Privacy Policy
Last updated: 26 July 2026
MOBYLABS (UK) LTD, a company registered in England and Wales under company number 11384101, with its registered office at 124 City Road, London, England, EC1V 2NX (“MobyLabs,” “we,” or “us”), is committed to safeguarding the privacy of individuals whose Personal Data we process in connection with Orenia, a product of MobyLabs. This includes visitors to our website at orenia.app (“Website”), users of the Orenia platform and related applications (“Services”), contacts for customers and prospective customers, contacts for suppliers and service providers, candidates for employment, and any other individuals whose Personal Data we obtain in the course of our business (each, “you”).
This Privacy Policy describes how and why we collect, use, and share Personal Data and explains your rights regarding that data. “Personal Data” means any information relating to an identified or identifiable natural person.
MobyLabs is the data controller for Personal Data described in this Privacy Policy that we process for our own purposes (for example Account Information, internal Website analytics, marketing, and recruitment). We are committed to processing Personal Data in compliance with applicable data protection laws, including the UK General Data Protection Regulation (“UK GDPR”), the EU General Data Protection Regulation (EU) 2016/679 (“GDPR”) where it applies, and other laws described in Section 11.
Where a customer uses the Services to process Personal Data of their own end users or staff (“Customer Data”), that customer is typically the controller and we act as a processor under applicable contracts. This Privacy Policy explains that relationship; end users of a customer Account should contact that customer first about their Personal Data in Customer Data.
This Privacy Policy applies to Personal Data we process in connection with the Services, our Website, and our business operations, including recruitment. Local-language versions of our Website may be subject to additional privacy terms reflecting local legal requirements.
- Information we collect
- How we use Personal Data
- How we share Personal Data
- Marketing choices
- Your rights
- Information from third-party sources
- Data security
- International data transfers
- Data retention
- Cookies and browser storage
- Additional disclosures for specific jurisdictions
- Changes to this Privacy Policy
- Contact us
1. Information we collect
We collect Personal Data from multiple sources, either directly from you or from customers, colleagues, agents, integrations, and publicly available sources. The categories of Personal Data we collect include:
- Contact and identification data: name, organization, title, job responsibilities, phone number, mailing address, email address, and profile or social identifiers you choose to provide.
- Account and authentication data: login identifiers, role within an Account, authentication events, and related security metadata (credentials are typically managed by our identity provider).
- Financial data: billing contact details, invoicing information, and limited payment metadata returned by payment processors (we do not store full payment card numbers on the Services).
- Customer service data: Personal Data provided by or on behalf of customers regarding their employees, guests, end users, counterparties, or other individuals, in connection with use of the Services (this may form part of Customer Data).
- Content and operational data: documents, policies, site and access configuration, service requests, agent and workflow configurations, messages, and other content you or your organization submit to the Services.
- AI processing data: prompts, retrieved passages or documents, model and provider selections, generated outputs, and feedback processed when you use Knowledge, Concierge, L2 agents, or other AI-assisted features.
- Workflow and credential data: workflow definitions, typed inputs and outputs, execution status, errors, returned outputs, and credentials or credential references that a customer supplies for its L2 agents to access external systems.
- Compliance data: where required, government-issued identifiers, identification document copies, beneficial ownership data, and due diligence information.
- Recruitment data: identification and contact information, resume or curriculum vitae, and data obtained from recruiters or recruitment platforms.
- Device and usage data: Internet Protocol (IP) address, device identifiers, browser type, approximate location inferred from IP address, and usage data related to the Website or Services.
We do not intentionally collect Personal Data from children under 16 years of age. If you believe that we have inadvertently collected such data, please contact us using the details in Section 13.
2. How we use Personal Data
We use Personal Data for the following purposes:
- Provision of the Services. We process Personal Data to create and administer Accounts, authenticate users, deliver product features (including Wallet, Atlas, Knowledge, and Orchestra), and provide support, as necessary to perform our contractual obligations (UK GDPR / GDPR Article 6(1)(b)).
- Responding to inquiries. We process contact and identification data when you contact us with a question or inquiry, based on our legitimate interest in responding to potential customers and business contacts (Article 6(1)(f)).
- Management of business and customer relationships. We use contact, financial, and service data for invoicing, customer and vendor relationship management, and record-keeping, as necessary to perform our contractual obligations (Article 6(1)(b)).
