OrbitumAIOrbitumAiBook a call

Legal

Privacy & Data Handling Policy

Effective date: August 6, 2026

Data controller / operator: Brewongo.ai LLC, a Texas limited liability company doing business as “OrbitumAI” (“OrbitumAI,” “we,” “us,” or “our”)

This policy explains how OrbitumAI collects, uses, shares, protects, and retains information — both the personal information of website visitors and prospects, and the proprietary data our clients entrust to us during engagements. It works together with our Cookies Policy, Terms & Conditions, and AI Safety & Governance Policy.

1. Information we collect

We collect information in three broad ways:

  • Information you give us — such as your name, business email, company, role, and message when you contact us, request a proposal, or subscribe to updates.
  • Client engagement data — the documents, datasets, credentials, and materials a client provides so we can perform the Services. This may include personal data belonging to the client’s own customers or staff, for which the client is the controller and OrbitumAI acts as a processor/service provider.
  • Automatically collected data — device, browser, and usage information gathered through cookies and similar technologies as described in our Cookies Policy.

2. How we use information

We use information to provide and improve our Services; respond to inquiries and deliver proposals; operate, secure, and analyze our website; perform contracts and process payments; and comply with legal obligations. We process client engagement data only to perform the Services and on the client’s documented instructions, or as required by law.

3. No training of third-party models on client data

Our commitment: We do not use a client’s proprietary or confidential data to train, fine-tune, or otherwise improve any public, shared, or foundational third-party AI model for the benefit of anyone other than that client.

When we use Third-Party AI Services (such as those from OpenAI, Anthropic, Google, Microsoft, or Amazon Web Services) to process client data, we configure them, wherever the provider offers the option, so that client inputs and outputs are not used to train the provider’s models, and we prefer enterprise or API tiers that contractually exclude such training. Any client-specific model tuning we perform is done for that client and kept segregated from other clients. We may use aggregated, de-identified information that cannot reasonably be linked to a client or individual to improve our own methods, consistent with our Terms & Conditions.

4. Subprocessors and infrastructure vendors

We engage trusted third parties (“subprocessors”) to help deliver the Services, host data, and operate our business. We require each to be bound by written obligations of confidentiality and data protection no less protective than this policy, and we remain responsible for their handling of data. Our current subprocessors include the categories below. This list may be updated as our delivery network and tooling evolve; material changes will be reflected here.

Subprocessor / categoryRoleLocation
Tailored AI (Entropy AI Pvt. Ltd.)Engineering & delivery partner (builds and supports Deliverables under OrbitumAI’s direction)India
Additional authorized delivery partnersEngineering, delivery, and support, engaged from time to time under equivalent obligationsVarious
Cloud infrastructure providers (e.g., Amazon Web Services, Microsoft Azure, Google Cloud)Hosting, storage, and computeUnited States and other regions, per configuration
Third-Party AI Service providers (e.g., OpenAI, Anthropic)AI model inference used to build and run DeliverablesUnited States / provider regions
Business & operations tools (e.g., email, analytics, scheduling, payment, CRM)Website operation, communications, and billingUnited States / provider regions

Where an engagement requires it, we can provide a client-specific, up-to-date subprocessor list and agree in an SOW or data-processing addendum to notify the client before adding a new subprocessor that processes its data.

5. Data retention and deletion

We keep information only as long as necessary for the purposes described in this policy or as required by law. For client engagement data, unless a Statement of Work or applicable law specifies otherwise:

  • We retain client engagement data for the duration of the engagement and for a limited wind-down period after termination.
  • We delete or return client engagement data within thirty (30) to ninety (90) days after contract termination, on the timeline agreed in the SOW, unless the client requests earlier deletion or a longer period is legally required.
  • Backups and archival copies are purged on our routine backup-rotation cycle after the primary deletion.
  • Certain records (such as invoices and contracts) may be retained longer to meet tax, accounting, and legal obligations.

On written request, we will confirm deletion. De-identified or aggregated data that can no longer be linked to a client or individual may be retained.

6. International data transfers

OrbitumAI is based in the United States and works with delivery partners and vendors in other countries, including our engineering partner in India. As a result, information may be transferred to, stored in, and processed in countries other than the one in which it was collected. Where required, we implement appropriate safeguards for cross-border transfers (such as standard contractual clauses or equivalent mechanisms) and require recipients to protect the data consistently with this policy.

7. Security measures

We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, alteration, and loss. Depending on the engagement, these may include encryption in transit and at rest, access controls and least-privilege permissions, credential and secrets management, network protections, logging and monitoring, and vendor due diligence. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; we work to promptly address vulnerabilities we identify.

8. Your privacy rights

Depending on where you live, you may have rights over your personal information — including the right to access, correct, delete, or receive a copy of it; to opt out of certain sharing or targeted advertising; and to not be discriminated against for exercising these rights. Residents of certain U.S. states (such as under the Texas Data Privacy and Security Act and the California Consumer Privacy Act) and individuals in the EU/UK (under the GDPR) have specific rights.

For personal data we process on behalf of a client, please direct requests to that client (the controller); we will assist them in responding. To exercise rights over information OrbitumAI controls, contact us at privacy@orbitumai.com. We will verify your request and respond within the timeframe required by applicable law. You may also have the right to lodge a complaint with your local data-protection authority.

9. Breach notification

If we become aware of a personal-data breach affecting information we control or process, we will investigate promptly, take steps to contain and remediate it, and notify affected clients and, where required, individuals and regulators, without undue delay and consistent with applicable law and our contractual commitments.

10. Children’s privacy

Our website and Services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it.

11. Changes to this policy

We may update this policy to reflect changes in our practices, technology, or the law. Material changes will be posted here with an updated “Effective date,” and, where appropriate, we will provide additional notice.

12. Contact us

For privacy questions or requests, contact our privacy team at privacy@orbitumai.com, or by mail to Brewongo.ai LLC, McKinney, Texas, USA.