Privacy Policy

Effective Date: May 12, 2025  |  Last Updated: May 12, 2025

Octos Cloud (operated by Octosinfra.com; "we," "us," or "our") is committed to protecting the privacy and security of the personal data entrusted to us. This Privacy Policy describes how we collect, use, store, disclose, and safeguard your information when you access our website (octosinfra.com), cloud management portal, APIs, or any related services (collectively, the "Services").

This Policy is drafted in compliance with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), the Digital Personal Data Protection Act, 2023 ("DPDPA"), and other applicable Indian regulations.

1. Definitions

  • Personal Data: Any data about an individual who is identifiable by or in relation to such data, as defined under the DPDPA.
  • Data Principal: The individual whose personal data is collected (i.e. you, the user).
  • Data Fiduciary: Octos Cloud (Octosinfra.com), which determines the purpose and means of processing personal data.
  • Data Processor: Any entity that processes personal data on behalf of the Data Fiduciary.
  • Services: All cloud infrastructure services, compute, storage, networking products, the customer portal, APIs, documentation, and the octosinfra.com website.

2. Scope

This Policy applies to all users of Octos Cloud's website and Services, including customers, prospective customers, website visitors, API consumers, and business contacts. It covers data collected both online and offline in connection with our Services.

3. Information We Collect

3.1 Information You Provide

  • Account Registration Data: Full name, email address, phone number, organisation name, billing address, GST number (where applicable), and login credentials.
  • Billing and Payment Data: Payment method details (credit/debit card numbers, UPI IDs, bank account information) processed via PCI-DSS compliant payment gateways. We do not store full card numbers on our servers.
  • Support and Communication Data: Information provided through support tickets, emails, phone calls, or feedback forms.
  • Identity Verification Data: KYC documents (Aadhaar, PAN, GST certificate, company registration) as required for regulatory compliance.

3.2 Information Collected Automatically

  • Usage and Log Data: IP addresses, browser type and version, device identifiers, operating system, access timestamps, pages visited, referral URLs, and clickstream data.
  • Service Telemetry: Resource consumption metrics (CPU, RAM, storage, bandwidth) associated with your account for billing and infrastructure optimisation.
  • Cookies and Tracking Technologies: We use cookies, web beacons, and similar technologies for session management, analytics, and service improvement. See Section 10 for details.

3.3 Customer Data (Service Data)

Data uploaded, stored, processed, or transmitted by you through our cloud infrastructure. Octos Cloud acts as a Data Processor for Customer Data. We do not access, monitor, or use Customer Data except as necessary to provide, secure, and maintain the Services, or as required by law.

4. Purpose of Data Collection

We collect and process your personal data strictly for the following lawful purposes:

  • Provisioning, operating, maintaining, and securing the Services.
  • Account creation, authentication, and identity verification.
  • Billing, invoicing, payment processing, and tax compliance (including GST).
  • Customer support and technical troubleshooting.
  • Service improvement, capacity planning, and infrastructure analytics.
  • Compliance with legal, regulatory, and contractual obligations.
  • Security monitoring, fraud detection, and abuse prevention.
  • Sending transactional communications (service alerts, billing notifications, security advisories).
  • Marketing communications (only with your explicit opt-in consent; you may opt out at any time).

5. Consent

Where processing requires consent under the DPDPA, we obtain your clear, informed, and freely given consent before collecting or processing your personal data. You have the right to withdraw consent at any time by contacting us at the details in Section 14. Withdrawal of consent does not affect the lawfulness of processing performed prior to withdrawal, but may result in the inability to provide certain Services.

6. Data Sharing and Disclosure

We do not sell, rent, or trade your personal data. We may share data only under the following circumstances:

  • Data Centre and Infrastructure Partners: Subcontracted service providers operating our data centre facilities, subject to strict contractual confidentiality and data protection obligations equivalent to this Policy.
  • Payment Processors: PCI-DSS compliant payment gateways for transaction processing.
  • Legal and Regulatory Compliance: When required to comply with applicable law, regulation, court order, or governmental request, including orders from the Data Protection Board of India.
  • Business Transfers: In connection with a merger, acquisition, reorganisation, or sale of assets, with prior notice and continued protection of your rights.
  • With Your Consent: Where you explicitly authorise disclosure to a third party.

