Privacy Policy
Effective date: 21 August 2026 · Last updated: 19 September 2026
1. Who we are
This Privacy Policy explains how Orgs AI Ltd ("Orgs AI," "we," "us," or "our"), a company registered in England and Wales under company number 17410509 with its registered office at 008 Westbourne Studios, 242 Acklam Road, London W10 5JJ, collects, uses, and protects information in connection with the Orgs AI platform, including the OrgsOS coordination substrate, our website at orgs.ai, our dashboards, and related services (collectively, the "Service").
If you have questions, contact us at privacy@orgs.ai.
Change of controller.Before 21 August 2026, personal data processed in operating the Service was controlled by Ramsey Sami Ajram, the platform's founder, in his personal capacity. Under a deed dated 21 August 2026, Mr Ajram transferred the platform's business to Orgs AI Ltd, and agreed to transfer to it the personal data processed in operating the Service together with the records of processing relating to that data. From that date, Orgs AI Ltd is the controller, and this notice is issued in its name.
2. Scope and our role
Orgs AI is a platform for coordinating AI and human work. Because of how the Service operates, we handle data in two distinct roles:
- As a controller. For information about your account, billing, our website, and our own operational logging, we decide why and how the data is processed. This policy governs that data.
- As a processor.When you operate an Org on the Service, the Org processes content and records you and your end users supply ("Customer Data"). For most Customer Data you are the controller, and we act on your instructions in relation to it. Our terms of service, which we ask every customer to accept before they use the platform, and this notice are the written record of that relationship today. We are putting a written data processing agreement in place with each customer to set out in full the processor terms that article 28 of the UK GDPR requires. If your customer agreement conflicts with this notice about Customer Data, the customer agreement controls.
This distinction matters: if you are an end user whose data was entered into an Org by one of our customers, that customer, not Orgs AI, is responsible for how your data is used, and you should direct privacy requests to them.
3. Information we collect
- Account and identity data. Name, email, organization name, role, authentication identifiers, and session data. Authentication and user management are handled through our identity provider, Clerk.
- Billing data. Plan, transaction history, and payment metadata. Card details are handled by our payment processor, Stripe; we do not store full card numbers.
- Configuration and specification data. The Orgs, Operators, Agents, Playbooks, Workflows, DecisionSpecs, and other primitives you define, including their settings and decision-authority rules.
- Connector data. When you link a third-party service (for example GitHub, Slack, Telegram, Google Ads, Google Calendar, Meta, Microsoft Ads, LinkedIn, Reddit, X, Stripe, Perplexity, SendGrid, or a CMS such as Ghost), we access data within the scopes you grant. We store references to your credentials in an encrypted secrets vault, not the credentials themselves in plaintext specifications, and we rotate and expire them according to defined policies.
- Customer Data and artifacts. Content your Org processes or produces: code, documents, marketing and campaign content, customer and lead records, reports, and similar artifacts. The nature of this data is determined by you.
- Operational memory. The Service maintains memory to coordinate work, including episodic records (events and outcomes), semantic facts, and procedural learnings. This is held in our own stores (our database). Memory may contain Customer Data.
- Audit and decision records. Each significant action produces an audit record (who acted, what was done, when, the outcome, and which governance policies were evaluated) and an associated decision trace. These support security, accountability, and explainability.
- Usage and device data. Log data, IP address, browser and device information, and product interaction events, collected through standard server-side logging. We do not currently use third-party product-analytics tools; this data is collected only through our own application and infrastructure logs.
4. How we use information
We use information to:
- provide, operate, and maintain the Service and execute the Orgs you configure;
- authenticate users and enforce decision-authority and security policies;
- coordinate work between AI Operators and humans, including via the memory and audit systems;
- route requests to AI model providers to generate Operator outputs (see Section 5);
- communicate with you about your account, support, and service changes;
- bill for the Service and prevent fraud and abuse;
- maintain security, investigate incidents, and meet legal obligations; and
- improve the Service. We do not use Customer Data to train foundation models, and our model providers are contractually prohibited from training on data we send through their APIs, except where you explicitly opt in.
Where required by law, we rely on a lawful basis for each purpose (for example, performance of a contract, legitimate interests, consent, or legal obligation).
5. AI model processing and sub-processors
Operator outputs are generated by large language models. To produce a response, relevant context, which may include Customer Data, is sent to one or more AI model providers. We send this data directly to the providers we use. The Service also contains a model-comparison facility that would route onboarding interview turns through OpenRouter, a third-party aggregation layer. That facility is switched off in production: it refuses every request when the Service is running in production mode, so no live traffic reaches OpenRouter. Our primary inference provider is Anthropic (Claude models), with OpenAI used as a secondary or fallback provider.
