Privacy Policy
Effective date: September 10, 2026
Last updated: September 10, 2026
Version: 1.0
Introduction
This Privacy Policy explains how OrchcastAI, operating under the brand Orchcast.AI (“Orchcast.AI,” “we,” “us,” or “our”), collects, uses, discloses, retains, and protects personal information when you use orchcast.ai, the Orchcast.AI applications, Channel Relay, and related services (collectively, the “Services”).
Who We Are
The data controller or business responsible for your personal information is: OrchcastAI 437 Helmcken Street Vancouver, British Columbia V6B 2E6, Canada Privacy inquiries: [email protected] If a customer organization uses the Services to process personal information under its own direction, that customer is generally the controller or business and Orchcast.AI acts as its processor or service provider. In those cases, contact the customer organization first regarding its data practices or your rights
Scope
This Policy applies to personal information processed through the Services. It does not govern third-party websites, platforms, or services that have their own privacy policies, including Meta, Facebook, Instagram, Google, payment providers, hosting providers, or AI providers.
“Personal information” means information about an identifiable individual and includes “personal data,” “personal information,” and similar terms under applicable privacy laws. This Policy is intended to address Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”), substantially similar provincial private-sector laws, Québec’s private-sector privacy law, and applicable United States federal and state privacy laws. Legal rights and obligations vary by location and apply only when their statutory conditions are met.
For this Policy:
- “Controller” means the person or organization that determines why and how personal information is processed.
- “Processor” or “service provider” means a person or organization that processes personal information for a controller under instructions.
- “Customer Content” means prompts, files, text, images, audio, video, brand information, messages, connected-platform content, and other material submitted to or generated through the Services for a customer.
- “Sensitive personal information” includes information treated as sensitive under applicable law, such as account credentials, precise geolocation, government identifiers, financial-account credentials, health information, biometric identifiers used for identification, racial or ethnic origin, religious beliefs, sexual orientation, citizenship or immigration status, and contents of private communications where protected.
- “Sale,” “sharing,” and “targeted advertising” have the meanings assigned by the applicable U.S. state privacy law. A disclosure may qualify even when no money is exchanged.
This Policy does not apply to employment or applicant information governed by a separate workforce notice. It also does not convert Orchcast.AI into the controller of information that a customer processes under its own authority
2A. Our Privacy Commitments
Orchcast.AI will:
- remain accountable for personal information under its control and designate a Privacy Officer
- identify purposes before or when information is collected
- obtain meaningful consent where required and provide a lawful way to withdraw it
- limit collection to information reasonably necessary for disclosed purposes
- limit use, disclosure, and retention to authorized and lawful purposes
- take reasonable steps to maintain accuracy where information is used to make a decision about an individual
- apply safeguards proportionate to sensitivity and risk
- maintain transparent privacy practices
- provide access, correction, deletion, portability, objection, appeal, and complaint mechanisms where applicable and
- require service providers handling personal information to protect it and use it only for contracted purposes.
Information We Collect
Depending on how you use the Services, we may collect:
- Account and identity information: name, email address, account identifier, authentication information, organization, role, profile information, and account preferences.
- Workspace and team information: workspace membership, invitations, permissions, approval activity, assignments, and audit events.
- Content and brand information: text, documents, images, audio, video, brand guidelines, prompts, instructions, drafts, approvals, comments, and generated outputs you submit to or create through the Services.
- Connected-platform information: information made available through an integration you authorize, such as Facebook Page or Instagram professional-account identifiers, usernames, Page information, granted permissions, access tokens, posts, captions, media, comments, messages, engagement or insight data, publishing status, and related metadata. We only request and process information needed for enabled features and authorized permissions.
- Transaction information: subscription, plan, invoice, and payment status. Complete payment-card information is processed by Stripe or another disclosed payment processor and is not directly stored by OrchcastAI.
- Communications: support requests, feedback, survey responses, and other messages you send us.
- Device, usage, and log information: IP address, browser and device type, operating system, timestamps, referring URLs, pages or features used, diagnostic events, error reports, security events, and approximate location inferred from IP address.
