Summary — what you should know
ORXA ("we," "our," or "us") operates an AI agent platform that enables businesses and developers to build, configure, and deploy AI-powered assistants. This Privacy Policy explains what information we collect, how we use and store that information, and what rights you have over your data.
By registering for or using the Platform, you agree to the practices described in this policy. This policy applies to registered users, workspace members, and visitors who interact with authentication flows.
We collect your email address, full name, profile image (optional), and password (stored hashed with bcrypt). For Google OAuth users, we receive and store Google-issued tokens to maintain your session.
Short-lived JWT access tokens (15 min) and refresh tokens (7 days) are used for authentication. Sessions are tracked in Redis with metadata including login activity and failed attempts.
We store workspace names, descriptions, logos, member roles, and workspace invitations (including invitee email addresses).
Agent names, descriptions, system instructions, model selection, temperature settings, token limits, and metadata are stored to operate your AI agents.
Uploaded files (PDF, DOCX, TXT) are stored in cloud file storage (AWS S3). Parsed text content is stored in our database. Text, Q&A content, website content, and Notion page content are processed and indexed. Vector embeddings are generated by OpenAI and stored in our database for semantic search.
Input messages, AI-generated responses, tool invocations (inputs and outputs), and performance metrics (token counts, cost, duration) are stored as part of execution records.
OAuth provider credentials are managed through Composio. Custom integration credentials (API keys, OAuth2 secrets, JWT keys) are encrypted with AES-256-GCM before storage. WhatsApp session credentials and active integration tokens are also stored.
Company name, tax ID, billing address, invoice records, and payment event logs from Xendit are stored for payment processing and audit.
Token consumption logs, integration token refresh logs, and aggregated dashboard analytics are collected and cached for performance.
We use your information to:
Good to know
We do not use your information for advertising or sell it to third parties.
Custom integration credentials are encrypted at the application level using AES-256-GCM with PBKDF2-SHA256 key derivation before being written to the database.
| Provider | Data Transmitted | Purpose |
|---|---|---|
| OpenAI | Document chunks, conversation messages, knowledge context | Embeddings and AI responses |
| Anthropic | Conversation messages, system instructions, knowledge context | AI responses (Claude models) |
| Conversation messages, system instructions, knowledge context | AI responses (Gemini models) |
No PII Detection
We do not perform PII detection or content redaction before transmitting data to AI providers. We recommend avoiding uploading documents containing sensitive personal data unless you have reviewed the relevant provider's data processing terms.
When an agent processes a message:
Content from your documents is transmitted to OpenAI for embedding generation regardless of which AI model your agent uses for responses.
Your Data Rights
Depending on your jurisdiction, you may have the right to:
To exercise your rights, contact us at the address in Section 13.
We do not sell your personal data. We share data only with AI model providers, integration partners, payment processors, cloud infrastructure providers, and user-configured external services as described above. We may also disclose information if required by law.
| Measure | Details |
|---|---|
| Password hashing | bcrypt with automatic salt |
| Account lockout | Locked after repeated failed attempts |
| Rate limiting | Per-user and per-IP |
| Session management | Short-lived JWTs with token rotation and reuse detection |
| Credential encryption | AES-256-GCM for integration secrets |
| Email verification | Required before account activation |
| Workspace isolation | Data scoped to workspaces |
| RBAC | Role-based permissions enforced at API level |
| SSRF protection | Custom integration URLs validated |
We may update this Privacy Policy from time to time. We will update the "Last Updated" date and notify registered users of material changes via in-platform notification or email.
This Privacy Policy is governed by the laws of the Republic of Indonesia.
ORXA
Email: admin@vereintech.com
Website: https://www.vereintech.com/orxa
For data deletion requests or privacy concerns, include "Privacy Request" in the subject line.
Questions? Contact us at admin@vereintech.com
Last reviewed April 17, 2026.