Privacy Policy
Privacy & Data Protection
Last Updated: August 2026
Octonomus Consulting (“Octonomus”, “we”, “our”, or “us”) respects your privacy and is committed to protecting personal data entrusted to us.
This Privacy & Data Protection Policy explains how we collect, use, process, store, protect, and disclose personal data when you visit our website, communicate with us, request information, submit an enquiry, access our resources, or otherwise interact with Octonomus through digital channels.
This Policy is designed with reference to applicable Indian data protection requirements, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), as and when the relevant provisions apply to our processing activities.
Company: Octonomus Consulting
Location: Uttar Pradesh, India
Email: support@octonomus.com
1. Our Privacy Commitment
At Octonomus, we believe personal data should be handled responsibly, transparently, and securely.
Our approach is guided by the following principles:
- Purpose-driven data processing
- Transparency
- Data minimization
- Appropriate consent and lawful processing
- Data accuracy
- Reasonable retention
- Security and confidentiality
- Accountability
We aim to collect and process only the personal data reasonably necessary for the relevant business or operational purpose.
2. Personal Data We Collect
The information we collect depends on how you interact with Octonomus.
Information You Provide
You may voluntarily provide:
- Name
- Business email address
- Phone number
- Company or organization name
- Job title or professional information
- Information submitted through enquiry and contact forms
- Consultation requests
- Information provided when downloading or requesting resources
- Information contained in business communications
- Other information you voluntarily provide to us
Technical Information
When you visit our website, certain information may be collected automatically, including:
- IP address
- Browser type and version
- Device information
- Operating system
- Website pages visited
- Referring website
- Access date and time
- Website interaction information
- Approximate location derived from technical information
We seek to limit collection to information reasonably required for the relevant purpose.
3. How We Use Personal Data
We may use personal data to:
- Respond to enquiries and requests
- Provide information about our services and capabilities
- Arrange consultations and business discussions
- Communicate with prospective and existing clients
- Provide requested resources
- Improve website functionality and user experience
- Understand website performance and usage
- Maintain website and information security
- Detect and prevent misuse, fraud, or unauthorized activity
- Manage business relationships
- Meet applicable legal and regulatory obligations
- Establish, exercise, or defend legal rights
- Support legitimate business operations
We will not use personal data for purposes that are incompatible with the purpose communicated at the time of collection, unless permitted by applicable law.
4. Notice and Consent
Where consent is required, we will seek consent through an appropriate mechanism and provide information necessary for an individual to make an informed decision.
Where applicable, our notices will identify:
- The personal data being collected
- The purpose or purposes of processing
- The relevant service, functionality, or business purpose enabled by the processing
- Available methods for exercising applicable rights
- Available methods for withdrawing consent
The DPDP Rules require applicable notices to be clear, standalone, understandable, and to include an itemized description of personal data and specified purposes.
Where processing is based on consent, individuals may withdraw consent through an appropriate mechanism, subject to applicable law and the consequences of withdrawal.
5. Our Role in Data Processing
Depending on the nature of an engagement, Octonomus may act as a Data Fiduciary, Data Processor, or another legally applicable role.
When Octonomus determines the purpose and means of processing personal data, it may act as a Data Fiduciary.
When Octonomus processes personal data on behalf of a client according to the client’s instructions, the client may act as the Data Fiduciary and Octonomus may act as a Data Processor.
The applicable responsibilities will depend on the nature of the relationship, processing activity, contractual arrangements, and applicable law.
6. How We Share Personal Data
We do not sell personal data.
Where necessary, personal data may be shared with:
- Technology and infrastructure providers
- Cloud and hosting providers
- Website and analytics providers
- Communication and collaboration providers
- Professional advisers
- Security and technology service providers
- Business partners where necessary and permitted
- Government, regulatory, or law enforcement authorities where legally required
- Relevant parties in connection with a merger, acquisition, restructuring, or business transfer
We seek to ensure that third parties receiving personal data provide appropriate safeguards and process information only for authorized purposes.
7. Data Processors and Service Providers
Octonomus may engage third-party providers to support our technology and business operations.
These may include providers supporting:
- Cloud infrastructure
- Website hosting
- Analytics
- Cybersecurity
- Communications
- Customer relationship management
- Forms and enquiry management
- Business operations
- Technical support
Where appropriate, contractual, technical, and organizational safeguards will be used to protect personal data.
