orb22 Privacy Policy
Effective date: October 5, 2026
This Privacy Policy explains how DSBC LLC ("DSBC", "we", "us"), a Delaware limited liability company that offers orb22 under the names 22nd Floor and orb22, handles personal information. Contact: support@22floor.com, [MAILING ADDRESS].
1. Our two roles
- Customer account data. When a business ("Customer") and its staff sign up for and use orb22, we decide how their account information is used. For that information we are the controller (or "business" under California law).
- Visitor data. When a person ("Visitor") talks with an AI assistant ("Agent", shown on websites as the orb) on a Customer's website or hosted page, we process that conversation on behalf of the Customer. The Customer is the controller (or "business") and decides why the data is collected. We are its processor (or "service provider"). The Customer's own privacy policy, linked before each call, explains its practices and how to reach it. If you are a Visitor, please read it and send requests to that business. We will help it respond.
2. Customer account data
What we collect
- Account details: name, business email, password (stored as a salted hash), workspace name, role, invite code.
- Billing details: plan, Minutes used, invoices, and payment records. Card numbers are handled by our payment processor, Stripe, not stored by us.
- Content you provide to build Agents, such as website pages, files, knowledge, and settings, and the product catalog we read from the public product pages of your website if you scan it for products (public business data, not personal data).
- Support messages and feedback.
- Technical data about your use of the builder: sign-in times, IP address, browser type, and error logs, kept for security.
How we use it and our legal bases
- To create and run your account and provide the service (performance of our contract with you).
- To bill you, keep records, and meet legal obligations (contract and legal obligation).
- To secure the service, prevent fraud and abuse, and fix problems (legitimate interests).
- To send service notices, and, with an option to opt out, product updates (contract and legitimate interests; consent where the law requires it).
We do not sell Customer account data or share it for cross-context behavioral advertising.
3. Visitor data we process for Customers
What is processed
- Voice, in real time only. Nothing is sent until you tap Start. Then your microphone audio streams from your browser to our voice AI provider (OpenAI) to power the conversation. We do not record or store audio. Our provider does not use it to train models, and may keep API data for up to 30 days for abuse monitoring under its policies.
- Transcript. A text transcript of what you and the Agent said. Email addresses and long number sequences, such as phone or card numbers, are automatically masked in the stored transcript.
- What you provide. Answers to the business's intake questions, your name if you give it, and your email address if you type it.
- Call details. Start and end time, length, the website the call came from, the traffic source (for example a campaign tag or referring site), which cards, products or offers were shown or clicked, the version of the notice you accepted by tapping Start, and a written summary or assessment if the business has enabled one.
- Abuse limits. A random device ID stored in your browser's storage on the business's website, and short-lived counters keyed to that ID and to your IP address to limit how many calls can be made per device and per network each day. Counters, including the IP address, expire within 2 days. We do not store your IP address with the transcript.
- AI summary. Unless the business turns summaries off, after a call ends Anthropic's AI writes a short summary of it from the transcript and the call details: what you asked about, how the call ended, and a suggested next step for the business. It is labeled as written by AI wherever the business sees it, and it is deleted together with the call.
- Purchase tracking, only if the business turns it on. Whether you bought something on the business's website after the call: the order number, total, currency, and discount codes, sent to us by the business's website or its shop platform (for example Shopify). To link a purchase to your call, the widget adds a call reference to the order links it shows you, and may store a random visitor ID and that call reference in your browser's storage and in a first-party cookie on the business's website. Unless the business turns this setting off, this happens only after you agree to analytics cookies on its website, and it never happens when your browser sends a Global Privacy Control signal. An email address from the order is sent to us only as a one-way hash; we keep the email only if it matches the one you typed in the call, and otherwise keep a salted hash. We never receive card numbers or addresses, and purchases that do not match a call are not stored.
