Skip to content
ORchestrate
  • Problem
  • Solution
  • How It Works
  • Matching
  • Founders
Start your free trial
ProblemSolutionHow It WorksMatchingFoundersStart your free trial

U.S. State Privacy Notice

Effective date: September 19, 2026

This notice supplements the Privacy Policy of Orchestrate AI LLC, a Texas limited liability company ("Orchestrate," "we," "us"). It gives the disclosures that the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"), asks a business to make, and it describes how we handle privacy requests from residents of other U.S. states. Read it together with the Privacy Policy, which describes our practices in full; where the two describe the same practice, this notice is the more detailed statement and the Privacy Policy is the shorter one.

Like the Privacy Policy, this notice is not a contract. It describes our practices as of its effective date, creates no contractual or third-party-beneficiary rights, and does not modify any agreement between Orchestrate and a Customer.

1. What This Notice Covers, and What It Does Not

This notice covers the personal information Orchestrate collects for its own business purposes, which is the information described in Section 1.3 of the Privacy Policy: information from visitors to our marketing site at or.chestrate.com, from people who request a demo or a trial or otherwise contact us, from Customer billing contacts, and the account-level administrative information about users of our application at app.or.chestrate.com.

It does not cover Customer Data. Schedules, staff rosters, provider names and credentials, shift and site information, and case and procedure detail in the application are processed on a Customer's behalf and at its direction, under that Customer's written agreement with us. Section 1.1 of the Privacy Policy explains why, and Section 8 below explains what happens to a request we receive about that data: we refer it to the Customer organization and support that organization's response, because that organization — not Orchestrate — decides how to respond.

It does not cover protected health information. Where a Customer's use of the application involves protected health information under HIPAA, Orchestrate acts as that Customer's business associate. The CCPA does not apply to protected health information collected by a covered entity or business associate and governed by HIPAA, or to medical information governed by California's Confidentiality of Medical Information Act. If you are a patient, contact your healthcare provider.

2. Whether the CCPA Applies to Us Today

It does not. The CCPA applies to a for-profit business that meets at least one of three thresholds in Civil Code section 1798.140(d): more than 25 million dollars in annual gross revenue; buying, selling, or sharing the personal information of 100,000 or more California consumers or households in a year; or deriving 50 percent or more of annual revenue from selling or sharing personal information. Orchestrate meets none of them as of the effective date of this notice.

We publish this notice anyway, and we will honor the requests described in Section 8 as a matter of policy, because the disclosures are ones a customer's reviewer is entitled to see and the request handling costs us little at our size. Publishing it does not mean the statute applies to us, and honoring a request under it does not mean the statute applies to us. If we later cross a threshold, these disclosures become the statutory ones and we will say so here. Where a statute does apply to a particular request, we follow that statute's timing and its rules rather than this notice's description of our practice.

3. Notice at Collection

We give this notice at or before the point we collect personal information from you. Every page of our site links to the Privacy Policy and to this notice from the footer, and the demo and trial request form links to the Privacy Policy directly below its submit button.

At the point of collection, the short version is: we collect the categories of personal information listed in Section 4, for the purposes listed there, from the sources listed there; we do not sell your personal information and we do not share it for cross-context behavioral advertising; and we keep it for the periods in Section 5.

4. Categories of Personal Information We Collect

The table below uses the statutory categories in Civil Code section 1798.140(v)(1), lettered A through K as the statute letters them, so that a reviewer can check our disclosure against the statute line by line. A category we do not collect is listed anyway, marked None, rather than omitted — a missing row is ambiguous in a way a stated negative is not.

The "disclosed to" column names categories of recipients, not individual companies. The companies themselves are named in Section 4 of the Privacy Policy: Amazon Web Services for hosting, storage, logging, transactional email, and authentication; Purelymail for our mailboxes; Stripe for card and subscription billing; and our professional advisors. We disclose personal information to these recipients for a business purpose only, and not in exchange for money or other valuable consideration. Amazon Web Services and Purelymail process it on our behalf under their service terms with us; Stripe handles payment information under its own privacy policy; and our professional advisors are bound by professional or contractual duties of confidentiality.

