PRIVACY POLICY

Effective 16 July 2026 · Last updated 16 July 2026
This Privacy Notice for Org AI LLC ("we," "us," or "our") describes how and why we access, collect, store, use, and share ("process") personal information when you use our services (the "Services"), including when you:
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have questions, contact us at support@organization.ai.

SUMMARY OF KEY POINTS

This summary provides key points from our Privacy Notice. Use our table of contents to find the section you are looking for.
We act in two different roles. For our websites and your account, we decide how information is used. For the content your organization brings into its Company Brain, we act only on that organization's instructions. Learn more about our role and the scope of this notice.
What personal information do we process? Depending on how you interact with us, this may include your account and contact details, billing details, and technical information about your use of our own Services. Learn more about personal information you disclose to us.
Do we process sensitive personal information? Yes, in limited cases and only where necessary to provide the Services. Learn more about sensitive information we process.
Do we train AI models on your data? No. We do not use your content or personal information to train or fine-tune AI models. Where we send a request to an AI provider through our own account, we configure the controls that provider offers and rely on the terms that apply to our use of it so that submitted content is not used to train or improve its models. Learn more in artificial intelligence-based products.
In what situations and with which parties do we share personal information? With a defined set of service providers who help us run the Services. Learn more about when and with whom we share your personal information.
How do we keep your information safe? We use encryption, key management, tenant isolation, and clearance-based access controls. No system can be guaranteed 100% secure. Learn more about how we keep your information safe.
What are your rights? Depending on where you are located, you may have rights of access, correction, deletion, portability, and objection. Learn more about your privacy rights.
How do you exercise your rights? Visit https://organization.ai/privacy/data-request or contact us.

TABLE OF CONTENTS

1. SCOPE OF THIS NOTICE AND OUR ROLE
2. WHAT INFORMATION DO WE COLLECT?
3. HOW DO WE PROCESS YOUR INFORMATION?
4. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?
5. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
6. INTERNATIONAL TRANSFERS OF INFORMATION
7. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
8. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
9. HOW DO WE HANDLE YOUR SOCIAL LOGINS?
10. HOW LONG DO WE KEEP YOUR INFORMATION?
11. HOW DO WE KEEP YOUR INFORMATION SAFE?
12. DO WE COLLECT INFORMATION FROM MINORS?
13. WHAT ARE YOUR PRIVACY RIGHTS?
14. CONTROLS FOR DO-NOT-TRACK AND GLOBAL PRIVACY CONTROL
15. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
16. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
17. DO WE MAKE UPDATES TO THIS NOTICE?
18. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
19. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

1. SCOPE OF THIS NOTICE AND OUR ROLE

In Short: We act as a controller for our websites and your account. For the content your organization puts into its Company Brain, we act as a processor on that organization's instructions, and that organization's own privacy notice applies.
Org AI LLC provides an agentic collaboration platform to business customers. Their people use it to search and reason over their organization's own knowledge (the "Company Brain"). Our processing falls into two distinct roles, and it matters which one applies to you.

(a) Where we act as a controller

We decide the purposes and means of processing for information about visitors to our websites, people who sign up or hold an account, billing and administrative contacts, people who apply for a job with us, and people who contact us. This Privacy Notice describes that processing.

(b) Where we act as a processor

"Customer Content" means the documents, files, messages, and other material that a customer organization chooses to bring into its Company Brain, whether uploaded directly, created on our platform, or ingested from an application that the customer connects (for example Google Workspace, Microsoft 365, Slack, Notion, Dropbox, GitHub, or a CRM). Customer Content may contain personal information about people who never signed up with us, such as a customer's own employees, clients, suppliers, or contacts.
For Customer Content, the customer organization is the controller. It decides what is connected and ingested, who inside the organization may see it, what is shared with AI providers, and how long it is kept. We process Customer Content only on that customer's documented instructions, under our Data Processing Agreement (DPA). The same applies to visitors who use an answer surface that a customer chooses to embed on the customer's own website.
If your personal information appears inside a customer's Company Brain and you want to access, correct, or delete it, please contact that organization directly, as they control it. If you contact us, we will refer you to them and support them in responding. Their own privacy notice, not this one, governs that processing.

2. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

In Short: We collect personal information that you provide to us.
We collect personal information that you voluntarily provide when you register, express an interest in our products, participate in activities on the Services, or contact us. What we collect depends on how you interact with us:
Sensitive Information. Where necessary to provide the Services, with your consent or as otherwise permitted by applicable law, we process the following categories of sensitive information:
We do not collect credit-worthiness data, and we do not process sensitive personal information in order to infer characteristics about you.
Payment Data. We collect data necessary to process your payment if you make a purchase, such as your payment instrument number and its security code. All payment data is handled and stored by Stripe. You may find their privacy notice here: https://stripe.com/privacy.
Social Media Login Data. You may register using an existing account with an identity provider we support. See "HOW DO WE HANDLE YOUR SOCIAL LOGINS?" below.
Customer Content. Content brought into a Company Brain is processed in our role as a processor. See "SCOPE OF THIS NOTICE AND OUR ROLE".
All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes.

Information automatically collected

In Short: Some information, such as your IP address and browser or device characteristics, is collected automatically when you use our Services.
We automatically collect certain information when you visit, use, or navigate our Services. It is primarily needed to maintain the security and operation of the Services and for our internal analytics and reporting. It includes:
Where we collect it. We collect this information on our own websites and applications, and on pages or surfaces that a customer organization chooses to create or embed on our platform. We do not track you across websites we do not operate, and we do not build cross-site advertising profiles.
Location. We do not collect device location data. We do not use GPS or equivalent precise-location technology. Where a customer selects a storage region for their data, that is a preference they set, not a measurement of where you are.

Google API

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google Workspace data to train or improve generalized AI or machine-learning models. Where such data is processed by an AI provider, it is only to deliver a feature the user has asked for, as described in "DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?". Equivalent commitments apply to the other platforms we connect to, including Microsoft 365, Slack, Notion, Dropbox, and GitHub.

Information collected from other sources

In Short: We may collect limited business contact data from public databases, marketing partners, and other outside sources.
To provide relevant marketing and to keep our records up to date, we may obtain business information from public databases, joint marketing partners, affiliate programs, data providers, and other third parties. This includes mailing addresses, job titles, email addresses, phone numbers, and company-level interest signals used for business marketing and event promotion.
These signals are about organizations and their likely interest in business software. We do not use them to build a behavioural profile of you as an individual, and we do not infer personal characteristics from them.

3. HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.

4. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?

In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason to do so.
If you are located in the EU or UK, this section applies to you.
The GDPR and UK GDPR require us to explain the legal bases we rely on:
If you are located in Canada, this section applies to you.
We may process your information with your express consent, or where consent can be inferred (implied consent). You can withdraw your consent at any time. In limited cases, applicable law permits processing without consent, for example for investigations, fraud detection and prevention, certain business transactions, or where disclosure is required to comply with a subpoena, warrant, or court order.

5. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In Short: We share information with a defined set of service providers who help us run the Services, each under a written contract. We do not sell your personal information.

Our service providers (sub-processors)

We engage the following categories of service providers. Each acts on our instructions under a written contract that restricts their use of the information to providing services to us.
CategoryProviderWhat they process
InfrastructureAmazon Web Services (AWS) infrastructure servicesOur primary infrastructure: hosting and compute, file and document storage, key management and encryption, databases, and outbound email delivery
Application deliveryCloudflareDelivery and protection of our websites and application; connection metadata such as IP address
DatabasePlanetScaleAccount, workspace, and configuration data
Search indexQdrantVector representations (embeddings), short text excerpts, and related metadata used to search a Company Brain
ConnectorsPipedreamAuthorizing and retrieving data from applications a customer chooses to connect
PaymentsStripePayment and billing information
AnalyticsGoogle Analytics, Google Tag ManagerUsage analytics on our own websites and platform-hosted pages
AI providersSee "DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?"Text submitted for an AI feature, and the resulting output
Our full Sub-processor List, which names each sub-processor, what it processes, and where it processes it, and describes how we notify customers of changes, is available separately. We maintain it and will update this Notice when it changes materially.

