OrviumOrvium
How it works Features Channels Pricing FAQ Blog Partners
ENES
Book a Demo
How it works Features Channels Pricing FAQ Blog Partners Book a Demo
{ Legal }

Trust Center

Last updated: September 4, 2026

This page describes, in general terms, the technical and organizational measures Orvium applies to protect personal data, and where we stand on Chile’s Ley 21.719. We describe controls that are actually in place — we do not list aspirations here.

Encryption

  • All traffic to orvium.ai travels over HTTPS/TLS. HTTP requests are permanently redirected to HTTPS and the site is served with HSTS.
  • Data at rest in our databases and object storage is encrypted by the provider with AES-256.
  • Secrets and API keys are held in a managed secret store, never in source control.

Access control

  • Access to production data is role-based and granted on a need-to-know basis. Most of the team has no standing access to personal data.
  • Multi-factor authentication is mandatory on every administrative account.
  • Access is reviewed periodically and revoked the same day a person leaves the team.
  • Administrative actions on personal data are logged.

Website security

  • A Content-Security-Policy restricts which origins may execute scripts, and blocks framing and plugin content.
  • Security headers in place: HSTS, X-Content-Type-Options, Referrer-Policy and Permissions-Policy.
  • Web fonts are served first-party, so no visitor IP is disclosed to a font CDN.
  • Form endpoints are rate-limited and protected by a honeypot rather than by an invasive, cookie-setting CAPTCHA.
  • No analytics or advertising script executes before the visitor consents.

Data handling

  • Customer data is logically isolated per account.
  • Conversations are never used to train external AI models.
  • We apply data minimization: forms ask only for fields we can justify against a stated purpose.
  • Retention periods are defined per category and enforced; see the Privacy Policy.

Incident response

We maintain a documented procedure to detect, contain and investigate security incidents. Where an incident affects personal data, Ley 21.719 requires us to notify the Agencia de Protección de Datos Personales without undue delay, and to notify affected data subjects when the breach is likely to result in a high risk to their rights. To report a vulnerability or a suspected incident, write to privacidad@orvium.ai. We do not pursue legal action against researchers who report in good faith and do not exfiltrate data.

Ley 21.719 readiness

The law enters into force on 1 December 2026. We publish our honest status rather than a compliance claim we cannot yet back:

RequirementStatus
Information duty at the point of collectionImplemented
Prior blocking of third-party tags + granular consentImplemented
Consent records kept as evidenceImplemented in the browser; server-side persistence pending
Public channel to exercise ARSOPB rightsImplemented
Published subprocessor listImplemented
Signed DPAs with every providerIn progress
Records of processing activitiesIn progress
Internal rights-request SLA and ticketingIn progress
Legal review of all published textsPending

We deliberately do not claim to be “compliant with Ley 21.719” while any row above is unfinished. Stating it before it is true would itself be a risk.

OrviumOrvium

The AI agent ecosystem that runs your sales on autopilot.

Features

Features Channels Pricing How it works

Company

FAQ Blog Partner Program Careers Book a Demo

Legal

Privacy PolicyCookie PolicyTerms & ConditionsDPA

Transparency

Exercise your rightsSubprocessorsTrust CenterCookie preferences
© 2026 Orvium. All rights reserved. · Powered by Braincoders