1.Our Role and Your Role
The Service is sold to businesses, and a business using the Service will normally upload data about other people — most often its own employees. It is important to be clear about who is responsible for what.
- Account data — information you give us when you sign up, book a demo, contact support, or pay for the Service. We decide the purposes for which this limited category is used, and for it we act as the Data Fiduciary (data controller).
- Customer content — the operational data your organization enters into the Service, including tasks, processes and FMS flows, inventory, attendance, and employee and performance records. Your organization decides what to collect, why, and for how long. Your organization is the Data Fiduciary for that data, and we act solely as a Data Processor, processing it on your instructions in order to provide the Service.
This distinction matters in practice. If you are an employee of a business that uses OpsDock and you wish to access, correct, or delete records held about you, you should contact your employer, who controls that data and decides what happens to it. We will assist our customer in responding to such a request, but we cannot act on it independently or override our customer’s instructions.
Where your organization uploads personal data relating to any other individual — employee, contractor, customer, or vendor — you confirm that you have a lawful basis to do so, that you have obtained any consent required by applicable law, and that you have given those individuals any notice the law requires. The corresponding obligations are set out in our Terms & Conditions.
2.Information We Collect
We collect the following categories of information:
- Account information — name, email, phone, organization, and role.
- Content and operational data you enter into the Service — tasks, processes/FMS, inventory, attendance, employee records, and similar.
- Usage and log data — device, browser, IP address, pages visited, actions taken, and timestamps.
- Billing information — plan, invoices, and transaction records. Card and payment credentials are collected and stored directly by our payment gateway partner; we do not store complete card details on our systems.
- Support communications — messages, tickets, and correspondence you send us, including over email or WhatsApp.
- Cookies and similar technologies.
- Data exchanged through third-party integrations you choose to connect.
3.How We Use Information
We use information to:
- Provide, operate, maintain, and improve the Service.
- Authenticate users and secure accounts.
- Provide support.
- Send service, transactional, and (where permitted) product communications.
- Generate analytics and reports.
- Detect, investigate, and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
4.Service Improvement, Analytics & AI
We use data to operate the Service, to generate insights for you, and to make the product better. Because this is the area customers ask about most, we want to be specific about what it does and does not mean.
- Insights for you — our analytics, scorecard, and AI features generate reports and operational insights from your own organization’s data, and the output is shown only to your organization. We do not use one customer’s data to generate insights, benchmarks, or recommendations for another customer.
- Aggregated and de-identified data — we may create statistical, aggregated, or de-identified data derived from use of the Service. This data is stripped of identifiers and cannot reasonably be used to identify you, your organization, or any individual. We may use and retain it to improve, secure, benchmark, and develop the Service, and to publish general industry trends.
- Product improvement — we analyse usage patterns, performance metrics, error logs, and feature adoption in order to fix defects, improve reliability, and decide what to build next.
- Support and troubleshooting — authorized personnel may access account data only where necessary to resolve a support request you have raised, investigate a security incident, or comply with law. Such access is limited, logged, and subject to confidentiality obligations.
We do not use your content, your employee records, or any personally identifiable data to train machine-learning models that are shared across customers or made available to any third party. We do not sell personal data, and we do not use your operational data for advertising, profiling, or resale.
Where a third-party AI or model provider is used to deliver a feature to you, that provider acts as a sub-processor under contractual restrictions: it may process the data only to provide that feature to you, and it is not permitted to retain your data beyond what is needed to return a result, or to train its models on your data.
5.Data Storage, Security & Location
Operational data you enter into the OpsDock application is stored on dedicated server infrastructure that we lease and administer ourselves, located in India (Mumbai region). Enquiry and contact details submitted through forms on this website are handled separately, on managed cloud infrastructure. Where a specific feature or integration you choose to enable requires processing elsewhere, that processing is limited to delivering the feature you requested.
We apply reasonable technical and organizational measures appropriate to the nature and scale of the Service, and we review and strengthen them as the Service grows. These currently include encryption of data in transit using TLS, access controls that separate one organization’s data from another’s, restricted administrative access on a need-to-know basis, network and firewall restrictions on our database infrastructure, and regular backups.
However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your account credentials, for managing which people in your organization have access and at what permission level, and for promptly removing users who leave your organization.
6.Sub-processors & Infrastructure
We rely on third-party providers ("sub-processors") to operate the Service. Each is engaged under obligations of confidentiality and data protection, and is permitted to process data only to provide services to us. As at the effective date of this Policy, these fall into the following categories:
- Server and data-centre infrastructure — leased dedicated servers on which we run and administer the OpsDock application and its database ourselves. Our infrastructure provider supplies the servers, network, and physical data-centre security; it does not access or process your data.
- Managed cloud services used for this website and for enquiry forms, including database and hosting services.
- Website hosting and content delivery.
- Messaging and communication providers, including Meta / WhatsApp where you choose to enable that integration.
- Payment processing — our payment gateway partner, which collects and holds payment credentials directly.
- Email, support, and business communication tools.
- AI and model providers, where required to deliver a specific feature, subject to the restrictions described above.
