Who we are
ORQO is a customer conversations platform operated by [legal company name], headquartered at [registered address] (“ORQO” or “we”). This policy explains how we handle personal data when you use our website and platform.
Our role in processing data
We deal with two kinds of data:
- Your account data as an ORQO customer, such as your name, email, and billing details. We are the controller of this data.
- Your customers’ data that you manage inside ORQO, such as contacts, messages, and orders. You are the controller of it; we process it on your behalf and only according to your instructions.
If you are a customer of a company that uses ORQO and want to exercise your data rights, contact that company directly, and we will help them fulfil your request.
The data we collect
- Account data: name, email, phone number, organization and workspace names, and login and two-factor authentication data.
- Billing data: plan, subscription date, and payment and invoice history. Card data is processed by the payment gateway; we do not store full card numbers.
- Business data: contacts, custom fields, tags and notes, messages and media, campaigns and templates, automation, orders from the connected store, and the knowledge files you add to AI agents.
- Meta channel data: when WhatsApp, Instagram or Messenger is connected: account and number identifiers, access tokens, incoming and outgoing messages, and delivery and read states.
- Usage data: technical logs, device and browser type, platform usage events, error reports, and notification identifiers.
- Communication data: what you send us via email, the contact form, or support.
How we use data
- Providing the platform: receiving and sending messages, running campaigns and automation, and showing reports.
- Operating AI agents according to the settings you define.
- Managing subscriptions, billing, and usage limits.
- Providing support and contacting you about your account.
- Protecting the platform and preventing abuse.
- Improving the product using aggregated usage data.
- Complying with legal requirements.
We do not sell personal data, and we do not use your customers’ data for our own marketing purposes.
Artificial intelligence
When you enable an AI agent, we send the relevant conversation text, the customer-profile data the agent needs, and excerpts from the knowledge sources you added, to an AI model provider to generate the reply. Knowledge sources are indexed in a search base dedicated to your workspace.
The platform logs what the agent does in the conversation history and the run log, and you can stop the agent or take over the conversation manually at any time.
[Confirm: whether customer data is used to train any models, and the model providers’ terms in this regard]
Service providers
We rely on trusted providers to run the platform, and share only what is necessary for their role:
| Provider | Purpose |
|---|---|
| Meta | WhatsApp, Instagram and Messenger channels |
| Clerk | Login and identity management |
| Creem | Payment and subscription processing |
| Appwrite | File and media storage |
| OpenAI · Anthropic · Google Gemini | AI models for agents and summaries |
| Qdrant | Indexing knowledge sources for search |
| Pusher | Real-time updates inside the platform |
| OneSignal | Browser and mobile notifications |
| PostHog | Product usage analytics |
| Sentry | Technical error tracking |
| Email provider | Account messages and notifications |
| The integrations you connect | Google Sheets and Meet, Shopify, WooCommerce, EasyOrders, and n8n — only when enabled from your account |
The list comes from the code settings · confirm the providers actually used in production and the email provider (L2)
We may disclose data if a competent authority lawfully requests it.
Transferring data outside your country
Some providers may process data in countries outside Egypt or Saudi Arabia. We choose providers that apply appropriate safeguards to protect data, and we comply with the transfer requirements of the applicable laws. [Location of the main servers]
Retention period
We keep data for as long as your account is active or as needed to provide the service. When a workspace or account is deleted, we delete its data within [number of days] days, and it is removed from backups within [period], except what must be kept by law, such as billing records.
Data deletion
You can delete contacts and conversations from inside the platform, and disconnect any channel from the channel settings, which deletes its access tokens.
To request deletion of your account or all of your data, email us at hello@orqo.site with the subject “Data deletion request” from the email registered on the account, and we will confirm deletion within [number of days] days.
If you contacted a company that uses ORQO via WhatsApp, Instagram or Messenger and want your data deleted, ask the company itself, or email us and we will forward your request to them.
Meta requires a data-deletion instructions link or a callback URL · confirm the approved mechanism (L3)
Data protection
- Encrypted connection between your browser and the platform.
- Private files that open only for a signed-in user or via a signed temporary link.
- Verification of message signatures coming from payment gateways and channels.
- Roles and permissions inside every organization and workspace, plus two-factor authentication.
- Logs of what the AI agent does inside conversations.
No system is completely secure, but we review our measures continuously, and we will notify you as required by law if a breach affects your data.
Your rights
Under the applicable laws, such as Saudi Arabia’s Personal Data Protection Law and Egypt’s Personal Data Protection Law No. 151 of 2020, you have the right to:
- Know the data we hold about you and obtain a copy of it.
- Correct inaccurate data.
- Request deletion of your data.
- Object to some kinds of processing or restrict it.
- Withdraw your consent where processing is based on it.
To exercise any of these rights, email us at hello@orqo.site.
Cookies
We use essential cookies for login and session protection, cookies that store your preferences such as language and appearance, and analytics tools that help us understand product usage. You can control them from your browser settings.
Children
ORQO is intended for businesses, and we do not provide the service to anyone under 18.
Changes
We may update this policy. We show the last-updated date at the top of the page, and we will notify you inside the platform or by email of any material change.
Contact us
For any privacy question: hello@orqo.site · [legal company name and address]