- Cookies and similar technologies: session, preference, security, analytics, advertising, and attribution information. Advertising cookies or pixels may collect device identifiers, IP address, browser information, page activity, referring URLs, campaign interactions, and similar internet or network activity. Users can modify non-essential cookie and advertising preferences through the cookie-settings control made available on the website. See the Cookie Policy. This link and the associated consent controls must be publicly available and verified before this Policy is published.
We may receive information directly from you, your organization, connected services you authorize, service providers, and automatically from your use of the Services.
3A. Third-Party Sign-In and Connected Accounts
If you register, sign in, or connect an account through Google, Meta, Facebook, Instagram, or another supported provider, we receive only the information and permissions made available through the authorization screen and the provider’s settings. This may include your name, email address, provider-specific user identifier, profile image, Page or professional-account identifiers, authorized content, and permission scope. OrchcastAI does not receive your third-party password. You can withdraw access through OrchcastAI, where supported, or through the provider’s account settings.
3B. Information We Do Not Obtain Without Separate Disclosure
OrchcastAI does not use third-party visitor-identification or de-anonymization services to convert anonymous website traffic into named contact records unless that practice is first approved, added to this Policy and the Cookie Policy, and made subject to legally required notice and consent or opt-out controls. OrchcastAI does not purchase data-broker profiles for undisclosed use. If either practice is introduced, this Policy must be updated before collection begins.
We do not intentionally collect government identifiers, precise geolocation, health information, biometric templates, financial-account credentials, or other sensitive personal information unless a specific feature clearly requests it, collection is lawful, and any required consent has been obtained. Users must not upload such information unless Orchcast.AI has expressly authorized that use in writing.
If you provide personal information about another person, you represent that you have lawful authority to provide it and to instruct us to process it. Customers are responsible for providing required notices and obtaining required permissions for Customer Content.
How We Use Information
We use personal information to:
- provide, operate, secure, support, and improve the Services
- create and administer accounts, workspaces, roles, permissions, and subscriptions
- process content and instructions, generate outputs, and provide brand, workflow, analytics, approval, and publishing features
- connect to authorized third-party accounts and perform actions you request, such as retrieving permitted data or publishing approved content
- authenticate users, prevent fraud and abuse, troubleshoot failures, maintain audit records, and enforce our Terms
- communicate about service operations, security, support, billing, and product updates
- understand service performance and develop new features
- comply with law and protect the rights, safety, and integrity of users, Orchcast.AI, and others
- carry out other purposes disclosed when information is collected or with your consent.
Where applicable, our legal bases include performing a contract, taking steps requested before entering a contract, consent, compliance with legal obligations, and legitimate interests such as securing and improving the Services. Where we rely on legitimate interests, we consider and balance those interests against your rights.
Where Canadian law requires consent, we seek consent appropriate to the sensitivity of the information and the reasonable expectations of the individual. You may withdraw consent subject to legal or contractual restrictions and reasonable notice, but withdrawal may prevent us from providing features that require the information.
AI Processing
The Services may send prompts, uploaded content, and relevant context to AI or media- processing providers to deliver features you request. Outputs may be inaccurate, incomplete, or unsuitable and should be reviewed by a person before use or publication.
OrchcastAI does not use Customer Content to train generalized OrchcastAI models. OrchcastAI does not authorize its AI service providers to use Customer Content to train generalized provider models. Customer Content is processed only to provide, secure, support, and maintain the features requested by the customer, subject to the provider terms and configurations approved through OrchcastAI’s vendor-review process. This commitment does not prevent customer- directed fine-tuning or training performed under a separate written agreement and explicit customer instructions.
Do not submit sensitive personal information, confidential information, or third-party content unless you are authorized to do so and the feature is appropriate for that information.
Orchcast.AI will not use automated processing to make a legally binding or similarly significant decision about an individual unless that use is clearly disclosed, lawfully authorized, and accompanied by safeguards required by applicable law. Customers may not use the Services for employment, housing, credit, insurance, healthcare, education admissions, law enforcement, immigration, legal services, or other high-impact decisions without a separate written agreement expressly authorizing the use and defining required safeguards.
Meta, Facebook, and Instagram Integrations
When you connect a Facebook Page or Instagram professional account, Meta provides information based on the permissions you approve. Orchcast.AI uses that information only to provide the connected features you request, maintain the connection, display permitted account or content information, publish or manage content when authorized, retrieve permitted engagement or insight data, support the integration, and protect against misuse.
