TechStrata LLC, doing business as TechStrata (“TechStrata,” “we,” “us,” or “our”), provides enterprise AI workforce and systems services, including ORiele, TechStrata’s AI Workforce Execution Platform.
This Privacy Notice explains how TechStrata collects, uses, discloses, safeguards, and otherwise processes personal information when TechStrata determines the purposes and means of processing. This includes information collected through the TechStrata website, TechStrata-controlled forms and communications, events, sales and marketing activities, public demonstrations, and public-facing TechStrata or ORiele AI experiences.
TechStrata also processes data on behalf of business customers that deploy ORiele or other TechStrata services. In those circumstances, the business customer generally determines the purposes and means of processing, and TechStrata acts as a service provider, processor, or business associate, as applicable. Customer Data processed on behalf of a customer is governed primarily by the customer’s instructions, the applicable customer agreement, any Data Processing Addendum (“DPA”), any Business Associate Agreement (“BAA”), and the customer’s own privacy notice. This Privacy Notice provides transparency about that role but does not replace those agreements.
If a written agreement between TechStrata and a customer contains privacy, security, data-processing, retention, or compliance terms that differ from this Notice, the written agreement controls for that customer relationship to the extent of the conflict.
1. Scope and Our Data-Processing Roles
When TechStrata Acts for Itself
TechStrata acts as a business or data controller when we decide why and how personal information is processed for our own purposes. Examples include:
- operating and securing the TechStrata website;
- responding to inquiries, demo requests, and support requests;
- managing business contacts, prospects, customers, and events;
- operating TechStrata-controlled public AI demonstrations;
- administering accounts and business relationships;
- conducting permitted B2B marketing and communications;
- measuring website and campaign performance;
- preventing abuse, fraud, and security incidents; and
- complying with legal and regulatory obligations.
When TechStrata Processes Customer Data
When a business customer deploys ORiele or another TechStrata service, TechStrata may process data solely to provide the contracted service and carry out the customer’s authorized configuration and instructions. Depending on the deployment, Customer Data may include conversation content, voice or messaging data, workflow inputs, records retrieved from connected systems, data created or updated by configured workflows, operational logs, execution traces, support records, and other data necessary to perform the customer’s approved business processes.
In those circumstances, the customer controls the business purpose, source systems, integrations, user permissions, retention settings, workflow rules, and authorized actions. TechStrata processes Customer Data for the customer and does not acquire ownership of that data by providing the service.
If you interact with an ORiele agent deployed by a TechStrata customer, your relationship is primarily with that customer. The customer’s privacy notice explains how that customer uses your information. Requests concerning that customer’s use of your information should generally be directed to the customer. TechStrata will assist customers with valid privacy requests as required by applicable law and contract.
2. Information We Collect or Process
The information TechStrata collects or processes depends on how you interact with us and how a customer configures the Services.
A. Contact and Business Information
We may collect information such as:
- name;
- business email address;
- business telephone number;
- company name;
- job title or role;
- industry;
- business location;
- communication preferences; and
- information you provide when requesting a demo, resource, consultation, event registration, support, or other business interaction.
B. Communications and Inquiry Information
We may collect the content of communications you send to us, including messages submitted through forms, email, chat, or other channels, together with information necessary to respond to the request.
C. AI Interaction Data
When you interact with a TechStrata-controlled AI experience, we may process:
- text prompts and responses;
- conversation content;
- information voluntarily provided during the interaction;
- session context;
- structured fields captured by the agent;
- routing or workflow results;
- timestamps and interaction metadata; and
- quality, reliability, and diagnostic information associated with the interaction.
D. Voice, Messaging, and Call Data
Where voice, telephone, SMS, or similar communications are used, we may process:
- telephone numbers;
- call or message timestamps;
- call duration;
- call routing and delivery metadata;
- audio recordings where recording is enabled and lawful;
- call or message transcripts;
- delivery and response status; and
- technical information required to operate and troubleshoot the communication.
Recording and monitoring practices are subject to applicable law, the notice provided at the time of the interaction, and the applicable customer configuration or agreement.
E. Account, Administrative, and Customer Relationship Data
For customers, administrators, authorized users, and business contacts, we may process account identifiers, organization information, user roles, permissions, support history, contract-related information, billing contact details, and administrative records necessary to operate the relationship.
F. Connected-System and Integration Data
ORiele is designed to operate across authorized business systems. When a customer enables an integration, TechStrata may process information necessary to carry out the configured workflow, including information retrieved from or written to systems such as CRM, helpdesk, scheduling, commerce, communications, hospitality, healthcare, analytics, database, or other operational platforms.
Depending on customer configuration, this may include:
- customer or end-user records;
- account or case information;
- appointment, reservation, order, or ticket information;
- workflow status;
- notes and structured fields;
- task or ownership information;
- approved knowledge or document content;
- identifiers required to locate or update records; and
- the result of an authorized action taken through an integration.
The connected system remains subject to its own terms, privacy practices, permissions, and security controls.
G. Device, Website, and Usage Information
When you use our website or online services, we may collect:
- IP address;
- browser and device type;
- operating system;
- referring URL or source;
- pages viewed and links selected;
- timestamps and session information;
- approximate location derived from IP address;
- cookie or similar identifiers; and
- performance, security, and error information.
