Legal

Privacy Policy

What Opsylo collects, why, who else ever sees it, and how you get it back or have it erased.

Last updated: 29 July 2026DPDP Act 2023IT Rules 2021

1. What we collect

Two different things, and it matters which is which:

  • Account data — the email and hashed password of each user, an optional phone number, your workspace name, and billing details such as legal entity name, GSTIN and billing address. We also keep request logs including IP address for security and abuse handling.
  • Workspace content — everything you enter into the modules: contacts, jobs, invoices, ledger entries, employees, files. This is yours. We process it to run the service and for nothing else.

2. Payments

Subscription payments, UPI mandates and wallet top-ups are handled by Razorpay. Card numbers and UPI PINs never reach Opsylo — Razorpay’s PCI-DSS environment holds them. What we receive back is a payment identifier and a signature, which we verify with an HMAC-SHA256 comparison performed in constant time so that a forged signature cannot be discovered by timing the check.

3. Your rights, in the product

Under the Digital Personal Data Protection Act 2023 — and equivalently under GDPR where it applies — you can obtain a copy of your data and ask for it to be erased. Both are self-service in the app at /privacy; you do not have to email anyone or wait for us.

Erasure redacts personal data in place. Financial records must stay balanced and are subject to statutory retention, so a contact’s identifying details are removed while the transactions they relate to remain as anonymised entries. Deleting the person does not delete the ledger, and we would rather tell you that than quietly do one and imply the other.

4. How it is protected

Every request is scoped to your workspace before it reaches the database, and that isolation is asserted by end-to-end tests that create two workspaces and check neither can read the other’s records. Stored secrets — payment and integration credentials, AI provider keys — are held in AES-256-GCM envelopes and are never returned to a browser or written to a log. Passwords are hashed, never stored or recoverable in plaintext, and two-factor authentication is available on every account.

Our security page states precisely which controls are enforcing today and which are built but not yet switched on. We would rather publish that distinction than let you assume the stronger reading.

5. Who else sees it

We do not sell personal data and we do not share it for advertising. Data reaches a third party only where the service you are using requires it:

  • Razorpay — payments and refunds.
  • AI model providers — the content of an assistant request, when you use an AI feature. No provider is given your data to train on.
  • Delivery providers — email, SMS and WhatsApp gateways, for messages you send from the product to your own customers.
  • Cloud hosting and object storage — for the database and uploaded files.

6. How long we keep it

Workspace content is retained while your account is active and for a wind-down period after cancellation so you can export it. Accounting records are kept for the statutory retention period that applies to them. Deletions inside the product are soft — flagged and timestamped rather than destroyed — which is what makes an accidental deletion recoverable; erasure requests under §3 go further and redact.

7. Grievance officer

Under the Information Technology Rules 2021 and Razorpay’s merchant requirements, the grievance officer for Opsylo Technologies Inc. is:

  • Officer: Compliance & Legal Lead (Grievance & Compliance Officer)
  • Entity: Opsylo Technologies Inc.
  • Email: grievance@opsylo.com (privacy matters: privacy@opsylo.com)
  • Address: Corporate Office, Tech Park, Pune, Maharashtra, 411001, India
  • Response: Acknowledgement within 24 hours; resolution within 15 business days