Legal

Privacy Policy

Effective Date: June 30, 2026

Last Updated: June 30, 2026

1. Introduction

Welcome to Orvitt.

Orvitt is an AI-powered enterprise software platform designed to help organizations build, manage, measure, and optimize relationship-driven revenue through trusted business relationships, strategic partnerships, referral ecosystems, advisors, relationship partners, and other commercial relationships.

This Privacy Policy explains how Orvitt collects, uses, shares, stores, transfers, and otherwise processes Personal Information when individuals interact with the Orvitt website, the Orvitt SaaS platform, customer workspaces, APIs, browser applications, integrations, mobile applications (if offered), AI-powered features, customer support, marketing communications, enterprise services, and any other services provided by Orvitt (collectively, the "Services").

2. Scope

This Privacy Policy applies whenever Personal Information is processed by Orvitt in connection with providing the Services.

This Policy applies to: prospective customers, customers, trial users, website visitors, business contacts, partners, advisors, relationship partners, contractors, vendors, event attendees, webinar participants, newsletter subscribers, job applicants (except where a separate notice applies), and other individuals whose Personal Information is processed through the Services.

This Policy does not apply to third-party websites, third-party software, third-party integrations operating under their own privacy notices, or information processed solely on behalf of enterprise customers where Orvitt acts as a processor, except as specifically described herein.

3. Definitions

"Account" means an account registered to access the Services.

"Affiliate" means any entity controlling, controlled by, or under common control with Avila Essence LLC.

"AI Services" means any artificial intelligence, machine learning, large language model, recommendation engine, inference engine, automation capability, or similar functionality made available through the Services.

"Applicable Privacy Laws" means all applicable privacy and data protection laws including, where applicable: GDPR, UK GDPR, Swiss Federal Act on Data Protection, California Consumer Privacy Act (CCPA) as amended by the CPRA, Florida Information Protection Act, and any other applicable federal, state, or international privacy legislation.

"Customer" means the legal entity purchasing or subscribing to the Services.

"Customer Data" means all information submitted to the Services by or on behalf of a Customer. Customer Data remains the property of the Customer, subject only to the limited rights necessary for Orvitt to provide the Services.

"Personal Information" (or "Personal Data") means information relating to an identified or identifiable natural person, including any equivalent term under Applicable Privacy Laws.

"Relationship Data" means information concerning business relationships, strategic partnerships, advisors, relationship partners, referral sources, introductions, opportunities, pipelines, organizational relationships, and similar commercial information submitted by Customers through the Services.

"Services" means all products, software, APIs, websites, applications, AI capabilities, integrations, consulting services, implementation services, and related offerings provided by Orvitt.

"Subprocessor" means a third-party engaged by Orvitt to Process Customer Data on behalf of Customers in connection with providing the Services.

"User" means any authorized individual using the Services.

4. About Orvitt

The Services are provided by:

Avila Essence LLC
7110 Pinehaven Drive
Lakeland, Florida 33810
United States

Questions concerning this Privacy Policy may be directed to the Privacy Officer at privacy@orvitt.com.

5. Our Role as Controller and Processor

When Orvitt Acts as a Data Controller

Orvitt acts as a data controller when determining the purposes and means of Processing Personal Information for its own business operations, including: account registration, billing, subscriptions, website analytics, customer support, security, fraud prevention, marketing communications, recruiting, legal compliance, and contractual administration.

When Orvitt Acts as a Data Processor

For most enterprise customers, Orvitt acts solely as a data processor. In these situations, the Customer determines what information is uploaded, the lawful basis for Processing, retention periods, which users receive access, and is responsible for responding to privacy requests concerning Customer Data.

Orvitt Processes Customer Data only in accordance with documented Customer instructions, pursuant to applicable agreements, as required to provide the Services, or as otherwise required by law.

Customer Responsibilities

Customers are responsible for ensuring that they have all necessary rights, permissions, consents, and legal bases required to submit Customer Data to the Services. Customers further represent that any Personal Information uploaded into the Services has been collected in compliance with Applicable Privacy Laws.

6. Categories of Personal Information We Collect

6.1 Account Information

When an individual registers for the Services, we may collect: first and last name, employer or organization, business email address, telephone number, job title, department, company size, industry, billing address, account credentials, authentication information, user preferences, language preferences, time zone, and profile photographs or avatars (if voluntarily provided).

6.2 Subscription Information

When purchasing subscriptions or enterprise services, we may collect subscription tier, billing contact information, invoice history, payment status, transaction identifiers, tax information where required, purchase order information, contract information, and customer success information. Payment card information is generally processed directly by our third-party payment providers. Orvitt does not ordinarily store complete payment card numbers or security codes.

