Legal

Privacy Policy

Last updated: August 24, 2026

OrbisAI Security (“we,” “our,” or “us”) is dedicated to protecting your privacy and handling your personal data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian laws. This Privacy Policy outlines our practices for the collection, use, processing, and protection of your personal data when you use Orbis AppSec, our cybersecurity software (the “Service”).

By using our Service, you provide your explicit and informed consent to the collection and processing of your information as described in this policy. Please read this policy carefully to understand our practices regarding your data.

1. Principles of Data Processing

Our data processing is guided by the principles of the DPDP Act, including:

  • Lawful Purpose: We process your data for a lawful and specified purpose.
  • Purpose Limitation: We only process data for the purpose for which it was collected.
  • Data Minimization: We collect only the data necessary to provide the Service.
  • Accuracy: We strive to keep your data accurate and up-to-date.
  • Security: We implement robust security measures to protect your data.
  • Accountability: We are accountable for compliance with the DPDP Act.

2. Information We Collect and the Purpose of Collection

We act as a Data Fiduciary and a Data Processor for the data we collect. We collect the following categories of information:

a. Personal Data

This is information that can be used to identify you, as defined under the DPDP Act and IT Act, 2000. We collect this data with your consent during registration and use of the Service.

  • Contact Information: Your full name, email address, and company name.
  • Account Credentials: Your username and encrypted password.
  • Billing Information: If you subscribe to a paid plan, we collect billing details, which may include your billing address and payment information. This is handled by a secure third-party payment gateway, and we do not store your credit card details on our servers.

Purpose: We use this information to create and manage your account, provide access to the Service, communicate with you, process payments, and provide customer support. This is necessary for the performance of our contract with you.

b. Technical Information and Usage Data (Non-Personal)

This data does not directly identify you but is collected automatically to improve the Service.

  • Usage Data: Information about your interaction with the Service, such as features used, time spent on the application, and the frequency of use.
  • Device and Log Data: Your IP address, browser type, operating system, and unique device identifiers.

Purpose: To monitor and analyze Service usage, enhance performance, troubleshoot issues, and ensure the security and integrity of our platform. This helps us optimize Orbis AppSec for a better user experience.

c. Submitted Code (Highly Confidential)

As the core function of Orbis AppSec, you submit your source code for analysis.

Strict Confidentiality: The code you submit is processed in a secure, isolated environment. We treat this data as highly confidential and process it solely for the purpose of identifying vulnerabilities and generating reports for you. We do not use this code for training any models, sell it, or share it with any third party outside of our secure processing infrastructure. Your Submitted Code is your intellectual property, and we act as a processor on your behalf to analyze it.

4. Your Rights as a Data Principal

In accordance with the DPDP Act, you have the following rights concerning your personal data:

  • Right to Access: You have the right to obtain information about the personal data we process about you.
  • Right to Correction and Erasure: You can request the correction of inaccurate data and the erasure of your personal data.
  • Right to Nominate: You can nominate another person to exercise these rights on your behalf in the event of your death or incapacity.
  • Right to Grievance Redressal: You have the right to a swift and effective mechanism for grievance redressal.

How to Exercise Your Right to Erasure: To exercise your right to demand the deletion of all of your personal information, please send an email to our dedicated email address: admin@orbisappsec.com. Upon receiving a valid request from the email address linked to your account, we will take all reasonable and necessary steps to permanently delete your personal data from our active systems and records within a reasonable timeframe, subject to our legal obligations for data retention.

5. Data Security and Safeguards

We implement “reasonable security practices and procedures” as required under the IT Act and SPDI Rules. These measures include, but are not limited to, encryption of data in transit and at rest, access control, firewalls, and regular security audits. While we strive to protect your data, no method of transmission over the Internet or electronic storage is 100% secure. You acknowledge this inherent risk.

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, to comply with our legal obligations, and to resolve disputes. Once your data is no longer required, we will securely erase or anonymize it. Submitted Code is retained only for the duration required for analysis and reporting, after which it is securely deleted from our systems.

7. Disclosure to Third Parties

We do not sell, rent, or trade your personal information. We may share your data with trusted third-party service providers who assist us in operating the Service (e.g., cloud hosting, payment processing). These providers are contractually bound to use your data only for the purpose of providing services to us and are required to maintain appropriate security measures. We will disclose your information if required by law or in response to a valid legal process, such as a court order or government request, in compliance with Section 69 of the IT Act, 2000. We will also disclose data if necessary to protect our rights, property, or safety, or that of our users or the public.

8. Children's Privacy

Our Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal data from children without verifiable parental consent. If we become aware that we have collected personal data from a child without appropriate consent, we will take immediate steps to delete that information from our servers in compliance with the DPDP Act.

9. Grievance Redressal

In accordance with the IT Act and SPDI Rules, we have a designated Grievance Officer to address your queries and complaints regarding our data handling practices. You may contact the Grievance Officer at the contact details provided below.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by posting the new Privacy Policy on our website and updating the “Last Updated” date. Your continued use of the Service after the changes become effective constitutes your acceptance of the revised policy.

11. Contact Us and Grievance Officer Details

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact our team or our designated Grievance Officer:

Grievance Officer / Data Protection Contact:Email: admin@orbisappsec.comOrbisAI SecurityBengaluru, Karnataka, India

Looking for help rather than legal detail? Visit Support or read our Terms of Service.