Legal

Privacy Policy

Effective Date: May 15, 2026

Prelude Research, Inc. (d/b/a Origin Technology) (“Origin,” “we,” “us,” or “our”) is committed to protecting the privacy of individuals who interact with our website, products, and services. This Privacy Policy explains what personal data we collect, how we use and disclose it, and the rights and choices available to you.

1. What Personal Data We Collect

Data You Provide

Origin collects identifying information including email address, first name and last name, your company name and job title, and your address, state, province, ZIP/Postal code, city.

We also gather data through direct communications via email, chat, and social media. When users employ Single-Sign-On (SSO) authentication, Origin receives only email and SSO configuration details; authentication credentials remain with the SSO provider.

Users connecting third-party applications or security platforms must provide API keys or similar credentials, which we encrypt and store.

When a Customer administrator connects a workspace identity provider (such as Google Workspace, Okta, or Microsoft Entra ID), Origin ingests directory data (including users, groups, organizational structure, and related attributes) on the Customer’s behalf to enable observability features.

CCPA Categories: Identifiers, personal information per California Civil Code Section 1798.80(e), commercial information, and professional employment data.

Data Collected Automatically

When Origin software is deployed on an endpoint, we collect telemetry from that device to provide our observability services. The scope of telemetry is determined by the Customer that deployed the software and the features it enables, and may include application, process, file, and network activity, identity and authentication events, and related signals.

Where AI observability features are enabled, telemetry may also include the content of prompts submitted to AI assistants from the monitored device and the responses returned by those assistants. Origin uses this content to operate analytics, reporting, and detection features on behalf of the Customer. See Section 5 for additional information for individuals whose endpoints are monitored.

CCPA Categories: Identifiers, personal information, commercial information, and electronic network activity information.

Cookie and job candidate data are addressed separately in Sections 3 and 4.

2. How Personal Data Is Used

Legal Bases for Processing

Contract Performance:

  • Providing services to Customers and their authorized users
  • Communicating with customers, suppliers, and business partners

Legal Compliance: We use personal data to satisfy regulatory obligations.

Legitimate Interests: Origin uses information for detecting, preventing, and addressing fraud and other illegal activity, and to enhance, optimize, and secure our services.

Consent-Based Processing: We may use data where you provide explicit authorization, including sharing with business partners.

We do not knowingly collect special category data under GDPR, sensitive information under U.S. state laws, or biometric data under Illinois, Texas, or Washington statutes.

3. Cookies

Origin uses functional cookies necessary for website operation and analytics cookies for performance tracking and customer identification. You can manage cookie preferences through your browser settings.

4. Job Candidates

Applicants’ CVs and submitted data are used for communication and application assessment. With consent, we may contact candidates about similar opportunities. Data retention covers recruitment completion plus a reasonable period for recording decision rationales and defending legal claims.

5. If You Are a Monitored User

Origin is sold to organizations (each a “Customer”) that deploy our software to gain observability into the endpoints, identity events, and AI tooling activity of their workforce. If a Customer has deployed Origin in connection with a device or accounts you use for work, Origin processes data about you on the Customer’s behalf and under the Customer’s instructions.

What may be collected. The specific scope is set by the Customer based on the features it enables. Depending on that configuration, Origin may collect from monitored endpoints:

  • Application, process, file, and network activity
  • Identity and authentication events drawn from the Customer’s connected identity provider
  • The content of prompts submitted to AI assistants and the responses returned, where AI observability features are in scope
  • Other telemetry described in Section 1

Exercising your rights.Where applicable law gives you rights of access, correction, deletion, restriction, portability, or objection in relation to monitoring data, those rights are exercised against the Customer that controls the data. Please direct rights requests to your organization’s privacy, security, or IT function. Origin will assist the Customer in responding to verified requests in accordance with our agreements and applicable law.

Questions for Origin. You may contact us directly at contact@originhq.com with general questions about this Privacy Policy or about Origin as a service. We may need to refer rights requests back to the Customer that controls the data.

6. Data Disclosure

Third-Party Recipients

Service Providers. IT support and hosting providers process data per Origin’s instructions. Our current sub-processor list is available online.

Business Transfers. Personal data may be disclosed during mergers, acquisitions, financing, or asset sales.

Affiliates.Subsidiaries and joint ventures receive data under this policy’s terms.

Business Partners. Selected partners may receive data for product and service offerings.

Professional Advisors. Legal, financial, and insurance consultants access relevant information.

Legal Compliance. Data is disclosed to satisfy laws, regulations, and governmental requests.

CCPA Categories Disclosed: Identifiers, personal information, commercial information, electronic network activity, and professional employment data.

7. Transfer of Personal Data

Personal data is processed at Origin offices and other locations where the parties involved in the processing operate. Data may be transferred internationally where adequate controls are in place ensuring the security of your personal data.

8. Data Security

Origin implements encryption, firewalls, access controls (including multi-factor and two-factor authentication), and other industry-standard security measures. Database volumes are encrypted at rest and in transit. We enforce least-privilege access controls, granting employees access only when job-required and for necessary durations.

9. Data Retention

Personal data is retained as long as necessary to fulfil the purposes for which it was collected, or as required by law. Without specific service agreements, data is deleted when no longer needed or upon deletion requests, subject to legal exceptions.

10. Direct Marketing

Origin may contact users about products and services based on previous interactions or with explicit consent. Recipients may unsubscribe via email links or by contacting us. GDPR residents have the right to object to marketing processing by contacting us.

11. Your Rights Under GDPR

EU residents possess the following rights:

  • Access. Confirmation of processing and access to personal data.
  • Rectification. Correction of inaccurate or incomplete data.
  • Erasure. Deletion requests, subject to GDPR exceptions.
  • Restriction. Processing limitations in specific circumstances.
  • Portability. Data in structured, machine-readable format for transfer.
  • Objection. Right to object to legitimate interest or direct marketing processing.
  • Automated Decision-Making. We do not make any decisions based solely on automated processing.
  • Consent Withdrawal. Ability to withdraw prior authorizations.
  • Complaint Authority. Right to lodge complaints with competent Data Protection Authorities.

12. Your Rights Under CCPA and U.S. State Privacy Laws

Residents of California and other relevant U.S. states possess the following rights:

  • Access. Request categories and specific personal data collected within the prior 12 months.
  • Deletion. Request personal data removal, subject to statutory exceptions.
  • Correction. Request correction of inaccurate data.
  • Disclosure. Request specific information about personal data collection and processing.
  • Non-Sale/Sharing. Origin does not “sell” or “share” personal data as those terms are defined under the CCPA, though disclosures to third parties occur as described in Section 6.
  • Non-Retaliation. No discrimination for exercising privacy rights.

13. “Shine the Light” Right

California residents may request annual disclosure of third-party personal data sharing for direct marketing purposes pursuant to California Civil Code Section 1798.83.

14. Privacy Rights for Minor Users

Users under 18 can request removal of publicly posted content or information by contacting us.

15. Children’s Privacy

Origin does not knowingly collect data from children under 13, or under 16 in certain jurisdictions such as EU countries. We take appropriate steps to delete such data upon discovery.

16. Changes to the Privacy Policy

Origin may update this policy to reflect practice or legal changes. Material modifications will be communicated via our website or other means.

17. Contact Information

Questions regarding this Privacy Policy should be directed to contact@originhq.com.

Last Updated May 2026