Legal
Privacy policy
Last updated: September 1, 2026
1. Who we are
Orkasa is a product of Mozzi Studio LLC, a limited liability company registered in Wyoming, United States (filing 2026-002007383), with its registered address at 30 N Gould St, Ste N, Sheridan, WY 82801, USA. Our operations are run from Panama. Orkasa (“we”) is a B2B SaaS platform offering a real estate CRM to brokers and agents across Latin America. We comply with Panama Personal Data Protection Law 81, as well as the data protection frameworks of every country where our customers operate.
2. What data we collect
- Account data: name, email, password (hashed), brokerage name, role, phone number.
- Usage data: properties uploaded, leads captured, posts published, photos uploaded, AI interactions.
- Technical data: IP address, user agent, session cookies, error logs.
- Your customers data (leads): name, email, phone, real-estate interests, KYC documents when applicable. This data is yours; you are the data controller before the data subject.
3. What we use the data for
- Provide the CRM service and keep your account operational.
- Process portal publications and lead communications on your behalf.
- Send transactional emails (alerts, confirmations, receipts) and, with your consent, product updates.
- Improve Orkasa: aggregated, anonymous telemetry and A/B testing.
- Comply with legal obligations (KYC/AML, requests from authorities).
4. Who we share data with
We work with sub-processors that are SOC 2 / ISO 27001 compliant:
- Supabase — database, authentication, storage.
- Vercel — application hosting.
- Anthropic — Claude, used for the listing studio (data is not used for model training).
- Google — Gemini Flash Image, for photo enhancement.
- Stripe — payment processing.
- Resend — transactional emails.
- Meta Platforms (Facebook / Instagram) — only when the user voluntarily connects their account, to publish properties on their Facebook Page and/or Instagram Business account. See section 11.
- TikTok — only when the user voluntarily connects their account, to send posts to their TikTok account. See section 14.
- LinkedIn — only when the user voluntarily connects their account, to post on their profile or their agency's page. See section 15.
We never sell your data or your customers data. We only share with authorities under a valid legal request.
5. How long we keep the data
For as long as your account is active. If you cancel, you get 30 days to export everything. After 30 days we delete the data, except records we are legally required to retain (billing, KYC) for up to 5 years.
6. Your rights
Under Panama Law 81 and equivalent regulations across other countries in the region, you can exercise your ARCO rights:
- Access: request a copy of your data.
- Rectification: correct inaccurate data.
- Cancellation: delete your data when no longer needed.
- Opposition: withdraw consent for non-essential uses.
To exercise these rights, write to privacidad@orkasa.app.
7. Security
Encryption at rest (AES-256) and in transit (TLS 1.3). Postgres RLS scoped by brokerage_id — each brokerage data is isolated. Daily backups with 30-day retention. MFA available for owners. Annual pen-tests.
8. Cookies
We use only strictly necessary cookies (session, language preferences) and, optionally, aggregated anonymous analytics. We do not use third-party advertising tracking cookies.
11. Meta integration (Facebook and Instagram)
Orkasa lets you publish properties directly to your Facebook Page and your Instagram Business account through the Meta API. This integration is completely optional and requires your explicit authorization.
Data we access through Meta:
- Your Facebook Page name and ID.
- The Page Access Token, needed to publish on your behalf.
- Your Instagram Business account ID linked to the Page (if any).
How we use that data:
- Exclusively to publish the properties you create and approve inside Orkasa on your Facebook Page and/or Instagram Business.
- Tokens are stored encrypted in our database, never shared with third parties, and never used for any other purpose.
What we do NOT do:
- We do not read your inbox, messages or comments.
- We do not access your audience data or your post metrics.
- We do not publish anything unless you initiate the action from Orkasa.
You can disconnect the integration at any time from Settings → Integrations. When you disconnect, we delete the stored token. To revoke access from the Meta side, visit facebook.com/settings → Apps.
If you have questions about the Meta API usage, write to privacidad@orkasa.app.
13. Google Workspace integration (Gmail and Calendar)
Orkasa lets you connect your Google account to send emails and sync calendar events with your real estate leads. This integration is completely optional and requires your explicit authorization through Google's official consent screen.
Data we access through Google APIs:
- Your email address (userinfo.email scope): to identify the connected account.
- Permission to send emails (gmail.send scope): when you reply to a lead from the Orkasa interface, we send the email on your behalf from your account.
