1. Scope
This Privacy Notice explains how Orthotropy Technology Co., Ltd. (正向演繹科技有限公司), registered in Taipei City, Taiwan, handles personal information on its websites and online service (the "Service"). The Service uses AI to process content you provide ("Customer Content") and generate content for you ("Output"). It is currently in Closed Beta, by invitation, and payment collection is not active. Future billing practices described here apply only when paid purchases become available.
We are the controller for personal information we use to manage Accounts, inquiries, website analytics, security, and our business obligations. Where we process personal information in Customer Content solely on a customer's instructions, that customer is the controller and we act as its processor under a data processing agreement where required. This notice does not replace that agreement or the customer's privacy notice. Contact us at hello@orthotropy.com if you need help identifying the responsible controller.
2. Information we collect
Sources are you, your device, chosen authentication providers, and, after billing launches, the Merchant of Record. Information about others may come from Customer Content or public sources used at a customer's direction. We provide legally required indirect-collection notices.
| Category | Examples | Purposes and recipients |
|---|---|---|
| Identifiers, contact and customer-record information | Name, email, Account and authentication identifiers, IP address | Accounts, support, security; hosting, authentication, support providers |
| Professional or employment information | Company, role | Inquiries and Service; hosting and support providers |
| Customer Content, Output and related personal information or inferences | Text, files, links, instructions, saved Output, information about people | Requested processing, support, security; hosting and AI providers |
| Internet or other network activity and approximate location | Device, browser, referrer, pages, Service activity, error/security logs, cookie/session identifiers, IP-derived region | Operation, security, website analytics; infrastructure and analytics providers |
| Commercial information | Plan, usage; after launch, orders, payment status, amounts, taxes, limited billing details | Paid access, billing support, legal records; infrastructure providers and Merchant of Record |
The table covers the preceding 12 months where activities were active. Beta creates no checkout, Subscription, or invoice records. Once billing launches, the Merchant of Record collects card details; we do not receive full card numbers.
Contact requests include optional name, email, message, topic, optional affected URL, route, campaign/sample attribution, receipt time, signed session/form-token data, and pseudonymous rate-limit keys derived from IP, email, and session data. Raw IP is processed transiently for the key, not stored in the lead record. Pseudonymous identifiers may remain personal information.
Authentication credentials or tokens are used for sign-in and security, not sensitive-characteristic inference. Without required Account, contact, or billing information, we may be unable to provide the related Service or respond. Optional fields and analytics may be declined without losing ordinary access.
3. Information you should not submit
Do not include passwords, private keys, API keys, access tokens, session cookies, card details, regulated health data, special-category or other sensitive information, or confidential third-party information unless a separate written agreement permits and safeguards processing.
Provide only needed information. For others' data, you must have a lawful basis, give required notices, and obtain consent where required. Our own data protection obligations remain.
4. How we use information
We provide access and AI processing, generate and store Output, authenticate users, manage Accounts and Plans, respond to inquiries and privacy requests, troubleshoot, prevent abuse, and meet legal obligations. Contact requests support Beta evaluation, Service suitability, requested collaborations, replies, form security, and operational records. Future billing data supports paid access, records, and refunds.
When we are controller and the GDPR or UK GDPR applies, relevant legal bases are:
- Contract or requested pre-contract steps: necessary individual Account administration, requested Service, purchases, and support.
- Legitimate interests: business inquiries, organization Accounts, security, abuse prevention, troubleshooting, and legal claims, balanced against your rights. Our content-improvement use follows Section 5.
- Legal obligation: duties under applicable EU or UK law. Other legal duties require an appropriate basis, such as legitimate interests where permitted.
- Consent: optional uses for which we separately request it. Withdrawal does not undo earlier lawful processing. Current website analytics behavior is described in Section 6.
Taiwan processing requires specific purposes and a basis permitted by its Personal Data Protection Act, such as a contractual or similar relationship with safeguards, informed consent, or legal duty. GDPR legitimate interests do not replace a Taiwan-law basis.
We send necessary Service and Account notices, not marketing email. Contact or access requests are not marketing consent. Customer-instructed processing follows its instructions and data processing agreement.
