Last updated: 17 July 2026

1. Who we are

Oruco designs, builds and manages AI operating systems, agents, workflows, dashboards and related business infrastructure. For personal information collected through this website, booking process and Oruco’s own sales and administration, Oruco is the data controller. For questions about this policy or our use of personal information, contact team@oruco.com.

2. What this policy covers

This policy explains how we collect, use, disclose, store and protect personal information when you visit oruco.com, book an AI Audit, contact us, receive marketing, become a client, supply services to us, or otherwise interact with Oruco. It also explains your rights under applicable UK data protection law, including the UK GDPR and the Data Protection Act 2018.

This policy does not replace a client agreement, data processing agreement or project-specific privacy notice. Where Oruco processes personal information solely on a client’s documented instructions, the client is generally the controller and Oruco acts as a processor. In that situation, the client’s privacy notice governs the relationship with the individuals concerned.

3. The information we collect

We may collect identity and contact information such as your name, job title, organisation, business email address, telephone number, location and professional profile. We may also collect the content of messages, meeting notes, audit answers, project requirements, proposals, contracts, billing details and any files or information you choose to provide.

When you use the website, we may collect technical and usage information such as your IP address, browser and device type, operating system, referring page, approximate location, pages viewed, links selected, session events, timestamps and diagnostic information. We do not intentionally collect more information than is reasonably needed for the stated purpose.

4. Information from other sources

We may receive business contact information from public professional sources, introductions, referral partners, event organisers, clients, suppliers and service providers. Where we receive personal information from another source, we use it only where we have a lawful basis and where the use is compatible with the circumstances in which it was obtained.

5. AI Audit bookings and meetings

If you book an AI Audit or another meeting, we collect the details needed to arrange and prepare for it. This can include your name, email address, company, time zone, selected time, answers to booking questions and information about your current systems or operational problems. The booking interface is provided through Cal.com, which processes booking information on our behalf and may place necessary cookies or use related technologies to operate the booking service.

We use booking information to schedule the meeting, send confirmations and reminders, prepare relevant questions, conduct the session, follow up and decide whether Oruco’s services are a suitable fit. Please do not include sensitive personal information in a booking form unless it is genuinely necessary and you are authorised to share it.

6. Client and project information

During an audit, implementation or managed service, clients may provide information about staff, customers, suppliers, leads, transactions, communications, workflows and connected tools. The exact categories depend on the agreed project. We use this information to understand the current process, design the system, configure integrations, test workflows, provide support, monitor performance and meet our contractual obligations.

Where Oruco acts as a processor, we process client-controlled personal information only on documented instructions, subject to the agreed contract and data processing terms. Clients are responsible for ensuring they have a lawful basis to provide the information and for giving appropriate privacy information to affected individuals.

7. How we use personal information

We use personal information to operate and secure the website; respond to enquiries; arrange AI Audits; assess requirements; prepare proposals; enter into and perform contracts; build, test and manage client systems; provide support; manage billing and records; improve our services; prevent misuse; comply with law; establish or defend legal claims; and communicate relevant service updates.

We may use aggregated or de-identified information to understand patterns, improve workflows and demonstrate general service performance. We do not attempt to re-identify information that has been properly anonymised.

8. Our lawful bases

Depending on the activity, we rely on one or more lawful bases. Contract applies where processing is necessary to take requested steps before a contract or to perform a contract with you. Legitimate interests apply where processing is reasonably necessary to operate, improve and protect Oruco, develop business relationships, provide relevant business communications and manage services, provided those interests are not overridden by your rights and interests.

We rely on consent where the law requires it, including for certain non-essential cookies or marketing activities. You may withdraw consent at any time, although withdrawal does not affect processing already carried out lawfully. We rely on legal obligation where processing is needed to comply with tax, accounting, regulatory, court or other legal requirements.

9. Marketing communications

We may send service news, educational material or relevant business-to-business marketing where permitted by law. You can opt out at any time by using the unsubscribe method in the message or by contacting us. We will keep a minimal suppression record where necessary to respect your choice. Opting out of marketing does not stop essential communications about an active booking, contract, security issue or service.

10. Cookies, analytics and lead identification

The website and embedded services may use cookies, pixels, local storage and similar technologies. Some are necessary for the site, security and booking tools to function. Others help us understand visits, measure engagement, diagnose problems and identify potential business interest. Our site is hosted through Framer, bookings are provided through Cal.com, and website measurement or lead-identification technology may be provided by services such as Leadsy.

