Orion

Enterprise

The Orion privacy framework

How CGM Innovation isolates your data, which regulations we align to, who processes data on our behalf, where it lives, and what we can evidence today. Written for the privacy, legal and security teams who have to sign off on Orion.

1. Data isolation

Multi-tenant with strict logical separation

Every record carries the owning account. Access rules are enforced in the database on each request, so one customer's campaigns, personas and metrics are never reachable from another account.

Encryption at rest and in transit

Stored data is encrypted at rest with AES-256 by our hosting platform, and all traffic to Orion is served over TLS 1.2 or higher.

Role-based access control

Roles live in a dedicated server-side table and are verified on every request. Admin capability is never inferred from anything the browser can change.

Credential handling

Tokens for connected ad, creative and AI platforms are stored per user, scoped to that user's account, and only used to run the syncs you trigger.

2. Compliance alignment

GDPR (EU/EEA)

Lawful basis, purpose limitation, data-subject access, correction, export and erasure requests handled within statutory timelines.

CCPA / CPRA (US)

Right to know, delete, correct and opt out of sale or sharing. Orion does not sell personal information.

POPIA (South Africa)

CGM Innovation operates from South Africa and processes customer data in line with POPIA's eight conditions for lawful processing.

Data Processing Agreements

A DPA covering roles, processing scope, security measures and sub-processors is available for every enterprise contract.

Breach notification

Confirmed personal-data breaches are notified to affected enterprise customers and the relevant regulator within 72 hours of us becoming aware.

3. Sub-processor transparency

The categories below cover every third party that may process customer data on Orion's behalf. Named entities, contract terms and hosting regions for your account are listed in the DPA, and enterprise customers are notified before a new sub-processor is added.

Cloud hosting & databaseApplication hosting, database, authentication and file storageEU / US regions
PaddleMerchant of record: checkout, billing, tax and invoicingEU / US
AI model providersPersona, messaging and creative-brief generation from the prompts you submitUS / EU
Email deliveryTransactional email: auth, billing notices and scheduled performance reportsEU / US
Marketing platform APIs you connectRead-only performance metrics from the accounts you authoriseProvider-dependent

4. Cross-border data transfers

  • Primary storage location for each enterprise account is documented in the DPA before onboarding.
  • Transfers out of the EEA/UK are covered by Standard Contractual Clauses with the relevant sub-processor.
  • For South African enterprises hosted abroad, transfers rely on POPIA section 72 — recipient countries or contracts providing substantially similar protection.
  • Sub-processor list changes are notified to enterprise customers in advance, with a window to object.

5. Audit & certification status

SOC 2 Type II

Readiness programme in progress — not yet certified

ISO 27001

Controls aligned to the standard — not yet certified

Penetration testing

Periodic testing; summary reports available to enterprise clients under NDA

Access reviews

Internal review of privileged access on a scheduled cadence

We publish status, not badges we haven't earned. Where a certification is still in progress we say so, and we will update this page the moment an audit report is issued.

6. Enterprise privacy dashboard

Audit logs

A per-account record of data access and export events, available to enterprise administrators on request while the in-app view is rolled out.

Compliance status

Live status for GDPR, POPIA and SOC 2 readiness — shown with honest states (aligned, in progress, certified) rather than badges we haven't earned.

Data flow visibility

A map of exactly which data Orion touches at each funnel stage, per persona, so your privacy team can review it without reading code.

Data flow: awareness → consideration → action

1

Awareness

In
Company profile, industry, USP — supplied by you
Processing
Persona generation and awareness-stage messaging
Out
Personas, hooks, headlines stored in your account
2

Consideration

In
Persona attributes, brand voice
Processing
Comparison messaging, objection handling, ad-set drafting
Out
Ad sets and creative briefs stored in your account
3

Action

In
Aggregate metrics from the platforms you connect
Processing
CTR/CVR/CPA analysis, budget and task recommendations
Out
Reports and tasks stored in your account

Orion works from the business inputs and aggregate campaign metrics you provide. It does not require customer lists, contact databases or personal data about your end users to build personas or funnel messaging.

Talk to us

For a DPA, sub-processor notification list, penetration-test summary or a security questionnaire, email support@orionmarketing.app. Enterprise SSO details live on the SSO page.