These providers act as our sub-processors and are contractually limited to processing data to deliver the requested output, on terms that prohibit training on our data. We engage other sub-processors for hosting, storage, memory, authentication, payments, and communications, including: Clerk (authentication), Stripe (payments), Neon (database hosting), Vercel (application hosting and scheduled jobs), Railway (backend API and worker hosting, and the Redis instance that holds abuse-prevention counters derived from IP addresses), SendGrid and Resend (email), Anthropic and OpenAI (AI inference), Brave Search (web search), Jina AI (web page retrieval), and ip-api.com (IP geolocation).
Onboarding and business research. When you go through onboarding, the Service researches you and your business so it can pre-fill your setup. To do that it sends search queries to the Brave Search API. Those queries can contain personal data you have given us, including your name, your business name, and your city. It retrieves publicly available web pages through Jina Reader, which receives the address of each page requested, including any business URL you supply. It also sends the IP address your request arrives from to ip-api.com, which returns an approximate city so that the search results are local to you. Each of these three providers handles that data under its own published terms, which are not the same terms our inference providers are held to.
In addition, when you connect a third-party service to an Org, that service is engaged as a sub-processor at your direction for the data your Org sends it (see Section 6). The list above is the current list of sub-processors we engage. Before we add a new sub-processor that will handle Customer Data, we will tell customers at least 30 days beforehand, by email to the account contact and by notice in the dashboard. If you object within that period, write to privacy@orgs.ai and we will look for a reasonable alternative. If we cannot find one, you may end your subscription for the affected part of the Service without further charge.
6. Connectors and third-party services
When you connect a third-party service, that service's own privacy terms govern the data held there. We access it only within the scopes you authorize and only to perform the actions your Org is configured to take. For advertising connectors specifically (for example Google Ads, Meta, and Microsoft Ads), campaigns are created in a paused state and require explicit human approval before any spend is enabled. For research connectors (for example Perplexity), the queries your Org runs are sent to that provider and processed under its terms. For messaging connectors (for example Telegram), the text of the messages your Org sends or asks you to approve, together with the identifier of the chat they are delivered to, is sent to that provider's servers. You can revoke a connector's access at any time through the dashboard or the third party, which stops future access; data already processed may persist in memory and audit records subject to Section 7.
7. Data retention
We retain data for as long as needed to provide the Service and meet legal, accounting, and security obligations. Default retention for operational memory reflects the platform's design and is configurable by you within these limits:
| Data type | Default retention | Maximum |
|---|---|---|
| Episodic memory (events/outcomes) | 90 days | 365 days |
| Semantic memory (facts) | Indefinite (until deleted) | - |
| Procedural memory (learnings) | Indefinite; gated and reversible | - |
| Audit and decision records | 365 days | - |
| Account and billing records | Account duration + 6 years | - |
Sensitive categories flagged as protected topics (for example personal identifiers, credentials, and financial data) are masked on access, and that access is itself audited. On account termination or a valid deletion request, we delete or anonymize data within 30 days, except where retention is legally required.
8. How we share information
We do not sell personal information. We share it only:
- with sub-processors and service providers under contract (Section 5);
- with third-party services you connect (Section 6);
- in connection with a merger, acquisition, or asset sale, subject to this policy;
- to comply with law or a valid legal request, or to protect rights, safety, and security; and
- with your consent or at your direction.
9. International transfers
We are based in the United Kingdom, and our primary database is hosted in the United Kingdom (London). Some processing and compute takes place outside the UK, including in the United States and the European Economic Area, through our hosting providers. Where data is transferred across borders, we rely on appropriate safeguards such as the UK International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses), the EU Standard Contractual Clauses, and adequacy decisions where available.
10. Security
We protect data with measures including: storing credentials as encrypted vault references rather than plaintext, with rotation and expiry; encryption in transit and at rest; least-privilege scoping and decision-authority enforcement; isolation between Orgs and between tenants; immutable audit logging with no-credentials-in-logs and complete-audit-trail invariants; and access controls and monitoring. No system is perfectly secure, but we work to protect data against unauthorized access, loss, and misuse.
11. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, to object to certain processing, and to withdraw consent. To exercise these rights, contact privacy@orgs.ai. We will respond within the timeframe required by applicable law. If your personal data was entered into an Org by one of our customers, we will refer your request to that customer, who acts as the controller.
For UK and EU residents (UK GDPR / EU GDPR):in addition to the rights above, you have the right to lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner's Office (ICO), ico.org.uk.
For California residents (CCPA/CPRA): you have rights to know, delete, and correct your personal information, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not use it for cross-context behavioural advertising.
12. Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will delete it.
13. Changes to this policy
We may update this policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice as required by law.
14. Contact us
Orgs AI Ltd
008 Westbourne Studios, 242 Acklam Road, London W10 5JJ, United Kingdom
privacy@orgs.ai
orgs.ai