What we hold, and why

ORI11 is a trading name of Oglofus Ltd (company number 14840351, registered in England and Wales), 25 Easten Terrace, Wallsend, Tyne and Wear, NE28 0JW, United Kingdom. For everything on this page we are the data controller unless it says otherwise. Write to privacy@ori11.com.

Before you have an account

You can build a brief without signing up, and that is not the same as being anonymous. While you work:

Our basis for this is the steps you have asked us to take before entering into a contract, and our legitimate interest in being able to show you a brief we did not lose. If you abandon a brief we delete it after 90 days.

Delete Instagram or Facebook data

We read your professional profile or selected Facebook Page, its descriptions, captions, business details and up to 40 photographs. We save copies to your brief and file storage.

Imported information can be sent to our AI providers to understand your business and prepare your website. Imported text and photographs may appear on your public website after you approve the design.

This is a one-time import. We do not post to your social accounts or keep access tokens. Disconnecting in Meta stops future access; it does not delete copies already saved with ori11.

We keep imported data while needed for the website service you requested, subject to the retention periods below. You can request earlier deletion. Removing access in Meta alone does not remove stored or published copies.

Email privacy@ori11.com with the subject “Social data deletion”, your Instagram username or Facebook Page link, and your ori11 account email or website reference. If you have no account yet, include your brief’s session ID if available. Do not send passwords, access tokens or the private resume link. We may ask you to verify ownership.

You can request deletion of imported profiles, captions and photographs, saved copies, and briefs or website content derived from them. Tell us whether the request concerns Instagram, Facebook, or both. We will explain any effect on your website and confirm when the request has been completed; a request is not an instant deletion.

You can also open “Remove social data” in your brief’s Sources or your project workroom. We record the request and give you a private status link. For an unsubmitted brief, this closes and removes the whole brief because imported and generated content can be mixed. Active websites require a review of the affected content first.

Request social data deletion

Once you subscribe

We hold your name, email, phone number if you gave one, your business details, your brief and everything you send us for the build. Card numbers never reach us: Stripe collects and stores those, and we see only the last four digits and the outcome.

After your subscription ends we keep your project for 90 days so you can come back, then delete it. You can ask us to delete it sooner.

Automated reading of your business

ORI11 works by reading your existing web presence and drafting a brief from it. That reading is done partly by large language models operated by the providers named below, which means the content of your website, your profiles and your brief is sent to them for processing. We say this plainly because it is the part clients ask about, and because a notice that lists a payment processor and omits this would be describing a different product.

Nothing we send is used to train those providers’ models under the terms we hold with them. No decision with a legal or similarly significant effect on you is made by a model: what they produce is a draft you review, edit and sign off.

Who else sees data, and where

WhoWhat forWhere
Cloudflareserving published sites, R2 storage, bot protection (Turnstile)UK/EU and US
Backblazeprivate storage of original uploaded images and documentsUS
Stripepayments, subscriptions and merchant payoutsUK/EU and US
Resendtransactional emailUS
Anthropicreading a business and drafting a briefUS
OpenAIreading a business and drafting a briefUS
Googlereading a business and drafting a briefUS
Metaoptional advertising measurement and conversion attribution after consentUK/EU and US
Bright Datafetching a business’s own public pages during researchUS

Where a provider is outside the UK we rely on the UK International Data Transfer Agreement, or the UK Addendum to the European Commission’s standard contractual clauses, unless the country is covered by UK adequacy regulations. We will tell you which applies to a named provider if you ask.

Your rights

You can ask for a copy of what we hold, ask us to correct or delete it, object to processing, or ask us to restrict it. Write to privacy@ori11.com and we will answer within a month. If we get it wrong you can complain to the Information Commissioner’s Office at ico.org.uk.

Processing schedule

Which way round. For your own account we are the controller. For the people who use your finished site — someone sending an enquiry, booking a table, placing an order — you are the controller and we are your processor. This section is about the second.

We undertake to you that we:

Cookies and what is stored on your device

We use no advertising or analytics cookies unless you explicitly accept them. On our public marketing pages, you can choose whether we use the Meta Pixel and Conversions API plus Google Tag Manager and Google Analytics to measure whether our marketing leads to visits, completed briefs, checkout starts and purchases. If you reject, neither browser script is loaded and no optional measurement event is sent.

We send no Google or Meta page views from the brief, login, account, studio or payment pages. After consent, only named funnel actions are sent from the brief and payment journey: Lead/generate_lead when you complete a brief, InitiateCheckout/begin_checkout when checkout opens, and Purchase/purchase after a verified payment. Google receives an event identifier and, for checkout and purchase, value and currency. Meta also receives the /start source path, browser and network information, Meta cookie identifiers where present, and one-way SHA-256 hashes of your email and our internal customer reference. We do not send brief contents, email addresses, card details, payment-method details, private URLs or private page contents to Google or Meta. You can change your choice at any time using “Cookie settings” on a public page; withdrawing it stops future events but cannot recall events already sent.