1. Introduction
Ontio, Inc. ("Ontio," "we," "us," or "our") operates a graph-native Decision Intelligence Platform that helps organizations model, query, and reason over their operational data. This Privacy Policy explains how we collect, use, disclose, and safeguard information in connection with our website (ontio.ai), our platform, and related services (collectively, the "Services").
We treat two categories of information differently under this Policy:
- Site and Account Data: information we collect directly from visitors, prospects, and registered platform users (e.g., name, work email, company, role).
- Customer Data: the operational data a customer connects and ingests into its own knowledge graph instance through the Ontio platform, and any personal data that data may contain.
If you are an individual whose personal data appears within a customer's Customer Data (for example, an employee, vendor, or customer of one of our business customers), please direct any privacy inquiry to that organization. Ontio acts as a data processor on their behalf, as described in Section 2, and generally cannot act on individual requests concerning Customer Data without that organization's instruction.
2. Controller and Processor Roles
For Site and Account Data, Ontio is the data controller (or "business" under the CCPA/CPRA).
For Customer Data, our customer is the data controller and Ontio acts as a data processor (or "service provider"). We process Customer Data only on the customer's instructions, only for the purposes set out in the applicable order form and Data Processing Agreement ("DPA"), and only to provide, secure, and support the Services, never for our own independent purposes.
3. Information We Collect
3.1 Information You Provide Directly
- Contact details submitted through forms, demo requests, or sign-ups (name, email, company, role)
- Account credentials and profile information for platform users
- Billing and contact information for paid subscriptions
- Content of support requests and other communications with us
3.2 Customer Data
Ontio's platform ingests operational data from customer-connected source systems through a steps of pipeline into a knowledge graph. The categories of data ingested (and whether that data includes personal data) are determined entirely by the customer and the source systems it connects. Ontio does not decide what personal data is ingested; we process whatever the customer instructs us to process.
3.3 Information Collected Automatically
- Usage and telemetry data (features used, query patterns, session activity, error and performance logs)
- Device and network log data (IP address, browser type, timestamps)
- Cookies and similar technologies on our marketing website (see Section 9)
4. How Deployment Model Affects Data Handling
Ontio is offered in four deployment models, and the model a customer selects materially changes what data, if any, Ontio can access:
| Deployment Model | Where Customer Data Resides | Ontio's Access to Customer Data |
|---|---|---|
| Cloud | Ontio-managed cloud environment (multi-tenant/customer-owned graph instance) | Processes data as needed to run the Service |
| Hybrid | Split between the customer's environment and Ontio-managed components | Limited to the components Ontio operates |
| On-Premises | Entirely within the customer's own infrastructure | No direct access outside an explicit, customer-initiated support engagement |
| Air-Gapped | Entirely within an isolated customer environment with no external connectivity | No access under any circumstance |
Customers on On-Premises or Air-Gapped deployments should note that Ontio does not receive, store, or otherwise process Customer Data as part of ordinary Service operation.
5. How We Use Information
We use Site and Account Data to:
- Operate, secure, and improve the Services and our website
- Communicate about your account, product updates, or requested information
- Provide customer support
- Detect, investigate, and prevent fraud, abuse, or security incidents
- Comply with legal and regulatory obligations
We use Customer Data solely to deliver the contracted Services (e.g., running the data ingestion and processing pipeline, executing queries, generating decision outputs) as instructed by the customer. We do not use Customer Data to train foundation models outside the customer's own environment, sell it, or use it for our own marketing.
6. AI Model Providers and Other Subprocessors
Certain platform functions rely on third-party subprocessors, currently including:
- OpenAI, Gemini and Anthropic: LLM inference supporting the ontology pipeline's language-augmented steps and natural-language query interpretation
- Neo4j: the underlying graph database
- Qdrant: vector similarity search
- PostgreSQL: relational, analytical, and application data storage
- LangSmith: LLM observability and tracing used for platform reliability
- Microsoft Presidio, Hugging Face: automated detection and redaction of personal data prior to downstream processing, where configured
If a customer configures Ontio to route data to an external LLM provider or to a customer-supplied (bring your own) LLM, the handling of that data is governed by the privacy terms and contractual agreements of the chosen LLM provider, not Ontio. Customers are solely responsible for reviewing and managing their agreements and data privacy obligations with external or customer-provided LLM providers; Ontio is not responsible for data privacy or data handling practices of these third-party or customer-selected LLMs. Longer-term protections such as Zero Data Retention require a separately negotiated agreement with the provider and are not automatic or self-service. For guidance, see your deployment documentation or contact your account team.
Where Microsoft Presidio is configured to redact personal data before a request reaches an external provider, that data does not reach the provider's systems at all, regardless of its retention terms.
A current subprocessor list is available on request at privacy@ontio.ai.
7. Data Security
We maintain administrative, technical, and physical safeguards designed to be appropriate to the sensitivity of the data we process, including encryption in transit and at rest for Ontio-managed components, role-based access controls, tenant isolation, data masking and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
8. Data Retention and Deletion
We retain Site and Account Data for as long as needed to provide the Services and for legitimate business or legal purposes. Customer Data is retained and deleted in accordance with the applicable customer agreement and our Data Deletion Policy at ontio.ai/data-deletion.
9. Cookies and Similar Technologies
Our marketing website uses cookies for essential site function, analytics, and, where applicable, marketing attribution. You can control cookies through your browser settings; disabling some cookies may affect site functionality.
10. International Data Transfers
Where we transfer personal data across borders, we rely on appropriate safeguards such as Standard Contractual Clauses or other legally recognized transfer mechanisms.
11. Your Privacy Rights
Depending on your location, you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing:
- California residents have rights under the CCPA/CPRA, including the right to know, delete, correct, and opt out of certain sharing.
- EEA/UK residents have rights under the GDPR/UK GDPR, including access, rectification, erasure, restriction, portability, and objection.
To exercise these rights regarding Site and Account Data, contact privacy@ontio.ai. We will respond within the timeframe required by applicable law. If your personal data appears within a customer's Customer Data, please direct your request to that organization; we will assist our customer in responding if contractually required to do so.
12. Children's Privacy
The Services are not directed to individuals under 16, and we do not knowingly collect personal data from children.
13. Changes to This Policy
We may update this Policy periodically. Material changes will be posted on this page or, where required by law, communicated directly. The Last updated date above reflects the most recent revision.
14. Contact Us
Ontio Holdings, privacy@ontio.ai