top of page

INTERNATIONAL DATA TRANSFERS ADDENDUM (GDPR & GLOBAL PRIVACY FRAMEWORK)

This document forms an integral part of ORO Technologies LLC Privacy Policy and Data Protection Framework. In case of conflict between this Addendum and the Privacy Policy or Terms and Conditions, the Privacy Policy and master legal documents shall prevail.

1. Overview

ORO Technologies LLC operates a global voice-first technology platform that facilitates accessibility-focused, communication, marketplace, mobility-related, safety-related, and digital technology services through independent users, providers, partners, and third-party infrastructure. Due to the international nature of its infrastructure, data may be processed and transferred across multiple jurisdictions, including but not limited to the United States, European Economic Area (EEA), Latin America, and other regions where service providers or infrastructure partners operate.

All international transfers are conducted in compliance with applicable data protection laws, including Regulation (EU) 2016/679 (GDPR), and other equivalent privacy frameworks where applicable.

1.1 Definitions of Specialized Data Categories

For purposes of this Addendum:

“Voice Data” includes audio inputs, speech recordings, voice commands, speech-to-text outputs, text-to-speech interactions, wake-word activations, and metadata associated with voice-enabled interactions.

“AI Data” includes machine-generated outputs, automated recommendations, behavioral signals, fraud-detection indicators, safety scoring mechanisms, and algorithmically processed interactions.

“Accessibility Data” includes accessibility preferences, assistive technology interactions, disability-related platform configurations voluntarily provided by the User, and accessibility-related usage patterns strictly necessary for platform functionality.

Such categories may be processed through automated systems, cloud infrastructure providers, or third-party subprocessors strictly for operational, accessibility, security, fraud-prevention, compliance, and platform-integrity purposes.

2. Standard Contractual Clauses (SCCs)

Where required under applicable law, ORO Technologies LLC relies on the Standard Contractual Clauses (SCCs) approved by the European Commission as a legal mechanism for international data transfers.

These clauses ensure:

  • Adequate protection of personal data

  • Enforceable rights for data subjects

  • Legal remedies in case of violations

3. Roles of the Parties

Depending on the nature of the processing activity, Oro Technologies LLC may act as Data Controller, Data Processor, or Technology Intermediary. Independent drivers, service providers, and third-party partners may act as independent data controllers under applicable law.

3.1 Independent Third-Party Controllers and International Processing Ecosystem

The ORO Platform operates through a distributed international technology ecosystem involving independent service providers, infrastructure partners, cloud providers, telecommunications operators, payment processors, accessibility technology providers, artificial intelligence providers, cybersecurity vendors, mapping services, analytics providers, and other third-party entities.

Depending upon the applicable service, jurisdiction, operational activity, legal framework, or processing purpose, certain third parties may act as independent controllers, independent businesses, separate processors, separate service providers, or legally distinct entities operating under their own privacy practices, contractual frameworks, and regulatory obligations.

ORO does not control the independent privacy practices, security procedures, operational decisions, regulatory compliance programs, or legal obligations of such independent third parties except to the extent required by applicable law or contractual arrangements.

4. Scope of Data Transfers

Data transfers may include:

  • User identification data

  • Trip and transaction data

  • Location data

  • Device and usage data

These transfers are necessary to:

  • Operate the platform

  • Facilitate services between users

  • Ensure safety and fraud prevention

  • Comply with legal obligations

4.1 Voice, AI, and Safety Data Processing

The Platform may process voice commands, AI-generated interactions, safety signals (including S.O.S. alerts), and accessibility-related inputs for the purpose of:

  • Service facilitation

  • Safety and fraud prevention

  • Platform optimization

  • Accessibility improvement

Such data may be transmitted to third-party infrastructure providers, including emergency coordination or security partners where applicable, strictly for operational processing.

ORO does not independently execute emergency interventions.

4.1.1 Emergency Communications and Third-Party Safety Infrastructure

Users acknowledge that emergency-related communications, including S.O.S. signals, safety alerts, or accessibility-triggered notifications, may rely on third-party telecommunications systems, cloud infrastructure providers, mapping services, emergency coordination interfaces, security vendors, or public emergency authorities.

ORO does not guarantee:

real-time transmission;

continuous connectivity;

location precision;

emergency intervention;

dispatch outcomes;

or successful communication with emergency responders.

Emergency-related functionalities operate strictly as assistive technological tools and not as emergency-response, rescue, medical, law-enforcement, or public-safety services.

4.1.2 Third-Party Emergency and Security Coordination Disclaimer

Users acknowledge and agree that ORO is a technology company and platform provider and does not operate law-enforcement agencies, emergency-response organizations, medical-response systems, rescue services, security companies, public-safety authorities, or governmental emergency centers.

Where emergency-related functionalities, S.O.S. alerts, safety communications, accessibility-triggered notifications, emergency escalation systems, or security-related features are available, such functionalities may involve independent third-party security providers, emergency-coordination partners, telecommunications providers, or governmental authorities operating under separate legal, operational, technical, and regulatory frameworks.