8. Data Security
Security is an important part of how we operate as a technology and cybersecurity company.
We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, destruction, or other unauthorized processing.
Depending on the nature and sensitivity of the information, measures may include:
- Access controls
- Authentication mechanisms
- Encryption
- Secure infrastructure
- Security monitoring
- Logging
- Vulnerability management
- Backup and recovery
- Secure development practices
- Incident response procedures
- Third-party security controls
The DPDP Rules specify reasonable security safeguards including encryption, access controls, logging and monitoring, backups, contractual safeguards with processors, and appropriate technical and organizational measures.
No digital environment can be guaranteed to be completely secure. We therefore continuously review and improve our security practices.
9. Personal Data Breaches
Octonomus maintains procedures for identifying, assessing, containing, and responding to personal data breaches.
Where applicable, we will follow the notification and response requirements prescribed under relevant data protection laws.
The DPDP Rules establish requirements concerning notification of certain personal data breaches to affected Data Principals and the Data Protection Board of India.
10. Data Retention
We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, unless a longer period is required or permitted by law.
Retention may depend on:
- The purpose for which information was collected
- The nature of the business relationship
- Legal and regulatory requirements
- Security requirements
- Accounting requirements
- Dispute resolution
- Contractual obligations
When personal data is no longer required, we take reasonable steps to securely delete, anonymize, or otherwise dispose of it.
11. International Data Processing
Octonomus is based in India and may work with clients, technology providers, and business partners located in other countries.
As a result, personal data may be processed or stored outside India where necessary for legitimate business purposes.
Where applicable, we will implement appropriate contractual, technical, and organizational safeguards for international processing and transfers and comply with applicable legal requirements.
12. Cookies and Similar Technologies
Our website may use cookies and similar technologies to:
- Enable essential functionality
- Maintain security
- Remember preferences
- Understand website usage
- Measure performance
- Improve user experience
- Support relevant communications where applicable
Where consent is required, we will provide appropriate mechanisms to manage cookie preferences.
You may also manage cookies through your browser settings. Disabling certain cookies may affect website functionality.
13. Analytics and Third-Party Technologies
We may use third-party technologies for website analytics, performance monitoring, security, communications, forms, and other business purposes.
Such technologies may process technical or personal information in accordance with their own terms and privacy practices.
Where appropriate, we seek to use providers that maintain reasonable security and privacy safeguards.
14. AI and Personal Data
Octonomus provides AI-related technology and may use artificial intelligence and automated technologies in appropriate business and operational contexts.
Where personal data is processed through AI-enabled systems, we seek to apply appropriate safeguards relating to:
- Privacy
- Security
- Confidentiality
- Purpose limitation
- Human oversight
- Transparency
- Responsible use
We do not intentionally use personal data for unrelated AI purposes without an appropriate legal basis, authorization, or applicable notice.
15. Children's Personal Data
Our corporate website is primarily intended for businesses, organizations, and professional users.
We do not intentionally seek to collect children’s personal data through ordinary website enquiries.
Where the DPDP framework applies to children’s personal data, Octonomus will implement the applicable safeguards and requirements.
The DPDP Rules establish specific requirements relating to verifiable parental consent and processing of children’s personal data.
16. Your Data Protection Rights
Subject to applicable law and the commencement of relevant provisions, individuals may have rights relating to their personal data, including:
Access
Request information about personal data being processed and relevant processing activities.
Correction
Request correction of inaccurate or incomplete personal data.
Erasure
Request deletion of personal data where applicable.
Withdrawal of Consent
Withdraw consent where processing is based on consent.
Grievance Redressal
Raise concerns regarding the processing of personal data.
Nomination
Exercise applicable nomination rights under the DPDP framework.
Requests may be submitted to: support@octonomus.com
We may take reasonable steps to verify the identity of the requester before responding to certain requests.
17. Exercising Your Rights
To submit a privacy or data protection request, contact:
Please include sufficient information to help us understand your request.
Where applicable, we will provide mechanisms through which individuals can exercise their rights and raise grievances.
We may request additional information where reasonably necessary to verify identity and protect against unauthorized requests.