H. Information from Third Parties and Public Sources
We may receive business contact information from your organization, business partners, event organizers, service providers, public professional sources, or lawful B2B data sources. We may also receive engagement information from CRM, email, analytics, or business-development tools used to manage our relationship with you.
I. Sensitive and Regulated Information
TechStrata’s public website, public demonstrations, and ordinary sales or marketing interactions are not intended for unnecessary sensitive personal information. Do not submit government identifiers, financial credentials, passwords, medical information, or other highly sensitive information through a public TechStrata experience unless the experience expressly states that the information is required and is configured for that purpose.
This limitation does not mean that ORiele cannot support regulated business workflows. Customer-deployed services may process sensitive or regulated Customer Data, including protected health information (“PHI”), where the deployment, contract, customer configuration, and applicable compliance framework authorize that processing.
3. How ORiele Processes Data to Execute Work
ORiele is an AI Workforce Execution Platform. Depending on customer configuration, an ORiele agent may receive an interaction or system trigger, retrieve authorized context, apply approved knowledge and business rules, route work, request missing information, call an integration or API, create or update a record, schedule or book an action, initiate an approved communication, create a task or ticket, escalate an exception, or record the result of a completed workflow.
These actions are performed within the permissions, integrations, rules, and operational boundaries configured for the customer’s deployment. ORiele does not obtain independent authority over a customer’s connected systems merely because an integration is enabled.
Customers are responsible for determining which systems may be connected, which users and agents may access them, what actions may be performed, what data may be used, and where human approval or review is required.
4. How We Use Information
We use personal information and other data for purposes that include:
Providing and Operating the Services
We process information to provide website functionality, respond to requests, authenticate users, operate AI agents, maintain conversation and workflow context, execute customer-authorized actions, synchronize approved data with connected systems, deliver communications, and complete other functions requested by a user or customer.
Customer-Directed Workflow Execution
For customer deployments, we process Customer Data to carry out the customer’s documented instructions and configured business workflows. This may include reading data from connected systems, applying workflow rules, preparing or executing authorized system actions, routing exceptions, and recording completion or handoff information.
Reliability, Quality, and Support
We may use service data, logs, diagnostics, feedback, and appropriately controlled interaction records to troubleshoot issues, monitor reliability, investigate errors, support customers, evaluate agent behavior, validate workflow execution, and improve the safety and performance of the Services.
Security and Abuse Prevention
We process technical and usage information to authenticate access, enforce permissions, detect suspicious activity, prevent misuse, investigate potential attacks, protect systems and users, and maintain the confidentiality, integrity, and availability of the Services.
Analytics and Business Intelligence
We may use aggregated, statistical, or de-identified information to understand product performance, system reliability, feature adoption, operational trends, and website or campaign effectiveness. Where information is de-identified, we take reasonable measures designed to prevent it from being associated again with an identifiable individual except where permitted by law for validation or security purposes.
Business Communications and Marketing
We may use business contact information and engagement data to respond to inquiries, provide requested materials, manage events, communicate about products or services, follow up on demonstrated business interest, and conduct lawful B2B marketing. Marketing communications include an opt-out mechanism where required.
Legal, Compliance, and Corporate Purposes
We may process information to comply with law, respond to lawful process, enforce agreements, protect rights and property, investigate misconduct, maintain records required for compliance, and support a merger, financing, acquisition, reorganization, or sale of business assets subject to applicable safeguards.
5. Customer Data, AI Models, and Product Improvement
Customer Data is not a product that TechStrata sells or trades.
Unless a customer expressly agrees otherwise in writing, TechStrata does not use Customer Content submitted to or generated through a customer deployment to train generalized or foundation AI models for independent use outside that customer’s service relationship.
TechStrata may process Customer Data as necessary to provide, secure, support, maintain, and improve the contracted service for that customer, including troubleshooting, quality assurance, reliability testing, abuse prevention, and customer-requested optimization, subject to the applicable agreement and access controls.
Where third-party AI, communications, infrastructure, analytics, or other technology providers process Customer Data as part of the Services, TechStrata treats those providers as service providers or subprocessors as appropriate and subjects their access to applicable contractual, security, confidentiality, and data-protection requirements.
TechStrata may use aggregated or de-identified operational information that does not identify a customer end user to evaluate service reliability, security, capacity, and product performance, subject to contractual restrictions and applicable law.
6. How We Disclose Information
TechStrata discloses personal information only for legitimate business, service, legal, or customer-directed purposes.
Service Providers and Subprocessors
We may engage providers that support cloud infrastructure, AI processing, communications, identity, monitoring, analytics, CRM, customer support, security, payment administration, business operations, or other functions necessary to operate TechStrata and provide the Services.
These providers are permitted to process information only for the services they provide to TechStrata, subject to contractual and security obligations appropriate to their role.
For customer deployments, additional subprocessor terms or lists may be provided under the applicable customer agreement or DPA.
