Privacy Policy
Version 1.0
Privacy Policy
OPM Technologies, a Division of OPM Corporation Private Limited
1. Introduction
OPM Technologies, a division of OPM Corporation Private Limited ("OPM Technologies," "we," "us," or "our"), is committed to protecting the privacy and security of the personal information entrusted to us by our customers, users, and partners. This Privacy Policy describes how we collect, use, store, share, and protect information in connection with our Software-as-a-Service (SaaS) products, platforms, websites, APIs, and related services (collectively, the "Services").
By accessing or using our Services, you ("User," "Customer," or "you") agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of our Services immediately.
This Privacy Policy applies to end users of our SaaS platforms, business customers and their authorised users, visitors to our websites and marketing pages, individuals who contact us for support, sales, or inquiries, and API integrators and technology partners.
2. About OPM Technologies
OPM Technologies operates as a division of OPM Corporation Private Limited, a company incorporated under the Companies Act, 2013, and registered in India. Our SaaS products are designed to serve businesses across various industries, providing cloud-based software solutions, including but not limited to enterprise resource planning, data analytics, workflow automation, collaboration tools, and related software services.
Registered Office: OPM Corporation Private Limited, 82, K7, Kalinga Nagar, Bhubaneswar, Odisha, India
Data Controller / Data Fiduciary: OPM Corporation Private Limited, acting through its division OPM Technologies, is the Data Fiduciary/Controller with respect to the personal data processed under this policy.
3. Definitions
For this Privacy Policy:
"Personal Data" means any information that identifies or can be used to identify a natural person, directly or indirectly, including but not limited to name, email address, phone number, IP address, device identifiers, and usage data.
"Sensitive Personal Data or Information (SPDI)" means financial information, health data, biometric data, passwords, and any other category defined as sensitive under applicable law.
"Customer Data" means all data, files, content, and information submitted by a Customer or its authorised users through the Services.
"Usage Data" means data automatically collected about how users interact with our Services, including logs, telemetry, and analytics.
"Sub-processor" means any third party engaged by us to process Customer Data on our behalf.
"Data Fiduciary" has the meaning ascribed under the Digital Personal Data Protection Act, 2023 (India).
"Data Principal" means the individual to whom personal data relates.
"GDPR" means the General Data Protection Regulation (EU) 2016/679.
"Processing" means any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
4. Information We Collect
4.1 Information You Provide Directly
Account Registration Data includes your full name, business name, and job title, email address and phone number, username, password, and authentication credentials, billing address, GST or tax identification numbers, and payment information, as well as company size, industry, and business type.
Profile and Configuration Data includes profile photographs or avatars, user preferences, notification settings, interface configurations, and custom roles, permissions, and access configurations set within the platform.
Communication Data includes information shared through support tickets, live chat, and email correspondence, feedback, survey responses, testimonials, and feature requests, as well as the content of messages sent through our communication tools where applicable.
Contract and Transactional Data includes subscription plan details and usage tiers, purchase history, invoices, payment records, and signed agreements, order forms, and contracts.
4.2 Customer Data
When you use our SaaS platforms, you may upload, input, or generate data, including records about your employees, clients, transactions, or operations. This is referred to as Customer Data. OPM Technologies processes Customer Data solely on your instructions as a Data Processor, where you are the Data Controller. We do not own, sell, or independently use Customer Data except as necessary to provide the Services or as required by law.
4.3 Automatically Collected Data
Technical and Device Data includes IP addresses and geographic location derived from IP, browser type, version, and language settings, device type, operating system, and hardware identifiers, and screen resolution and time zone.
Usage and Behavioural Data includes pages visited, features used, and buttons clicked, session duration, frequency of access, navigation paths, error logs, crash reports, and diagnostic data, search queries made within the platform, and API call logs including endpoints, parameters, and response codes.
Cookies and Tracking Technologies include session cookies to maintain login states, persistent cookies to remember preferences, analytics cookies to understand usage patterns, and marketing cookies to measure campaign effectiveness, along with pixel tags and web beacons on marketing pages. For detailed information, refer to our Cookie Policy in Section 13.
4.4 Data from Third-Party Integrations
If you connect third-party services to our platform, such as CRM tools, payment gateways, cloud storage, or communication applications, we may receive data from those services as authorised by you. The data received depends on the permissions you grant and is governed by both this Privacy Policy and the privacy policies of those third parties.
