Introduction

This is the overview of the Orsiso Privacy Policy and covers the current Privacy Policy with respect to the Orsiso application and Orsiso.com website and how we manage and maintain your personal data.

Security and Privacy is of paramount importance to us here at Orsiso and we will take every measure possible to ensure that the information you share with us is secured and protected in every way possible.

Your Orsiso information is used to operate and improve the features, offerings and content presented to you by Orsiso and Aureliant Pte Ltd; to personalize the content provided to you; to fulfill your requests for products, programs, and services; to communicate with you and respond to your inquiries; to conduct research about your use of Orsiso; and to help offer you other products, programs, or services that may be of interest.

Specific Note during the Beta Phase: Please also refer to the Terms & Conditions of Use section specifically with respect to the use of Beta software. As a registered user of Orsiso you are expected to acknowledge and abide by these terms. For more information please refer to the Terms & Conditions of Use section.

What information do we store?

At the moment, Orsiso stores the following information belonging to registered users:

We DO NOT store any information that is held on your existing social networks (Name, Birth Date, lists of friends, photos and other information) however certain reference data may be cached by Orsiso.

As part of the account setup process, you will also be requested to provide necessary information that allows Orsiso to access your accounts on various third party sites, which may include details such as email addresses, user ids and passwords as and when required. In addition, we may request certain personal data regarding your name and other basic information such as age, location, profession in order to help personalize our services and offering however this is strictly voluntary.

For Facebook, Flickr and Bebo, you will be required to authorise Orsiso to access your account details and to have specific access to your information and (in the case of Facebook) the ability to update your status. We do NOT store your username and password to these sites, and instead store the authorization code provided to access these sites, which can be revoked at any time by amending the appropriate settings from within your account settings managed by these third party sites.

For Facebook chat, LinkedIn, Twitter, as well as the Yahoo!, MSN and AIM chat networks, you will be asked to provide your login details, and this implicitly means you authorize us to store your username and password and us it to update your status via the social network's API and to retrieve information, updates and replies from your accounts online.

For the FaceBook notification feed, we store the specific URL to the RSS (Real Simple Syndication) feed from this network. This URL is personal to you and in order to retrieve information for your profile we store this information on our servers.

When you update your status on various social networks, we will not store the information contained regarding the status message itself but will record certain basic information such as the time and name of the network you are updating.

When you invite friends to use Orsiso or send messages through Orsiso, we may collect and maintain information associated with those messages, including email addresses and content.

Security Measures in Place

Physical access to our servers and network security

Our servers are hosted on the Amazon EC2. This is essentially a system of virtual servers. In practice, it means that the physical security of our server as well as the router/firewall/network access control is provided by Amazon itself. Please read the Amazon Web Services: Overview of Security Processes document if you want to know more

Server security

All password information stored by Orsiso in relation to your account is securely encrypted using a digital hash mechanism.

We follow widely recognized best practices to ensure server security. These include only installing needed services, application of security updates/patches, detailed monitoring and file system integrity checking. We also have a very limited set of people authorized to access the servers. Administrative access is restricted to the Aureliant sysadmin.

Application security

Communication between the server and the client is encrypted over SSL. This takes place every time we send sensitive information such as passwords. In addition, all server invocation by the client is signed using a secret key, making sure that only the OrSiSo client can get data from the server.

Here too we maintain best practices to make sure that your data remains secure. Safeguards are in place to prevent common attacks such as SQL injection and "man-in-the-middle" attacks. We also routinely review our code for potential security risks so that we can address any issues as quickly as they arise.

What we do with the information

As part of the normal usage of the Orsiso application, we will track certain information pertaining to the user including information on the nature of the notifications and data that is sent to your client application. This information will only be stored at an aggregate level and will never contain any specific content of the information you receive.

This information will be entirely for internal monitoring, auditing and performance management purposes to ensure that the services we offer will be prioritized and optimized for your personal experience when connected to Orsiso. As part of this process, we will store information based on your usage at an aggregate level only. We will never store the specific content of notifications, chat messages or other communications you receive or send via Orsiso unless it is directed towards Orsiso (bugs, feedback, suggestions and so on).

In addition to the above, Orsiso may process personal information for such purposes as:

Orsiso processes personal information on our servers in the United States of America. For users outside the United States, please note that any personally-identifying information you enter into the Site will be transferred out of your country and into the United States. You consent to such transfer through your use of the Site and our Services. You also warrant that you have the right to transfer such information outside your country and into the United States. If you have any specific queries concerning the nature of the information we store, please contact us at the email and or address shown in the Contact section of Orsiso.com or in the Contact section below.

Information sharing

In addition to the uses noted above, Orsiso only shares personal information with other companies or individuals outside of Orsiso in the following limited circumstances:

Please contact us at privacy@orsiso.com for any additional questions about the management or use of personal data.

Cookies

Orsiso may use cookies on the Websites it operates. Cookies are small text files that are placed on your computer's hard drive by our servers to identify your computer to our servers. Except for your IP Address, no personally identifiable information stored in the Orsiso cookies will be shared with outside companies for any purpose without your permission.

Ability to Delete Your Personal Information

Your information is entirely private and will never be disclosed to anyone outside the organisation or other users without your express consent. We will never sell on or repackage your data at any time.

We promise to provide you with the option to delete all data held by Orsiso that was generated while your account was active.

Your account will be deleted immediately, but it will remain in our backup systems.

Contact details

If you require any further information regarding the Orsiso Privacy Policy, please email us at privacy@orsiso.com and we will be happy to respond to your concerns and feedback.

Alternatively, you can write to us at the following address:

Aureliant Pte Ltd
No.3 Shenton Way,
Shenton House, #03-08,
Singapore 068805

Nature of terms are subject to change

We reserve the right to modify these terms and conditions at any time, especially during the Beta testing phase, but also in future releases of the software.

We will notify you of any changes to the privacy policy both via our public website as well as notifications to your email address as and when significant changes are made that we feel require your attention and/or approval.

However we urge you to check this Privacy Page every now and then in case we neglect to highlight any changes that will have an impact on you yet we were not able to notify you of such a case in a reasonably timely manner.