This addendum governs personal data that ORIKIN processes on a customer’s behalf when the agent handles their calls and messages. It forms part of the Terms of Service. Data collected by this website is a separate matter, covered by the Privacy Policy.
Effective 1 August 2026
For data the agent handles on your behalf, you are the controller and ORIKIN is the processor. You determine why the data is processed and what the agent may do with it. We act on your documented instructions, and the configuration you set is part of those instructions.
Subject matter: operating a conversational agent across your voice and messaging channels. Duration: for as long as your agreement runs, plus the deletion window below.
Categories of data subject: the people who contact you. Categories of data: the contents of those conversations and whatever identifiers arrive with them, typically a phone number or messaging handle, together with the details a caller volunteers.
Data is encrypted in transit and at rest. Access is limited to the personnel who need it to operate the service and is logged. Systems are segregated by customer, and administrative access requires multi-factor authentication.
Where the deployment is on-premise or air-gapped, the data stays inside your infrastructure and these controls become yours to operate; our obligations then apply to the software we supply rather than to hosting.
We use a small number of sub-processors for infrastructure, telephony and model inference. Each is bound by written terms no less protective than these.
A current list is available on request. We will give you advance notice of any addition or replacement, and you may object on reasonable data-protection grounds.
ORIKIN operates from the United Arab Emirates and may process data in other jurisdictions. Where data moves out of a region whose law restricts transfers, we rely on an approved transfer mechanism — standard contractual clauses or an adequacy finding — and apply additional safeguards where the circumstances require them.
If your obligations require processing to remain within a specific jurisdiction, tell us before deployment. It can usually be accommodated, including through an on-premise installation.
Your data is not used to train models that serve other customers. Where you ask us to tune behaviour for your own deployment, that work is confined to your deployment.
We will notify you without undue delay after becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification duties, and will keep you updated as the picture becomes clearer.
If someone contacts us directly about data we hold on your behalf, we will not respond substantively. We will refer them to you and tell you promptly, then assist you in answering.
Conversation data is retained for the period configured in your agreement. On termination, you may export it, and we will delete it within thirty days unless the law requires us to keep it longer.
Deletion covers backups on their normal rotation, rather than pretending backups can be edited on demand.
You may verify our compliance once in any twelve-month period, on reasonable notice, through documentation and a written response to your questions, or through an on-site audit where a regulator requires one.
Data protection enquiries may be sent to contact@orikin.ai.