4.5 Data from Partners and Public Sources
We may also receive business contact details from data enrichment providers, company firmographic data from public registries, and information shared by resellers or referral partners.
5. How We Use Your Information
5.1 Providing and Operating the Services
We use your information to create and manage your account, authenticate users and manage access, process transactions and subscriptions, deliver core product functionality, store and retrieve Customer Data on your behalf, and provide technical support and resolve issues.
5.2 Improving and Developing the Services
We analyse usage patterns to identify areas of improvement, conduct product experiments, develop new features and integrations, debug errors and performance bottlenecks, and train internal quality assurance systems using anonymised or aggregated data only.
5.3 Security and Fraud Prevention
We use your data to detect, investigate, and prevent unauthorised access, fraud, and abuse, monitor for anomalous behaviour and potential security threats, enforce our Terms of Service and Acceptable Use Policies, and comply with legal obligations related to security disclosures.
5.4 Communication and Relationship Management
We send transactional emails including receipts, invoices, password resets, and system alerts, notify you about planned maintenance, outages, or service changes, share product updates and release notes, and respond to support tickets and inquiries.
5.5 Marketing and Promotional Activities
Where consent is obtained, we send newsletters, product announcements, and promotional offers, personalise marketing content based on your preferences and usage, and measure the effectiveness of marketing campaigns. You may opt out of marketing communications at any time, as described in Section 11.
5.6 Legal and Compliance
We use your information to meet obligations under applicable law, including tax, audit, and regulatory requirements, respond to lawful requests from courts, law enforcement, and regulatory bodies, enforce our contractual rights, and maintain records for dispute resolution.
5.7 Business Analytics and Reporting
We generate aggregated, anonymised reports on platform usage, benchmark service performance, and support internal financial reporting and business planning.
6. Legal Basis for Processing
We rely on the following legal bases depending on the purpose of processing. Account creation and service delivery are processed based on the performance of the contract. Security and fraud prevention are based on our legitimate interests. Compliance with legal obligations constitutes a legal obligation basis. Marketing communications are processed based on your consent. Analytics and product improvement activities are carried out based on legitimate interests. Processing of Customer Data is carried out based on our contractual obligation and any applicable Data Processing Agreement.
For users in the European Economic Area, the United Kingdom, or other jurisdictions with similar frameworks, we identify and document the applicable legal basis for each processing activity. Customers may request a copy of our Records of Processing Activities by contacting us.
7. Data Sharing and Disclosure
OPM Technologies does not sell, rent, or trade personal data. We share information only in the following circumstances.
7.1 Sub-processors and Service Providers
We engage third-party service providers who process data on our behalf. These include cloud infrastructure providers such as AWS, Google Cloud, and Microsoft Azure for hosting and storage, payment processors for billing and subscription management, email and communication providers for transactional and marketing emails, analytics providers for usage tracking, customer support platforms for ticketing and help desk management, and security and monitoring tools for vulnerability scanning and incident detection. All sub-processors are bound by contractual data processing agreements and are required to implement appropriate security measures. A list of current sub-processors is available upon request.
7.2 Within OPM Corporation Group
We may share information with OPM Corporation Private Limited and its affiliated divisions for business operations, consolidated reporting, and shared IT infrastructure. All intra-group transfers are governed by internal data transfer agreements.
7.3 Business Partners and Integrations
If you connect our platform to third-party tools, data may be shared with those tools in accordance with your authorisation and their privacy policies.
7.4 Legal Requirements
We may disclose personal data if required to do so by a valid court order, subpoena, or legal process, requests from law enforcement agencies or regulatory authorities, tax authorities, auditors, or statutory bodies, or requirements under the Information Technology Act, 2000, the DPDP Act, 2023, or equivalent laws. We will, where legally permissible, notify you before complying with such a request.
7.5 Business Transfers
In the event of a merger, acquisition, restructuring, sale of assets, or change of control involving OPM Corporation Private Limited or OPM Technologies, personal data may be transferred to the acquiring entity. You will be notified via email or prominent notice on our platform at least 30 days before such a transfer takes effect, and you will have the right to delete your account before the transfer.