ORO does not control and cannot guarantee the availability, responsiveness, actions, decisions, response times, intervention outcomes, operational capabilities, communications performance, staffing levels, technical infrastructure, or effectiveness of any third-party emergency, safety, security, medical, rescue, governmental, or law-enforcement entity.

Any emergency response, security intervention, public-safety action, law-enforcement activity, rescue effort, medical assistance, or governmental response remains solely the responsibility of the applicable third-party organization or competent authority.

4.2 Biometric and Sensitive Data Disclaimer

Unless expressly required by applicable law or explicitly disclosed through a separate consent mechanism, ORO does not intentionally collect, process, or use voice data for the purpose of uniquely identifying individuals through biometric identification technologies.

Voice-enabled functionalities are designed primarily for accessibility, platform interaction, command processing, and service facilitation.

Users acknowledge that certain jurisdictions may classify voice recordings or speech patterns as biometric or sensitive information under applicable laws. Where legally required, ORO shall implement additional consent, disclosure, or compliance mechanisms in accordance with applicable regulations.

4.3 No Biometric Authentication or Identity Verification Services

ORO does not represent, warrant, or guarantee that voice-enabled interactions, speech-processing systems, voice commands, speech-recognition technologies, accessibility functionalities, or AI-assisted communication tools can accurately authenticate, verify, validate, identify, or confirm the identity of any individual.

Voice inputs may be affected by environmental conditions, background noise, telecommunications limitations, connectivity disruptions, speech impairments, accents, language variations, hardware limitations, third-party infrastructure dependencies, artificial voice generation technologies, or other operational factors.

Unless expressly stated through a separate legally binding service description, voice-enabled functionalities are provided solely as accessibility, communication, and platform-interaction tools and shall not be interpreted as biometric authentication systems, identity-verification services, security-certification mechanisms, or legally reliable proof of identity.

Users remain solely responsible for maintaining account security credentials, protecting account access, safeguarding authentication methods, and complying with all applicable security requirements.

5. Additional Safeguards

In addition to SCCs, Oro implements:

  • Encryption (in transit and at rest)

  • Access control policies

  • Data minimization principles

  • Incident response protocols

  • including AI system safeguards and voice-data anonymization where applicable

5.1 Cross-Border Infrastructure and Data Localization Limitations

Users acknowledge that the Platform operates through globally distributed infrastructure, including cloud providers, telecommunications systems, AI-processing systems, accessibility tools, and cybersecurity services that may process data across multiple jurisdictions.

ORO does not guarantee that data will remain exclusively within any specific country or geographic region unless expressly required by mandatory applicable law.

Data may be processed, transferred, backed up, mirrored, or temporarily stored internationally for operational continuity, security, redundancy, accessibility functionality, fraud prevention, disaster recovery, and system integrity purposes.

5.2 Data Retention and Minimization Principles

ORO retains personal data only for the period reasonably necessary to fulfill operational, legal, regulatory, accessibility, fraud-prevention, cybersecurity, dispute-resolution, safety, and contractual purposes.

Retention periods may vary depending on:

applicable law;

security requirements;

accessibility obligations;

ongoing investigations;

dispute resolution;

or legitimate business needs.

Certain data may remain in encrypted backups, disaster-recovery systems, or legally required archives for limited periods.

5.3 Third-Party Infrastructure and Subprocessor Dependency

The Platform relies upon independent third-party infrastructure providers, including cloud service providers, telecommunications operators, artificial intelligence providers, accessibility technology providers, cybersecurity vendors, mapping services, payment processors, analytics providers, hosting services, and other operational subprocessors.

Certain personal data, voice interactions, accessibility-related information, geolocation data, communication records, safety-related information, and operational metadata may be processed through such third-party systems as reasonably necessary for the operation, maintenance, security, accessibility, integrity, continuity, and lawful functioning of the Platform.

ORO does not own, operate, or control the infrastructure of all third-party providers involved in the transmission, routing, storage, processing, security, accessibility, or communication of data and therefore cannot guarantee uninterrupted availability, error-free processing, continuous connectivity, or operational performance of independent third-party systems.

To the maximum extent permitted by applicable law, ORO shall not be liable for failures, interruptions, delays, outages, cybersecurity incidents, infrastructure disruptions, telecommunications failures, or operational limitations attributable to independent third-party providers.

6. Data Subject Rights (EU Users)

Users located in the European Union have the right to:

  • Access their data

  • Request correction or deletion

  • Restrict or object to processing

  • File complaints with supervisory authorities

  • Voice commands and accessibility inputs

  • AI interaction logs

  • Emergency/S.O.S. activation data

  • including rights related to automated decision-making, AI-assisted processing, fraud-prevention systems, platform-integrity mechanisms, risk-scoring systems, accessibility automation, and account-safety measures, where such rights are granted under applicable law, including GDPR Article 22.