What we do not do. We do not create, collect, or store voiceprints or any other biometric identifier, and we do not use your voice to identify or verify who you are. We do not perform emotion recognition. We do not use Visitor data to make decisions that have legal or similarly significant effects on you. A written assessment, if the business uses one, is an AI-generated recommendation about products, not a decision about you. An AI summary is a note for the business about the call, not a decision about you.
How it is used
- To run the conversation, answer your questions from the business's knowledge, and, if enabled, write a summary or assessment and show offers or links.
- To give the business the transcript, your answers, and your contact details so it can follow up, and to send them to tools the business has connected, such as its Klaviyo email account or its own systems via webhook. Whether the business may send you marketing email depends on the consent you gave it.
- To prevent abuse and keep the service secure.
We do not use Visitor data to train or improve AI models, to build profiles, or for our own marketing, and we do not sell it or share it for cross-context behavioral advertising. The business decides how it uses your data after it receives it.
4. Who receives data
- The Customer whose Agent you used.
- Our subprocessors, which host the service or run AI models under contracts that limit their use of the data: Cloudflare (hosting, database, storage, network security), OpenAI (real-time voice conversation), and Anthropic (knowledge import, answers, answer extraction, summaries, and assessments). See our subprocessor list. The widget's fonts are served by orb22 itself, so no font provider receives your data.
- Integrations the Customer enables, such as Klaviyo or a webhook destination the Customer controls.
- Payment processor (Stripe), for Customer billing only.
- Authorities or others where required by law, to protect rights and safety, or in connection with a merger or sale of our business, subject to this policy.
5. Retention
- Visitor transcripts and call records, including the notice record and the AI summary, are deleted automatically 90 days after the call. Customers can delete individual calls sooner at any time.
- Purchase records are deleted automatically 90 days after the purchase. If the call is deleted sooner, the purchase is kept only as a sale, without the link to the call or the email address. The visitor ID and call reference stay in your browser until you clear site data; the cookie expires after 90 days.
- Abuse limit counters, including IP addresses, expire within 2 days. The device ID stays in your browser until you clear site data.
- Customer account data is kept while the account is open. After an account closes, the Customer can ask for an export for 30 days, and we delete it within a further 30 days, except billing records we must keep for tax and accounting (generally up to 7 years).
- Deleted data can remain in database backups for up to 30 days before it is overwritten.
- Our AI providers may keep API data for a limited period (currently up to 30 days for both OpenAI and Anthropic) for abuse monitoring or safety, and longer only where their policies allow, such as to investigate a violation of their usage policies.
6. Your rights
Visitors: please contact the business whose Agent you used. If you contact us, we will forward your request to that business where we can identify it, and help it respond. To help us find your call, tell us the website, the approximate date and time, and the email address you typed, if any.
Everyone, for data we control: you can ask us at support@22floor.com to exercise the rights you have under the law where you live. Depending on where you are, these include:
- EU, EEA, UK, and Switzerland. Access, correction, deletion, restriction, portability, and objection to processing based on legitimate interests or for direct marketing. Where we rely on consent, you may withdraw it at any time. You may complain to your local data protection authority.
- California and other US states with privacy laws. To know what personal information we collected, and its sources, purposes, and recipients; to access, correct, or delete it; and to opt out of sale, sharing, targeted advertising, or profiling (we do not do these). We do not use sensitive personal information to infer characteristics. We will not discriminate against you for exercising your rights. You may use an authorized agent, and we will verify requests using information linked to your account. If we deny your request, you may appeal by replying to our answer. In the past 12 months we collected the categories described in Sections 2 and 3 (identifiers, commercial information, internet or network activity, audio information processed in real time, and professional information) for the purposes and recipients listed above, and we did not sell or share them.
- Canada, including Quebec. Access and correction, withdrawal of consent, and, in Quebec, deletion, de-indexing, portability, and information about decisions based exclusively on automated processing (we do not make such decisions about you). You may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, the Commission d'accès à l'information.
