it. That verification email is delivered by our email sub-processor, which therefore receives the shopper’s email address for that purpose alone. Order details may include the shopper’s name, contact details, delivery information and the items ordered.
How We Use It
Product and order information is used solely to answer that customer’s question in the conversation in which it was asked. We do not use it for advertising or profiling, and we do not build a copy of your catalogue or your order history.
Storage and Encryption
Product and order information is read from your store at the time a question is asked, rather than maintained as a separate copy. The details actually shown to a customer are retained as part of that conversation’s history and are encrypted at rest (AES-256-GCM), in the same manner as other live chat data. Store credentials are stored encrypted and are never exposed to end users or third parties.
Data Sharing
Where your shoppers’ personal data reaches Orivio through a connected store, you remain the controller of that data and we process it on your behalf and on your instructions. Product and order details relevant to a question may be processed by AI services in order to compose a reply, if you enable AI features, subject to the same no-training guarantees described in Section 10. We do not sell, rent, or otherwise share this data.
Disconnection and Deletion
You can disconnect a store at any time — from the Install tab in Orivio, or from the Orivio plugin inside your own store. Upon disconnection the stored credentials are removed and no further product or order information is read. Order and product details already shown in a conversation are retained as part of that conversation’s history. To delete them, delete your Orivio account via Settings → Account → Delete Account, or request deletion via support@orivio.ai.
2J. Slack User Data
What We Access
When you connect Slack inside Orivio, we receive messages sent in the Slack channels you connect, together with the basic sender information Slack provides so the person can be identified in your inbox.
How We Use It
Message data is used solely to display conversations in your Orivio live chat inbox, enable your team to reply, and provide conversation history. We do not use Slack data for advertising, profiling, or any purpose unrelated to delivering the Orivio service.
Storage and Encryption
All messages received via Slack are encrypted at rest (AES-256-GCM) in the same manner as other live chat data. Bot tokens are stored encrypted and are never exposed to end users or third parties.
Data Sharing
We do not sell, rent, or share Slack data with third parties. Message content may be processed by AI services (e.g., for suggested replies) only if you enable AI features, subject to the same no-training guarantees described in Section 10.
Disconnection and Deletion
You can disconnect Slack at any time from Settings → Connected Apps. Upon disconnection the stored token is removed and no new messages are received. Existing conversation history from Slack is retained in your account for continuity. To delete all Slack message data, delete your Orivio account via Settings → Account → Delete Account, or request deletion via support@orivio.ai.
3. Legal Basis for Processing
Contract
To provide services you subscribe to.
Consent
When you connect third-party services (e.g., Gmail, Google Calendar, Outlook, Microsoft Calendar, WhatsApp, Facebook Messenger, Instagram, Telegram, Twilio SMS, Stripe).
Legal Obligation
To comply with tax, accounting, and regulatory requirements.
Legitimate Interests
To improve services, maintain security, and prevent misuse.
4. Data Sharing and Disclosure
No Selling or Renting
We do not sell or rent your data.
Service Providers
Trusted third parties providing hosting, payment, or support services.
Business Transfers
As part of mergers, acquisitions, or restructuring.
Legal Authorities
When required to comply with laws or valid legal requests.
Sub-processors
We use trusted service providers (sub-processors) to operate Orivio. Key sub-processors include: Hetzner Online GmbH (infrastructure hosting, Germany), OpenAI LLC (AI processing, USA), Cohere Inc. (AI search-result ranking, Canada/USA), Stripe/PayPal (payment processing), Twilio Inc. (SMS delivery, USA), Resend (transactional and contact-form email, USA), and MaxMind, Inc. (IP geolocation database, USA). Each acts under contract and, where relevant, relies on approved transfer safeguards (such as the EU Standard Contractual Clauses with the UK Addendum) and security controls. A current list of sub-processors is available on request.
