Privacy and Security Agreement
1. Introduction
This Privacy and Security Agreement outlines how ADM Tech LLC ("Company") collects, uses, and protects personal information when using "orc8r" ("Service"). This Agreement is part of the commitment to maintaining privacy and securing data.
2. Data Collection
2.1 Account Information
Information related to account creation and administration, such as names, usernames, phone numbers, email addresses, and billing information, is collected. Billing information is handled by the third-party payment processor, Stripe, Inc., and is not stored on the Company's servers.
2.2 Usage Data
Data on how the Service is interacted with, including log files, usage patterns, and device information, is collected. This data helps improve the Service and ensure its security.
2.3 Customer Content
Customer content includes any data, software, text, audio, video, or images transferred for processing, storage, or hosting by the Service. The Customer retains ownership of their content.
2.4 Cookies and Usage Measurement
The Service sets two first-party cookies of its own. A session cookie is set when a user signs in and removed when they sign out; it keeps the user signed in and is required for the Service to work. A visitor cookie (orc_v) holds a random identifier, set once on the first page a browser loads and kept for 13 months, so that the number of distinct browsers and distinct signed-in users active on the Service can be counted per day, week and month. The identifier is not linked to a name or email address; the Service stores it only as a keyed, irreversible hash together with the days on which it was active, and never shares it with third parties or uses it for advertising. Clearing cookies or using a private window issues a new identifier; the Service works without the visitor cookie, and browsers that block it are not counted. Requests to the API and to static assets set no cookies apart from the session cookie on sign-in and sign-out.
For signed-in users the same daily activity is recorded under a keyed hash of the account identifier. The key is held by the operator of the Service, so the operator can relate these activity records to an account; they are used only to report how many users were active and whether they were new or returning.
When the operator has enabled it, the public website (not the signed-in Service) also loads Microsoft Clarity, a third-party session-analytics service that sets its own cookies and is governed by Microsoft's privacy statement. The signed-in Service loads no third-party analytics.
3. Data Use
3.1 Service Provision
Data is used to provide, maintain, and improve the Service. This includes using account information for billing and customer support, and usage data to enhance Service performance.
3.2 Legal Compliance
Data may be used to comply with legal obligations, resolve disputes, and enforce agreements.
4. Data Protection
4.1 Encryption
Industry-standard encryption is used to protect data both in transit and at rest. Customers have the option to manage their own encryption keys.
4.2 Access Control
Customers control who has access to their data through access management features, including user permissions and roles.
4.3 Security Measures
Rigorous security measures are implemented to protect data, including multi-factor authentication, SSL/TLS for data transmission, and regular security audits.
4.4 Data Retention
Personal information is retained as long as necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements. The retention period varies depending on the type of data and its use. The daily activity records described in section 2.4, for visitors and for signed-in users alike, are kept for 400 days by default and then deleted, including the record of when an identifier was first seen.
5. Data Handling and Payment Processing
5.1 Payment Processing
All payments are processed by Stripe, Inc. Payment information is not stored on the Company's servers. Stripe's privacy policy applies to all payment transactions.
5.2 Data Handling
Customer data is stored in encrypted form in the CRM system. Personal information is not sold or shared with third parties for marketing purposes.
6. Responsibilities
6.1 Account Security
Customers are responsible for maintaining the security of their account credentials. Strong passwords and multi-factor authentication should be used where possible.
6.2 Compliance
Customers must ensure that their use of the Service complies with applicable laws and regulations, including data protection laws.
7. Third-Party Services
7.1 Integration with Third-Party Services
The Service may integrate with third-party services. The Company is not responsible for the privacy practices of these third parties. Customers should review their privacy policies to understand how data is handled.
8. Legal Requests
8.1 Government Requests
Customer content will not be disclosed unless required to comply with the law or a binding order of a governmental body. Attempts will be made to redirect such requests to the Customer and notify them of the demand unless legally prohibited from doing so.
9. Changes to this Agreement
This Privacy and Security Agreement may be updated from time to time. Significant changes will be notified by posting the new agreement on the Company's website. Continued use of the Service after the changes take effect constitutes acceptance of the new terms.
10. Contact Information
For any questions or concerns about this Privacy and Security Agreement, contact the Company at contact@admte.ch.