Customer-Directed Integrations
When a customer connects ORiele to an external system, data may be retrieved from or transmitted to that system to carry out the customer’s configured workflow. The customer determines which integration is enabled and is responsible for its authority to connect the system and instruct TechStrata to process the relevant data.
Business Partners
We may disclose information to a business partner where you request or authorize the disclosure, where necessary to deliver a jointly offered event or service, or where otherwise permitted by law. We do not provide personal information to unrelated third parties for their independent marketing without an appropriate legal basis or authorization.
Legal, Safety, and Rights Protection
We may disclose information when reasonably necessary to comply with law or legal process, respond to a lawful government request, protect the rights or safety of TechStrata, customers, users, or others, investigate fraud or security incidents, or enforce our agreements.
Corporate Transactions
Information may be disclosed in connection with a merger, acquisition, financing, due diligence process, reorganization, sale of assets, or similar transaction, subject to appropriate confidentiality and legal protections.
No Sale of Personal Information
TechStrata does not sell personal information for monetary consideration. TechStrata does not operate as a data broker. TechStrata also does not use Customer Data for cross-context behavioral advertising.
Mobile opt-in information and SMS consent are not sold or shared with third parties for their independent marketing purposes.
7. Security, Access, and Operational Controls
Security is part of the design and operation of TechStrata’s services. We use administrative, technical, and organizational safeguards designed to protect personal information and Customer Data against unauthorized access, acquisition, alteration, disclosure, destruction, or misuse.
Depending on the service and deployment, these safeguards include controls such as:
- encryption of data in transit;
- encryption of stored data where supported by the service architecture;
- identity and authentication controls;
- role-based and least-privilege access;
- multi-factor authentication for appropriate privileged access;
- scoped permissions for integrations and connected systems;
- controlled handling of secrets, credentials, and service tokens;
- separation of customer environments and access boundaries where applicable;
- logging, monitoring, and audit trails;
- operational and security event monitoring;
- vulnerability management and security testing;
- secure software-development and change-management practices;
- backup, resilience, and recovery controls;
- incident-detection and incident-response procedures;
- confidentiality obligations and security responsibilities for personnel; and
- vendor and subprocessor risk management.
TechStrata personnel do not access Customer Data as a routine business practice. Human access, where technically or operationally necessary, is limited to authorized personnel with a legitimate need for purposes such as customer-authorized support, security investigation, service maintenance, incident response, compliance, or other permitted service operations. Such access is subject to applicable controls, confidentiality obligations, and internal procedures.
TechStrata’s security and control environment is assessed through SOC 2. TechStrata maintains a SOC 2 report covering the systems and controls within the scope identified in that report. Security and compliance documentation may be made available to eligible customers or prospects under appropriate confidentiality terms.
No system connected to the internet can be guaranteed absolutely secure. TechStrata therefore maintains a risk-based security program designed to prevent incidents, reduce exposure, detect abnormal activity, and respond appropriately if an incident occurs.
8. HIPAA and Regulated Healthcare Deployments
TechStrata supports HIPAA-regulated healthcare deployments for eligible services and configurations. Where TechStrata acts as a business associate and processes PHI on behalf of a covered entity or another business associate, the parties must enter into an applicable BAA before PHI is processed through the covered deployment.
For such deployments, TechStrata processes PHI only as permitted by the applicable agreement, BAA, customer instructions, and law, and applies administrative, technical, and organizational safeguards appropriate to the covered service.
HIPAA compliance is a shared responsibility. Customers remain responsible for determining whether their use of the Services is subject to HIPAA, using only eligible configurations and integrations for PHI, maintaining required policies and access controls, providing lawful notices and authorizations, and configuring workflows consistent with their own compliance obligations.
Public TechStrata demonstrations and ordinary marketing interactions should not be used to submit PHI unless TechStrata expressly identifies the specific experience as eligible for that purpose.
9. Data Retention and Deletion
TechStrata retains information only for as long as reasonably necessary for the purpose for which it was collected or processed, to provide the Services, maintain security and business records, comply with law, resolve disputes, or enforce agreements.
Retention periods vary by data type and context.
- Website and business-contact information may be retained while a business relationship or legitimate business purpose continues and thereafter as necessary for legal, compliance, recordkeeping, or suppression-list purposes.
- Public AI interaction records, call recordings, and transcripts are retained according to the needs of the applicable public experience, quality and security requirements, and applicable law.
- Customer Data is retained according to the customer’s agreement, service configuration, retention settings where available, and applicable legal requirements.
- Security logs, operational telemetry, and audit records may be retained for periods appropriate to security, reliability, fraud prevention, investigation, compliance, and contractual obligations.
- Backup copies may persist for a limited period after deletion from active systems until backup cycles expire, unless preservation is required by law.
At the end of a customer relationship, Customer Data is returned, deleted, or retained as provided in the applicable agreement and law.
10. Cookies, Analytics, and Privacy Signals
TechStrata may use cookies and similar technologies to operate the website, remember preferences, maintain security, understand site performance, measure engagement, and improve user experience.
These technologies may include:
- essential technologies required for security or functionality;
- preference technologies that remember settings;
- analytics technologies that help us understand website usage; and
- marketing technologies where lawfully deployed and appropriately disclosed.