Orchcast.AI does not ask for or store your Facebook or Instagram password. You can remove the integration through the Services, through your Meta account settings, or by contacting [email protected]. Removing access stops future collection through that connection, but information already stored may be retained for the limited periods and purposes described below.
Use of information received from Meta is also subject to applicable Meta platform terms and developer policies. We do not sell Meta Platform Data, use it for surveillance, attempt to derive sensitive characteristics, or combine it with unrelated data for undisclosed purposes. We do not transfer Meta Platform Data to data brokers. Access tokens and permissions are restricted to authorized use, stored using safeguards appropriate to their sensitivity, and revoked or deleted when no longer required, subject to documented security and legal exceptions.
How We Disclose Information
We may disclose personal information:
- to infrastructure, hosting, database, storage, security, analytics, customer-support, communications, payment, and AI or media-processing providers acting for us
- to connected platforms when you direct us to publish, retrieve, synchronize, or otherwise exchange information
- to your organization’s authorized workspace owners, administrators, members, and reviewers according to configured permissions
- in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to appropriate safeguards
- when required by law or reasonably necessary to protect rights, safety, security, and integrity
- with your direction or consent.
We may also disclose limited information to affiliates under common control that are bound to protect it consistently with this Policy; to professional advisers such as lawyers, auditors, insurers, and accountants under duties of confidentiality; or to another user when you intentionally share content in a collaborative workspace or public area. Content designated public or published to a connected platform may be viewed, copied, or redistributed by others according to that platform’s settings and policies.
We may disclose information in response to a subpoena, court order, warrant, regulatory demand, or other valid legal process; to establish, exercise, or defend legal claims; to investigate fraud, abuse, security threats, or violations of these Terms; or to protect the rights, property, safety, and integrity of OrchcastAI, customers, users, platforms, or the public. We assess requests for legal validity and scope and disclose only information reasonably necessary, unless prohibited from doing so.
If OrchcastAI is involved in financing, due diligence, restructuring, merger, acquisition, insolvency, or sale of all or part of its business or assets, information may be reviewed or transferred subject to confidentiality and appropriate safeguards. Where required, we will notify affected persons before their personal information becomes subject to a materially different privacy policy.
OrchcastAI does not sell personal information for money. Because OrchcastAI uses advertising cookies or pixels, disclosure of online identifiers and internet or network activity to advertising or measurement partners may be considered “sharing,” targeted advertising, or a “sale” under certain U.S. state privacy laws even when no money is exchanged. Where those laws apply, users may opt out through the website’s cookie-settings control and any legally recognized universal opt-out mechanism. OrchcastAI will not use sensitive personal information for targeted advertising.
We do not permit service providers to use personal information for purposes unrelated to providing their contracted services to us, subject to their applicable terms and our agreements.
We remain accountable for personal information transferred to service providers for processing. We assess providers based on risk and use contractual, technical, and organizational measures intended to require confidentiality, security, limited processing, incident notification, deletion or return, and assistance with lawful privacy requests. The current material providers will be identified on the Subprocessor List. This list must be publicly available, complete, and verified against production before this Policy is published.
7A. Material Service Providers and Subprocessors
Depending on the Services and optional features a customer enables, OrchcastAI may use
- Google Cloud, Cloudflare, and Vercel for hosting, networking, delivery, security, application infrastructure, storage, or related technical services
- OpenAI, Anthropic, Cohere, and Google Gemini for optional AI functions that process prompts, Customer Content, relevant context, and requested outputs
- Stripe for subscription billing, payment processing, invoicing, and payment-related fraud prevention
- Amplitude for product analytics and service-usage measurement
- SendGrid for transactional email, including account verification, password resets, billing notices, and service communications
- Google Workspace for company email, collaboration, support, and internal business operations. OrchcastAI does not directly store complete payment-card information. Service providers may process information in Canada, the United States, or other jurisdictions where they or their approved subprocessors operate. The provider used for a particular transaction depends on the enabled feature and production configuration. OrchcastAI does not authorize AI providers to use Customer Content to train generalized provider models.
