Burón Privacy Policy

Effective Date: 18th July 2025

1. Introduction

Orion Technologies (KVK-nummer: 96085703) ("Burón", "we", "us", "our") is committed to protecting your privacy and handling your personal data transparently. This Privacy Policy explains how we collect, use, share, and safeguard your information when you interact with our website, platform, and related services. It also outlines your rights and choices regarding your data.

This policy applies to visitors, users, and customers globally, regardless of where you access our services.

2. What Data We Collect

We collect information in these categories:

A. Information You Provide

Account and Contact Information: Name, email address, company, password, and other details provided during sign-up, registration, or communications.

Billing and Payment: If you purchase services, we collect billing and payment information via secure third-party providers.

Content and Inputs: Data and files you upload or process through our platform, including marketing data, queries, and AI-related inputs.

Support and Feedback: Information you provide when contacting support, requesting demos, or submitting feedback.

B. Data Collected Automatically

Device and Usage: IP address, browser type, device information, operating system, referral source, interaction data, and event logs.

Cookies and Tracking Technologies: Session and persistent cookies, pixels, and similar technologies for authentication, analytics, optimization, and marketing (see Section 7 below).

Location Data: Approximate geolocation inferred from your IP for security and product improvement.

C. Third-Party and Integration Data

Connected Accounts: Data imported from integrated marketing or analytics platforms (e.g. BigQuery, Snowflake, Google Ads, Meta), subject to your configuration and authorizations.

AI Vendors: If AI features are used, your inputs may be processed by third-party AI providers for model inference. We do not use your data to train models unless you opt in.

We do not knowingly collect sensitive personal data (such as health, genetic, or religious data), nor do we target or knowingly collect data from children under 16.

3. How We Use Your Data

Your data is used for the following purposes:

Service Delivery: To create and manage your account, authenticate users, provide platform functionality, deliver customer support, and process transactions.
Legal basis: Contract performance and legitimate interest

Analytics and Improvement: To monitor usage, optimize features, diagnose issues, and improve our services.
Legal basis: Legitimate interest

Communications: To send service notifications, updates, security alerts, and (with your consent) marketing materials. You may unsubscribe at any time.
Legal basis: Contract performance (service communications), Consent (marketing)

Security and Compliance: To detect, investigate, and prevent fraud, abuse, or violations of our terms; to comply with legal obligations.
Legal basis: Legal obligation and legitimate interest

Research and Development: To analyze trends, develop new features, and maintain platform integrity.
Legal basis: Legitimate interest

Legal and Contractual: To fulfill contractual obligations and legal requirements.
Legal basis: Legal obligation and contract performance

Legitimate Interest Assessment: Where we rely on legitimate interest, we have assessed that our legitimate business needs do not override your fundamental rights and freedoms. You have the right to object to processing based on legitimate interest.

We may aggregate or de-identify data for research, product development, or statistical purposes.

4. Data Sharing and Disclosure

We may share your data in the following circumstances:

Service Providers: With vendors and subprocessors who deliver infrastructure, hosting, AI processing, analytics, payment processing, customer support, or other operational services. These parties are contractually required to process data only as instructed and maintain security.

Current service providers include:

  • Vercel (hosting and infrastructure)
  • Upstash/Redis (data caching)
  • Neon (database services)
  • OpenAI, Google Cloud Platform/Gemini, Anthropic (AI processing)
  • Resend (email communications)
  • Mixpanel (analytics)
  • Stripe (payment processing)

Note: This list of service providers may be updated as we add or remove services. We recommend checking this policy periodically for changes.

AI Processing: When you use AI features, your inputs are processed by third-party AI providers (OpenAI, Google Gemini, Anthropic) for model inference. We do not use your data to train AI models unless you explicitly opt in.

Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets.

Legal and Regulatory: When required by law, subpoena, government request, or to protect the rights, safety, or property of Burón, our customers, or others.

Affiliates and Group Companies: For operational purposes consistent with this policy.

With Your Consent: When you instruct us to share data (e.g., via integrations or team features).

We select service providers committed to robust security and privacy controls, and restrict data use to the specific services requested.

Note: Where AI vendors process your data, we select providers committed to robust security and privacy controls, and restrict use to your requested AI operations.

5. International Data Transfers

Your information may be processed in countries outside your own, including in the EU, UK, and United States. Where required, we use approved transfer mechanisms such as Standard Contractual Clauses to safeguard your data.

6. Data Retention

We retain personal data only as long as necessary for the purposes described above, to comply with legal obligations, and to resolve disputes. The retention period may vary based on data type and applicable law. Data is deleted, anonymized, or securely destroyed once no longer needed.

7. Cookies and Similar Technologies

Burón uses cookies and similar technologies to authenticate users, enhance experience, track usage, and deliver analytics and marketing. Essential cookies are necessary for platform operation. You can manage non-essential cookie preferences in your browser or via in-product controls. For full details, see our Cookie Policy.

8. Your Rights and Choices

Depending on your jurisdiction, you may have rights to:

  • Access: Request a copy of your personal data.
  • Rectification: Correct inaccurate or incomplete data.
  • Deletion: Request erasure of your data, subject to legal or contractual obligations.
  • Restriction/Objection: Limit or object to certain types of processing.
  • Portability: Obtain a machine-readable copy of your data.
  • Withdraw Consent: Where processing is based on consent, withdraw at any time.
  • Lodge a Complaint: Contact your local data protection authority.

To exercise your rights, please contact us using the details below. We may request verification of your identity before acting on your request.

9. Data Security

We implement technical and organizational measures to protect personal data against unauthorized access, loss, misuse, or alteration. These include encryption, access controls, and regular security reviews. While we strive to protect your data, no method of transmission or storage is completely secure.

10. Children's Privacy

Our services are not directed to individuals under 16. If we become aware that a child has provided us with personal data, we will promptly take steps to delete such information.

11. Changes to this Policy

We may update this Privacy Policy from time to time. Material changes will be notified via our website or direct communication. Continued use of the service indicates acceptance of any changes.

12. Contact Us

For questions, requests, or concerns regarding this Privacy Policy or your personal data, contact:

Orion Technologies
Attn: Data Protection Officer
Email: privacy@buron.ai