Legal
Privacy policy
How CastNest Inc handles personal information, and why our software architecture means your QuickBooks data never reaches us.
- Effective
- 6 September 2026
- Last updated
- 6 September 2026
The short version
- We never receive your QuickBooks data. Orvanta QBD runs on your machines; there is no Orvanta service in the path.
- We collect what you send us — an enquiry, a support request, billing details.
- Analytics cookies load only if you accept them, and never for advertising.
- We have never sold or shared personal information, and we do not intend to.
- You can ask for a copy of your information, or ask us to delete it, at privacy@orvantahq.com.
The sections below are the binding version; this summary is not.
1.Who we are and what this policy covers
CastNest Inc (a Delaware corporation) trades as Orvanta and provides Orvanta QBD, software that connects QuickBooks Desktop to AI assistants. In this policy, “Orvanta”, “we” and “us” mean CastNest Inc. You can reach us at privacy@orvantahq.com; section 15 lists our contact details in full.
This policy explains what personal information we collect through orvantahq.com, when you contact us, and when you buy or use our software — and what we do with it. For the purposes of the UK and EU General Data Protection Regulation, Orvanta is the controller of the information described here.
It does not cover your QuickBooks data. Section 2 explains why that distinction matters more than anything else in this document.
2.We do not receive your QuickBooks data
Orvanta QBD is software you install and run on your own computers. When your AI assistant asks a question, the request travels from your assistant to your server to your copy of QuickBooks, and the answer travels back the same way. Orvanta operates no service in that path.
We therefore have no access to, and hold no copy of:
- your QuickBooks company file or any records in it
- the questions your team asks or the answers returned
- your Orvanta QBD audit logs, which stay on your own machine
- your credentials, API keys, certificates or QuickBooks passwords
The software does not transmit company file contents to us. If we introduce licence validation or update checks in a future release, they will transmit only licence, version and installation-identifier information — never financial data — and we will describe them here before they ship.
One consequence is worth stating plainly: because we cannot see your data, we also cannot recover it for you. Backups of your company file remain your responsibility.
Separately, your AI assistant provider — Anthropic, for example, if you use Claude — receives whatever your assistant is asked and told, under your agreement with them. That relationship is outside our control and outside this policy. We suggest reviewing their terms alongside ours.
3.Personal information we collect
Information you give us
- Enquiries. When you use our contact form or email us: your name, email address, any company name you provide, the topic you select, and the contents of your message.
- Customer account information. If you buy a plan: billing contact name and email, company name, billing address, tax or VAT registration number where relevant, purchase order references, and the plan you hold.
- Support correspondence. What you send us when you ask for help, including any log excerpts or configuration files you choose to share. Please redact anything sensitive before sending it; we ask for the least we need to solve the problem.
Information collected automatically
- Server logs. Our hosting provider records standard request information — IP address, user agent, requested URL, referring page, timestamp and response status — for security, abuse prevention and diagnosing faults.
- Analytics. If — and only if — you accept analytics cookies, Google Analytics records the pages you view, an approximate location derived from a truncated IP address, your device and browser type, and how you arrived at the site.
We run no advertising or cross-site tracking scripts of any kind. Section 4 lists every cookie we use and how to change your choice.
Information from others
- Payment processor. If you pay by card, our processor confirms the outcome and gives us limited details such as the last four digits, card brand and expiry. We never receive or store your full card number.
Sensitive information
We do not seek special category data (health, biometrics, race, religion, political opinions, trade union membership, sex life or sexual orientation), government identifiers, or precise geolocation, and we ask that you do not send them to us.
5.How we use personal information, and our legal bases
Where the UK or EU GDPR applies, we must have a lawful basis for each use. This table sets out both.
| Purpose | Information used | Legal basis (UK/EU GDPR) |
|---|---|---|
| Replying to your enquiry | Name, email, company, message | Legitimate interests — responding to someone who contacted us; or steps prior to entering a contract |
| Providing the software, licences and support | Account and contact details, support correspondence | Performance of a contract |
| Taking payment and keeping accounting records | Billing details, transaction records | Performance of a contract; legal obligation (tax and company law) |
| Telling customers about updates, security fixes and changes that affect their licence | Customer contact details | Performance of a contract; legitimate interests — service continuity |
| Product and marketing emails to non-customers who asked to hear from us | Name and email | Consent, withdrawable at any time |
| Understanding which pages are useful | Analytics data — pages viewed, approximate location, device type | Consent, withdrawable at any time |
| Keeping the site secure and preventing abuse | Server logs, IP address, Cloudflare Turnstile bot check | Legitimate interests — network and information security |
| Establishing, exercising or defending legal claims | Whatever is relevant to the matter | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have considered the effect on you and concluded that our interest does not override your rights. You can ask us for that assessment, and you can object — see section 10.
We do not make decisions producing legal or similarly significant effects about you by automated means, and we do not carry out profiling.
6.Marketing
We send marketing email only to people who asked for it, and to existing customers about products similar to the one they bought. Every message carries an unsubscribe link that works immediately, and you can also email hello@orvantahq.com.
Unsubscribing stops marketing, not service messages. We will still email you about security fixes, billing and changes to your licence, because those are part of providing the product.
We do not sell, rent or share your details with anyone for their own marketing.