Other situations in which we may share information

Reviews, case studies, and user stories

We may publish reviews, case studies, and user stories about how our Services are used. Where we do, the material is pseudonymized and aggregated, and it does not identify a customer organization or an individual, unless that organization has separately and explicitly agreed to be named.

6. INTERNATIONAL TRANSFERS OF INFORMATION

In Short: We are based in the United States and use service providers in several countries, so your information may be transferred outside your country. Choosing a storage region is an operational option, not a data-localization guarantee.
Org AI LLC is established in the United States. Our service providers and AI providers are located in the United States and other countries. As a result, personal information may be transferred to, stored in, and processed in countries other than the one you live in, and those countries may have data protection rules that differ from those in your country.
Where we transfer personal information out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards recognized under applicable law, such as the European Commission's Standard Contractual Clauses (and the UK Addendum where relevant), together with supplementary technical measures including encryption in transit and at rest.
About storage regions. We offer customers the ability to choose a home region for storing their data. We provide this primarily as an operational and cost feature: keeping data close to where it is used reduces latency and data-transfer (egress) costs. We do not offer it as a data-localization or regulatory-compliance guarantee. Even where content is stored in a chosen region, processing may take place elsewhere. In particular, when an AI feature is used, the text submitted for that feature is sent to an AI provider that may process it in another country, most commonly the United States.

7. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

In Short: We use cookies and similar technologies to run the Services and to understand how they are used.
We use cookies and similar technologies (such as web beacons and pixels) when you interact with our Services. Some are strictly necessary: they keep the Services and your account secure, prevent crashes, save your preferences, and support basic site functions.
We also use analytics technologies to understand how our Services are used so we can improve them. We use these on our own websites and applications, and on pages or surfaces a customer chooses to create or embed on our platform. We do not use them to track you across websites we do not operate.
Where required by applicable law, we ask for your consent before setting non-essential cookies, and you can change your choice at any time. Specific information about the technologies we use and how to refuse them is set out in our Cookie Notice.

Google Analytics

We may share information with Google Analytics to track and analyze the use of the Services. To opt out of being tracked by Google Analytics, visit https://tools.google.com/dlpage/gaoptout. For more information on Google's privacy practices, see the Google Privacy & Terms page.

8. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?

In Short: Yes. We use third-party AI providers to power features you ask for. We do not train AI models on your data, and we do not allow our providers to do so.
As part of our Services we offer products and features powered by artificial intelligence and machine learning ("AI Products"), including search and question answering over a Company Brain, summarization, translation, classification, transcription, and document, image, and audio generation.

We do not train models on your data

We do not use Customer Content or your personal information to train, fine-tune, or improve AI models, whether our own or those of any third party. For requests we send to an AI provider through our own account, we configure the controls that provider makes available and rely on the terms that apply to our use of it, so that content we submit is not used to train or improve its models. Content is sent only to produce the output for the specific request being made. Where you use your own AI provider account (see below), that provider's own terms govern instead, and they may permit training.

Our AI providers

We provide AI Products through the following third-party AI service providers: Anthropic, OpenAI, Google Cloud AI, Microsoft Azure AI, Amazon Bedrock, Together.ai, Groq, Hugging Face, Perplexity, xAI, DeepSeek, and OpenRouter. Which provider handles a given request depends on the feature and on the configuration chosen by your organization.
OpenRouter is an aggregator. Where a request is routed through OpenRouter, OpenRouter forwards it to a further model host to produce the output, and that onward host processes the submitted text under its own terms. Our configuration reaches the aggregator, not the onward host. If you would rather requests were not routed through an aggregator, your administrators can disable OpenRouter for your organization.

What is sent to an AI provider

Content is not sent to an AI provider merely because it exists in a Company Brain. It is sent when someone uses an AI feature, and only what is needed to answer that request:
An organization's administrators control which sources are connected, which AI providers are enabled, and who may use AI features, and can restrict or disable them.

