Privacy Policy
Last updated: November 9, 2025
This Privacy Policy explains how Oria One Inc. ("we," "us," or "our") collects, uses, discloses, and safeguards personal information when you use our website oria.one and any related products or services (collectively, the "Services"). If you do not agree with this policy, please do not use the Services.
1. Who we are and how to contact us
Controller: Oria One Inc., 1007 N Orange St., 4th Floor, Suite #4801, Wilmington, DE 19801, United States.
Email: andrew@oria.one
For EEA/UK users, we are the "controller" of your personal data under GDPR. We may appoint an EU/UK representative or Data Protection Officer and will update this notice if/when that occurs.
2. Scope
This Policy applies to personal information we collect online and offline in connection with the Services. It does not cover third-party websites, apps, or services that may link to or from the Services.
3. Information we may collect
We aim to collect only what we need. The categories below are intentionally broad and may not all apply to every user:
- Identifiers & contact details: name, email, postal address, phone number, account credentials.
- Commercial & transactional data: purchases, subscriptions, and related records.
- Internet/technical data: device and browser type, IP address, cookie IDs, usage logs, crash/diagnostic data, and general location derived from IP.
- User content: messages, feedback, and other content you submit.
- Payment info: processed by our payment provider (we generally receive limited details such as transaction confirmations).
- Inferences: preferences or service usage patterns derived from other data.
4. Sources of information
- Directly from you (forms, sign-ups, support).
- Automatically (cookies, pixels, SDKs, server logs).
- From service providers/partners (e.g., analytics, payments, hosting).
- From publicly available sources where permitted.
5. Why we use information (purposes)
We use information to:
- provide, operate, and maintain the Services;
- process transactions and send related communications;
- personalize, monitor, and improve performance and features;
- communicate with you about updates, security alerts, and marketing (where permitted);
- detect, prevent, and address fraud, abuse, or security incidents;
- comply with legal obligations and enforce terms.
6. Legal bases (EEA/UK)
Where GDPR applies, our processing is based on one or more of: contract, legitimate interests (e.g., securing and improving the Services), consent (e.g., certain marketing/cookies), legal obligation, and vital interests (rarely).
7. Cookies and similar technologies
We use cookies and similar tools for core functionality, analytics, and (where applicable) marketing. You can control cookies via your browser settings. Where required, we will request consent and honor your choices.
8. How we share information
We share personal information as needed with:
- Service providers/Processors (hosting, infrastructure, analytics, customer support, payments);
- Professional advisers (legal, tax, audit);
- Authorities or third parties when required by law or to protect rights, safety, or the Services;
- Business transfers (in connection with a merger, acquisition, or similar event).
We do not sell personal information for money. If we engage in activities that constitute a "sale" or "sharing" for cross-context behavioral advertising under applicable US state laws, we will provide required notices and opt-out mechanisms.
9. International transfers
We are based in the United States and may transfer, store, or process information in countries outside your own. Where GDPR applies, we rely on lawful transfer mechanisms (e.g., Standard Contractual Clauses) and implement appropriate safeguards.
10. Retention
We retain personal information only as long as necessary for the purposes above, including to meet legal, accounting, or reporting requirements. When no longer needed, we take reasonable steps to delete or de-identify it.
11. Security
We implement reasonable administrative, technical, and physical safeguards designed to protect personal information. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
12. Your rights
EEA/UK/Swiss residents
You may have rights to access, rectify, erase, restrict or object to processing, portability, and to withdraw consent at any time (without affecting prior processing). You also have the right to lodge a complaint with your local supervisory authority.
US state privacy rights (e.g., CA/VA/CO/CT/UT and others)
Depending on your state, you may have rights to access, correct, delete, obtain a copy, and to opt out of targeted advertising, certain profiling, or "sales" of personal information. If we deny your request, you may have a right to appeal our decision.
How to exercise rights
Email us at the address above and describe your request and jurisdiction. We may need to verify your identity. Authorized agents may submit requests where permitted by law and with proper authorization. We will honor browser-based opt-out signals (such as Global Privacy Control) where legally required.
13. Children's privacy
Our Services are not directed to children and we do not knowingly collect personal information from children under 13 (US) or under 16 (EEA/UK) without appropriate consent. If you believe a child provided information to us, contact us and we will take appropriate steps.
14. Third-party services and links
The Services may link to third-party sites or services. Their privacy practices are governed by their own policies, not this one.
15. Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the "Last updated" date above and, where required, provide additional notice.
16. How to contact us
If you have questions or requests regarding this Policy or our data practices, contact:
andrew@oria.one or write to Oria One Inc., 1007 N Orange St., 4th Floor, Suite #4801, Wilmington, DE 19801, USA
