Enterprise
The Orion privacy framework
How CGM Innovation isolates your data, which regulations we align to, who processes data on our behalf, where it lives, and what we can evidence today. Written for the privacy, legal and security teams who have to sign off on Orion.
1. Data isolation
Multi-tenant with strict logical separation
Every record carries the owning account. Access rules are enforced in the database on each request, so one customer's campaigns, personas and metrics are never reachable from another account.
Encryption at rest and in transit
Stored data is encrypted at rest with AES-256 by our hosting platform, and all traffic to Orion is served over TLS 1.2 or higher.
Role-based access control
Roles live in a dedicated server-side table and are verified on every request. Admin capability is never inferred from anything the browser can change.
Credential handling
Tokens for connected ad, creative and AI platforms are stored per user, scoped to that user's account, and only used to run the syncs you trigger.
2. Compliance alignment
GDPR (EU/EEA)
Lawful basis, purpose limitation, data-subject access, correction, export and erasure requests handled within statutory timelines.
CCPA / CPRA (US)
Right to know, delete, correct and opt out of sale or sharing. Orion does not sell personal information.
POPIA (South Africa)
CGM Innovation operates from South Africa and processes customer data in line with POPIA's eight conditions for lawful processing.
Data Processing Agreements
A DPA covering roles, processing scope, security measures and sub-processors is available for every enterprise contract.
Breach notification
Confirmed personal-data breaches are notified to affected enterprise customers and the relevant regulator within 72 hours of us becoming aware.
3. Sub-processor transparency
The categories below cover every third party that may process customer data on Orion's behalf. Named entities, contract terms and hosting regions for your account are listed in the DPA, and enterprise customers are notified before a new sub-processor is added.
4. Cross-border data transfers
- Primary storage location for each enterprise account is documented in the DPA before onboarding.
- Transfers out of the EEA/UK are covered by Standard Contractual Clauses with the relevant sub-processor.
- For South African enterprises hosted abroad, transfers rely on POPIA section 72 — recipient countries or contracts providing substantially similar protection.
- Sub-processor list changes are notified to enterprise customers in advance, with a window to object.
5. Audit & certification status
SOC 2 Type II
Readiness programme in progress — not yet certified
ISO 27001
Controls aligned to the standard — not yet certified
Penetration testing
Periodic testing; summary reports available to enterprise clients under NDA
Access reviews
Internal review of privileged access on a scheduled cadence
We publish status, not badges we haven't earned. Where a certification is still in progress we say so, and we will update this page the moment an audit report is issued.
6. Enterprise privacy dashboard
Audit logs
A per-account record of data access and export events, available to enterprise administrators on request while the in-app view is rolled out.
Compliance status
Live status for GDPR, POPIA and SOC 2 readiness — shown with honest states (aligned, in progress, certified) rather than badges we haven't earned.
Data flow visibility
A map of exactly which data Orion touches at each funnel stage, per persona, so your privacy team can review it without reading code.
Data flow: awareness → consideration → action
Awareness
- In
- Company profile, industry, USP — supplied by you
- Processing
- Persona generation and awareness-stage messaging
- Out
- Personas, hooks, headlines stored in your account
Consideration
- In
- Persona attributes, brand voice
- Processing
- Comparison messaging, objection handling, ad-set drafting
- Out
- Ad sets and creative briefs stored in your account
Action
- In
- Aggregate metrics from the platforms you connect
- Processing
- CTR/CVR/CPA analysis, budget and task recommendations
- Out
- Reports and tasks stored in your account
Orion works from the business inputs and aggregate campaign metrics you provide. It does not require customer lists, contact databases or personal data about your end users to build personas or funnel messaging.
Talk to us
For a DPA, sub-processor notification list, penetration-test summary or a security questionnaire, email support@orionmarketing.app. Enterprise SSO details live on the SSO page.