Privacy Statement
Last Updated: June 8, 2026
OriginVeiga ("we", "us", or "our") is committed to protecting the privacy and security of your business and customer data. This Privacy Statement describes how Kyle Andrew Oliveira, DBA OriginVeiga (and its future assigns, including a future OriginVeiga LLC) collects, processes, stores, and transfers data in connection with our B2B AI automation services, physical hardware nodes, and website platforms.
1. Data Processing and Tier-Specific API Disclosures
We design our systems to give businesses control over where their data travels. Data processing varies significantly depending on your subscription tier:
Starter and Pro Tiers (External APIs)
To power automated AI support channels (such as website AI chatbots and AI email responders) and complex database integrations, the Starter and Pro tiers process Client inputs and customer questions using third-party artificial intelligence Application Programming Interfaces (APIs), including but not limited to OpenAI LLC and Anthropic PBC. By utilizing these tiers, you acknowledge that data will be transmitted to these external providers. We configure all third-party integrations to restrict providers from using client inputs to train their public models.
Enterprise Tier (100% Localized and Air-Gapped)
Enterprise client data is handled with strict physical security boundaries. All AI model executions, custom workflows, database operations, and queries run locally on the provided in-network physical hardware node. No company data, files, or training materials are transmitted to external APIs or public servers, ensuring full air-gapped security compliance.
2. Written Information Security Program (WISP) & 201 CMR 17.00
We are committed to maintaining the highest standard of administrative, technical, and physical safeguards for personal data:
In compliance with Massachusetts standard 201 CMR 17.00, OriginVeiga maintains a comprehensive Written Information Security Program (WISP). This WISP outlines the protocols we enforce to safeguard personal information (including names, email addresses, phone numbers, and customer credentials) from unauthorized access, leakage, or loss. Our technical infrastructure utilizes industry-standard encryption protocols (SSL/TLS) for data in transit and localized database security for data at rest.
3. Statutory Adherence (CCPA & GDPR)
We respect the rights of individuals regarding their personal information:
- No Sale or Sharing of Data: OriginVeiga does NOT sell, rent, or lease personal information or client business data to third parties. We do not share personal information with third parties for cross-context behavioral advertising.
- Data Minimization: We restrict our data collection strictly to what is necessary to perform our automation services, answer client inquiries, or manage subscription accounts.
- Privacy Rights: To the extent applicable under CCPA, GDPR, and other frameworks, clients and their customers have the right to request access to, correction of, or deletion of their personal information by contacting us at info@originveiga.com.
4. Data Retention & Customer Win-Back Buffer
We retain proprietary business data, FAQs, manuals, and custom training records provided by the Client for the duration of the subscription to ensure system accuracy.
60-Day Win-Back Retention Period: Upon subscription cancellation or termination of services, we will retain the Client's custom training data and model checkpoints for up to sixty (60) days. This storage buffer exists solely to allow for seamless reactivation of services should the client choose to rejoin. After 60 days, all such files are permanently deleted.
Immediate Deletion: The Client has the right to bypass the 60-day storage buffer by submitting a written request to info@originveiga.com requesting immediate, permanent deletion of all proprietary data from our servers.
5. Tracking Technologies, Analytics, and Marketing Pixels
We use website tracking technologies to optimize our marketing and understand user behavior:
- Cookies: Small text files placed on your browser to log visitor sessions and navigation history. These are necessary to persist state for our chat widgets and user navigation.
- Google Analytics: We use Google Analytics to collect aggregated, anonymous data regarding website traffic, page view duration, and user interactions.
- Meta Pixel (Conversion Tracking): We integrate tracking pixels (including the Meta Pixel) to track the effectiveness of our social media marketing efforts, target custom audiences, and serve retargeting advertisements based on your visits to our site.
You can configure your browser settings to reject cookies or opt out of tracking, though some functionalities of the website may be limited.
6. Governing Law and Bristol County Jurisdiction
This Privacy Statement is governed by the laws of the Commonwealth of Massachusetts. Any legal disputes regarding privacy practices, data handling, or terms must be submitted to the exclusive jurisdiction of the state or federal courts covering Bristol County, Massachusetts (Westport, MA jurisdiction).