8.International transfers
We are based in the United States and serve customers worldwide, so personal information may be processed in countries other than your own — including countries whose data protection laws differ from those where you live.
Where we transfer personal information out of the United Kingdom or the European Economic Area, we rely on one of the following safeguards:
- the European Commission's Standard Contractual Clauses, and the UK International Data Transfer Addendum where the UK GDPR applies;
- an adequacy decision covering the destination country; or
- the EU–US and UK–US Data Privacy Framework, where the receiving organisation is certified.
Google Analytics, where you have consented to it, involves a transfer to Google LLC in the United States. Google is certified under the EU–US and UK–US Data Privacy Framework and we also have its standard data processing terms in place. Declining analytics prevents that transfer entirely.
You can ask us for a copy of the safeguards we use by emailing privacy@orvantahq.com.
9.How long we keep information
We keep personal information only as long as we need it for the purpose we collected it for, and then delete it or make it permanently anonymous.
| Category | Retention period |
|---|---|
| Enquiries that do not become customers | Up to 24 months from the last contact, then deleted |
| Customer account and contact records | For the life of the relationship, then up to 24 months |
| Invoices, payments and accounting records | 7 years, as tax and company law require |
| Support correspondence | Up to 36 months from resolution |
| Marketing consent records | Until consent is withdrawn, plus 24 months as proof |
| Server logs | Up to 90 days, except where retained for a specific investigation |
| Analytics data | 14 months from collection, then deleted by Google Analytics |
| Your cookie choice | Stored in your own browser until you clear site data or change it |
Where information is needed for an ongoing legal claim or regulatory matter, we keep it until that matter concludes.
10.Your rights
Everyone
Whatever your location, you can ask us for a copy of the personal information we hold about you, ask us to correct it, ask us to delete it, or ask us to stop sending marketing. Email privacy@orvantahq.com and we will action it.
United Kingdom and European Economic Area
Under the UK and EU GDPR you have the right to:
- access the personal information we hold about you;
- have inaccurate information corrected;
- have information erased, in the circumstances the law provides for;
- restrict how we process it while a dispute is resolved;
- receive information you gave us in a portable, machine-readable format, and have it sent to another controller where technically feasible;
- object to processing based on legitimate interests, and object at any time to direct marketing; and
- withdraw consent at any time, without affecting processing already carried out.
You also have the right to complain to a supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EEA, the authority in your country of residence or workplace. We would appreciate the chance to address your concern first.
California
Under the CCPA as amended by the CPRA, California residents may request to know the categories and specific pieces of personal information we have collected, the sources, the purposes and the categories of recipient; may request correction or deletion; and may not be discriminated against for exercising those rights.
In the twelve months before the date of this policy we collected the categories described in section 3 — identifiers, commercial information, internet activity and professional information — for the business purposes in section 5. We have not sold personal information, and we have not shared it for cross-context behavioural advertising. We do not use or disclose sensitive personal information for purposes requiring a right to limit. We do not knowingly collect or sell the personal information of anyone under 16.
Other US states
Residents of states with comprehensive privacy laws — including Virginia, Colorado, Connecticut, Utah and Texas — have comparable rights to access, correct, delete and obtain a copy of their personal information, and to opt out of targeted advertising, sale and certain profiling. We do not carry out any of those three activities. Where your state provides an appeal route and we decline a request, we will tell you how to appeal.
Making a request
Email privacy@orvantahq.com. We may ask for information to verify your identity, and will use it only for that purpose. We respond within one month (UK/EU) or 45 days (United States), and will tell you if we need an extension the law allows. An authorised agent may act for you with written permission we can verify. Requests are free unless they are manifestly unfounded or excessive.
11.How we protect information
We apply technical and organisational measures appropriate to the risk: encryption in transit, access limited to staff who need it, multi-factor authentication on our business systems, and vendors selected partly on their security posture.
The most significant protection is architectural rather than procedural: because Orvanta QBD runs on your infrastructure, your financial data is not aggregated on our systems and cannot be exposed by a breach of them.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a breach affects your personal information and the law requires notification, we will notify you and the relevant regulator within the applicable deadlines. To report a vulnerability, email security@orvantahq.com — we will acknowledge it and will not pursue good-faith researchers who follow responsible disclosure.
12.Children
Orvanta QBD is business software, not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, email privacy@orvantahq.com and we will delete it.
13.Third-party sites and services
Our website links to other organisations — Intuit, AI assistant providers and standards bodies among them. We do not control those sites and are not responsible for their privacy practices. Their policies govern what happens once you leave ours.
14.Changes to this policy
We update this policy when our practices or the law change. The “last updated” date at the top always reflects the current version. If a change materially affects how we handle your personal information, we will give notice by email or a prominent notice on the site before it takes effect. Continuing to use the site or the software after that date means the updated policy applies.
15.How to contact us
The controller of the personal information described in this policy is CastNest Inc, a Delaware corporation, trading as Orvanta. Contact us by email:
- Privacy questions, requests and complaints: privacy@orvantahq.com
- General enquiries: hello@orvantahq.com
- Security reports: security@orvantahq.com
UK and EU representative. Where Article 27 of the UK or EU GDPR requires us to appoint a representative, our appointed representative is [EU/UK representative — appoint if required].
We aim to resolve every concern directly. If we cannot, you may complain to your supervisory authority as described in section 10.