- Marketing and business development. We may communicate with you regarding product updates, events, and news about Orenia. For existing customers and contacts, we may rely on our legitimate interest in maintaining professional relationships (Article 6(1)(f)). For electronic marketing (email, newsletters), we provide an opt-out mechanism in each communication. Where applicable law requires prior consent for electronic marketing, we will obtain your consent before sending such communications (Article 6(1)(a)).
- Keeping our Website and IT systems safe. We use identification, contact, financial, and device data to monitor usage and detect fraud, abuse, and misuse, based on our legitimate interest in ensuring safe use of our systems (Article 6(1)(f)).
- Improving the Services. We may use de-identified or aggregated usage information and, where permitted, limited Personal Data to understand how the Services are used and to improve reliability and features, based on our legitimate interests (Article 6(1)(f)). This analysis is performed internally using first-party data; we do not use third-party analytics providers.
- Complying with legal or regulatory obligations. We process identification, contact, financial, compliance, and device data for fraud detection, statutory returns, and other legal obligations, as necessary for compliance with law (Article 6(1)(c)).
- Recruitment. We collect and process recruitment data for screening, evaluating, and hiring candidates, and for related record-keeping and compliance. Where you have applied for a position, processing may be necessary to take steps at your request prior to entering into a contract (Article 6(1)(b)). Compliance data may be processed to meet legal requirements (Article 6(1)(c)).
- Processing on behalf of customers. Where we process Customer Data as a processor, we do so on the customer’s documented instructions and under contract, not under this Privacy Policy alone as the governing controller notice for that data.
AI models and providers. The selected model and provider are shown to the customer in the relevant L2-agent or Concierge profile. To provide an AI-assisted feature, Orenia sends the prompt and any content needed to fulfil the request — such as retrieved passages, documents, or workflow context — to the configured model provider and receives the generated output. Orenia does not use Customer Data to train generalized AI or machine-learning models. Where Orenia manages the provider relationship, we require the provider to process Customer Data only to provide the requested feature and not to use it to train generalized models.
Customers may select an Orenia-managed model provider or configure their own provider account or inference endpoint. When a customer configures its own provider, Orenia transmits the content necessary to fulfil the customer’s instruction to that provider. The customer selects and configures the provider, supplies or authorizes its credentials, and is responsible for the provider’s terms, lawful use, retention, and model-training settings. Orenia remains responsible for handling the data and credentials within the Services in accordance with the customer’s instructions, our contract, and applicable law.
Customer L2 agents and external systems. Orchestra helps customers formalize execution sequences and typed inputs and outputs for customer-developed L2-agent code. Orenia receives and manages credentials that customers provide for external systems and supplies those credentials as environment variables to the relevant L2-agent flow. Orenia also processes workflow definitions, sequencing rules, execution status, errors, and any inputs or outputs returned through the Services. The customer determines the agent code, external systems, purposes, and lawful basis for this processing; Orenia processes this data on the customer’s instructions and remains responsible for protecting it while it is under our control.
Special categories of Personal Data. We do not seek to collect special category data (such as health data or data revealing racial or ethnic origin) for our own purposes. If such data appears in Customer Data, the customer determines the purposes and legal basis; we process it only as instructed and permitted by contract and law. We may process special category data where necessary to establish, exercise, or defend legal claims (Article 9(2)(f)) or where you have given explicit consent (Article 9(2)(a)).
Automated decision-making. We do not engage in automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you without human involvement required by applicable law.
3. How we share Personal Data
We may share your Personal Data with the following categories of recipients:
- Affiliates. We may share Personal Data with affiliated entities under common ownership or control to provide the Services and administer customer relationships, including invoicing and business development.
- Suppliers and service providers. We share Personal Data with vendors who process data on our behalf under written agreements, including cloud hosting and infrastructure providers, identity and authentication providers, payment processors, email and support tools, and other IT service providers. These vendors are contractually required to process Personal Data only on our instructions (or as otherwise permitted by law), to implement appropriate technical and organizational security measures, and to notify us without undue delay upon becoming aware of a personal data breach affecting your data.
- AI model providers. When a customer selects an Orenia-managed model, the applicable model provider processes the content needed to provide inference or embeddings on our behalf. When a customer configures its own provider account or endpoint, the disclosure is made at the customer’s instruction and the provider’s processing is governed by the customer’s configuration, agreement, and the provider’s terms.
- Other users in your Account. Information you submit in an Account may be visible to other authorized users and administrators of that Account according to permissions configured by the Account owner.