6.3 Communications Information

We collect information provided when individuals communicate with Orvitt, including through customer support, email, live chat, implementation meetings, webinars, surveys, sales discussions, training sessions, conferences, and customer success meetings.

6.4 Device and Usage Information

We automatically collect technical information including IP address, browser type, operating system, device identifiers, browser language, time zone, network information, screen resolution, referral URLs, application version, and crash reports. We also collect information regarding pages visited, features accessed, workflows executed, dashboards viewed, reports generated, search activity, AI features utilized, integrations enabled, login history, and session duration.

7. Customer Data

Customers may choose to upload, import, synchronize, or otherwise provide Customer Data through the Services. Customer Data may include CRM records, contact information, business relationships, strategic partner information, referral partner information, advisor information, relationship partner profiles, opportunity pipelines, account plans, sales notes, communications, meeting summaries, introductions, commercial opportunities, contract information, and business intelligence.

Customer Data, Customer Content, Relationship Intelligence, uploaded files, CRM records, business records, and other information submitted through the Services remain the exclusive property of the Customer or its licensors. Except for the limited rights necessary to provide, secure, maintain, and improve the Services as authorized by applicable agreements, Orvitt acquires no ownership interest in Customer Data.

8. Relationship Data

Because Orvitt is designed to help organizations build relationship-driven revenue ecosystems, the Services may process specialized commercial relationship information ("Relationship Data"). Relationship Data includes advisors, relationship partners, referrals, introductions, partnership networks, and related metadata. Relationship Intelligence constitutes Customer Data where submitted by or on behalf of a Customer. Orvitt processes such information solely to provide the Services and does not independently commercialize identifiable Relationship Intelligence.

Customers are solely responsible for ensuring that Relationship Data uploaded into the Services is processed in accordance with applicable law.

9. AI Inputs and Outputs

9.1 AI Inputs

Certain Services permit Users to submit information to AI-powered functionality including prompts, documents, CRM records, meeting notes, emails, proposals, relationship information, strategic plans, sales materials, customer communications, business objectives, and uploaded files. Users should avoid submitting highly sensitive Personal Information into AI features unless expressly authorized by their organization and necessary for the intended business purpose.

9.2 AI Outputs

AI Services may generate summaries, recommendations, relationship insights, opportunity analyses, suggested communications, relationship partner recommendations, strategic analyses, account planning suggestions, workflow recommendations, reports, and business intelligence. AI-generated outputs are probabilistic in nature. They may be inaccurate, incomplete, outdated, or inappropriate for a particular purpose. Users remain solely responsible for reviewing, validating, and approving AI-generated content before relying upon it for legal, financial, employment, healthcare, compliance, or other material business decisions.

9.3 AI Model Improvement

Unless otherwise expressly agreed in writing with a Customer, Orvitt does not use identifiable Customer Data or Customer Content to train publicly available or general-purpose foundation AI models. Orvitt may use aggregated, anonymized, or de-identified information to improve the Services, evaluate product performance, enhance system reliability, develop new features, and conduct internal analytics, provided such information cannot reasonably identify an individual or Customer.

10. Information from Third Parties

The Services may receive information from third parties where authorized by the Customer or User. Examples include CRM platforms, calendar providers, email providers, identity providers, enterprise directories, collaboration platforms, customer support systems, payment processors, cloud storage providers, analytics providers, and marketing platforms.

Depending upon Customer configuration, integrations may include services such as Google Workspace, Microsoft 365, HubSpot, Salesforce, Slack, LinkedIn (where supported and authorized), and other enterprise software platforms. Customers remain responsible for configuring integrations in accordance with their internal security and privacy requirements.

11. Special Categories of Personal Data

Orvitt does not intentionally request or require Customers to upload Special Categories of Personal Data (as defined under GDPR) or Sensitive Personal Information beyond what is reasonably necessary for the Services. Customers should not upload information concerning racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic information, biometric identifiers used for unique identification, health information, sexual orientation, or other sensitive information, unless such processing is necessary for a lawful business purpose and appropriate legal safeguards have been implemented.

12. Legal Bases for Processing (GDPR and UK GDPR)

Where the GDPR or UK GDPR applies, Orvitt processes Personal Data on one or more of the following legal bases:

  • Performance of a Contract — to provide the Services, fulfill contractual obligations, process subscriptions, deliver customer support, and administer customer accounts.
  • Legitimate Interests — securing the Services, improving product functionality, preventing fraud, enforcing agreements, responding to inquiries, measuring product performance, and developing new features, provided such interests are not overridden by the rights and freedoms of affected individuals.
  • Consent — where required by law; individuals may withdraw consent at any time where processing is based solely upon consent.
  • Legal Obligations — to comply with applicable laws, court orders, lawful governmental requests, and regulatory requirements.
  • Vital Interests — in limited circumstances, where necessary to protect the vital interests of an individual.

