Knowledge base
Security, privacy, and data ownership
Your data stays in your workspace and belongs to you. How access, consent, approvals, audit trails, and deletion work at Orkie.
The principle
Your data belongs to you. It lives in your workspace, it is used to serve your business, and it goes nowhere else. Everything in this article follows from that.
Your data stays in your workspace
Each workspace is a private, separate space. No workspace can see another. No report, audience, or AI answer can draw on data from a different business. There is no shared pool, no benchmark built from client data, and no training of models on your records for anyone else's benefit.
When you connect a service, data flows between that service and your workspace only. Orkie does not resell, license, or share it.
First-party tracking
The Orkie pixel reports from your domain to your workspace. It is not an ad network's tracker in disguise. That means:
- You decide which platforms, if any, receive conversion data.
- Anything sent to a platform for measurement is hashed and gated by consent.
- If you leave a platform, an agency, or Orkie, your history is still yours.
Consent is enforced, not just recorded
Recording consent is easy. Honoring it every time is the hard part.
- The pixel respects your consent banner. Declined visitors are not tracked for marketing.
- Marketing permission is recorded only when a person actually opts in through a separate, clearly labeled choice.
- Before any automated message sends, the CRM checks consent and suppression again. An unsubscribe after signup blocks the message.
- Your workspace chooses single or confirmed double opt-in.
- Consent posture and acceptance rates are visible by region so you can see your standing at any time.
Who at Orkie can see what
Orkie operators need access to do the work you have hired them to do. That access is deliberate and limited.
- Operators work inside your workspace under their own named accounts, not a shared login.
- Their access is scoped to the modules relevant to your engagement.
- Their actions appear in the same audit trail as your team's.
- They never see your passwords or connector credentials. Connections use each platform's own approval screen, and the resulting access is held by the workspace, not by a person.
- Engineering staff do not browse customer workspaces. Access for support or incident work is limited, logged, and time-bound.
If you want a tighter arrangement, such as operator access to specific modules only, tell us and it will be set that way.
Approvals and the audit trail
Every action that changes something in your workspace is recorded: what was done, by whom, when, and on whose approval.
Actions that carry real-world consequences (sending to customers, moving money, or pushing data to an ad platform) wait for a person to approve the exact request. An AI assistant cannot approve its own proposal. Permanent changes to customer records, like deleting or merging them, need a second admin: the person who asks cannot be the person who approves. An approved request is locked to its exact details and can run once.
This applies to everyone equally: your team, your agency, Orkie operators, and any AI assistant connected to the workspace.
What the AI assistant can and cannot reach
When you connect Claude or ChatGPT, the assistant acts with your permissions and nothing more. It uses bounded, structured reads. It has no access to raw databases, credentials, code, servers, or other workspaces. Revoke a connection and it stops on the next request.
No scraping
Orkie gathers data through the pixel on your own site, through connections you approve, and through messages sent to you. It does not scrape competitor sites, harvest social profiles, or buy third-party lists. If a data source is in your workspace, it is there because you put it there.
Deletion on request
You can ask for any of the following at any time:
- Deletion of a specific person's data, to honor a privacy request.
- Removal of a module and its data.
- Export of your workspace data in a standard format.
- Deletion of the whole workspace.
Your operator confirms the scope with you, because some data is shared between modules, and then carries it out. Exports are yours to keep.
Security practices
Data is encrypted in transit and at rest. Access requires authentication, and roles limit what each person can do. Sensitive values such as discount codes and connector tokens are stored protected and released only to the module that needs them at the moment it needs them. Errors and unusual activity are monitored so problems are caught early.
Questions
If your legal or IT team has a security questionnaire, we are happy to complete it. Contact us or raise it on your first call.
Last reviewed 2026-09-20. Something unclear? Tell us and we will fix the article.
See your real numbers.
Talk to us about your business, or call. No pressure, no hard sell. Call 1-877-ORKIE-15.