Privacy Policy
How Ophriel Systems collects, uses, shares, and protects personal data, written against the notice requirements of India’s Digital Personal Data Protection Act, 2023.
Effective date: TODO · Last updated: TODO
We act in two different roles. Which one applies changes who is responsible.
This is the single most important distinction in this policy. Under the DPDP Act, the party that decides the purpose of processing is the Data Fiduciary and carries the legal obligations. Depending on which data is in question, that party is either you or us.
Data inside Ophriel CRM
Personal data about your customers that you enter into or generate within Ophriel CRM — names, contact details, booking records, payment references. You, the client, decide why and how that data is processed.
- Data Fiduciary
- You (the client business)
- Data Processor
- Ophriel Systems
We process this data only on your documented instructions, under the Data Processing Addendum signed with your subscription agreement. We do not use it for our own purposes, do not sell it, and do not mine it.
Data collected on ophriel.com
Personal data you give us directly through this website — the demo request form, or by emailing or calling us. We decide why and how this data is processed, so the responsibility is ours, not a client's.
- Data Fiduciary
- Ophriel Systems
- Data Processor
- Ophriel Systems (and the sub-processors named below)
This is the data covered by the rights and grievance process set out further down this page.
In short: if you are a customer of one of our clients and want your data corrected or deleted, your request goes to that business, not to us — they are the Data Fiduciary. We will support them in acting on it. If you contacted Ophriel Systems directly through this website, your request comes to us.
What we collect, and why
Data you give us directly on this website
When you submit the demo request form on our contact page, we collect:
- Your name
- Your business name (optional)
- Your email address
- Your phone number (optional)
- The content of your message
Purpose: to respond to your enquiry, arrange a demonstration, and prepare a quote. Legal basis: your consent, given by submitting the form. We do not add you to a marketing list, and we do not use this data for any purpose other than responding to you and any follow-up directly about it.
If you email or call us instead, we hold whatever you choose to tell us, for the same purpose.
Data processed inside Ophriel CRM on behalf of clients
Where our client has entered their own customers’ personal data into the platform, we process it strictly as their Data Processor, on their instructions, for the purpose of operating the software they have subscribed to. The categories of data are determined by our client, not by us, and are set out in the Data Processing Addendum signed with them.
Analytics and cookies
This website uses no analytics and sets no cookies. We do not run Google Analytics or any equivalent, we do not use tracking pixels, and we do not embed third-party advertising or social media trackers. If this changes, this policy will be updated before any such tool is enabled.
Our hosting provider may keep standard server logs (including IP addresses) for security and operational purposes, as is normal for any website.
Withdrawing your consent
Where we rely on your consent, you may withdraw it at any time by emailing ophirelsystems@gmail.comwith the subject line “Withdraw consent”. Withdrawal is as easy as giving consent was. On withdrawal we will stop processing your data for the purpose concerned and delete it, unless we are required by law to retain it.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
What you can ask us to do
As a Data Principal under the DPDP Act, you have the following rights in respect of personal data for which Ophriel Systems is the Data Fiduciary.
- Access
- Ask for a summary of the personal data we hold about you and how it is being processed.
- Correction
- Ask us to correct inaccurate or misleading data, or complete data that is incomplete.
- Erasure
- Ask us to delete personal data where it is no longer needed for the purpose it was collected for, and where we are not required by law to keep it.
- Grievance redressal
- Raise a complaint with our Grievance Officer, named below. We acknowledge within 48 hours and resolve within 15 days.
- Nomination
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
To exercise any of these, email ophirelsystems@gmail.com. We may ask you to verify your identity before acting on a request.
Sub-processors we use
We use the following third parties to deliver the service. Each is bound to process data only for the purpose described. We do not sell personal data to anyone, and we do not share it with third parties for their own marketing.
- DigitalOcean
- Purpose: Application and database hosting
Data involved: All data held in Ophriel CRM, and website infrastructure
Processing location: Bangalore, India (BLR1) - Razorpay
- Purpose: Payment processing and collections
Data involved: Payment and transaction data. Card details are handled entirely by Razorpay; Ophriel CRM does not store them.
Processing location: India - Resend
- Purpose: Transactional email delivery for demo requests submitted on this website
Data involved: Name, business name, email address, phone number, and message content submitted via the demo request form
Processing location: TODO: confirm processing region
Client deployments are hosted in India, in DigitalOcean’s Bangalore region (BLR1). The region is named in each client’s Data Processing Addendum before signing — see Security & Data.
How long we keep data
- Demo requests and enquiries: retained for TODO months from last contact, then deleted, unless you become a client.
- Client business records: retained for the life of the contract and for TODO years afterwards, to the extent required by Indian tax and companies legislation.
- Data inside a client deployment:retained per the client’s own instructions and their Data Processing Addendum. On termination, data is exported to the client and then deleted from our systems within TODO days.
Security
We apply reasonable security safeguards to prevent personal data breaches, including tenant isolation, application-layer encryption of sensitive fields, and automated backups stored separately from the primary host. These are described in more detail on our Security & Data page. In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act.
Children
Our website and services are directed at businesses, not at children. We do not knowingly collect personal data of anyone under 18 through this website. Where a client processes children’s data inside the platform, the obligation to obtain verifiable parental consent rests with that client as Data Fiduciary.
Grievance Officer
Complaints about how we handle personal data should be addressed to our Grievance Officer:
- Name: Jonathan Jeshua S
- Email: ophirelsystems@gmail.com
- Address: 21, Rettaimalai Srinivasan Street, Zamin Pallavaram, Chennai, Tamil Nadu 600043, India
- Response time: acknowledged within 48 hours, resolved within 15 days of receipt
If you are not satisfied with our response, you may escalate the complaint to the Data Protection Board of India.
Changes to this policy
We may update this policy as the service or the law changes. The effective date at the top of this page will change when we do. Material changes affecting how we use your data will be notified to you directly where we hold your contact details.
Questions about your data?
Write to us and a person will answer — there is no ticket queue to disappear into.