Statutory categoryWhat we collect in itSourcesBusiness or commercial purposesCategories of third parties we disclose it to
A. IdentifiersYour name and work email address; a postal address if you send us one; the IP address a request was sent from; for application users, the log-in email address and account identifier held in our authentication provider.You, when you submit a request or write to us. Your browser and our hosting infrastructure, automatically. The Customer organization that provisions an application account.Responding to demo, trial, and support requests and administering our sales process; operating, securing, and supporting the site and the application; authenticating users; administering Customer accounts and billing; preventing fraud and abuse; complying with law and enforcing our agreements.Hosting, email, and authentication providers; payment processor, for billing contacts; professional advisors; the Customer organization an account belongs to; recipients described in Section 4.4 of the Privacy Policy (legal process, and a merger or sale of assets).
B. Customer records under Civil Code section 1798.80(e)Name, business telephone number and address where you give them to us; practice or group name; billing contact details; and, for Customers who pay by ACH bank debit or by invoice, the bank or billing details on the authorization or order form. Card numbers are entered on Stripe's hosted payment pages and are not collected by us.You. The Customer organization, on an order form or authorization.Administering Customer accounts, billing, collections, and contractual relationships; responding to requests; complying with tax and accounting obligations.Payment processor; hosting and email providers; professional advisors, including our accountants and auditors.
C. Protected classification characteristicsNone. We do not collect characteristics protected under California or federal law for our own business purposes.———
D. Commercial informationThe record of what you asked us for — a demo request, a trial request, or an inquiry — and, for Customers, subscription, invoice, and payment history.You. Our own billing records.Responding to and following up on your request; administering our sales process; administering Customer accounts and billing; complying with tax and accounting obligations.Payment processor; hosting and email providers; professional advisors.
E. Biometric informationNone.———
F. Internet or other electronic network activityYour browser's user-agent string; the pages you request and the time of each request, which our hosting infrastructure processes to deliver the site and may log; when you submit a request, the referring page, the page's path, and any campaign parameters or ad-click identifiers in its address; the anti-spam signals described in Section 2.2 of the Privacy Policy. No analytics or advertising tags are active on the site, so nothing is collected by any third-party tag.Your browser. Our hosting infrastructure (Amazon CloudFront and API Gateway).Operating and securing the site; filtering automated submissions and investigating abuse; measuring site performance; attributing a request to the campaign or referral that produced it.Hosting provider. No advertising or analytics platform, because no such tag is active.
G. Geolocation dataNone collected directly. We do not collect precise geolocation. An IP address, collected under category A, can indicate approximate location; we do not use it for that purpose.———
H. Sensory informationNone. The site and the application collect no audio, electronic, visual, thermal, olfactory, or similar information.———
I. Professional or employment-related informationThe practice or group you work for; the group size, number of sites, and current scheduling setup you describe on the request form; for application users, the assigned application role and the Customer organization the account belongs to.You. The Customer organization that provisions an application account.Responding to your request and administering our sales process; provisioning, authenticating, securing, and supporting application accounts; administering Customer relationships.Hosting and authentication providers; the Customer organization an account belongs to; professional advisors.
J. Non-public education informationNone.———
K. InferencesNone. We do not draw inferences from any of the above to create a profile reflecting preferences, characteristics, aptitudes, or behavior, and we do not profile you in furtherance of decisions that produce legal or similarly significant effects.———
Sensitive personal informationAn application user's account log-in in combination with the password or second authentication factor that allows access to the account. Nothing else — see Section 6.You, when you set or reset your credentials. The Customer organization that provisions the account.Authenticating you and securing your account. Nothing else — see Section 6.Authentication provider (Amazon Cognito).

5. How Long We Keep It

Retention is set by the kind of record rather than by statutory category, because one record — a demo request — contains information from several categories at once. The table below states the period for each kind of record; the table in Section 4 tells you which categories a record contains. These periods restate Section 6 of the Privacy Policy, and they describe what we actually do; where a period is enforced by an automatic expiry, the table says so.

Kind of recordHow long we keep it
Demo and trial requests, the IP address and user-agent stored with them, and related correspondenceFor as long as we have an active sales relationship with you or another legitimate business need. We review these records at least quarterly and aim to delete them within twenty-four (24) months after our last contact with you, and copies may persist for a limited further period in routine encrypted backups before those backups roll off. We will delete them sooner on request, unless we are required to keep them.
Application account information, including log-in credentials and authentication factorsFor the life of the Customer relationship and for any post-termination period the applicable customer agreement and its exhibits set, after which we delete or de-identify it in accordance with that agreement.
Billing contacts, payment instructions, and invoice and payment historyFor the life of the Customer relationship, and afterwards for the period our tax and accounting obligations require.
Infrastructure, application, and security logsFor as long as we need them to operate and secure the service, and for any longer period a customer agreement requires. Access logs for the application's API are deleted automatically after 400 days. Our cloud audit trail and our other logs are not currently subject to an automatic expiry period; we review them as part of our periodic privacy review and delete them when they are no longer needed.
Records we are required to keep by law, and records a Business Associate Agreement requires us to retainFor the period that law or that agreement requires.
Campaign-attribution values and application interface state stored in your own browserUntil they are replaced or you clear your browser's storage. We credit your first request for 90 days, after which a later request replaces it.

