1. Who we are
Octoryn Router is operated by Octopus Core Pty Ltd (ACN 696 931 236, ABN 28 696 931 236), a company registered in New South Wales, Australia. In this notice, “Octoryn”, “we”, “us” and “our” refer to Octopus Core Pty Ltd in its capacity as operator of Octoryn Router.
Privacy questions may be sent to privacy@octopusos.ai. Data protection enquiries may be sent to dpo@octopusos.ai.
2. Scope and roles
We act as controller for information about website visitors, prospects, customer administrators and support contacts. For prompts, outputs and other customer content routed on a customer’s instructions, the customer is normally the controller and we act as processor or service provider.
Independent model providers may process content under the selected route, customer configuration and their applicable terms. Customers choose or approve eligible providers through their workspace and policy configuration.
3. Information we collect
The information involved depends on how you interact with Octoryn.
- Contact and account information, such as name, business email, organisation, role and workspace membership.
- Authentication and security information, including credential identifiers, login events, IP address and abuse-prevention signals. Secret values are not intended to appear in public website content.
- Router operational records, such as request identifiers, selected route, provider outcome, token usage, latency, status and error information.
- Customer content, including prompts, inputs and model outputs, only to the extent configured or required to deliver, secure and troubleshoot the requested service.
- Website information needed to deliver and protect the site, including browser, device, network and essential cookie information.
- Support correspondence and information you deliberately submit to us.
4. How we use information
We use personal information only for defined service and business purposes.
- Provide, authenticate, route, secure and monitor the Router service.
- Administer workspaces, access, provider eligibility, budgets and support.
- Detect abuse, investigate incidents and maintain service reliability.
- Measure service usage and meet contractual, accounting and legal obligations.
- Communicate about service changes, requests and customer relationships.
- Improve documentation and operations using aggregated or de-identified information where practical.
5. Legal bases and customer instructions
Where a legal basis is required, processing may rely on performance of a contract, legitimate interests in operating and securing the service, compliance with law, or consent where specifically requested. Customer content is processed on documented customer instructions, including the agreement, workspace configuration and API requests.
Octoryn Router selects model supply under configured policy. It is not intended by itself to make decisions that determine an individual’s legal rights or access to essential services. Customers remain responsible for human review and lawful use in any consequential workflow.
6. Sharing and subprocessors
We disclose information only where needed to operate the service, follow customer instructions, protect rights and systems, or comply with law. Recipients may include infrastructure, security, communications and professional service providers, and model providers eligible under the customer’s route.
We do not sell personal information. Current customer-specific subprocessors and model providers are governed by the applicable agreement, DPA and workspace configuration.
7. International processing
The managed Router production environment is operated in the configured Australian region. A selected model provider may process data in other locations depending on the provider account, route and customer configuration.
Customers should use residency policies and provider eligibility controls appropriate for their workload. Contractual safeguards apply where required by the applicable data terms.
8. Retention
We retain information only for as long as needed for the purpose collected, the configured service, security, dispute resolution and legal obligations. Retention periods may differ for account records, operational logs, customer content, support records and financial records.
Customer agreements and workspace configuration may define more specific retention or no-content-retention requirements. Backups and provider-side copies may follow separate documented deletion cycles.
9. Security
We use technical and organisational measures designed to protect information against unauthorised access, alteration, disclosure and loss. Measures are selected according to risk and may include access controls, encryption in transit, protected workload credentials, environment separation, monitoring and incident response.
No internet service can guarantee absolute security. Customers must protect API keys, apply least privilege and avoid sending data that the selected route is not approved to process.
10. Your choices and rights
Depending on your location and relationship with us, you may request access, correction, deletion, restriction, objection or portability, or make a privacy complaint. We may need to verify identity, authority and the relevant workspace before acting.
Send privacy requests to privacy@octopusos.ai. If we process customer content for an organisation, we may direct the request to that customer because it controls the data.
11. Changes and contact
We may update this notice when the service, law or information handling changes. The effective date above identifies the current published version. Material changes will be communicated through an appropriate service or customer channel.
Privacy: privacy@octopusos.ai · Data protection: dpo@octopusos.ai · Legal notices: legal@octopusos.ai