13. How We Use Personal Information

Orvitt processes Personal Information for legitimate business purposes, including to: provide, operate, maintain, and improve the Services; authenticate users; administer accounts; process subscriptions and payments; provide customer support; implement enterprise deployments; enable integrations; facilitate relationship management workflows; generate AI-powered insights; produce analytics and reporting; improve product functionality; secure the Services; detect fraud and abuse; investigate security incidents; comply with legal obligations; communicate with Customers and Users; and enforce contractual rights.

Orvitt will not process Personal Information for purposes materially incompatible with those described in this Privacy Policy unless permitted by applicable law or with the appropriate legal basis.

14. Cookies and Similar Technologies

Orvitt uses cookies and similar technologies to operate, secure, improve, and personalize the Services. Depending on applicable law, users may be presented with cookie consent choices before non-essential cookies are placed. For full details, please see our Cookie Policy.

15. Analytics and Telemetry

Orvitt uses analytics and operational telemetry to improve the Services. Analytics may include information regarding system performance, user engagement, workflow completion, application reliability, service availability, feature usage, and infrastructure utilization. Where feasible, analytics are aggregated or pseudonymized before analysis. Analytics are not used to profile individuals for decisions producing legal or similarly significant effects.

16. Marketing Communications

Orvitt may send communications concerning newsletters, product updates, educational content, webinars, feature announcements, security notices, industry insights, event invitations, and promotional offers. Where required by law, marketing communications will be sent only with the appropriate consent or other lawful basis. Recipients may unsubscribe at any time. Operational communications relating to account administration, security, billing, or service availability may continue regardless of marketing preferences.

17. Disclosure of Personal Information

Orvitt does not sell Customer Data. We disclose Personal Information only as described in this Privacy Policy, pursuant to Customer instructions, or as otherwise permitted or required by applicable law.

Personal Information may be disclosed to service providers (cloud infrastructure, hosting, authentication, customer support, payment processing, communications, email delivery, analytics, AI processing, and professional services), enterprise integrations (where authorized by Customers), professional advisors (attorneys, accountants, auditors, insurers, consultants), and in connection with corporate transactions (mergers, acquisitions, asset sales, restructurings). Orvitt may also disclose Personal Information where required by law to comply with court orders, lawful governmental requests, or to protect the rights of Orvitt, prevent fraud, or respond to emergencies involving risk of serious harm.

Unless legally prohibited, or where notification would create a material risk of harm or violate applicable law, Orvitt will use commercially reasonable efforts to notify the affected Customer before disclosing Customer Data in response to a governmental or law-enforcement request.

18. Subprocessors

Orvitt utilizes carefully selected subprocessors to assist in delivering the Services. Subprocessors may provide services relating to cloud hosting, content delivery, AI inference, customer communications, email delivery, authentication, payment processing, logging, monitoring, analytics, customer support, security monitoring, and infrastructure management. All subprocessors are subject to written contractual obligations requiring appropriate technical and organizational safeguards consistent with applicable privacy laws.

Where required under applicable law or contract, Orvitt will maintain and make available an up-to-date list of authorized subprocessors upon request. Orvitt remains responsible for the performance of its subprocessors to the extent required by applicable law and contractual obligations.

19. International Data Transfers

Because Orvitt operates internationally, Personal Information may be transferred to and processed in jurisdictions other than the country where it was originally collected, including the United States and other countries where Orvitt, its affiliates, or authorized subprocessors operate.

Where required by applicable privacy laws, Orvitt implements appropriate safeguards for international transfers, which may include the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, the Swiss Federal Data Protection and Information Commission's recognized transfer mechanisms, adequacy decisions issued by competent authorities, and additional contractual, organizational, and technical safeguards appropriate to the nature of the transfer.

20. Information Security

Orvitt maintains a comprehensive information security program designed to protect the confidentiality, integrity, availability, and resilience of Personal Information and Customer Data. Orvitt implements administrative, technical, and physical safeguards appropriate to the nature of the Services, including: written security policies, employee confidentiality obligations, role-based access controls, encryption of data in transit using industry-standard protocols, encryption of stored data where appropriate, multi-factor authentication for administrative access where supported, audit logging, infrastructure monitoring, endpoint protection, vulnerability management, automated backups, and incident response procedures.

Orvitt incorporates privacy-by-design and security-by-design principles into the development and operation of the Services. While no security program can eliminate all risk, Orvitt will notify affected Customers of confirmed Security Incidents involving Customer Data without undue delay after becoming aware of such incidents, where required by applicable law or contractual obligation.