Before publication, engineering and legal owners must verify this list against production infrastructure, contracts, data-flow records, and provider settings. OrchcastAI will maintain the public subprocessor list and update it when a provider or its processing purpose materially changes. Where required by contract or law, affected customers will receive advance notice and an opportunity to object to a new subprocessor on reasonable data-protection grounds.
We may create aggregated or de-identified information. We will not attempt to re-identify information that is maintained as de-identified, except to test whether de-identification controls are effective or as otherwise permitted by law, and we require recipients to observe comparable restrictions.
Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including to provide the Services, maintain security and audit records, comply with law, resolve disputes, and enforce agreements.
Unless a longer period is required or permitted by law
- Active accounts: account information and Customer Content are retained while the subscription remains active.
- Cancelled or closed accounts: Customer Content remains accessible until the paid subscription period ends. After account closure, covered account information and Customer Content are scheduled for deletion from active systems within 30 days.
- Authentication tokens: access tokens expire according to their configured security period. Refresh tokens remain valid only until their applicable expiration, logout, revocation, or account termination event.
- Connected-platform tokens: OAuth tokens are encrypted and retained only while the applicable integration remains connected. They are deleted or revoked when the customer disconnects the integration or closes the account.
- Application and operational logs: operational logs are retained for up to 90 days.
- Security and audit logs: security and audit logs may be retained for up to 12 months for fraud prevention, incident investigation, access accountability, and compliance.
- Backups: encrypted backups are retained for up to 35 days and are then automatically overwritten or deleted through the applicable backup lifecycle.
- Billing and legal records: transaction, invoice, tax, and associated legal records may be retained for up to seven years where required for tax, accounting, dispute resolution, or legal compliance.
- Legal exceptions: relevant information may be retained longer when required by law, a valid litigation hold, a fraud or security investigation, an unresolved billing dispute, or the establishment, exercise, or defence of legal claims.
Deletion from active systems does not necessarily remove information immediately from encrypted backups. Backup copies remain isolated from routine use and expire within the backup period stated above unless preservation is legally required. We may retain de-identified information that cannot reasonably identify an individual.
Retention periods are established through a written retention schedule based on purpose, sensitivity, legal requirements, limitation periods, security needs, customer instructions, and backup architecture. When retention ends, information is securely deleted, destroyed, or irreversibly de-identified. A customer’s deletion instruction does not require us to delete information that we must preserve by law, to establish or defend legal claims, to investigate fraud or security incidents, or to protect the Services, but access to retained information will be limited to the applicable purpose.
Your Choices and Privacy Rights
Depending on where you live, you may have rights to access, know about, correct, delete, restrict, object to, or receive a portable copy of personal information, and to withdraw consent. You may also have rights to opt out of sale, sharing, targeted advertising, or certain profiling, and to appeal a denied request. We will not discriminate against you for exercising applicable rights.
To submit a request, email [email protected] with the subject “Privacy Request.” If available, you may also use the privacy or account settings within the Services. We may verify your identity and authority before completing a request. Authorized agents may submit requests where permitted by law, subject to verification.
If we process information for a customer organization, we may direct your request to that organization or assist it in responding. You may also complain to your local data-protection authority.
Where applicable law requires it, users may opt out of sale, sharing, or targeted advertising through the website’s cookie-settings control or by sending a valid Global Privacy Control signal. OrchcastAI must maintain a conspicuous “Your Privacy Choices” or “Do Not Sell or Share My Personal Information” link wherever legally required. Requests may also be submitted to [email protected]
9A. Canadian Residents
Subject to applicable law, Canadian residents may request access to personal information under our control, an account of its use and disclosure, and correction of inaccurate or incomplete information. They may challenge our compliance, withdraw consent where processing depends on consent, and complain to the Office of the Privacy Commissioner of Canada or the applicable provincial regulator. We will respond within the period required by the law that applies to the request and provide reasons if access is lawfully refused.
Residents of Québec may also have rights concerning data portability, cessation of dissemination or de-indexation, and information about automated decisions, where those rights apply. Orchcast.AI will conduct privacy impact assessments where required, including before certain information-system projects or transfers of personal information outside Québec.