6. Sensitive Personal Information

The only sensitive personal information we collect as a business is an application user's account log-in in combination with the password or second authentication factor that allows access to the account. We collect no Social Security, driver's license, state identification, or passport number; no precise geolocation; no racial or ethnic origin, religious or philosophical belief, or union membership; no genetic or biometric data; no information about sex life or sexual orientation; and no health information for our own purposes.

We use and disclose that credential information only to authenticate you and to secure your account — purposes that Civil Code section 1798.121(a) and the CCPA regulations permit without offering a right to limit. We do not use or disclose sensitive personal information to infer characteristics about you, and we do not use it for any purpose beyond those permitted ones. That is why this site has no "Limit the Use of My Sensitive Personal Information" link: there is no use to limit. If that ever changes, we will add one and say so here.

The contents of an email you send us are not treated as sensitive personal information, because we are the intended recipient of a message you address to us. Health information in the application — including any protected health information and any workforce health information a Customer records, such as a staff member's pregnancy status for radiation-safety scheduling — is Customer Data processed on the Customer's behalf. It is outside this notice and is addressed in Section 1 above. We make it visible only to the Customer's administrators and do not copy it for our own purposes.

7. We Do Not Sell or Share Personal Information

We do not sell personal information, and we have not sold it in the preceding twelve months. We do not share personal information for cross-context behavioral advertising, and we have not shared it for that purpose in the preceding twelve months. We receive no money or other valuable consideration for disclosing personal information.

We have no actual knowledge that we sell or share the personal information of consumers under 16 years of age. Our site and application are business tools intended for adults, and we do not knowingly collect personal information from anyone under 18.

The disclosures we do make are the ones in the last column of the table in Section 4: to the service providers named in Section 4, on the terms described there, to our professional advisors, to the Customer organization an account belongs to, and for the legal and corporate purposes described in Section 4.4 of the Privacy Policy.

8. Your Rights

We will honor these requests from a California resident, and — as Section 8.2 of the Privacy Policy already commits — from a resident of any U.S. state, subject to the limits at the end of this section.

  • Right to know and to access. You may ask us to tell you the categories of personal information we have collected about you, the categories of sources, the business or commercial purposes for collecting it, the categories of third parties to whom we disclose it, and the specific pieces of personal information we hold. The table in Section 4 answers the category questions for everyone, in advance; a request lets you ask about your own information specifically. We will look back at least twelve months, and beyond that where you ask and it is not impossible or disproportionately difficult for us.
  • Right to delete. You may ask us to delete the personal information we collected from you. We will also direct our service providers to delete it, except where an exception in Civil Code section 1798.105(d) applies — for example where we need it to complete a transaction, to detect or prevent security incidents, or to comply with a legal obligation.
  • Right to correct. You may ask us to correct inaccurate personal information we hold about you. Tell us what is wrong and what it should say, and give us any documentation that helps us assess it.
  • Right to portability. Where you ask for the specific pieces of personal information we hold and you gave that information to us electronically, we will provide it in a portable and, to the extent technically feasible, readily usable format that lets you transmit it to another entity without hindrance.
  • Right to opt out of sale or sharing. We do not sell or share personal information (Section 7), so there is nothing to opt out of and this site has no "Do Not Sell or Share My Personal Information" link. If that ever changes, we will add one and say so here before it does.
  • Right to limit the use of sensitive personal information. We use sensitive personal information only for permitted purposes (Section 6), so there is nothing to limit. If that ever changes, we will offer the right and say so here before it does.
  • Right to non-discrimination. We will not deny you goods or services, charge you a different price, provide a different level or quality of service, or suggest that we will, because you exercised a privacy right. We offer no financial incentive in exchange for personal information.
  • Right to appeal. If we decline your request, you may ask us to reconsider by replying to our response. We will consider what you send us and respond. Several state privacy statutes require an appeal mechanism; we offer one to everyone.

The limits. First, a request about Customer Data in the application is governed by Section 1.1 of the Privacy Policy: we act on the Customer's instructions for that data, so we will refer your request to that organization and support its response rather than acting on it ourselves. Second, we may decline a request, in whole or in part, where law permits or requires us to retain the information; where we cannot verify your identity or an agent's authority; where honoring it would adversely affect the rights or freedoms of another person, or the security or integrity of our systems; where we no longer hold the information; or where the request is repetitive, excessive, or manifestly unfounded, for which we may also charge a reasonable fee to the extent applicable law allows. We will tell you which limit we relied on.