- Your organization. If you use an email address or Account administered by an organization, that organization may access profile and Account information as described in our Terms of Use and this Policy.
- Business transfers. In connection with any reorganization, merger, acquisition, or transfer of assets, we may transfer Personal Data to the extent permitted by applicable data protection law. We will take reasonable steps to ensure that any such transfer is conducted in compliance with applicable data protection law.
- Legal and regulatory disclosures. We may share Personal Data with law enforcement, regulatory, or government agencies in response to lawful requests, subpoenas, court orders, or other legal processes, or to establish, exercise, or defend legal claims.
4. Marketing choices
You have control over how we use your Personal Data for marketing purposes. Where required by applicable law (including the ePrivacy Directive / PECR for electronic communications), we obtain your consent before sending marketing communications. In all cases, you may opt out of receiving marketing communications at any time by:
- following the unsubscribe link in the relevant communication; or
- contacting us at hello@orenia.app.
If you opt out, we will retain your contact details on a suppression list and take reasonable steps to ensure we do not contact you again for marketing purposes, based on our legitimate interest in honoring opt-out requests and preventing future unwanted contact (Article 6(1)(f)). We retain suppression list data indefinitely for this purpose.
Transactional and service messages (for example security alerts, billing notices, or Privacy Policy updates) are not marketing and may continue after you opt out of marketing.
5. Your rights
If you are located in the United Kingdom or the European Economic Area (“EEA”), you have the following rights under the UK GDPR / GDPR (subject to applicable limitations):
- Access — Right to request a copy of the Personal Data we hold about you.
- Rectification — Right to request correction of inaccurate or incomplete Personal Data.
- Erasure — Right to request deletion of your Personal Data, subject to our legal obligations to retain certain data. If you have opted out of marketing communications, we may retain your email address on our suppression list (Section 4) even after an erasure request, to ensure we do not inadvertently re-contact you.
- Restriction — Right to request that we restrict processing of your Personal Data in certain circumstances.
- Portability — Right to receive your Personal Data in a structured, commonly used, machine-readable format and to transmit it to another controller, where technically feasible and where the legal conditions apply.
- Objection — Right to object to processing based on our legitimate interests, including direct marketing. We will cease processing unless we demonstrate compelling legitimate grounds (except for direct marketing, which we will stop).
- Withdrawal of consent — Where we rely on your consent, you may withdraw it at any time, free of charge, without affecting the lawfulness of processing carried out prior to withdrawal.
You also have the right to lodge a complaint with your local data protection authority (in the United Kingdom, the Information Commissioner’s Office (ICO)) if you believe that we have not complied with applicable data protection laws.
These rights may be limited where we have overriding legitimate interests or legal obligations to continue processing — including the establishment, exercise, or defense of legal claims — or where data is subject to confidentiality obligations owed to a customer.
To exercise these rights regarding Personal Data for which we are the controller, you should:
- email hello@orenia.app;
- provide sufficient information to verify your identity (such as confirming your name and email address associated with our records); and
- provide information relating to your request.
For Personal Data in Customer Data, contact the relevant customer (controller) first; we will assist that customer as required by contract and law.
We may request additional verification where we have reasonable doubts about your identity, but will ensure that any such request is proportionate to the Personal Data we hold about you.
We will respond to your request within one month of receipt. In complex cases or where we receive a high volume of requests, we may extend this period by a further two months; in that event, we will notify you within the first month and explain the reason for the extension (Article 12(3)).
6. Information from third-party sources
Where we obtain Personal Data about you from sources other than you directly (for example, from our customers, professional contacts, recruiters, identity providers, or publicly available sources), we will provide you with the information in this Privacy Policy:
- within one month of obtaining the data;
- at our first communication with you, if earlier; or
- at the time we first disclose the data to another recipient, if earlier,
except where providing such information would be impossible or involve disproportionate effort, or where processing is required by law or subject to confidentiality obligations (Article 14(5)).
7. Data security
We have implemented technical and organizational security measures to safeguard Personal Data in our custody and control. These measures include restricted access to Personal Data on a need-to-know basis and administrative, technical, and physical safeguards appropriate to the nature of the data and the risks involved.
While we take reasonable steps to protect Personal Data, no method of transmission over the Internet or electronic storage is completely secure. We encourage you to exercise caution when communicating sensitive information electronically. If you have reason to believe that your interaction with us is no longer secure, please contact us immediately at hello@orenia.app.