Using your own AI provider account (BYOK)

A customer organization may choose to supply its own AI provider API key ("bring your own key"). Where it does:

9. HOW DO WE HANDLE YOUR SOCIAL LOGINS?

In Short: If you register or log in using a third-party account, we receive limited profile information from that provider.
You can register and log in using an existing account with an identity provider we support. We currently support Google, Microsoft, and Slack, and we expect to support further providers, including Facebook and X, in future.
Where you choose to do this, we receive certain profile information from that provider, which typically includes your name, email address, and profile picture. We use it only for the purposes described in this Privacy Notice, principally to create and secure your account. We do not post to your account, and we do not import your contacts or friend lists.
We do not control, and are not responsible for, other uses of your personal information by that provider. We recommend that you review their privacy notice.

10. HOW LONG DO WE KEEP YOUR INFORMATION?

In Short: You control your content and can delete it. After deletion we hold it for a short grace period so it can be recovered, then it is removed automatically. Transaction records are kept for as long as the law requires.

Content and account data you control

You can delete your documents, member records, and user data, and you can delete your account. When you do:

Records we must keep

We retain transaction records, including billing and payment records, for as long as required for revenue, tax, anti-money-laundering, and fraud-prevention reporting under the laws of the jurisdictions in which we operate. These periods are set by law and are typically several years. Where we must retain such records, we keep only what is required for that purpose.
When we have no ongoing legitimate need to process personal information, we delete or anonymize it. Where that is not immediately possible, for example because it sits in a backup, we securely store it and isolate it from further processing until deletion is possible.

11. HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short: We use encryption, managed key custody, tenant isolation, and clearance-based access controls. No system can be guaranteed to be completely secure.
We have implemented technical and organizational measures designed to protect the information we process, including:
Despite these safeguards, no electronic transmission over the internet and no information storage technology can be guaranteed to be 100% secure. We cannot promise that unauthorized third parties will never defeat our security. You should access the Services within a secure environment.

If something goes wrong

We maintain procedures to detect, investigate, and respond to security incidents. If a security breach affects your personal information, we will notify you and the relevant supervisory authorities where, and within the timeframes, required by the laws that apply to that breach. Where we act as a processor for a customer organization, we will notify that organization without undue delay so that it can meet its own obligations.

12. DO WE COLLECT INFORMATION FROM MINORS?

In Short: We do not knowingly collect data from or market to children under 18 years of age.
We do not knowingly collect, solicit data from, or market to children under 18 years of age, or the equivalent age specified by law in your jurisdiction, nor do we knowingly sell such personal information. By using the Services, you represent that you are at least 18, or the equivalent age in your jurisdiction. If we learn that personal information from a user under that age has been collected, we will deactivate the account and take reasonable measures to promptly delete such data. If you become aware of any data we may have collected from a child, please contact us at support@organization.ai.

13. WHAT ARE YOUR PRIVACY RIGHTS?

In Short: Depending on where you are located, you may have rights that give you greater access to and control over your personal information.
In some regions, including the EEA, UK, Switzerland, and Canada, you have certain rights under applicable data protection laws. These may include the right to: request access to and obtain a copy of your personal information; request rectification or erasure; restrict processing; data portability; and not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. If such a decision were ever made solely by automated means, we will inform you, explain the main factors, and offer a simple way to request human review. In certain circumstances you may also object to processing. You can make a request by visiting https://organization.ai/privacy/data-request or by contacting us using the details in "HOW CAN YOU CONTACT US ABOUT THIS NOTICE?".
If your personal information is held inside a customer organization's Company Brain, that organization controls it. Please direct your request to them; see "SCOPE OF THIS NOTICE AND OUR ROLE".
We will consider and act upon any request in accordance with applicable data protection laws.
If you are located in the EEA or UK and believe we are unlawfully processing your personal information, you have the right to complain to your Member State data protection authority or the UK Information Commissioner's Office. If you are located in Switzerland, you may contact the Federal Data Protection and Information Commissioner.
Withdrawing your consent. Where we rely on your consent, you may withdraw it at any time by contacting us or updating your preferences. This will not affect the lawfulness of processing before withdrawal, nor processing carried out on another lawful basis.
Opting out of marketing communications. You can unsubscribe at any time using the link in our emails, by replying "STOP" or "UNSUBSCRIBE" to an SMS, or by contacting us. You will then be removed from our marketing lists. We may still send you service-related messages necessary for the administration of your account.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Sharing with subcontractors who provide support services, such as customer service, is permitted. Text messaging originator opt-in data and consent are never shared with third parties.