9B. United States Residents
Subject to eligibility and applicable state law, U.S. residents may have rights to:
- confirm whether we process their personal information and access it
- obtain a portable copy of covered information
- correct inaccuracies
- delete covered personal information
- know the categories or specific pieces collected, sources, purposes, and categories of recipients
- opt out of sale, sharing, targeted advertising, or qualifying profiling
- limit certain uses or disclosures of sensitive personal information
- withdraw consent where consent is the applicable basis
- use an authorized agent
- appeal a refusal to act on a request.
We will not discriminate against a person for exercising an applicable privacy right. We will respond within applicable statutory periods and explain any extension or denial. An appeal may be submitted to [email protected] with the subject “Privacy Appeal.” If an appeal is denied, we will provide any regulator-contact information required by applicable law
9C. California Notice at Collection
The categories described in Section 3 are the categories we may collect. We collect them for the business and commercial purposes in Section 4 and disclose them to the recipient categories in Section 7. The actual categories collected depend on the features used. We do not collect additional categories or use information for materially different, unrelated purposes without providing notice and obtaining consent where required.
For the preceding 12 months, Orchcast.AI’s disclosures concerning collection, business purposes, recipients, sale, sharing, and sensitive personal information must match the completed Factual Schedule below. No statement that information is not sold, not shared, or not used for targeted advertising may be published until tracking technologies, contracts, and data flows have been audited.
Subject to verification against production systems, the following table describes California categories OrchcastAI may collect and process. “May collect” does not mean every example in a statutory category is collected.
| California category | OrchcastAI examples | Collection status | Principal purposes and recipients |
|---|---|---|---|
| Identifiers | Name, business email, account ID, IP address, device or cookie identifier, connected-platform ID | Collected | Accounts, authentication, security, integrations, analytics, advertising; disclosed to relevant service providers and authorized platforms |
| Customer-record information | Business contact and billing contact information; subscription and payment status | Collected in limited form | Contract administration, support, billing and compliance; disclosed to Stripe and relevant operational providers |
| Protected classifications | Characteristics protected by California or federal law | Not intentionally collected | Users must not submit this information unless expressly authorized for a lawful feature |
| Commercial information | Plan, subscription, transaction, credit usage and service history | Collected | Service delivery, billing, support, analytics and fraud prevention |
| Biometric information | Biometric identifiers or templates used to identify a person | Not intentionally collected | Uploaded images, audio or video are Customer Content and are not treated as biometric identifiers unless a separately disclosed feature performs identification |
| Internet or network activity | Website, product, advertising, interaction, diagnostic and log activity | Collected | Security, operation, analytics, attribution and advertising |
| Geolocation | Approximate location inferred from IP address | Collected | Security, fraud prevention, localization and analytics; precise geolocation is not intentionally collected |
| Sensory information | Images, audio and video submitted as Customer Content | Collected when submitted | Customer-directed content processing and generation |
| Professional information | Company, role, team membership and business profile information | Collected | B2B accounts, permissions, support and communications |
| Education information | Non-public education records | Not intentionally collected | Prohibited unless expressly authorized under a separate written agreement |
| Inferences | Brand, content, preference, usage or performance insights | May be generated | Requested AI, personalization, analytics and product features; not used to infer legally protected or sensitive traits |
| Sensitive personal information | Credentials, precise geolocation, government IDs, health or biometric identifiers and other legally sensitive data | Not intentionally collected, except account authentication information required for security | Authentication and security only; users must not upload other sensitive information unless expressly authorized |
Based on the confirmed use of advertising cookies and pixels, OrchcastAI may disclose identifiers, commercial information, and internet or network activity to advertising or measurement providers in a manner that may constitute sharing, targeted advertising, or a sale under some U.S. state laws. OrchcastAI does not sell personal information for money. Users may exercise applicable opt-out rights through the cookie-settings control, a legally recognized universal opt-out signal, or [email protected].
The final published table must identify the categories actually collected, disclosed for a business purpose, sold, or shared during the preceding 12 months after a documented cookie, SDK, advertising-contract, and data-flow audit.
9D. Requests and Verification
Requests may be submitted through account controls, where available, or by emailing [email protected].