In the event that we become aware of circumstances suggesting a personal data breach, we will take appropriate steps in accordance with applicable law. In the event of a confirmed personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach (Article 33). Where a breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay (Article 34), unless an exemption applies (for example, where measures such as encryption render the affected data unintelligible to any unauthorized person). Our breach notification will include, where available, a description of the measures taken or proposed to address the breach and mitigate its possible adverse effects.
8. International data transfers
MobyLabs is based in the United Kingdom. When you provide Personal Data to us or we otherwise process your data, it may be transferred to, stored in, or accessed from the United Kingdom, the EEA, or other countries that may not provide the same level of data protection as your home jurisdiction (for example where our subprocessors host infrastructure).
For transfers of Personal Data from the UK or EEA to countries not covered by an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses and/or the UK International Data Transfer Agreement / Addendum, as applicable. We conduct transfer impact assessments where required and, where elevated risks are identified, implement supplementary technical and organizational measures — such as encryption in transit and at rest and access controls — designed to provide appropriate safeguards for your Personal Data.
9. Data retention
We retain Personal Data only as long as necessary for the purposes described in this Privacy Policy or as required by applicable law. The following retention criteria apply as a general guide (specific contracts may provide different periods):
| Category | Retention period |
|---|---|
| Customer Account and Service content (Customer Data) | Duration of the customer relationship plus a wind-down period under contract or law; then deletion or return per customer instructions |
| Account and authentication records | Duration of the account relationship plus up to 7 years where needed for security, disputes, or legal obligations |
| Inquiry and contact data (non-customers) | 12 months from last contact, unless the matter proceeds to a customer relationship |
| Marketing contacts | Until you opt out; contact details retained indefinitely on a suppression list to prevent future re-contact |
| Recruitment data | 12 months from the date of your application, unless you consent to longer retention |
| Financial and billing data | 7 years (tax and accounting requirements) |
| Website / service security logs (IP addresses, browser type, auth events) | Typically 90 days from collection (security and troubleshooting), unless needed longer for an investigation |
| Compliance data (AML/KYC, where applicable) | As required by applicable AML and legal obligations (often 5 years after the end of the business relationship) |
When retention is no longer necessary, we securely delete or anonymize Personal Data.
10. Cookies and browser storage
Our systems may automatically record certain technical information in server access logs, including IP addresses, browser type, and access times, for security and troubleshooting purposes. These logs are typically retained as described in Section 9.
We use only first-party cookies and browser storage necessary to authenticate users, protect sessions, apply customer-account configuration, and remember settings or interface preferences requested by users. We do not use third-party analytics or advertising cookies, tracking pixels, cross-site tracking, or browser storage for targeted advertising. We do not permit third parties to access these stored values.
These technologies are retained only for the session or for the period necessary to preserve the relevant account setting. Users may remove browser-stored preferences through their browser, although deleting authentication storage may sign them out.
11. Additional disclosures for specific jurisdictions
United Kingdom / EEA supervisory authorities. You may lodge a complaint with the ICO (UK) or your local EEA supervisory authority as described in Section 5.
California (United States). During the preceding 12 months, we may have collected identifiers, account and authentication information, commercial and billing information, internet or network activity, professional information, Customer Data, and inferences necessary to provide and secure the Services. We obtain this information directly from users and customers, automatically from use of the Services, and from customer-authorized sources. We use it for the purposes described in Sections 2 and 3 and disclose it to service providers, account administrators, legal authorities where required, and parties involved in a business transaction.
We do not sell Personal Information and do not share Personal Information for cross-context behavioural advertising. We do not use Sensitive Personal Information to infer characteristics about consumers. We have therefore not sold or shared Personal Information during the preceding 12 months.
Subject to applicable law, California residents may request access, correction, deletion, or portability and may use an authorized agent. We will not discriminate against you for exercising these rights. Requests may be submitted using the email or postal address in Section 13. We may verify your identity before responding.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. Where we make material changes, we will notify you by posting the updated Privacy Policy on our Website and, where practicable, by email. We encourage you to review this Privacy Policy periodically.
13. Contact us
For questions, concerns, or suggestions regarding this Privacy Policy or our data processing practices, please contact us:
MOBYLABS (UK) LTD
Email: hello@orenia.app
Registered office: 124 City Road, London, England, EC1V 2NX
Company number: 11384101
We have not appointed a Data Protection Officer, as we do not fall within the categories of controllers required to designate a DPO under Article 37 UK GDPR / GDPR.
Related: Terms of Use