Other parties
When you connect Gmail or Google Calendar, Google remains an independent controller of its own services. Similarly, when you connect Outlook or Microsoft Calendar, Microsoft remains an independent controller of its own services. When you connect WhatsApp, Facebook Messenger, or Instagram, Meta remains an independent controller of its own platforms and services. When you connect Slack, Slack Technologies remains an independent controller of its own service. When you connect a CRM, your CRM provider (such as HubSpot or Salesforce) remains an independent controller of its own service. When you connect an online store, the store platform (such as WooCommerce, Shopify or Wix) likewise remains an independent controller of its own service. These are systems you choose to connect and continue to control; they are not sub-processors engaged by Orivio.
5. Data Retention
Email and Calendar Data
Retained only as long as needed to deliver services, then deleted or anonymised.
Live Chat and Knowledge Base Data
Chat messages and knowledge base articles are retained for as long as your account is active, then deleted or anonymised on account closure.
Billing Records
Retained for at least six years in line with UK tax law.
Technical Logs
Kept for 15–30 days for performance monitoring and security diagnostics.
6. Your Rights
Access
Access the personal data we hold about you.
Correction
Request correction of inaccurate or incomplete data.
Deletion
Delete your account and data directly from Orivio: Login, go to Settings → Account, and click "Delete Account". Type "delete my account" to confirm. This immediately removes your Orivio account, email tags, meeting data, and preferences. Your Google or Microsoft account and original email/calendar data remain untouched. We may retain certain data as required by law (e.g., billing records). For assistance, contact support@orivio.ai.
Restriction
Restrict or object to certain types of processing.
Portability
Request a copy of your data in portable format.
Consent Withdrawal
Withdraw consent where processing is based on consent. Requests can be made by contacting support@orivio.ai. Identity verification may be required.
7. Data Security
Technical Measures
Encryption in transit and at rest. Private network access only.
Access Controls
Multi-factor authentication (MFA) enforced for administrative access. Least-privilege access with periodic reviews of permissions and logs. Secrets stored securely.
Incident Response
Documented process to detect, investigate, and contain security incidents. Notification to affected users and regulators where legally required. Post-incident remediation and improvements to prevent recurrence.
8. International Transfers
Data Protection Safeguards
We host core services in the UK/EEA (e.g., EU-West). Where a provider processes personal data outside the UK/EEA, we use approved transfer safeguards (such as the EU Standard Contractual Clauses with the UK Addendum) and appropriate security measures.
9. Cookies & Local Storage
We use only essential cookies needed to run the service (for example, to keep you signed in and protect the service). We do not use analytics, advertising, or other non-essential cookies. Your browser may store limited settings (e.g., preferences) to improve your experience. You can clear cookies and storage in your browser, but this may sign you out. If we introduce non-essential cookies in the future, we will ask for your consent first.
10. Use of AI and Machine Learning Services
Purpose
Some features such as automated email drafting, tagging, calendar management, live chat AI responses, AI-assisted search, and knowledge base article generation rely on third-party AI services (e.g., OpenAI, Cohere). Submitted data is processed solely to generate drafts, suggestions, or classifications.
No Training on Your Data
We do not permit AI providers to use your email, calendar, or other personal data to train or improve their models. Your data is processed only for the immediate task and is not stored for training purposes.
Data Minimisation
We limit the amount of personal data sent to these services and, where possible, anonymise or redact sensitive details before processing.
11. ICO Registration
We will register with the UK Information Commissioner's Office (ICO) where required. Our ICO registration number will be added here once issued. You can check the public register at https://ico.org.uk/.
12. Changes to This Policy
Policy Updates
We may update this Privacy Policy to reflect changes in technology, regulation, or business practice. Updates will be posted on our website with a new effective date.
13. Contact Us
If you have any questions or concerns about this Privacy Policy or how we process your data, please contact us at:
Email: support@orivio.ai
Address: Suite RA01, 195-197 Wood Street, London, E17 3NU
If you are not satisfied with our response, you can contact us again, or you may lodge a complaint with the Information Commissioner's Office (ICO): https://ico.org.uk/