DPDPA 2023 & GDPR Compliant Privacy NoticeEffective Date: August 2026

Privacy Policy & Notice

This Privacy Notice explains how PrivacyOS (operated by Vexalix Technology Private Limited) collects, processes, stores, and protects personal data in strict compliance with India's Digital Personal Data Protection Act (DPDPA), 2023, DPDP Rules, 2025, and global frameworks including the EU GDPR.

1. Overview & Data Fiduciary Identity

In Plain English: PrivacyOS is owned by Vexalix Technology Pvt. Ltd. (Gurugram, India). We take your data privacy seriously and adhere strictly to India's DPDP Act 2023.

This Privacy Policy governs the collection, processing, and handling of digital personal data by PrivacyOS, an enterprise software product developed, owned, and operated by Vexalix Technology Private Limited, a private limited company incorporated under the laws of India, having its corporate headquarters at:

Vexalix Technology Private Limited
C-042C, 4th Floor, Supermart, DLF Phase IV
Gurugram, Haryana 122009, India
CIN: U72900HR2020PTC085123 | Corporate Contact: info@privacyosglobal.com

2. Dual Capacity Role: Data Fiduciary vs. Data Processor

Under the DPDP Act 2023 and GDPR, PrivacyOS operates in two distinct legal capacities:

A. PrivacyOS as Data Fiduciary

When you visit our website (privacyosglobal.com), request a demo, sign up for a compliance assessment, or contact our sales team, we determine the purposes and means of processing your data as a Data Fiduciary.

B. PrivacyOS as Data Processor

When enterprise clients subscribe to the PrivacyOS platform to manage their own users' consents, DSR requests, or data discovery, PrivacyOS processes customer data solely on the documented instructions of the client pursuant to a signed Data Processing Agreement (DPA) under Section 8(2).

3. Personal Data We Collect

We limit our collection to what is necessary, adequate, and relevant for specified business purposes:

  • Identity & Contact Data: Full Name, professional work email, phone number, job title, company name, corporate website.
  • Commercial Inquiry Data: Industry sector, organization employee count, compliance areas of interest (Consent, DSR, DPIA, Breach, SOC 2, VAPT), and inquiry messages.
  • Technical & Log Telemetry: IP address, browser type and version, operating system, timestamp, session identifiers, and aggregated product usage statistics.
  • Client Account Credentials: Business email, hashed passwords, enterprise SSO metadata, and multi-factor authentication (MFA) tokens.

4. Purposes of Processing & Legal Basis

Processing PurposeLegal Basis (DPDPA)Legal Basis (GDPR)
Responding to assessment & consultation requestsSection 6(1) Explicit ConsentArticle 6(1)(a) Consent
Delivering PrivacyOS SaaS platform access & supportSection 4 / Contract PerformanceArticle 6(1)(b) Contract Performance
Statutory tax invoicing & corporate filings in IndiaSection 7(b) Legal ObligationArticle 6(1)(c) Legal Obligation
Platform security, fraud prevention & audit loggingSection 8(5) Security SafeguardsArticle 6(1)(f) Legitimate Interests

5. Multilingual Notice Accessibility (DPDPA Section 5(3))

Pursuant to Section 5(3) of the DPDP Act 2023, Data Principals in India have the right to access this privacy notice and all consent requests in English or any of the 22 scheduled Indian languages specified in the Eighth Schedule to the Constitution of India (including Hindi, Bengali, Tamil, Telugu, Marathi, Gujarati, Kannada, Malayalam, Punjabi, etc.).

To request this policy or any associated consent notice in your preferred scheduled language, please contact our Grievance Officer at dpo@privacyosglobal.com.

6. Your Data Principal Rights

As a Data Principal under the DPDP Act and GDPR, you possess the following enforceable rights:

Right to Access (Section 11)Request a summary of your personal data being processed and the identities of all third parties with whom data was shared.
Right to Correction & Erasure (Section 12)Correct inaccurate data, update incomplete records, or request complete erasure of your data when the purpose is fulfilled.
Right to Grievance Redressal (Section 13)Readily access an internal grievance redressal mechanism with statutory response timelines.
Right to Nominate (Section 14)Nominate an individual who shall exercise your data rights in the event of death or incapacity.

7. Data Storage, Location & Retention

All personal data managed by PrivacyOS is hosted in Tier-4, ISO 27001, and SOC 2 Type II certified Indian cloud data center regions (AWS Mumbai / ap-south-1 and Microsoft Azure Central India, Pune).

We retain personal data only for as long as necessary to fulfill the purpose for which it was collected or to satisfy statutory legal, accounting, and reporting obligations under Indian law. Upon expiration of the retention schedule or upon a verified erasure request, data is permanently overwritten or cryptographically destroyed.

8. Sub-processors & Third-Party Disclosures

PrivacyOS never sells, rents, or monetizes personal data. We engage vetted third-party service providers (sub-processors) under strict Section 8(2) Data Processing Agreements for infrastructure, transactional email, and authentication:

  • Cloud Infrastructure: Amazon Web Services India Pvt. Ltd. (Hosting, Databases, KMS Encryption)
  • Corporate Collaboration: Microsoft 365 / Azure Active Directory (Enterprise SSO, Identity Management)
  • Transactional Communications: Resend / Postmark (System alerts and verification emails)

9. Security Safeguards (DPDPA Section 8(5))

In accordance with Section 8(5) of the DPDP Act 2023, PrivacyOS implements comprehensive technical and organizational safeguards:

  • End-to-end data encryption in transit using TLS 1.3 and at rest using AES-256 with AWS KMS keys.
  • Role-Based Access Control (RBAC), mandatory Multi-Factor Authentication (MFA), and zero-trust network segmentation.
  • Periodic Vulnerability Assessment and Penetration Testing (VAPT) performed by CERT-In empaneled security auditors.
  • Real-time automated audit trails recording all data access and administrative modifications.

10. Grievance Redressal & Data Protection Board (DPB) Escalation

If you have concerns, inquiries, or complaints regarding the processing of your personal data, you may lodge a formal grievance with our designated Grievance Officer:

Designated Grievance Officer & DPO: Privacy & Legal Compliance Team

Entity: PrivacyOS by Vexalix Technology Private Limited

Address: C-042C, 4th Floor, Supermart, DLF Phase IV, Gurugram, Haryana 122009, India

Email: dpo@privacyosglobal.com | info@privacyosglobal.com

Phone: +91 8887946496 (Mon–Fri, 9:00 AM – 6:00 PM IST)

Internal SLA: We acknowledge complaints within 24 hours and resolve grievances within 7 business days (well within the statutory 30-day requirement).

If you are not satisfied with the resolution provided by our Grievance Officer, you have the statutory right under Section 13(4) of the DPDP Act 2023 to file a complaint before the Data Protection Board of India (DPBI).