Legal
Privacy Policy
Summary
What personal data we collect, why, how we use it, who we share it with, how long we keep it, and what rights you have. In short: we collect what we need to run the platform and be paid correctly, we do not sell personal data, and we do not use your data, your uploaded assets, or your agent traffic to train our own models.
This summary is for readability only. The full text below is what applies.
1. Who we are and what this covers
Origina operates the platform at www.origina.cloud. This policy explains how we handle personal data for which WE decide the purposes and means, principally personal data about our own users (people who register, sign in, and use the platform).
It does not cover personal data that you upload inside a dataset or send through an agent. For that data you are the controller and we act only as your processor on your instructions, those arrangements are governed by our Data Processing Agreement, not this policy.
If anything here is unclear, contact us at hello@origina.cloud before relying on it.
2. The two roles: controller and processor
For personal data about our own users, names, emails, logins, usage of the platform, we are the "controller": we decide why and how it is processed, and this policy applies.
For personal data contained in a customer's uploaded assets or agent traffic, the customer is the controller and we are the "processor": we act only on their documented instructions. Keeping these roles separate is deliberate, and it is why this policy and the Data Processing Agreement are two different documents.
3. Personal data we collect
Account and profile data: your name, email address, a hash of your password (never the password itself), and the organizations you belong to and your role in each.
Authentication data: session records, and, where you sign in with Google, GitHub, or Microsoft, the identifier and email address that provider returns to us. We do not receive your password for those services.
Organization and relationship data: memberships, invitations you send or accept, and API keys or Machine Identities issued from your account (we store only a non-recoverable hash of the secret).
Usage and transaction data: which assets you access, licences you request, grant, or hold, metered usage events, token ledger entries, invoices, and royalty statements.
Technical and device data: IP address and user agent, captured chiefly on security-relevant actions such as login, credential use, and acceptance of legal documents.
Communications: messages you send us (for example, support requests) and records of service notifications we send you.
Payment data: handled by our payment processors. We receive transaction references, amounts, and status, never full card numbers.
4. How we collect it
Directly from you, when you register, create or join an organization, list or license an asset, or contact us.
Automatically, as you use the platform, usage events, technical data, and security logs generated by your activity.
From third parties acting for you or for us: an OAuth provider you choose to sign in with, and our payment processors, which return transaction information to us.
5. Cookies and similar technologies
We use cookies and equivalent local storage that are strictly necessary to run the platform, principally to keep you signed in and to protect against abuse. Without these the service cannot function.
6. Why we use it, and our lawful basis
To provide the platform and your account, performance of our contract with you.
To meter usage, compute royalties, issue invoices, and process payments and payouts, performance of contract, and our legitimate interest in being paid and paying creators correctly.
To secure the platform, including authentication, rate limiting, fraud prevention, and audit logging, our legitimate interest in preventing abuse, and in some cases a legal obligation.
To send service communications such as licence requests, invitations, security alerts, and password resets, performance of contract.
To comply with legal, tax, and accounting obligations, legal obligation.
Where we rely on legitimate interests, we have weighed them against your rights; you may object, as described in Section 11.
7. What we do not do
We do not sell personal data, and we do not share it for cross-context behavioural advertising.
We do not use your personal data, your uploaded assets, or your agent traffic to train our own models.
We do not disclose an asset owner's endpoint URL or credentials to licensees; gateway calls are proxied precisely so this is never necessary.
8. Who we share it with
Service providers (subprocessors): infrastructure and hosting, database and object storage, email delivery, and payment processors, each only to the extent needed to perform their function for us, and under contract that restricts their use of the data.
Other platform users, only to the extent inherent in what you choose to do: an organization you request a licence from will see who requested it and the details of that request.
Authorities and advisors, where genuinely required by law or to establish, exercise, or defend legal claims.
A successor entity, if the business is merged, acquired, or its assets sold, subject to this policy or a materially equivalent one.
9. International transfers
Our infrastructure is currently hosted in the European Union. Some subprocessors may process limited data elsewhere.
10. How long we keep it
Account and profile data: for as long as your account exists, and afterwards only where we must, for example, transaction and tax records kept for the statutory period.
Audit logs and legal-acceptance records: retained as evidence of what happened and what was agreed, including after account closure, because their whole value is that they cannot be quietly erased.
Security logs: retained for a limited period appropriate to detecting and investigating abuse.
When a retention period ends, we delete or anonymise the data.
11. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, to object to processing based on legitimate interests, and to withdraw consent where we relied on it.
Some data cannot be deleted on request where we have an overriding legal obligation to keep it, such as financial and tax records; we will tell you when that is the case.
To exercise any of these, contact hello@origina.cloud. We will respond within the time the law requires. You also have the right to complain to your local data protection authority.
12. US state privacy rights
If you are a resident of a US state with a comprehensive privacy law (such as California), you may have rights to know, access, correct, and delete personal information, and to opt out of its sale or sharing. As stated above, we do not sell personal information or share it for cross-context behavioural advertising.
13. Children
The platform is for organizations and professional users. It is not directed to children, and you must be at least 18 to use it. We do not knowingly collect personal data from children; if you believe a child has provided us data, contact us and we will delete it.
14. Automated processing
We compute Trust Reports, Testbed scores, and search rankings automatically from evidence and usage. These describe assets, not people, and they do not make decisions that produce legal or similarly significant effects about you.
We use automated checks for security and fraud prevention (for example, rate limiting). Where such a measure would significantly affect you, a person can review the outcome on request.
15. Security
Passwords are hashed, never stored in plain text. API keys and agent credentials are stored only in a non-recoverable or encrypted form. Access to organization data requires authentication and verified membership of that specific organization. Sensitive actions are rate limited and recorded in an append-only audit log.
No system is perfectly secure. If a personal-data breach is likely to affect your rights, we will notify you and the relevant authority as and when the law requires.
16. Changes and contact
We may update this policy. We will notify you of material changes, and each version is retained separately so you can see what changed and when.
Questions, or to exercise a right: hello@origina.cloud.
Questions about this document? Contact hello@origina.cloud
Back to top ↑