  • Users acknowledge that certain automated systems may be necessary to protect platform security, accessibility integrity, fraud prevention, emergency coordination systems, cybersecurity operations, and regulatory compliance.

6.1 AI System Development and Training Limitations

Unless expressly permitted by applicable law, anonymized, aggregated, or otherwise lawfully processed, ORO does not use personally identifiable voice recordings or accessibility-sensitive interactions for the purpose of unrestricted public AI model training.

Certain anonymized or de-identified operational datasets may be processed for:

platform optimization;

voice-recognition improvement;

accessibility enhancement;

fraud prevention;

system integrity;

cybersecurity protection;

and service-quality improvement.

6.2 Automated Processing, Voice Interpretation, and System Limitations

Users acknowledge that certain Platform functionalities may rely upon automated processing, artificial intelligence systems, speech-recognition technologies, language-processing tools, accessibility automation, fraud-prevention mechanisms, safety systems, geolocation technologies, and other algorithmic processes.

Such systems may generate outputs, recommendations, interpretations, classifications, transcriptions, translations, accessibility adaptations, risk indicators, routing suggestions, safety signals, or automated operational responses that may contain inaccuracies, omissions, delays, interruptions, transcription errors, contextual misunderstandings, language-recognition limitations, environmental distortions, or other technological limitations.

ORO does not guarantee that automated systems, voice-recognition technologies, accessibility tools, artificial intelligence systems, or algorithmic processes will always operate without error, interruption, delay, misinterpretation, or technical limitation.

Users remain responsible for exercising independent judgment when interacting with the Platform and should not rely exclusively upon automated outputs, voice-generated responses, accessibility adaptations, AI-generated content, safety notifications, or technological recommendations when making decisions affecting their safety, wellbeing, legal obligations, or personal circumstances.

6.3 Accessibility Technologies and Assistive Functionality Disclaimer

The Platform may provide accessibility-oriented technologies, voice-enabled interactions, speech-processing tools, simplified user interfaces, text-to-speech systems, speech-to-text functionalities, accessibility automation, assistive communication features, and other inclusion-focused technological tools designed to improve usability for a broad range of users.

Users acknowledge that accessibility-related technologies may be affected by:

language limitations;

accent variations;

speech impairments;

background noise;

telecommunications conditions;

device capabilities;

internet connectivity;

third-party infrastructure dependencies;

hardware limitations;

environmental factors;

or other operational circumstances beyond ORO's reasonable control.

ORO does not represent, warrant, or guarantee that accessibility functionalities will operate continuously, without interruption, without error, or in a manner suitable for every individual circumstance, disability condition, accessibility need, language, communication style, technological environment, or personal preference.

Accessibility-related functionalities are intended solely to facilitate user interaction with the Platform and shall not be interpreted as healthcare services, rehabilitation services, assistive medical devices, therapeutic technologies, disability-evaluation tools, caregiver services, emergency-response systems, or legally mandated accommodations beyond those required under applicable law.

Nothing in this Addendum shall be interpreted as creating enhanced legal duties, fiduciary obligations, healthcare responsibilities, caregiver relationships, monitoring obligations, or special protective duties on the part of ORO toward any category of user.

6.4 Cross-Border Regulatory Compliance and Governmental Access Requests

Because the Platform operates through internationally distributed technological infrastructure, personal data, operational metadata, accessibility-related information, voice interactions, safety-related information, communications records, and system-generated data may become subject to lawful access requests, disclosure obligations, preservation requirements, judicial orders, regulatory mandates, governmental requests, national-security procedures, law-enforcement demands, public-health investigations, or other legally authorized processes in one or more jurisdictions.

ORO evaluates such requests in accordance with applicable law, contractual obligations, privacy commitments, data-protection requirements, jurisdictional authority, proportionality principles, and internal compliance procedures.

Where legally permitted, ORO may challenge, narrow, reject, seek clarification regarding, or otherwise review requests that appear unlawful, overbroad, disproportionate, technically infeasible, jurisdictionally defective, or inconsistent with applicable legal protections.

Nothing in this Addendum shall be interpreted as guaranteeing that data will be immune from lawful governmental access requests, judicial processes, regulatory investigations, or legally authorized disclosure obligations applicable to ORO, its service providers, infrastructure partners, or affiliated entities operating within applicable jurisdictions.

7. Full Legal Documentation

This Addendum does not constitute a standalone privacy policy and must be read in conjunction with the full ORO Privacy Policy, Terms and Conditions, and Data Protection Framework.

📧 Contact: privacy@orosay.com

GLOBAL LEGAL INTEGRATION NOTICE

These Terms form part of the unified global legal framework governing the ORO Marketplace Platform, including the Privacy Policy, Accessibility & Voice Policy, Community Guidelines, Safety Framework, Refund Policy, and all related legal disclosures published by Oro Technologies LLC.

Continued access to or use of the Platform constitutes legally binding acceptance of all applicable policies and future updates.

bottom of page