7.6 Consent-Based Sharing
With your explicit consent, we may share your information for purposes not listed above. You may withdraw such consent at any time.
8. Data Retention
We retain personal data for as long as necessary to fulfil the purposes described in this Privacy Policy, unless a longer retention period is required by law.
Account and profile data is retained for the duration of your subscription plus three years. Customer Data is retained for the duration of your subscription or as per the Customer's specific instructions. Billing and financial records are retained for seven years as required by Indian tax laws. Support and communication logs are retained for three years from the last interaction. Usage and analytics data is retained for two years, after which it is aggregated or anonymised. Security and audit logs are retained for one to three years, depending on the incident type. Marketing preference records are retained until consent is withdrawn, plus one additional year.
Upon expiration of the applicable retention period or upon your written request, we will securely delete or anonymise your data in accordance with our Data Deletion Policy. Deletion requests from Customers are processed within 30 days.
9. Data Security
OPM Technologies implements a comprehensive, multi-layered security program to protect personal data and Customer Data from unauthorised access, loss, alteration, or disclosure.
9.1 Technical Safeguards
Our technical safeguards include encryption of data in transit using TLS 1.2 or higher, encryption of data at rest using AES-256, role-based access controls and least-privilege access principles, multi-factor authentication for administrative access, regular vulnerability assessments and penetration testing, web application firewalls and DDoS protection, automated threat detection and monitoring, and secure development practices including code reviews and SAST/DAST testing.
9.2 Organisational Safeguards
Our organisational measures include mandatory security awareness training for all employees, background verification for personnel handling sensitive data, non-disclosure agreements with all staff and contractors, a dedicated Data Protection Officer or equivalent role, and an incident response plan with defined escalation procedures.
9.3 Physical Safeguards
Data is hosted in SOC 2 Type II and ISO 27001-certified data centres. We maintain physical access controls at all facilities handling data and ensure secure disposal of hardware containing personal data.
9.4 Security Incident Response
In the event of a data breach or security incident, we will contain and investigate the incident immediately, notify affected Customers within 72 hours of confirmation, notify relevant regulatory authorities as required by applicable law, provide a detailed incident report including scope, impact, and remediation steps, and take corrective measures to prevent recurrence.
10. International Data Transfers
OPM Technologies operates primarily in India and may transfer data to other countries for processing, storage, or support purposes. Where we transfer personal data outside India or the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses as approved by the European Commission, adequacy decisions by relevant data protection authorities, Data Processing Agreements with sub-processors in recipient countries, and compliance with the DPDP Act, 2023, for cross-border transfers from India.
If you are located in the EU/EEA, UK, or another jurisdiction with data transfer restrictions, you may request a copy of the applicable transfer mechanisms by contacting us at info@opmcorporation.com.
11. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data.
11.1 Rights Available to All Users
Right to Access: You may request a copy of the personal data we hold about you.
Right to Correction: You may request that we correct inaccurate or incomplete personal data.
Right to Deletion: You may request deletion of your personal data, subject to our legal retention obligations.
Right to Data Portability: You may request your data in a structured, commonly used, machine-readable format.
Right to Withdraw Consent: Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Right to Opt-Out of Marketing: You may unsubscribe from marketing emails using the unsubscribe link in any email or by contacting us at info@opmcorporation.com.
11.2 Additional Rights under GDPR / UK GDPR
Users in the EU/EEA and UK also have the right to object to processing based on legitimate interests, the right to restrict processing in specific circumstances, the right to lodge a complaint with a supervisory authority, and the right not to be subject to solely automated decision-making with legal effects.
11.3 Rights under the DPDP Act, 2023 (India)
Under the Digital Personal Data Protection Act, 2023, Data Principals have the right to information about processing, the right to correction and erasure of personal data, the right to grievance redressal, and the right to nominate a representative to exercise rights on their behalf.
11.4 How to Exercise Your Rights
To exercise any of the rights described above, submit a request to info@opmcorporation.com. We will respond to all verified requests within 30 days. We may require identity verification before fulfilling certain requests. If a request is complex or voluminous, we may extend the response period by an additional 30 days and will notify you accordingly.
Please note that certain rights may be limited where we process data as a Data Processor on behalf of a Customer. In such cases, we will direct you to the relevant Customer as the Data Controller.