21. Data Retention

Orvitt retains Personal Information only for as long as necessary to fulfill the purposes described in this Privacy Policy, provide the Services, comply with legal obligations, resolve disputes, enforce agreements, protect our legal interests, and maintain appropriate business records.

Data CategoryRepresentative Retention
Account InformationLife of account plus legally required retention
Billing RecordsUp to 7 years where required by law
Support RecordsUp to 3 years
Security LogsUp to 12 months unless longer retention is required
Customer DataAs directed by the Customer and governing agreement
BackupsRolling backup schedule before secure deletion/overwrite

22. Your Privacy Rights

Depending upon your jurisdiction, you may have certain rights concerning your Personal Information, including: the right to know whether Personal Information is being processed; the right to access, receive a copy of, or request correction of Personal Information; the right to request deletion; the right to restrict or limit certain processing; the right to object to certain processing activities; the right to data portability; the right to withdraw consent; the right not to be subject to unlawful discrimination for exercising privacy rights; and the right to appeal certain privacy decisions where required by law.

These rights are not absolute and may be subject to applicable legal exceptions. Before responding to certain requests, Orvitt may request information necessary to verify the identity and authority of the requesting individual. Where Orvitt processes Customer Data solely as a processor, requests relating to such Customer Data should generally be directed to the applicable Customer.

23. California Privacy Rights

If you are a California resident, you may have rights under the CCPA, as amended by the CPRA, including the right to know the categories of Personal Information collected, the sources from which Personal Information is collected, the business or commercial purposes for collection, the categories of third parties to whom Personal Information is disclosed, access specific pieces of Personal Information, request correction, request deletion, limit the use and disclosure of Sensitive Personal Information where applicable, and designate an authorized agent to submit requests on your behalf.

Orvitt does not sell Personal Information as that term is defined under the CCPA. Orvitt does not knowingly share Personal Information for cross-context behavioral advertising.

24. European Privacy Rights

Individuals located within the European Economic Area, the United Kingdom, or Switzerland may have rights under applicable data protection laws, including: Article 15 (Right of Access), Article 16 (Right to Rectification), Article 17 (Right to Erasure), Article 18 (Right to Restriction of Processing), Article 20 (Right to Data Portability), Article 21 (Right to Object), and Article 22 (Rights relating to Automated Decision-Making, where applicable).

Individuals also have the right to lodge a complaint with their competent supervisory authority if they believe their Personal Data has been processed unlawfully. Nothing in this Privacy Policy limits any rights available under applicable data protection laws.

25. Automated Decision-Making and AI Governance

Unless expressly stated for a specific Service, Orvitt does not use AI systems to make decisions that produce legal effects or similarly significant effects concerning individuals without appropriate human involvement. AI-generated outputs are intended to assist—not replace—human judgment. Customers and Users remain responsible for reviewing AI-generated outputs, validating recommendations, exercising independent business judgment, and complying with applicable laws and internal governance requirements.

26. Children's Privacy

The Services are intended exclusively for business and professional use. The Services are not directed to children under the age of 18, and Orvitt does not knowingly collect Personal Information directly from children. If Orvitt becomes aware that Personal Information has been collected from a child in violation of applicable law, Orvitt will take reasonable steps to delete such information. Parents or legal guardians who believe a child has submitted Personal Information may contact the Privacy Officer.

27. Third-Party Websites and Services

The Services may contain links to, or integrations with, third-party websites, software, or services. Orvitt is not responsible for the privacy practices, security, or content of third-party services. Users are encouraged to review the applicable privacy notices of those third parties before providing Personal Information. Integration with third-party services does not constitute an endorsement of such services.

28. Business Transfers

As Orvitt continues to grow, it may engage in strategic transactions including mergers, acquisitions, financings, reorganizations, or sales of assets. In connection with such transactions, Personal Information and Customer Data may be disclosed to prospective or actual purchasers, investors, lenders, advisors, or other authorized participants, subject to appropriate confidentiality obligations and applicable law. If ownership of Orvitt changes, Personal Information may be transferred to the successor entity as part of the transaction.

29. Changes to this Privacy Policy

Orvitt may update this Privacy Policy from time to time to reflect changes in applicable law, new product features, operational changes, security enhancements, or changes in our business practices. When material changes are made, Orvitt will take reasonable steps to notify Customers through appropriate means. Continued use of the Services after the effective date of an updated Privacy Policy constitutes acceptance of the revised Policy to the extent permitted by applicable law.

30. Contact Information

Questions regarding this Privacy Policy or Orvitt's privacy practices may be directed to:

Privacy Officer
Avila Essence LLC
7110 Pinehaven Drive
Lakeland, Florida 33810
United States

Email: privacy@orvitt.com

Requests concerning privacy rights should include sufficient information to enable Orvitt to verify the identity of the requesting individual and understand the nature of the request.