Back to Orgs.AI

Privacy Policy

Effective date: 21 August 2026 · Last updated: 19 September 2026

1. Who we are

This Privacy Policy explains how Orgs AI Ltd ("Orgs AI," "we," "us," or "our"), a company registered in England and Wales under company number 17410509 with its registered office at 008 Westbourne Studios, 242 Acklam Road, London W10 5JJ, collects, uses, and protects information in connection with the Orgs AI platform, including the OrgsOS coordination substrate, our website at orgs.ai, our dashboards, and related services (collectively, the "Service").

If you have questions, contact us at privacy@orgs.ai.

Change of controller.Before 21 August 2026, personal data processed in operating the Service was controlled by Ramsey Sami Ajram, the platform's founder, in his personal capacity. Under a deed dated 21 August 2026, Mr Ajram transferred the platform's business to Orgs AI Ltd, and agreed to transfer to it the personal data processed in operating the Service together with the records of processing relating to that data. From that date, Orgs AI Ltd is the controller, and this notice is issued in its name.

2. Scope and our role

Orgs AI is a platform for coordinating AI and human work. Because of how the Service operates, we handle data in two distinct roles:

This distinction matters: if you are an end user whose data was entered into an Org by one of our customers, that customer, not Orgs AI, is responsible for how your data is used, and you should direct privacy requests to them.

3. Information we collect

4. How we use information

We use information to:

Where required by law, we rely on a lawful basis for each purpose (for example, performance of a contract, legitimate interests, consent, or legal obligation).

5. AI model processing and sub-processors

Operator outputs are generated by large language models. To produce a response, relevant context, which may include Customer Data, is sent to one or more AI model providers. We send this data directly to the providers we use. The Service also contains a model-comparison facility that would route onboarding interview turns through OpenRouter, a third-party aggregation layer. That facility is switched off in production: it refuses every request when the Service is running in production mode, so no live traffic reaches OpenRouter. Our primary inference provider is Anthropic (Claude models), with OpenAI used as a secondary or fallback provider.

These providers act as our sub-processors and are contractually limited to processing data to deliver the requested output, on terms that prohibit training on our data. We engage other sub-processors for hosting, storage, memory, authentication, payments, and communications, including: Clerk (authentication), Stripe (payments), Neon (database hosting), Vercel (application hosting and scheduled jobs), Railway (backend API and worker hosting, and the Redis instance that holds abuse-prevention counters derived from IP addresses), SendGrid and Resend (email), Anthropic and OpenAI (AI inference), Brave Search (web search), Jina AI (web page retrieval), and ip-api.com (IP geolocation).

Onboarding and business research. When you go through onboarding, the Service researches you and your business so it can pre-fill your setup. To do that it sends search queries to the Brave Search API. Those queries can contain personal data you have given us, including your name, your business name, and your city. It retrieves publicly available web pages through Jina Reader, which receives the address of each page requested, including any business URL you supply. It also sends the IP address your request arrives from to ip-api.com, which returns an approximate city so that the search results are local to you. Each of these three providers handles that data under its own published terms, which are not the same terms our inference providers are held to.

In addition, when you connect a third-party service to an Org, that service is engaged as a sub-processor at your direction for the data your Org sends it (see Section 6). The list above is the current list of sub-processors we engage. Before we add a new sub-processor that will handle Customer Data, we will tell customers at least 30 days beforehand, by email to the account contact and by notice in the dashboard. If you object within that period, write to privacy@orgs.ai and we will look for a reasonable alternative. If we cannot find one, you may end your subscription for the affected part of the Service without further charge.

6. Connectors and third-party services

When you connect a third-party service, that service's own privacy terms govern the data held there. We access it only within the scopes you authorize and only to perform the actions your Org is configured to take. For advertising connectors specifically (for example Google Ads, Meta, and Microsoft Ads), campaigns are created in a paused state and require explicit human approval before any spend is enabled. For research connectors (for example Perplexity), the queries your Org runs are sent to that provider and processed under its terms. For messaging connectors (for example Telegram), the text of the messages your Org sends or asks you to approve, together with the identifier of the chat they are delivered to, is sent to that provider's servers. You can revoke a connector's access at any time through the dashboard or the third party, which stops future access; data already processed may persist in memory and audit records subject to Section 7.

7. Data retention

We retain data for as long as needed to provide the Service and meet legal, accounting, and security obligations. Default retention for operational memory reflects the platform's design and is configurable by you within these limits:

Data typeDefault retentionMaximum
Episodic memory (events/outcomes)90 days365 days
Semantic memory (facts)Indefinite (until deleted)-
Procedural memory (learnings)Indefinite; gated and reversible-
Audit and decision records365 days-
Account and billing recordsAccount duration + 6 years-

Sensitive categories flagged as protected topics (for example personal identifiers, credentials, and financial data) are masked on access, and that access is itself audited. On account termination or a valid deletion request, we delete or anonymize data within 30 days, except where retention is legally required.

8. How we share information

We do not sell personal information. We share it only:

9. International transfers

We are based in the United Kingdom, and our primary database is hosted in the United Kingdom (London). Some processing and compute takes place outside the UK, including in the United States and the European Economic Area, through our hosting providers. Where data is transferred across borders, we rely on appropriate safeguards such as the UK International Data Transfer Agreement (or the UK Addendum to the EU Standard Contractual Clauses), the EU Standard Contractual Clauses, and adequacy decisions where available.

10. Security

We protect data with measures including: storing credentials as encrypted vault references rather than plaintext, with rotation and expiry; encryption in transit and at rest; least-privilege scoping and decision-authority enforcement; isolation between Orgs and between tenants; immutable audit logging with no-credentials-in-logs and complete-audit-trail invariants; and access controls and monitoring. No system is perfectly secure, but we work to protect data against unauthorized access, loss, and misuse.

11. Your rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, to object to certain processing, and to withdraw consent. To exercise these rights, contact privacy@orgs.ai. We will respond within the timeframe required by applicable law. If your personal data was entered into an Org by one of our customers, we will refer your request to that customer, who acts as the controller.

For UK and EU residents (UK GDPR / EU GDPR):in addition to the rights above, you have the right to lodge a complaint with a supervisory authority. In the UK this is the Information Commissioner's Office (ICO), ico.org.uk.

For California residents (CCPA/CPRA): you have rights to know, delete, and correct your personal information, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not use it for cross-context behavioural advertising.

12. Children's privacy

The Service is not directed to children under 13, and we do not knowingly collect their personal information. If you believe a child has provided us personal information, contact us and we will delete it.

13. Changes to this policy

We may update this policy from time to time. We will post the updated version with a new "Last updated" date and, for material changes, provide additional notice as required by law.

14. Contact us

Orgs AI Ltd
008 Westbourne Studios, 242 Acklam Road, London W10 5JJ, United Kingdom
privacy@orgs.ai
orgs.ai