Introduction
With the ORCA Sonar - Automated Data Extraction from Files feature, you and your users can extract structured data from the files you upload into your ORCA vaults.
Everything stored in ORCA is encrypted and ORCA can NOT view the content of your files, contacts, or assets. However, ORCA Sonar processing requires temporary handling of unencrypted data during analysis. This document explains the extent of that visibility, how your data is processed, and what third parties are involved.
By activating ORCA Sonar, you agree that this document is an extension of ORCAβs Privacy Policy and Terms and Conditions.
Key Messages
- ORCA Sonar enables you to automatically extract structured data from files, using AI models.
- Confidentiality: Your data is never used to train AI models.
- Zero Retention: Files, prompts, and outputs are deleted immediately after processing.
- European Compliance: All data processing occurs within Europe, in compliance with EU data protection laws (including GDPR).
- Temporary Access: ORCA has theoretically the means to access the contents of your files and prompts during processing (but not after).
- AI Model: As per the date of this document, ORCA uses OpenAI's GPT 5 mini model (subject to change).
- Output accuracy: The data extracted and presented to you may be inaccurate or incomplete. ORCA is not responsible for incorrect data storage as a result of an AI analysis, and the User is required to review and validate the information at all times.
AI Model
Which provider and model is used?
ORCA utilizes OpenAI models for its ORCA Sonar functionality. As of the last update of this T&C, ORCA is specifically operating on the GPT 5 mini model. Please note that this may change in the future, and this document may not be updated to reflect such changes.
What is the agreement with the Model Provider?
ORCA has a dedicated agreement with the model provider to achieve zero data retention, ensuring that client data is handled in accordance with our privacy commitments. Furthermore, in the agreement it is limited how they can use data from these anonymous requests, including not using prompts and outputs to develop or improve their models, as well as deleting all information received once it is no longer necessary to provide outputs.
As noted above, ORCA calls model providers on your behalf, therefore your personal information (for example, IP address) is not exposed to them.
Output Reliability
AI outputs may be inaccurate, incomplete, or otherwise unreliable. Always review and validate all AI-extracted information before relying on it. ORCA and its model providers are not responsible for errors in data extraction or storage.
Data Visibility
During the processing of your data, ORCA theoretically has the means to access the contents of the files and prompts submitted.
How your data is processed:
- Your file is uploaded to the ORCA Server.
- The ORCA Server sends the file to the AI Model.
- The ORCA Server sends prompt(s) to the AI Model, requesting information about the file,
- The AI model returns its output(s) to the ORCA Server.
- The output is sent to the ORCA Client.
All of the actions on the ORCA Server take place in memory and are not stored.
During the processing above, the AI-relevant data, which includes:
- prompt input,
- prompt output, and
- file contents
is NOT encrypted. Afterwards, all of the AI-relevant data is erased both from the ORCA Server and the AI Model memory whilst the file content is stored encrypted following the strategy described in the Security White Paper.
Therefore, this access is strictly limited to the processing phase and does not imply any retention or further use of the data.
Data Usage
- Client Data is Never Used for Training: ORCA does not use any client data, including files and prompts, for the purpose of training its AI models. Your data remains confidential and is not utilized to improve or develop any AI models.
- Zero-Data Retention: All client data which is unencrypted in this process, including files and prompts, are immediately deleted after processing (the File is nevertheless stored encrypted, following the strategy described in the Security White Paper). ORCA adheres to a strict zero-data retention policy, ensuring that no information is stored or retained beyond the necessary processing time.
- Data Location: All client data is processed and stored within Europe. ORCA ensures compliance with European data protection regulations, providing a secure environment for your information.
Conclusion
By using ORCA Sonar functionality, you acknowledge and accept these Terms & Conditions.
Our general Terms of Service and Privacy Policy also apply here. If there is a conflict with our general Terms of Service, these Terms of Service apply. Your data privacy is of utmost importance to us, and we are committed to maintaining the confidentiality and security of your information.
Contacting ORCA
If you have questions about our data security, please contact us any time privacy@withorca.com.