5. AI and automated processing
AI providers process the Customer Content needed for your request and generate Output. Errors and unsupported inferences are possible; review Output, particularly for high-stakes use. We do not use the Service for solely automated decisions about individuals with legal or similarly significant effects.
Orthotropy does not use Customer Content or Output to train or fine-tune its own models. Future such use requires separate, informed, active opt-in explaining the data, purpose, and withdrawal choices; refusal does not affect your Plan. Accepting Terms, submitting content, or choosing analytics is not that opt-in.
Our improvement use of Customer Content and Output is limited to support, error correction, and abuse prevention. Authorized personnel may review the minimum needed under confidentiality and access controls. General improvement may use genuinely anonymized usage statistics that identify neither you nor Customer Content or Output.
AI model providers process Customer Content and Output under their respective terms and policies, which may permit retention or use to operate and improve their services. We do not claim universal zero retention. See Sections 7–9 for providers, transfers, and retention.
We do not independently source login-gated, paywalled, private, or social-platform content for AI processing. Content you lawfully submit follows the handling described here.
7. Sharing and service providers
Information in Section 2 is disclosed for these purposes:
- Hosting, authentication, operations, support: Account/contact information, technical data, and content needed for hosting or support. Contact intake uses Google Cloud and Firebase; email delivery and the controlled mailbox may involve Resend and Gmail. Contact fields stay in the Google Cloud/Firebase path. Operational alerts contain only a random lead ID, topic, receipt time, and console link, not raw contact details or message text.
- AI processing: relevant Customer Content, Output, and technical request data. Providers include DeepSeek, Google (Gemini), OpenAI, and Anthropic. Their terms and policies govern the processing described in Section 5. Roles depend on the service and agreement: processing on our instructions is as processor or subprocessor; processing for purposes providers determine may be as independent controller.
- Analytics: Google receives analytics information under the current settings described in Section 6.
- Payments: after launch, the Merchant of Record collects payment/billing data and supplies limited transaction information. It independently controls its payment, tax, fraud-prevention, and legal processing under its checkout privacy notice.
- Legal/business recipients: authorities or advisers for lawful disclosures, investigations, or claims; business-transfer recipients under safeguards; and recipients you direct or consent to.
Providers processing on our instructions have applicable data protection, security, and deletion obligations. Other infrastructure providers appear on our Security page. Before adding providers handling affected personal information, we update disclosures and obtain required consent or customer authorization. Controller customers receive legally required subprocessor details and change notices under their data processing agreement.
Request relevant identities, locations, functions, retention terms, or transfer safeguards at hello@orthotropy.com. Statutory information does not require a confidentiality agreement.
We do not sell personal information or share it for cross-context behavioral advertising under California definitions, and have not done so in the preceding 12 months. Business-purpose disclosures above are distinct. We do not knowingly sell/share information about anyone under 16 or use sensitive information to infer characteristics.
8. International transfers
Your information may be processed outside your country, in the countries where we and our service providers operate, depending on the provider and routing. Those countries may have different data protection laws.
Before restricted transfers, we put legally required safeguards in place. EEA transfers use applicable adequacy decisions or European Commission Standard Contractual Clauses, destination-law assessments, and necessary supplementary measures. UK transfers use applicable adequacy regulations, the UK International Data Transfer Agreement, or UK Addendum to those clauses, with required assessments and safeguards. Accepting Terms or this notice is not routine-transfer consent. Without adequate safeguards, we do not make the restricted transfer. Taiwan transfers also follow applicable Personal Data Protection Act restrictions.
Request details or safeguard copies at hello@orthotropy.com; redactions of unrelated confidential information do not withhold your statutory information.
9. Retention
We retain information only as long as necessary for its stated purpose:
- Accounts, Plans, Customer Content and saved Output: as needed for requested Service. On closure or valid deletion requests, we delete or anonymize without undue delay, except limited retention for specific legal duties, unresolved claims, or necessary security. Processor return/deletion follows customer instructions and the data processing agreement.