9. How to Submit a Request

By email, to security@or.chestrate.com with "Privacy Request" in the subject line. Or by mail, to the address in Section 14.

Civil Code section 1798.130(a)(1)(A) lets a business that operates exclusively online and has a direct relationship with the consumer designate an email address as the method for submitting requests. We operate exclusively online and have that direct relationship, so we do not operate a toll-free telephone line. We accept requests by mail as a second method regardless.

Please tell us what you are asking for, the email address or other details you used when you contacted us or that identify your account, and the state you live in. If you are making a request on behalf of someone else, read Section 11 first.

What happens next. We will confirm receipt within ten (10) business days and tell you how we will handle the request. We will respond substantively within forty-five (45) calendar days of receiving it. If we need more time we will tell you within that first period, and we may extend it by up to another forty-five (45) days. There is no charge, unless the request is manifestly unfounded or excessive and applicable law allows us to charge.

10. How We Verify a Request

We verify a request before acting on it, because acting on an unverified request is itself a disclosure of personal information to the wrong person. How much verification we need depends on how sensitive the information is and how much harm an unauthorized request could do.

  • If you have an application account, we verify you through that account: we will ask you to make the request from the email address on the account.
  • If you do not have an account, we match the details you give us against the record we hold — typically the email address you used and one or more of the other details you submitted, such as the practice or group name.
  • For a request for the specific pieces of personal information we hold, we apply a higher standard, and we may ask you to give us a signed declaration, under penalty of perjury, that you are the person whose information you are asking about.
  • If we cannot verify you to the standard the request requires, we will tell you, and we will explain what we would need. We may still be able to answer a narrower version of the request — for example, the categories of information we hold rather than the specific pieces.

We use the information you give us for verification only for that purpose, and we do not keep it longer than we need it for that purpose and for our record of having handled the request.

11. Authorized Agents

You may use an authorized agent to make a request for you. If you do, we will ask the agent for written permission signed by you, and we will ask you to verify your own identity directly with us and to confirm directly that you gave the agent permission. We may skip those steps where the agent provides a valid power of attorney under California Probate Code sections 4000 to 4465.

We may deny a request from an agent who does not submit proof of authorization.

12. Global Privacy Control and Other Opt-Out Preference Signals

We do not track you across other websites or services, and we do not sell personal information or disclose it for targeted advertising or cross-context behavioral advertising. Because there is no sale, sharing, or cross-site tracking to opt out of, we do not currently process browser "Do Not Track" or Global Privacy Control signals differently from any other request, and the absence of a response to one does not mean any such disclosure is happening.

If we ever enable cross-site advertising technology or begin to sell or share personal information, we will treat a Global Privacy Control signal as a valid opt-out request for the browser that sends it, and we will state that in this section and in Section 5.3 of the Privacy Policy before we do so.

13. Residents of Other U.S. States

Several other states have comprehensive consumer privacy statutes, and most of them apply only above thresholds that Orchestrate does not meet today. Rather than track which one applies to you, we apply one practice to everyone: we will honor a verified request from any U.S. resident to access, correct, or delete the personal information covered by this notice, subject to the limits in Section 8, and we offer the appeal in Section 8 to everyone.

Where a statute does apply to your request, we follow that statute — its response deadlines, its exceptions, and its appeal and complaint procedures — rather than this description of our practice. Where none applies, this section describes our practice rather than granting you a legal right, and honoring a request does not mean a statute applies to us.

State medical privacy and health data statutes may also give you rights concerning health information held by a healthcare provider. Those requests belong with your healthcare provider, not with us (Section 1).

14. Changes, and Contact

We may update this notice. We will post the updated version here with a new effective date, and the Privacy Policy's change process in its Section 10 applies to this notice as well.

Orchestrate AI LLC Attn: Privacy PO Box 9684, 770 Northcross Dr, Austin, TX 78766 Email: security@or.chestrate.com

See also the Privacy Policy, the EEA & UK Privacy Notice, and our Terms of Use.

Effective September 19, 2026. This notice supplements our Privacy Policy.

ORchestrate

Intelligent Anesthesia Scheduling Platform. Your entire group staffed in one click. Built by a chief CRNA and the engineer who solved it. Austin, TX.

As heard onAtomic Anesthesia podcast

Explore

  • Problem
  • Solution
  • How It Works
  • Matching
  • Founders

Get a demo

  • Start your free trial
  • Email us directly
© 2026 ORchestrate. All rights reserved.Built by a chief CRNA and the engineer who solved it.
Privacy PolicyTerms of UseU.S. State PrivacyEEA & UK Privacy