12. Children's Privacy
Our Services are not directed to individuals under the age of 18 years. We do not knowingly collect personal data from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately at info@opmcorporation.com, and we will promptly delete such data. Customers are responsible for ensuring that their end users meet the minimum age requirements before granting access to our platform.
13. Cookie Policy
13.1 What Are Cookies
Cookies are small text files stored on your device by your web browser when you visit a website or use a web-based application. We use cookies and similar technologies such as web beacons, pixels, and local storage to operate and improve our Services.
13.2 Categories of Cookies We Use
Strictly Necessary Cookies are essential for the operation of our Services and cannot be disabled. Examples include session authentication, CSRF protection, and load balancing.
Functional Cookies enable personalisation and enhanced features such as language preferences, dashboard layout, and saved filters.
Analytics Cookies help us understand how users interact with our platform. We use tools such as Google Analytics, Mixpanel, and Heap for this purpose.
Marketing and Advertising Cookies track your activity to enable targeted advertising via tools such as Google Ads, LinkedIn Insight Tag, and Facebook Pixel.
13.3 Managing Cookies
You can control cookies through your browser settings to block or delete them, through our Cookie Consent Banner available at your first visit, or through opt-out links provided by individual analytics providers. Please note that disabling certain cookies may affect the functionality of our Services.
14. Third-Party Links and Integrations
Our Services may contain links to third-party websites, integrations, or embedded content. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party services you connect to or visit through our platform.
15. Customer Responsibilities
Where OPM Technologies acts as a Data Processor, Customers as Data Controllers are responsible for ensuring they have a valid legal basis for providing personal data to us, obtaining necessary consents from their end users, providing adequate privacy notices to their end users, complying with applicable data protection laws in their jurisdiction, configuring access controls and permissions appropriately within the platform, and notifying OPM Technologies of any specific instructions regarding data processing.
Customers may enter into a separate Data Processing Agreement with OPM Technologies. Please contact us at info@opmcorporation.com to request a DPA.
16. Data Processing Agreement
For enterprise customers and those operating in regulated jurisdictions such as the EU, UK, or sectors subject to specific data protection regulations, OPM Technologies offers a formal Data Processing Agreement. The DPA governs the nature and purpose of processing, types of personal data and categories of data subjects, duration of processing, sub-processor management and approval, security obligations, audit rights, data subject request handling procedures, breach notification timelines, and data transfer mechanisms.
To request a DPA, contact us at info@opmcorporation.com.
17. Compliance with Applicable Laws
OPM Technologies is committed to compliance with applicable data protection and privacy laws, including the Digital Personal Data Protection Act, 2023 (India), the Information Technology Act, 2000 and associated rules (India), the General Data Protection Regulation (GDPR) applicable to the EU/EEA, the UK General Data Protection Regulation, the California Consumer Privacy Act and CPRA where applicable, and the personal data protection laws of other applicable jurisdictions.
We review our practices regularly to ensure ongoing compliance as laws evolve.
18. Grievance Redressal
In accordance with the Information Technology (Intermediaries Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act, 2023, we have appointed a Grievance Officer to address privacy-related concerns.
All complaints and grievances will be acknowledged within 48 hours and resolved within 30 days of receipt. If you are not satisfied with the resolution, you may escalate to the relevant Data Protection Board or supervisory authority in your jurisdiction.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, Services, legal requirements, or regulatory environment. When we make material changes, we will post the updated policy on our website with a new "Last Updated" date, notify registered users via email at least 14 days before the changes take effect, and display a prominent in-app notification for significant changes. Where required by law, we will seek your consent before applying the new terms.
Your continued use of our Services after the effective date of the revised policy constitutes your acceptance of the changes. We encourage you to review this policy periodically.
20. Contact Us
For any questions, concerns, requests, or complaints regarding this Privacy Policy or our data practices, please reach out to us through the following:
OPM Technologies, a Division of OPM Corporation Private Limited
Email: info@opmcorporation.com
Website: www.opmtechnologies.com
Mailing Address: OPM Corporation Private Limited, 82, K7, Kalinga Nagar, Bhubaneswar, Odisha, India.
We are committed to addressing all privacy inquiries promptly, transparently, and in good faith.