- Contact intake: raw records and alert state are scheduled for deletion 180 days after receipt; rate-limit records 48 hours after last update; body-free application/security logs 30 days after creation. Deletion completes without undue delay. Converted Account records follow their own schedule without retaining all contact fields indefinitely.
- Other operational/security records: as needed for troubleshooting, documented incidents, or specific abuse prevention, with continuing-need review.
- Billing/legal records: required tax/accounting/legal periods, unresolved claims, and applicable limitation periods; these do not justify unrelated content retention.
- Analytics/provider copies: providers' retention follows the relevant service, settings, terms, policies, and contracts, including data used to operate or improve their services and security/legal exceptions. We request deletion where applicable; no common 30-day or zero-retention guarantee applies. Provider details are available under Section 7.
Backups are limited to recovery/security and removed through the documented overwrite schedule; restored deleted data is not returned to ordinary use. Deletion responses explain retained categories, reasons, and deletion/review criteria, subject to lawful exceptions. Beta does not restrict statutory rights. Contractual export depends on Plan; statutory rights do not.
10. Security
We use reasonable technical and organizational measures designed to protect information against unauthorized access, loss, misuse, or alteration, including restricted access and confidentiality requirements for authorized personnel and providers. We notify affected individuals and relevant authorities of a personal-data breach when and as required by applicable law.
No internet service is completely secure. Protect your Account credentials and access devices, and contact hello@orthotropy.com if you suspect unauthorized access.
11. Your choices and rights
Depending on applicable law, rights may include access/copies, correction, deletion or stopping collection/processing/use, restriction, objection, portability, and consent withdrawal. Portability requires its legal conditions. For legitimate-interest objections, we stop unless law permits compelling grounds or legal-claim processing. Withdrawal does not undo earlier lawful processing.
Email hello@orthotropy.com or use our privacy-request form, without needing a paid Plan, active Account, or export tool. We may proportionately verify identity and agent authority and protect others' information. Requests are ordinarily free; we explain legally permitted fees or refusals.
Applicable deadlines control. GDPR responses normally take one month, extendable by two more where justified and notified in the first month. UK responses normally take one month, subject to lawful extension/clarification rules. California know/delete/correct requests normally take 45 days, with another 45 where permitted and explained. Taiwan access/copy decisions take 15 days; correction, cessation, or deletion decisions take 30 days, with lawful extensions and reasons notified in writing. Any shorter applicable deadline controls.
You may complain to the relevant authority where you live, work, or an infringement occurred, or seek judicial remedies. EEA residents may use national supervisory authorities; UK residents may contact the ICO. Contacting us first is optional.
California and other US states. Applicable rights include requesting categories or specific information, sources, purposes, recipients, correction, deletion, portability; opting out of sale, sharing, targeted advertising, or qualifying profiling; and limiting sensitive-information use. We do not engage in those advertising/sale activities or significant-effect automated decisions. GPC is honored as an applicable opt-out and keeps analytics off. We do not discriminate for exercising rights. Where appeals are available, email "Privacy appeal" to hello@orthotropy.com; we respond within the statutory period and explain further complaint routes.
For customer-instructed processing, contact the controller customer or us; we assist and route requests. Your rights against our controller processing remain available.
12. Children
The Service is intended for adults using it for business or professional purposes. You must be at least 18 to register or use it. It is not directed to children, and we do not knowingly collect children's information for Accounts. If you believe a child has provided personal information, contact hello@orthotropy.com so we can address it under applicable law.
13. Changes
We may update this Privacy Notice. For material changes, we provide advance notice through the Service or email where we can contact you, and update the date above. We explain a new purpose before processing for that purpose and obtain fresh consent or another valid legal basis where required. Continued use alone is not consent to a new optional purpose. Urgent legally required changes may be notified as soon as reasonably possible. We review the notice at least annually, including California disclosures where applicable.
14. Contact
Contact Orthotropy Technology Co., Ltd. (正向演繹科技有限公司), registered in Taipei City, Taiwan, at hello@orthotropy.com or through the privacy-request form for questions, requests, complaints, provider details, or safeguards.
Where a local representative is legally required, we publish its identity/contact details alongside this notice before the processing requiring appointment. Read this with the Terms of Service.