Where consent is required, non-essential technologies should not be used until consent has been obtained. You can also control cookies through your browser, but blocking necessary technologies may prevent parts of the site or booking experience from working correctly. We do not sell personal information collected through cookies.

11. AI systems and automated processing

Oruco uses AI-assisted tools to help analyse operational information, draft materials, classify data, support workflows and deliver contracted services. Unless a client has explicitly approved a different process with appropriate safeguards, Oruco does not use website visitor or client project information to make solely automated decisions that produce legal or similarly significant effects on an individual.

Human review, access controls, testing, approval steps and exception handling are used where appropriate to the risk. Client data is not treated as permission to train a public AI model. The use of any model or provider within a client engagement is governed by the project scope, client instructions and applicable data processing terms.

12. Who we share information with

We may share personal information with service providers that support hosting, booking, communications, document management, analytics, payments, accounting, security, infrastructure, automation and professional advice. We may also share information with a client or authorised integration provider where this is necessary to deliver the agreed service, and with public authorities, regulators, courts or advisers where required by law or needed to protect legal rights.

Providers receive only the information reasonably needed for their role and are expected to protect it under appropriate contractual and security obligations. We do not sell or rent personal information to third parties for their own advertising.

13. International transfers

Some technology providers may store or access information outside the United Kingdom. Where a restricted transfer occurs, we take reasonable steps to use a lawful transfer mechanism, such as UK adequacy regulations, the UK International Data Transfer Agreement, the UK Addendum to approved standard contractual clauses, or another permitted safeguard or exception. Additional technical and organisational measures may be used where appropriate.

14. How long we keep information

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including contractual, support, security, accounting, tax and legal requirements. Enquiry and booking information is generally kept while the opportunity is active and for a reasonable follow-up period. Contract, invoice and core business records may be kept for the period required by law or needed to establish, exercise or defend legal claims.

Client project data is retained according to the applicable agreement, client instructions, backup cycle and operational need. When information is no longer required, we delete it, anonymise it or securely isolate it until deletion is technically completed. Retention periods may be extended where a legal hold, dispute or regulatory requirement applies.

15. Security

We use proportionate technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, disclosure or access. Measures may include access controls, least-privilege permissions, authentication, encryption in transit, secure configuration, logging, backups, supplier review, testing and incident response procedures.

No internet service can guarantee absolute security. If we become aware of a personal data breach, we will investigate, contain and assess it, notify affected clients, individuals or the Information Commissioner’s Office where required, and take reasonable steps to reduce further risk.

16. Your data protection rights

Depending on the circumstances, you may have the right to be informed; request access to personal information; correct inaccurate or incomplete information; request erasure; restrict processing; receive certain information in a portable format; object to processing based on legitimate interests; object at any time to direct marketing; and withdraw consent where consent is the lawful basis.

These rights are not absolute and may be limited by law. We may need to verify your identity and clarify the request before acting. We aim to respond within the applicable legal time limit. If Oruco processes the information only on behalf of a client, we may refer the request to that client or assist them in responding.

17. Children’s information

Oruco’s website and business services are not directed at children, and we do not knowingly collect personal information from children through this website. If you believe a child has provided personal information to us without appropriate authority, contact us so that we can review and, where appropriate, remove it.

18. External links

The website may link to client sites, social platforms and other third-party services. Those organisations control their own processing and privacy practices. We are not responsible for an external site’s privacy notice, content or security, and you should review its information before providing personal data.

19. Complaints

Please contact us first if you have a concern so we can try to resolve it. You also have the right to complain to the Information Commissioner’s Office, the UK supervisory authority for data protection. Information about making a complaint is available at ico.org.uk. You may also have the right to seek a judicial remedy.

20. Changes to this policy

We may update this policy when our services, providers or legal obligations change. The latest version will be posted on this page and the date at the top will be revised. If a change materially affects how we use information already collected, we will take reasonable steps to provide additional notice where required.

21. Contact us

For privacy questions, requests or complaints, email team@oruco.com with the subject line “Privacy”. Please include enough information for us to understand the request, but do not send sensitive information by ordinary email unless necessary. Postal correspondence details can be provided on request.

Building Global AI Operating
Systems & Infrastructure

SINCE 2024

Certified & accredited

AICPA SOC 2 Type 2
ISO 27001
ISO 42001
Claude Partner Network member

Oruco

Building Global AI Operating
Systems & Infrastructure

SINCE 2024

Certified & accredited

AICPA SOC 2 Type 2
ISO 27001
ISO 42001
Claude Partner Network member

Oruco

Create a free website with Framer, the website builder loved by startups, designers and agencies.