We will collect only information reasonably necessary to verify identity, authority, residency, and the scope of a request. Verification information will be used only for verification and fraud prevention. Authorized agents must provide evidence of authority where law permits us to request it. If we cannot verify a request, we will explain the reason and any available next step.
The request should identify the account email, the right being exercised, the applicable jurisdiction, and enough detail to locate the relevant information. Do not send passwords, payment-card numbers, government identifiers, or access tokens. Where permitted, we may request confirmation through the account or another proportionate verification method.
For verified California requests, we will generally respond within 45 days and may extend once by an additional 45 days when reasonably necessary after providing notice. For Canadian access requests, we will respond within the period required by the applicable federal or provincial law. We ordinarily provide covered responses without charge, but may charge or refuse repetitive, excessive, manifestly unfounded, fraudulent, or legally exempt requests where the applicable law permits.
If a request is denied in whole or in part, we will explain the applicable reason unless prohibited by law and provide appeal or regulator-escalation information when required. Data-portability responses will use a reasonably accessible and usable format where required.
9E. Cookies, Targeted Advertising, and Browser Signals
OrchcastAI uses cookies and pixels for essential operations, preferences, analytics, attribution, and advertising. The cookie interface allows users to modify non-essential cookie categories. Non-essential cookies will not be activated where prior opt-in consent is legally required. Where applicable law requires recognition of Global Privacy Control or another approved universal opt- out signal, we will treat a valid signal as a request to opt out for the browser or device sending it. “Do Not Track” signals are handled only where legally required because no uniform industry standard otherwise applies.
Cookie and tracking categories include:
- Strictly necessary cookies: session management, authentication, security, fraud prevention, load balancing, and requested functionality. These cannot generally be disabled through the preference tool because the requested service would not function without them.
- Preference cookies: language, interface settings, consent status, and other choices. These may persist for the period disclosed in the Cookie Policy.
- Analytics and performance cookies: pseudonymous or identifiable usage, navigation, feature, diagnostic, and performance information used to understand and improve the Services.
- Advertising and attribution cookies or pixels: campaign interactions, referrals, conversions, and online activity used to measure advertising or provide interest-based advertising where permitted.
Cookie choices are generally specific to the browser, device, and domain. Clearing cookies, changing browsers, or using another device may require the user to set preferences again. Withdrawing consent does not affect processing that was lawful before withdrawal.
Before publication, OrchcastAI must complete and maintain an inventory identifying each cookie, pixel, SDK, provider, purpose, data category, duration, and recipient. The live cookie interface must actually prevent or disable rejected non-essential technologies; merely hiding personalized advertising is not sufficient.
9F. Marketing Communications
We send marketing communications only with the consent or other lawful authority required by applicable law. Canadian commercial electronic messages will include required sender identification and a working unsubscribe mechanism. U.S. commercial email will include legally required identification and opt-out information. Unsubscribe requests will be implemented within the applicable statutory period. Service, security, billing, and transactional notices are not marketing messages, although you may control them where the law permits.
Data Deletion
You may request deletion by:
- using the account-deletion or privacy controls in the Services, if available
- disconnecting Facebook or Instagram through the Services or your Meta settings
- emailing [email protected] with the subject “Data Deletion Request.”
For Meta-related deletion requests, the Services use the designated Meta data-deletion callback. After a valid request, we will delete or de-identify covered information unless retention is required or permitted for security, fraud prevention, legal compliance, dispute resolution, or another lawful exception. We will provide confirmation or status information as required.
Before production publication, Orchcast.AI must verify that the Meta callback authenticates signed requests, deletes all covered records and derived data, revokes or invalidates tokens, produces a confirmation code and status mechanism where required, records completion without retaining deleted content, and handles retries without duplicating or bypassing deletion.
Security
We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, encryption in transit, monitoring, and security review. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your credentials and promptly reporting suspected unauthorized access.
Our security program is designed to include least-privilege access, workforce confidentiality obligations, credential and secret management, vulnerability and dependency management, secure development practices, logging and monitoring, tested backup and recovery procedures, vendor oversight, incident response, and periodic review. These descriptions are commitments only to the extent implemented and documented before publication; unsupported security claims must be removed or corrected.