Account Information

To review or change the information in your account, or to terminate your account, log in to your account settings. On termination we will deactivate and delete your account and information as described in "HOW LONG DO WE KEEP YOUR INFORMATION?".
Cookies and similar technologies. Most browsers accept cookies by default. You can usually set your browser to remove or reject cookies, though this may affect certain features of the Services.
If you have questions about your privacy rights, email us at support@organization.ai.

14. CONTROLS FOR DO-NOT-TRACK AND GLOBAL PRIVACY CONTROL

Most web browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature you can activate to signal a preference not to have your online browsing activities monitored. No uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals. If a standard is adopted that we must follow, we will inform you in a revised version of this Privacy Notice. California law requires us to disclose how we respond to DNT signals; because no industry or legal standard exists, we do not respond to them at this time.
Global Privacy Control. We recognize and strive for adherence to the Global Privacy Control (GPC) standard. Where we detect a GPC signal from your browser, our aim is to treat it as a valid request to opt out of the sale or sharing of your personal information for targeted advertising purposes under applicable state privacy laws, including the California Consumer Privacy Act (CCPA), and to apply that preference without requiring further action from you. We are actively working to extend GPC support across all of our surfaces, and this Notice will be updated as that work completes. You can always exercise the same choices directly by visiting https://organization.ai/privacy/data-request or contacting us. For more information about GPC, visit globalprivacycontrol.org.

15. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

In Short: If you are a resident of California, Colorado, Connecticut, Delaware, Florida, Indiana, Iowa, Kentucky, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Rhode Island, Tennessee, Texas, Utah, or Virginia, you may have the right to request access to and details about the personal information we maintain about you, correct inaccuracies, obtain a copy of it, or delete it.

Categories of Personal Information We Collect

The table below shows the categories of personal information we have collected in the past twelve (12) months. For a full inventory, see "WHAT INFORMATION DO WE COLLECT?"
CategoryExamplesCollected
A. IdentifiersContact details, such as real name, alias, postal address, telephone or mobile contact number, unique personal identifier, online identifier, Internet Protocol address, email address, and account nameYES
B. Personal information as defined in the California Customer Records statuteName, contact information, education, employment, employment history, and financial informationYES, optional (see note 1)
C. Protected classification characteristics under state or federal lawGender, age, date of birth, race and ethnicity, national origin, marital status, and other demographic dataNO
D. Commercial informationTransaction information, purchase history, financial details, and payment informationYES (see note 2)
E. Biometric informationFingerprints and voiceprintsNO
F. Internet or other similar network activityBrowsing history, search history, online behavior, interest data, and interactions with our and other websites, applications, systems, and advertisementsYES, limited (see note 3)
G. Geolocation dataDevice locationNO
H. Audio, electronic, sensory, or similar informationImages and audio, video or call recordings created in connection with our business activitiesNO
I. Professional or employment-related informationBusiness contact details in order to provide you our Services at a business level or job title, work history, and professional qualifications if you apply for a job with usYES
J. Education InformationStudent records and directory informationNO
K. Inferences drawn from collected personal informationInferences drawn from any of the collected personal information listed above to create a profile or summary about an individual's preferences and characteristicsNO
L. Sensitive personal informationAccount login information, contents of email or text messages, and debit or credit card numbersYES
Note 1 (Category B). We collect this only where you choose to provide it, in line with our Terms. It is optional and is not required to use the Services.
Note 2 (Category D). Transaction and payment information is processed through our third-party payment provider, Stripe, in order to bill for the Services. We do not store card numbers ourselves.
Note 3 (Category F). We collect this only in relation to our own websites and applications, and to pages or surfaces a customer chooses to create or embed on our platform. We do not collect it from websites we do not operate, and we do not track you across other websites.
Sensitive personal information (Category L). We collect it only where necessary to provide the Services, and we do not use or disclose it to infer characteristics about you. You may have the right to limit its use or disclosure.
We may also collect other personal information outside of these categories when you interact with us in person, online, or by phone or mail, in the context of receiving support, participating in surveys, and the delivery of our Services.
We use and retain collected personal information as described in "HOW LONG DO WE KEEP YOUR INFORMATION?"

