Who we are
Orvio Labs s.r.o.
IČO: 238 51 694
Address: Uralská 689/7, Bubeneč, 160 00 Praha 6, Czech Republic.
Email: hello@orvio.ai
“Orvio” refers to orvio.ai and our Generative Engine Optimization products and services, including the free AI Visibility Report. Orvio is a brand and product line of Orvio Labs s.r.o., which is the data controller.
Scope
This notice describes how we process personal data when you visit orvio.ai, use the GEO tool, contact us, schedule meetings, or receive emails from us.
Data we process and purposes
Contact and business details
- Data: Your email address and any information you include when contacting us.
- Purpose: Respond to inquiries, support pre-contract steps, onboard clients.
- Retention: Up to 24 months after our last interaction.
Marketing (optional)
- Data: Your email address, if you opt in to updates.
- Purpose: Send product news and insights.
- Retention: Until you unsubscribe.
Meeting scheduling (Calendly iframe)
- Data: Name, email address, and scheduling details that you submit in the Calendly widget.
- Purpose: Arrange and manage calls.
- Notes: The widget is served from Calendly’s domain. Calendly presents and manages its own cookie consent. Cookies and other storage used by Calendly are not set or read by Orvio Labs. Calendly’s privacy policy applies to that widget.
GEO tool inputs and public web content
- Data: The domain you enter and publicly available pages that are fetched to generate your visibility snapshot. We do not access private or paywalled content.
- Purpose: Provide the requested report, improve service quality, prevent abuse.
- Retention: Aggregated or cached results for up to 12 months; not linked to you personally.
Analytics
- Providers: Google Analytics 4 (GA4) and Microsoft Clarity.
- Microsoft Clarity: We partner with Microsoft Clarity to capture how you use and interact with our website through behavioural metrics, heatmaps, and session recordings to improve our product and experience. Website usage data is captured using first- and third-party cookies and other tracking technologies to determine the popularity of products and services and online activity. We also use this information for site optimisation and security purposes. Clarity is only loaded if you have accepted cookies via our consent banner. For more information about how Microsoft collects and uses your data, visit the Microsoft Privacy Statement.
- Consent Mode v2: GA4 runs under Google Consent Mode v2. By default, all analytics storage is denied. If you accept cookies via our banner, full analytics (including session data and Clarity heatmaps / session recordings) are enabled. If you decline, GA4 continues to send cookieless, anonymous pings only — no cookies are set, no user identifiers are stored, and IP addresses are anonymized. Clarity is not loaded at all if you decline.
- Purpose: Understand product usage, improve user experience, site optimisation, and security.
- Retention: Per Google and Microsoft default retention settings (typically 14 months for GA4, 90 days for Clarity).
Technical logs
- Data: IP address, timestamp, user agent, and request metadata recorded by our hosting provider, Firebase / Google Cloud.
- Purpose: Security, reliability, abuse prevention, debugging.
- Retention: Typically about 30 days.
We do not seek to collect special category data. Our services target businesses and are not directed at children under 16.
Use of cookies and local storage
- On first visit a cookie consent banner is shown. If you accept, analytics cookies (GA4 + Clarity) are set. If you decline, no cookies or local storage are used for analytics — GA4 is still active in cookieless mode only.
- Your preference is stored in your browser’s localStorage under the key
orvio_cookie_consent and is respected on future visits.
- The embedded Calendly scheduling widget may use cookies or other storage under Calendly’s domain in order to provide its functionality. Calendly presents and manages consent for those cookies. Orvio Labs does not control or access them.
How we use data
- Respond to messages and schedule meetings.
- Generate AI visibility and GEO snapshots from public content.
- Maintain security and prevent abuse.
- Send opted-in updates.
- Analyze aggregated usage to improve the product.
We do not use personal data for automated decision-making that produces legal or similarly significant effects.
Sharing and processors
We do not sell personal data. We share data only with trusted providers that act as processors under written terms:
- Firebase (Google Cloud; EU and US): hosting, databases, security logs
- Google Analytics 4 (USA): web analytics under Consent Mode v2; cookieless when consent is denied
- Microsoft Clarity (USA): session recordings and heatmaps; only loaded with your consent
- Calendly (USA): scheduling. Calendly manages its own cookies and consent for the embedded widget and processes the meeting data you submit within that widget as described in its policy
We may disclose data to comply with laws, to enforce our terms, or to protect rights, safety, and security.
International transfers
If data is processed outside the EU or EEA, we use appropriate safeguards, including EU adequacy decisions where available, or Standard Contractual Clauses with supplementary measures.
Legal bases we rely on
- Consent: you opt in to receive updates.
- Contract: we process data to provide services you request.
- Legitimate interests: we operate, secure, measure, and improve Orvio in a proportionate way that respects privacy; you may object at any time.
Purpose to basis summary
- Responding to inquiries and onboarding, legitimate interests, or contract if you become a client.
- Marketing emails you opt in to, consent.
- Calendly scheduling data you submit, legitimate interests, or contract where relevant.
- GEO tool inputs and public-page fetching, legitimate interests.
- Analytics (cookieless GA4 pings), legitimate interests.
- Full analytics cookies (GA4 + Clarity), consent.
- Hosting and security logs, legitimate interests, and legal obligations where applicable.
Retention
- Inquiries, up to 24 months after last contact
- Marketing, until you unsubscribe
- GEO caches and aggregates, up to 12 months
- Security and technical logs, typically about 30 days
Backups may retain limited data for a short period before being overwritten.
Your rights (EEA and UK)
You can request access, rectification, or erasure. You can restrict or object to processing. You can withdraw consent for marketing at any time. You can request data portability for information you provided.
To exercise rights, email hello@orvio.ai. You can also lodge a complaint with your local authority. In the Czech Republic, contact Úřad pro ochranu osobních údajů (ÚOOÚ).
Security
We apply industry-standard measures, including TLS in transit, role-based access, least-privilege controls, monitoring, and limited retention. No system is perfectly secure. We investigate and respond to incidents promptly.
Changes
We may update this policy as our services evolve. We will post changes here with a new Last updated date.
Contact
Controller: Orvio Labs s.r.o. (IČO: 238 51 694)
Address: Uralská 689/7, Bubeneč, 160 00 Praha 6, Czech Republic.
Email: hello@orvio.ai