- Australia. Access and correction under the Australian Privacy Principles. You may complain to us first, and then to the Office of the Australian Information Commissioner.
- Israel. Access and correction under the Protection of Privacy Law. You may complain to the Privacy Protection Authority.
- Brazil. The rights in Article 18 of the LGPD, including confirmation, access, correction, anonymization, portability, deletion, and information about sharing. You may complain to the ANPD.
- Elsewhere, including Japan, Singapore, and India, the rights your local law gives you.
We respond within the time the law requires (for example, one month under the GDPR, 30 days in Canada and Quebec, and 45 days under California law).
7. International transfers
We are based in the United States. Our team may access data from the United States and Israel, and our subprocessors process data in the United States and, for Cloudflare's network, in other countries. Israel has an adequacy decision from the European Commission and is recognized by the UK. When personal data from the EEA, UK, or Switzerland is transferred to countries without such a decision, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum and Swiss amendments), and, where a recipient is certified, the EU-US Data Privacy Framework and its UK and Swiss extensions. For data from Brazil we use the ANPD's standard contractual clauses, and for other countries the safeguards their laws require. Contact us for a copy of the relevant safeguards.
8. Children
orb22 is not directed to children, and Customers may not place Agents on sites or pages directed to children. We do not knowingly collect personal information from children under 13, or under the age of digital consent where you live (up to 16 in parts of the EU). If you believe a child has used an Agent, contact the business or us and we will delete the conversation.
9. Security
We use encryption in transit (TLS) and at rest (by our hosting provider), access controls with least privilege, hashed passwords, per-workspace data separation, rate limits, optional domain allowlists for embedded Agents, automatic deletion schedules, and logging that avoids conversation content. No system is perfectly secure. If a breach affects your personal data, we will notify the Customer or you, and regulators, as the law requires.
10. Browser storage
The Agent widget stores a random device ID, and small settings needed to run the call, in the browser storage of the website you are visiting (local storage and session storage). The device ID is used only to apply abuse limits and keep the service secure. When the assistant opens another page of the same website for you during a call, or you follow one of that website's links during a call, the widget keeps a small resume state in that website's session storage for that browser tab only, so the same call can continue on the next page: the call's ID and access token, the call's language, the fact that you already agreed to the call, the last lines of the conversation, and the products or cart item shown on screen. It is deleted as soon as the next page picks the call up, and it is ignored after 90 seconds; session storage is also cleared when you close the tab. No new consent record or call is created when a call continues on another page. It is not used for advertising or to track you across websites, and it is not shared with other businesses. The builder uses a session cookie to keep Customers signed in. We do not use third-party advertising cookies. Where a business adds a traffic source tag to a link it shows you, that tag identifies the Agent as the source of your visit. The business decides whether to show you a cookie banner for its own website.
Analytics on our own website
Our marketing website (orb.22floor.com) and the orb22 builder use Google Analytics to measure visits and how the service is used, for example page views, signups and plan purchases. Google Analytics sets cookies and receives your IP address, browser details and the pages you view. We turn off Google's advertising features and do not link this data to the calls or visitor data described above. If you are in the European Economic Area, the United Kingdom or Switzerland, analytics cookies are off by default and Google receives only cookieless measurements. We use the Meta Pixel and Conversions API to measure and improve our ads. The Agent widget on our Customers' websites and their hosted assistant pages do not use Google Analytics. You can opt out with Google's browser add-on at tools.google.com/dlpage/gaoptout. Google's use of the data is described at policies.google.com/technologies/partner-sites.
11. Changes
We will post changes here and update the effective date. For material changes affecting Customers, we will give notice by email or in the service.
12. Contact
DSBC LLC, [MAILING ADDRESS]. Email: support@22floor.com. We have not appointed a data protection officer. [EU and UK representative under Article 27 of the GDPR and UK GDPR: NAME AND ADDRESS, to be added once appointed.]