7. Data Storage, Residency, and Security

7.1 Data Residency

Your Account Data and billing records are stored on servers located in India. Customer Data is stored in the region you select during provisioning (currently Mumbai, India).

7.2 Security Measures

We implement industry-standard technical and organisational safeguards, including but not limited to:

  • AES-256 encryption at rest and TLS 1.3 encryption in transit.
  • Multi-factor authentication (MFA) for portal access.
  • Role-based access controls (RBAC) and least-privilege principles.
  • 24/7 infrastructure monitoring, intrusion detection, and DDoS mitigation.
  • Regular vulnerability assessments and penetration testing.
  • Physical security controls at data centre facilities (biometric access, CCTV, fire suppression).

Despite these measures, no method of electronic transmission or storage is absolutely secure. We cannot guarantee unconditional security but commit to promptly addressing any vulnerabilities.

8. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes outlined in this Policy, or as required by applicable law. Specifically:

  • Active Accounts: Data is retained for the duration of your account and service subscription.
  • Post-Termination: Account data is retained for up to 90 days after termination to facilitate data retrieval, after which it is securely deleted or anonymised.
  • Billing Records: Retained for a minimum of 8 years as required under Indian tax and financial regulations.
  • Logs and Telemetry: Retained for up to 12 months for security and analytics purposes.

9. Cross-Border Data Transfers

Your data may be processed outside India for specific operational purposes (such as email delivery or analytics). When transferring data internationally, we ensure compliance with DPDPA requirements and implement appropriate contractual safeguards, including Standard Contractual Clauses (SCCs) and ensuring the recipient jurisdiction provides an adequate level of data protection as notified by the Central Government.

10. Cookies and Tracking

We use the following categories of cookies:

  • Essential Cookies: Required for authentication, security, and core functionality. Cannot be disabled.
  • Analytics Cookies: Help us understand how visitors interact with our website to improve user experience.
  • Preference Cookies: Store your settings and preferences for subsequent visits.

You may control non-essential cookies through your browser settings. Disabling certain cookies may affect the functionality of the Services.

11. Your Rights (Data Principal Rights)

Under the DPDPA and applicable Indian law, you have the following rights:

  • Right to Access: Request a summary of the personal data we hold about you and our processing activities.
  • Right to Correction: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of your personal data where processing is no longer necessary ("right to be forgotten"), subject to legal retention obligations.
  • Right to Withdraw Consent: Revoke previously granted consent for data processing.
  • Right to Nominate: Nominate a representative to exercise your rights in the event of your death or incapacity, as provided under the DPDPA.
  • Right to Grievance Redressal: Lodge a complaint regarding our data processing practices.

To exercise any of these rights, contact our Grievance Officer (see Section 14). We will respond to verified requests within 30 days.

12. Data Breach Notification

In the event of a personal data breach, we will:

  • Notify the Data Protection Board of India as required under the DPDPA.
  • Inform affected Data Principals (you) without unreasonable delay, describing the nature of the breach, likely consequences, and mitigation measures taken.
  • Document all breaches in our internal breach register, including response timelines and remediation actions.

13. Children's Privacy

Our Services are not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that a minor's data has been collected without verifiable parental consent, we will promptly delete such data and terminate the associated account.

14. Grievance Redressal and Contact

For privacy-related queries, data access requests, grievances, or complaints, contact our designated Grievance Officer:

  • Grievance Officer: Darshil Vala
  • Email: darshil@octosinfra.com
  • Address: 204, Aalabh, Tapovan Society, Akshar Marg, Rajkot, Gujarat, India – 360001
  • Response Time: Within 30 days of receipt of your request.

If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India as constituted under the DPDPA, 2023.

15. Policy Updates

We may update this Privacy Policy periodically to reflect changes in our practices, the Services, or applicable law. Material changes will be communicated via email to registered account holders or through a prominent notice on our website. Continued use of the Services after the effective date of any update constitutes your acceptance of the revised Policy.