Effective 11 September 2026
Privacy notice
How Vaalmika Platforms Inc. handles information in AdvisorOrbit.
Who handles your information
AdvisorOrbit is provided by Vaalmika Platforms Inc., Ontario, Canada. For privacy questions, access, correction, export or deletion requests, contact contact@vaalmi.com. We verify identity and authority before releasing or changing information. Please describe your request without emailing client files, recordings, passwords or identity documents; we will arrange a suitable way to handle any necessary information.
When an advisor or business uses AdvisorOrbit for client records, that business determines why the records are collected and used. We process those records to provide the workspace and on the business’s instructions. We also handle account, security and billing information to operate our own service. A client may contact their advisor or contact us for help directing a request.
Information we handle and why
Account information includes your name, email, workspace membership and authentication information. Workspace information includes contacts, client and household details, consent records, notes, recordings, transcripts, proposed and reviewed facts, policies, production records and activity history. Notes may contain sensitive financial, health, beneficiary or family information. Submit only information needed for your authorized work.
We use this information to save and organize records, manage team access, provide requested AI capture assistance, support customers, protect the service and meet applicable obligations. We use essential authentication cookies. We do not sell client records or use them for advertising.
Stripe handles payment details. AdvisorOrbit stores subscription and payment references and requires a billing address at checkout; full card details are handled by Stripe.
AI processing and permission
Saving a note or uploading a voice memo starts AI processing automatically and confirms that you have permission to share it. The note or recording is sent to Google’s Gemini API for transcription and extraction of suggested facts. The transcript may also be sent for extraction or a validation retry. Everyone recorded must have given the required permission, and the business must have authority to process any sensitive information and information about other people in the capture.
Real and deidentified client data require an approved workspace and reviewed provider configuration. Selecting a data mode does not remove identifiers. Client recording support is initially English only. Do not upload passwords, payment-card numbers, bank account numbers, government identity documents or material you have no authority to process.
Approved client-data processing requires a Google Cloud project with active billing. Under Google’s paid-service terms, prompts and responses are not used to improve Google’s products. Google separately describes retention of prompts, context and outputs for 55 days for abuse monitoring, with authorized review in relevant cases. This is not a promise of zero retention. Files uploaded through the Gemini Files API are removed after processing where possible and otherwise expire under Google’s file policy. Google’s terms and abuse-monitoring policy explain these practices.
AI can mishear names and numbers or propose incorrect facts. Every suggestion requires human review. A matching quote does not prove that a transcript is accurate. AdvisorOrbit does not make insurance eligibility, underwriting, medical or financial decisions for you.
Access and service providers
Authorized team members can access records according to their role. Team leaders may see shared business records and activity metadata; another advisor’s raw notes, recordings and evidence quotes are restricted in the app. Authorized service operators may access information when necessary for support, security or an approved data request.
We use Supabase for database, authentication and private recording storage; Vercel for application hosting; Google for enabled AI capture processing; Stripe for payments; and Resend for account messages. Providers receive the information needed for their functions. We may also disclose information where required by law or necessary to protect lawful rights and service security.
Processing locations and safeguards
Some service providers may process or retain information outside Canada, where local authorities may have lawful access. Canadian application or database hosting does not guarantee that all processing, support, logs and backups stay in Canada. Google’s paid-service terms permit temporary storage or caching in countries where Google or its agents have facilities. Businesses with location-specific requirements must confirm suitability before entering client data.
Controls include authenticated access, workspace and owner restrictions, private recording storage, expiring recording links, encrypted transport and authenticator requirements for team leaders. No service can guarantee absolute security. Users are responsible for securing their devices, credentials and exported copies.
Retention, export and deletion
Client records are kept for the workspace’s authorized business use until a reviewed retention or deletion instruction applies. A workspace can request a retention period for reviewed source notes and recordings. Unreviewed facts, pending commitments and legal or regulatory holds must be resolved before their supporting material is removed. Removing a source does not automatically remove previously reviewed facts.
Unconfirmed uploads and unreferenced recordings become eligible for cleanup after 24 hours. Approved workspace erasure first freezes access and processing, allows existing upload links to expire, and removes the active database records and recording objects. Storage failures are retried and are not reported as completed deletion.
A full workspace export can include structured records, notes, transcripts, evidence and original recordings. We verify the requester’s authority and the appropriate scope before delivery, including access to other people’s source material. Contact us for an individual account or client request; an advisor’s departure, subscription cancellation and full workspace deletion are distinct actions.
Account identities, external billing records, security or request records, provider-held copies and backups may have separate retention requirements. We will explain applicable holds and residual copies when fulfilling a request. Deletion from the active workspace does not instantly erase provider logs or backups. Restored backups must have completed deletions reapplied before service resumes.
Your choices and requests
You may ask for correction or access, request an export, or ask to withdraw permission or delete information. We may need to work with the business controlling client records and account for applicable retention obligations. Withdrawing permission does not reverse completed processing or independently delete stored records. Open the original source in a saved capture’s review panel and use “Withdraw AI permission” to stop queued processing, or contact contact@vaalmi.com for help. A provider request already sent may still finish. Contact us to discuss deletion of stored information.
This service is for adult business users. Do not create accounts for children. Include information about dependants or other individuals only with appropriate authority and only when necessary for the business purpose.
Changes and contact
We will update the date on this notice when it changes and provide notice of material changes where required. Our Terms of Service, subscription policy and support page provide further information.