Privacy policy
Effective
This policy explains how we handle personal information across the Orvion Group and Orvion Forge websites and the Orvion Core platform.
We use information to respond to enquiries, provide our services, connect accounts you authorise and keep the service secure. Your organisation controls the business information it chooses to put into Core.
To ask about your information, contact info@orvion-group.com. See data deletion for disconnecting an account or requesting removal.
Who we are
Orvion Group Ltd is based in the United Kingdom. Our registered address is 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom. Orvion Forge is our research and engineering division; Orvion Core is our business platform.
We are responsible for personal information we use for our own website enquiries, business relationships, account administration and service security.
When an organisation uses Core to handle its own business information, that organisation decides why it is used and which people may access it. We handle that information to provide the service under the applicable agreement and the organisation's instructions. Contact that organisation first about its use of your information; we can help route a request.
Information we handle
- Enquiries and correspondence
- Your name, business, business type, email, optional phone number and area, the challenge or enquiry you describe, submission reference and related correspondence. We may retain an internal email copy so our team can respond.
- Core accounts
- Your name, email, Microsoft sign-in identifiers, organisation memberships, access roles and account activity.
- Business information
- Information authorised users add to Core, including contacts, enquiries, documents, business context, campaign briefs, drafts, review decisions, tasks and recorded outcomes. This can include information about other people.
- Connected accounts
- The provider and selected account, Page, site or publication identifiers and names; permissions, connection status and timestamps; and the authorisation credentials needed to maintain the connection.
- Service and security information
- Request and error records, usage information, browser or device details and network information processed by our hosting and monitoring services. See the browser storage section for website analytics.
Information comes from you, your organisation's authorised users, your identity provider, connected services you authorise and operation of the service. Please avoid putting payment-card details, passwords or unnecessary sensitive personal information in enquiry forms or business content.
Why we use information
- Responding to business enquiries: to understand your request, assess how we can help, prepare a response and manage follow-up. Our basis is our legitimate interest in responding to people who contact us and developing relevant business relationships.
- Providing and administering services: to create accounts, apply access permissions, run requested workflows and support users. Where you are personally a party to a contract, this is necessary for that contract or steps you request before entering it. For business representatives, our basis is our legitimate interest in providing and administering the business relationship.
- Protecting and maintaining the service: to investigate errors, prevent misuse and preserve evidence of access and approved actions. Our basis is our legitimate interest in operating a reliable and secure service.
- Meeting legal requirements: where we must keep or provide information to comply with a legal obligation.
For customer business information processed on an organisation's behalf, that organisation is responsible for establishing its purposes and lawful basis. A provider's OAuth permission screen authorises access to an account; it does not replace the organisation's responsibilities for personal information.
You choose whether to contact us. Without the relevant contact details, we may be unable to reply. Sign-in information and permissions are needed to provide access to Core. Connecting a marketing channel is optional.
Connected channels and AI
Where available, an organisation administrator can connect LinkedIn, Facebook, Instagram, X, Webflow or beehiiv by signing in with that provider and approving access. Core does not ask for the provider account's password. Each organisation's connection is stored separately, with its authorisation credentials encrypted.
The current connection feature discovers and verifies available accounts, Pages, sites or publications. Connecting does not itself publish content, send newsletters or buy advertising. The provider shows the permissions requested before you authorise access.
Disconnecting clears that organisation's stored connection credentials. Connection metadata and activity history can remain. It does not remove content from the provider or revoke consent used by other organisations; you can also remove the Orvion app in the provider's own settings.
Core uses Microsoft Foundry for AI-assisted work, including analysis and drafting. Relevant task instructions and business content are sent to that service, and Core records results and usage information. Information you include in a task may therefore be processed by Microsoft. AI output can be inaccurate; the enquiry and marketing workflows include human review and approval steps.
Who receives information
Information is available to authorised people who need it, including users with access within your organisation. Our service providers include Microsoft for Azure hosting and security, Entra sign-in, Foundry AI processing, Communication Services email and Microsoft 365 email handling, as applicable to the service used.
A channel provider receives the requests needed to connect and check an account you authorise. The provider handles information in its own service under its terms and privacy policy. We may also disclose information where required by law or where necessary to establish, exercise or defend legal rights.
International processing
Microsoft's services and connected providers may process information outside the United Kingdom. The locations and transfer arrangements depend on the service and configuration. Contact our privacy team for the arrangements relevant to your service and information about the applicable safeguards.
Storage, security and retention
Core uses organisation access controls, encrypted channel credentials and records of decisions and actions. These measures help protect information; no service can promise absolute security.
We keep personal information for the purposes for which it was collected. In deciding how long, we consider completion of your enquiry, expected follow-up, an active business relationship, the service agreement, security and audit needs, legal requirements and any dispute or hold that requires preservation.
Business information held in Core follows the applicable organisation policy and service arrangements. Customers are responsible for information retained in their own source systems, such as their mailboxes and social channels. Copies held by Core remain our responsibility under those service arrangements.
Deleting an item from an active system does not necessarily remove it immediately from backups, security records or lawful hold records. Internal enquiry email copies also need to be handled separately from Core records. Contact us for the retention arrangements that apply to your information.
Cookies and browser storage
Core uses cookies for secure sign-in, checking login and channel-connection requests, and remembering the organisation you selected. Browser storage also remembers display preferences and supports recovery from application errors.
The website enquiry form uses session storage to keep an opaque submission reference and a fingerprint of the submitted fields for retries. It does not store the form's plain-text answers in that record.
Our website supports Microsoft Application Insights for performance and usage monitoring and Microsoft Clarity for interaction analytics where configured. These services can process page activity, technical details and browser identifiers and can use browser storage. Our enquiry event reporting includes category and success or error information rather than the form's name, email or message fields. Microsoft explains its practices in its privacy statement.
Browser settings allow you to manage storage and cookies. Blocking cookies required for Core sign-in or connections may prevent those functions from working.
Your rights
Depending on the applicable law and circumstances, you may ask to access, correct or erase your personal information, restrict its use or receive a portable copy. If processing relies on consent, you can withdraw it without affecting earlier lawful processing.
You can object to use based on legitimate interests and to use for direct marketing. Contact us using the details below. A right may be subject to legal conditions; if we cannot fulfil a request, we will explain why.
For an organisation's information in Core, contact its administrator first. For information we use for our own purposes, email info@orvion-group.com. We may need proportionate information to verify your identity and authority. Never send account passwords or access tokens.
You can also complain to the UK Information Commissioner's Office at ico.org.uk/make-a-complaint.
Changes to this policy
We will update this page when our practices change and identify the current version date. Where required, we will provide further notice of a material change.