1. Overview & Statutory Scope
OrbitoHQ Technologies Private Limited ("OrbitoHQ", "we", "us", or "our") is committed to safeguarding the privacy of our platform users, enterprise customers, and website visitors. This Privacy Policy is formulated in accordance with Section 43A of the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Digital Personal Data Protection (DPDP) Act, 2023, GDPR, and global data privacy standards.
This policy governs data collected through our SaaS project management platform, website (https://orbitohq.com), tenant subdomains, mobile interfaces, and payment gateway interactions.
2. Information We Collect
We collect essential information required to deliver project management services, enforce multi-tenant security, and process billing transactions:
- Account Information: Full name, official business email address, job title, encrypted credentials, contact number, and organization details provided during registration.
- Workspace Content: Projects, tasks, sprint backlogs, document attachments, workflow rules, comments, and audit logs created within your organization tenant.
- Technical & Session Log Data: IP address, device hardware specs, browser user agent, operating system, session tokens, login history, and system performance metrics.
- Payment & Transaction Information: Billing address, GSTIN (where applicable), subscription plan details, transaction IDs, and invoice records. Note: Credit/debit card numbers, UPI handles, and net banking credentials are captured directly by PCI-DSS Level 1 compliant payment gateways (such as Razorpay, Cashfree, and Stripe) and are never stored on OrbitoHQ servers.
3. Purpose & Processing of Information
We collect and process your personal and workspace data solely for lawful operational purposes:
- Providing workspace provisioning, single sign-on (SSO), and role-based access control (RBAC).
- Processing subscription payments, generating GST tax invoices, and fulfilling transactions via authorized payment aggregators.
- Delivering automated notification alerts, security OTPs, platform status updates, and support responses.
- Preventing fraudulent access, investigating technical vulnerabilities, and ensuring compliance with platform Terms of Service.
4. Payment Gateway & Third-Party Security
Financial transactions on OrbitoHQ are executed through accredited, PCI-DSS certified payment aggregators and gateways (including Razorpay, Cashfree, and Stripe). All payment data transfers are encrypted end-to-end via TLS 1.3 protocol. OrbitoHQ does not store sensitive cardholder data, CVV numbers, or bank account PINs on our servers.
5. User Rights & Data Protection Controls
Under the DPDP Act 2023 and global privacy frameworks, users retain rights to:
- Right to Access & Rectification: Inspect and update profile information via account settings.
- Right to Erasure: Request permanent erasure of account and workspace data upon subscription termination.
- Data Portability: Export tasks, sprint reports, and project data in structured CSV/JSON formats.
- Withdrawal of Consent: Unsubscribe from non-essential commercial emails at any time.
6. Grievance Redressal Officer (Indian IT Act Compliance)
In accordance with the Information Technology Act 2000 and Rules made thereunder, as well as Consumer Protection (E-Commerce) Rules 2020, the contact details of our Grievance Officer are provided below:
Grievance Officer: Mr. Rajesh Kumar
Designation: Nodal & Grievance Redressal Officer
Company: OrbitoHQ Technologies Private Limited
Corporate Address: Level 5, DLF Cyber City, Phase III, Gurugram, Haryana 122002, India
Email: grievance@orbitohq.com
Phone: +91 (0124) 408-4920
Response Timeline: Grievances will be acknowledged within 48 hours and resolved within 15 to 30 business days from receipt.