11A. Privacy and Security Incidents
We maintain procedures to investigate, contain, remediate, document, and learn from suspected privacy or security incidents. We will notify affected individuals, customers, regulators, and other parties when and within the time required by applicable law or contract. Under applicable Canadian requirements, we will assess the risk of significant harm, maintain required breach records, and report qualifying breaches. If Québec law applies, we will maintain the required confidentiality-incident register and notify the Commission d’accès à l’information and affected persons when there is a risk of serious injury.
International Transfers
We and our service providers may process information in countries other than where you live. Where required, we use recognized safeguards for cross-border transfers, such as adequacy decisions, standard contractual clauses, or other lawful mechanisms. [CONFIRM PRIMARY HOSTING AND PROCESSING COUNTRIES AND EEA/UK TRANSFER MECHANISM.]
Personal information transferred outside Canada may be accessible to courts, law-enforcement agencies, or national-security authorities under the laws of the destination. Orchcast.AI remains accountable for information under its control and uses contractual or other measures intended to provide a level of protection comparable to applicable Canadian requirements.
Children
The Services are intended for business users and are not directed to children under 18. We do not knowingly collect personal information from children. If you believe a child has provided information, contact [email protected].
OrchcastAI does not knowingly sell or share the personal information of anyone under 16. Because the Services are business-only and restricted to adults, OrchcastAI does not offer an opt-in process for minors
13A. External Links and Third-Party Services
The Services may contain links to websites or services not operated by OrchcastAI. Their privacy practices are governed by their own notices. A link or integration does not mean OrchcastAI controls or endorses the third party’s privacy practices. Review the applicable third- party notice before providing information
Changes to This Policy
We may update this Policy to reflect changes to the Services, law, or our practices. We will post the updated version, revise the “Last updated” date, and provide additional notice when required. We will retain prior versions as required by applicable platform rules or law.
Contact
Questions, complaints, or privacy requests may be sent to:
OrchcastAI 437 Helmcken Street Vancouver, British Columbia V6B 2E6, Canada Email: [email protected] Data Protection Officer or EU/UK representative, if applicable: [NAME AND CONTACT OR “NOT APPLICABLE” AFTER LEGAL REVIEW]
Factual Schedule — Must Be Completed and Approved Before Publication
The Privacy Officer, engineering owner, security owner, and legal reviewer must jointly confirm:
- the legal registration record supporting the confirmed name OrchcastAI, the trade name Orchcast.AI, the Vancouver address above, and every jurisdiction where customers or website users are located
- every production domain, application, mobile app, and service covered
- every category and source of personal information actually collected
- each purpose and lawful basis, including any purpose requiring express consent
- production and contract evidence confirming Google Cloud, Cloudflare, Vercel, OpenAI, Anthropic, Cohere, Google Gemini, Stripe, Amplitude, SendGrid, and Google Workspace; every additional provider or subprocessor; each processing location and purpose; and applicable contract safeguards
- all Meta permissions, fields, tokens, messages, comments, insights, media, and derived data processed
- implementation and vendor-contract evidence supporting the confirmed commitment that Customer Content is not used to train generalized models
- every cookie, pixel, SDK, analytics tool, advertising tool, duration, recipient, consent state, and universal opt-out signal response
- which advertising disclosures constitute sale, sharing, targeted advertising, or profiling under each applicable U.S. state law and whether the live opt-out works
- production evidence that the stated retention schedule is enforced: 30-day active-system deletion after account closure, 90-day operational logs, 12-month security and audit logs, 35-day encrypted backups, up to seven years for qualifying billing and legal records, and prompt revocation or deletion of disconnected-platform tokens
- implemented security controls and incident-response contacts
- request-verification, authorized-agent, appeal, and regulator-escalation procedures
- age controls and whether any child-directed use is possible
- CASL and U.S. marketing consent, identification, recordkeeping, and unsubscribe operations;
- whether French-language notices, Québec assessments, an EU/UK representative, a DPO, a cookie banner, or supplemental state notices are required
- whether any third-party sign-in provider returns profile images, contact lists, activities, or other optional fields, and whether each field is necessary
- whether any visitor-identification, intent-data, de-anonymization, data-broker, remarketing, or cross-site tracking service is active
- the California categories actually collected, disclosed, sold, or shared during the preceding 12 months, supported by production and contract evidence.