Sources of Personal Information

See "WHAT INFORMATION DO WE COLLECT?"

How We Use and Disclose Personal Information

See "HOW DO WE PROCESS YOUR INFORMATION?"
Will your information be shared with anyone else?
Yes. We disclose personal information to our service providers and contractors for business purposes, each under a written contract that limits them to performing services for us. The categories of recipients, and what they process, are listed in "WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?" Disclosures to a service provider or contractor for a business purpose are not a "sale" or "sharing" of personal information under applicable US state privacy laws.
We may also use your personal information for our own internal business purposes, such as internal research for technological development and demonstration. This is not a "sale" of your personal information.
We have not sold personal information, and we have not shared personal information for cross-context behavioral advertising, in the preceding twelve (12) months. We will not sell or share the personal information of website visitors, users, or other consumers.

Your Rights

You have rights under certain US state data protection laws. These rights are not absolute and in some cases we may decline a request as permitted by law. They include:
Depending on where you live, you may also have the right to: access the categories of personal data being processed; obtain a list of the categories of third parties, or the specific third parties, to which we have disclosed personal data; question how personal data has been profiled; and limit the use and disclosure of sensitive personal data.

How to Exercise Your Rights

Visit https://organization.ai/privacy/data-request, email us at support@organization.ai, or use the contact details at the bottom of this document. You may designate an authorized agent to make a request on your behalf; we may deny a request from an agent who does not submit proof of valid authorization.

Request Verification

We will verify your identity to confirm you are the person we hold information about. We will only use personal information provided in your request to verify your identity or authority. If we cannot verify your identity from information we already hold, we may request additional information for verification and fraud-prevention purposes.

Appeals

If we decline to act on your request, you may appeal by emailing support@organization.ai. We will inform you in writing of any action taken or not taken, and the reasons. If your appeal is denied, you may submit a complaint to your state attorney general.

16. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?

In Short: You may have additional rights based on the country you reside in.

Australia

We collect and process your personal information under the obligations and conditions set by Australia's Privacy Act 1988. This Privacy Notice satisfies the notice requirements defined in the Privacy Act: what personal information we collect, from which sources, for which purposes, and the other recipients of your personal information.
If you do not provide the personal information necessary for a purpose, it may affect our ability to offer you the products or services you want, respond to your requests, manage your account, or confirm your identity and protect your account.
You may request access to or correction of your personal information at any time using the details in "HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?". If you believe we are unlawfully processing your personal information, you may complain to the Office of the Australian Information Commissioner.

17. DO WE MAKE UPDATES TO THIS NOTICE?

In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.
We may update this Privacy Notice from time to time. The updated version will be indicated by an updated date at the top. If we make material changes, we may notify you by prominently posting a notice or by contacting you directly. We encourage you to review it frequently.

18. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

If you have questions or comments about this notice, email us at support@organization.ai or contact us by post at:
Org AI LLC
1007 N. Orange Street
4th Floor, Suite 1382
Wilmington, DE 19801
United States

19. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Based on the applicable laws of your country or state, you may have the right to request access to the personal information we collect from you, details about how we have processed it, to correct inaccuracies, or to delete it. You may also have the right to withdraw your consent. These rights may be limited in some circumstances by applicable law. To make a request, visit https://organization.ai/privacy/data-request.
If the information is held inside a customer organization's Company Brain, that organization controls it and you should direct your request to them. See "SCOPE OF THIS NOTICE AND OUR ROLE".