We may add, remove, or replace sub-processors as the Service evolves and as our infrastructure changes. This section will be updated to reflect material changes. Enterprise customers may request a current, named sub-processor list.
7.Third-Party Integrations & Services
The Service may integrate with third-party services and channels, including but not limited to WhatsApp, messaging providers, and other integrations. When you connect or use any third-party service, that third party’s own terms and privacy policies apply to you directly. We do not control and are not responsible for the practices, availability, data handling, or policies of any third party. Your use of such integrations is at your own risk.
8.WhatsApp & Messaging Integrations (Important)
Where an unofficial or unapproved WhatsApp connection is used, the connection may be disrupted, throttled, restricted, or disconnected at any time as a result of Meta’s / WhatsApp’s policies, fair-usage rules, or technical changes. OpsDock shall not be held liable or responsible for any such disconnection, suspension, data loss, message failure, account restriction, or any resulting business impact. You acknowledge that Meta’s and WhatsApp’s policies are outside our control and that you are responsible for complying with them.
9.Fair Usage Policy
The Service, including any trial or promotional plan currently offered, is provided on a fair-usage basis. Plans, pricing, features, limits, and availability are not permanent and may be added, modified, reduced, withdrawn, or discontinued at any time at the sole discretion of the company, with or without prior notice. We may throttle, limit, suspend, or terminate access where usage is excessive, abusive, automated, or inconsistent with normal business use, or where it threatens the stability, security, or cost-viability of the Service.
10.Data Sharing & Disclosure
We do not sell personal data. We may share data with service providers/sub-processors who help us operate the Service (under confidentiality obligations), with third-party integrations you enable, in connection with a merger or acquisition, or where required by law or to protect our rights, users, or the public.
11.Data Retention & Deletion
We retain account and operational data for as long as your account is active, and thereafter for as long as required for legal, tax, accounting, or dispute-resolution purposes.
On termination or expiry of your subscription, your data remains available for export for thirty (30) days. After that period we may permanently delete it from our active systems. Residual copies may persist in backups for a further limited period before being overwritten in the ordinary backup cycle.
You may request deletion of your data at any time. We will comply subject to legal retention requirements and to our need to retain records of transactions, invoices, and disputes. Aggregated and de-identified data that can no longer be linked to you or your organization may be retained indefinitely.
12.Your Rights
Subject to applicable law, including the Digital Personal Data Protection Act, 2023, you have the following rights in respect of personal data for which we are the Data Fiduciary:
- Access — obtain confirmation of whether we process personal data about you, and a summary of that data and the processing.
- Correction — have inaccurate or misleading data corrected, and incomplete data completed or updated.
- Erasure — request deletion of your personal data where it is no longer necessary for the purpose it was collected and no legal obligation requires us to retain it.
- Withdraw consent — where processing is based on your consent, withdraw it at any time. Withdrawal does not affect processing already lawfully carried out, and may prevent us from continuing to provide the Service.
- Grievance redressal — raise a complaint with our Grievance Officer, and thereafter with the Data Protection Board of India.
- Nomination — nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.
To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before acting on a request. Where your request concerns data that your employer uploaded to the Service, please see "Our Role and Your Role" above — that request must be directed to your employer, who controls the data.
13.Grievance Officer
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and the rules made thereunder, we have designated a Grievance Officer to receive and address complaints regarding the processing of personal data or this Policy.
- Grievance Officer: Sourabh Panigrai
- Email: [email protected]
- Address: Aviara Tech, DCB-408, 4th Floor, DLF Cybercity, near Infocity Square, Patia, Bhubaneswar, Odisha 751024
We aim to acknowledge complaints within 72 hours of receipt and to resolve them within 30 days, or such shorter period as applicable law requires. If you are not satisfied with our response, you may escalate the matter to the Data Protection Board of India.
14.Data Breach Notification
If we become aware of a personal data breach affecting data we hold, we will notify the Data Protection Board of India and affected users in accordance with applicable law and without undue delay. Our notification will describe, so far as known at the time, the nature of the breach, its likely consequences, and the measures taken or proposed to address it.
Where we act as a Data Processor for our customer’s content, we will notify the customer without undue delay so that the customer, as Data Fiduciary, can meet its own notification obligations to affected individuals and to the authorities. Giving notice under this section is not an admission of fault or liability.
16.Children’s Data
The Service is a business tool. It is not intended for or directed at children, and we do not knowingly permit any individual under the age of 18 to create an account.
Where a customer uploads personal data relating to an individual under the age of 18 — for example a young employee, apprentice, or trainee — the customer is responsible for obtaining verifiable consent from that individual’s parent or lawful guardian as required under the Digital Personal Data Protection Act, 2023, and confirms by uploading that data that it has done so. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.
17.Changes to This Policy
We may update this Policy at any time. Continued use of the Service after changes constitutes acceptance of the updated Policy.
18.Contact
Questions: [email protected], Aviara Tech, DCB-408, 4th Floor, DLF Cybercity, near Infocity Square, Patia, Bhubaneswar, Odisha 751024.
This document is provided for general use and does not constitute legal advice.