- Calendar events (calendar.events scope): we create and read events on your primary calendar to coordinate property viewings with clients and avoid conflicts with your existing schedule.
How we use that data:
- Send replies, proposals and follow-ups from your professional email account when you initiate the action from Orkasa.
- Create viewing events in your Google Calendar when you confirm an appointment with a client, and check your availability before proposing time slots.
- Access and refresh tokens are stored encrypted in our database (AES-256 at rest, TLS 1.3 in transit) and are never shared with third parties.
What we do NOT do:
- We do not read your inbox or email content — the integration can only send emails you initiate, never read them.
- We do not use your Gmail or Calendar data to train generative AI models, neither our own nor any third party's.
- We do not sell, rent or transfer your Gmail or Calendar data to third parties for advertising purposes.
- We do not access your contact list, files in Google Drive, or account settings.
Compliance with Google's Limited Use Policy:
Orkasa's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
You can disconnect the integration at any time from Settings → Integrations. When you disconnect, we delete the stored tokens and revoke access from Google's side. You can also revoke access directly from myaccount.google.com → Security → Third-party apps with account access.
If you have questions about our Google APIs integration, write to privacidad@orkasa.app.
14. TikTok integration
Orkasa can send property tours and carousels to your TikTok account through the Content Posting API. This integration is entirely optional and requires your explicit authorisation.
Data we access through TikTok:
- Your account identifier (open_id / union_id), so we know which account we are posting to.
- Your display name, your public @handle and your profile picture, so you can see which account you are publishing as.
- Access and refresh tokens, needed to send the content on your behalf.
How we use that data:
- Solely to send TikTok the posts you create and approve inside Orkasa.
- Tokens are stored encrypted in our database and are never shared with third parties or used for any other purpose.
What we do NOT do:
- We do not read your messages or comments.
- We do not access your analytics, your follower count or the list of videos on your account.
- We never post unless you start the action from Orkasa.
You can disconnect the integration at any time from Settings → Integrations. On disconnect we revoke the token with TikTok and delete it from our database. You can also withdraw the permission from your TikTok account settings, in the authorised applications section.
If you have questions about our use of the TikTok API, write to us at privacidad@orkasa.app.
15. LinkedIn integration
Orkasa can publish your properties on your LinkedIn profile, or on your agency's page, through the Posts API. This integration is entirely optional and requires your explicit authorisation.
Data we access through LinkedIn:
- Your member identifier, which is what signs every post sent from Orkasa.
- Your name and profile picture, so you can see which account you are publishing as.
- Your primary email address, solely to identify the connected account.
- An access token, needed to post on your behalf. LinkedIn caps it at 60 days.
- If you authorise posting as a company page, the name and identifier of the pages you administer.
How we use that data:
- Solely to publish, edit or delete on LinkedIn the posts you create and approve inside Orkasa.
- The token is stored encrypted in our database and is never shared with third parties or used for any other purpose.
- We do not write to your LinkedIn email: it only identifies the connection.
What we do NOT do:
- We do not read your network or your feed.
- We do not read your messages or invitations.
- We do not access the analytics of your posts.
- We never post unless you start the action from Orkasa.
You can disconnect the integration at any time from Settings → Integrations. On disconnect we revoke the token with LinkedIn and delete it from our database. You can also withdraw the permission on the LinkedIn side at linkedin.com → Permitted services.
If you have questions about our use of the LinkedIn API, write to us at privacidad@orkasa.app.
12. Account and data deletion
You can request the complete deletion of your Orkasa account and associated data at any time.
How to request it:
Write to privacidad@orkasa.app with the subject "Data deletion request" from the email associated with your account. We respond within 30 days.
What is deleted:
- Your user account and the brokerage data.
- Properties, photos, leads, messages and posts.
- All integration tokens (Meta, WhatsApp, Google, TikTok, LinkedIn) and the data synced from those platforms.
- If you connected Facebook, Instagram, WhatsApp Business, TikTok or LinkedIn, your tokens are revoked with the corresponding platform and all associated data is purged from our systems.
We retain for up to 5 years only the records required by law (billing, KYC/AML) in separated, encrypted storage with no operational access.
You can also revoke Orkasa access from the Meta side by visiting facebook.com/settings → Apps.
9. Changes to this policy
If we make material changes, we will notify you by email at least 30 days in advance. Minor changes are reflected in the "Last updated" date.
10. Contact
Questions, complaints, exercising your rights: privacidad@orkasa.app.