Privacy Policy

Effective August 2026 · This is our current policy and may be updated; we will post any changes on this page.
The short version: Orzyn is built on presence, not identity. We do not store biometric templates, and we do not sell your personal information. We collect the minimum needed to prove a real, present human authorized an action and to run our business.

This Privacy Policy explains how Orzyn LLC ("Orzyn," "we," "us") collects, uses, discloses, and protects information in connection with our website and the Orzyn human-accountability service (together, the "Services"). By using the Services, you agree to this Policy.

1. What Orzyn is — and is not

Orzyn produces proof that a real, present, uncoerced human authorized a specific consequential action, resistant to spoofing and injection, with a record that can be verified afterward. Orzyn is presence and authorization — not identity verification. We do not verify who a person is (name, age, citizenship, or other identifying attributes), and we do not store biometric templates.

2. Information we collect

3. How we use information

4. How we share information

We do not sell your personal information. We share information only with: service providers who process data on our behalf under contract; the organization that engaged Orzyn to put accountability behind an action (for enterprise deployments); and authorities where required by law or to protect rights and safety. We may also share information in connection with a merger, acquisition, financing, or similar transaction.

5. Healthcare data (HIPAA) — our Business Associate role

When Orzyn processes protected health information ("PHI") for a healthcare organization, we act as a Business Associate under HIPAA — not as a covered entity — and we use and disclose PHI only as permitted by our Business Associate Agreement ("BAA") with that organization and by applicable law. We do not use PHI for our own purposes. Orzyn is architected to minimize PHI in scope and stores no biometric templates. A BAA is available for qualifying healthcare deployments.

6. Data retention & security

We keep information only as long as needed for the purposes above or as required by law, then delete or de-identify it. We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the data. Our security and compliance program (SOC 2, HIPAA, ISO 27001) is in active readiness; no method of transmission or storage is perfectly secure.

7. Your choices & rights

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, to opt out of certain processing or sharing, and to appeal a decision. Orzyn does not sell personal information. To exercise a right, email privacy@orzyn.ai and we will respond as required by applicable law.

8. International users

Orzyn is operated from the United States. If you access the Services from outside the U.S., you understand your information may be processed in the U.S. and other countries with different data-protection laws. Where required, we use appropriate safeguards for cross-border transfers.

9. Children

The Services are for businesses and adults; users of the Orzyn application must be 18 or older. The Services are not directed to children, and we do not knowingly collect personal information from anyone under 18.

10. Changes to this Policy

We may update this Policy from time to time. We will post the updated version here with a new effective date. Material changes will be communicated as required by law.

11. Contact

Questions about this Policy or your data: privacy@orzyn.ai. Orzyn LLC.