Privacy Policy

Privacy & Data Protection

Last Updated: August 2026

Octonomus Consulting (“Octonomus”, “we”, “our”, or “us”) respects your privacy and is committed to protecting personal data entrusted to us.

This Privacy & Data Protection Policy explains how we collect, use, process, store, protect, and disclose personal data when you visit our website, communicate with us, request information, submit an enquiry, access our resources, or otherwise interact with Octonomus through digital channels.

This Policy is designed with reference to applicable Indian data protection requirements, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), as and when the relevant provisions apply to our processing activities. 

Company: Octonomus Consulting
Location: Uttar Pradesh, India
Email: support@octonomus.com

1. Our Privacy Commitment

At Octonomus, we believe personal data should be handled responsibly, transparently, and securely.

Our approach is guided by the following principles:

  • Purpose-driven data processing
  • Transparency
  • Data minimization
  • Appropriate consent and lawful processing
  • Data accuracy
  • Reasonable retention
  • Security and confidentiality
  • Accountability

We aim to collect and process only the personal data reasonably necessary for the relevant business or operational purpose.

2. Personal Data We Collect

The information we collect depends on how you interact with Octonomus.

Information You Provide

You may voluntarily provide:

  • Name
  • Business email address
  • Phone number
  • Company or organization name
  • Job title or professional information
  • Information submitted through enquiry and contact forms
  • Consultation requests
  • Information provided when downloading or requesting resources
  • Information contained in business communications
  • Other information you voluntarily provide to us
Technical Information

When you visit our website, certain information may be collected automatically, including:

  • IP address
  • Browser type and version
  • Device information
  • Operating system
  • Website pages visited
  • Referring website
  • Access date and time
  • Website interaction information
  • Approximate location derived from technical information

We seek to limit collection to information reasonably required for the relevant purpose.

3. How We Use Personal Data

We may use personal data to:

  • Respond to enquiries and requests
  • Provide information about our services and capabilities
  • Arrange consultations and business discussions
  • Communicate with prospective and existing clients
  • Provide requested resources
  • Improve website functionality and user experience
  • Understand website performance and usage
  • Maintain website and information security
  • Detect and prevent misuse, fraud, or unauthorized activity
  • Manage business relationships
  • Meet applicable legal and regulatory obligations
  • Establish, exercise, or defend legal rights
  • Support legitimate business operations

We will not use personal data for purposes that are incompatible with the purpose communicated at the time of collection, unless permitted by applicable law.

4. Notice and Consent

Where consent is required, we will seek consent through an appropriate mechanism and provide information necessary for an individual to make an informed decision.

Where applicable, our notices will identify:

  • The personal data being collected
  • The purpose or purposes of processing
  • The relevant service, functionality, or business purpose enabled by the processing
  • Available methods for exercising applicable rights
  • Available methods for withdrawing consent

The DPDP Rules require applicable notices to be clear, standalone, understandable, and to include an itemized description of personal data and specified purposes. 

Where processing is based on consent, individuals may withdraw consent through an appropriate mechanism, subject to applicable law and the consequences of withdrawal.

5. Our Role in Data Processing

Depending on the nature of an engagement, Octonomus may act as a Data Fiduciary, Data Processor, or another legally applicable role.

When Octonomus determines the purpose and means of processing personal data, it may act as a Data Fiduciary.

When Octonomus processes personal data on behalf of a client according to the client’s instructions, the client may act as the Data Fiduciary and Octonomus may act as a Data Processor.

The applicable responsibilities will depend on the nature of the relationship, processing activity, contractual arrangements, and applicable law.

6. How We Share Personal Data

We do not sell personal data.

Where necessary, personal data may be shared with:

  • Technology and infrastructure providers
  • Cloud and hosting providers
  • Website and analytics providers
  • Communication and collaboration providers
  • Professional advisers
  • Security and technology service providers
  • Business partners where necessary and permitted
  • Government, regulatory, or law enforcement authorities where legally required
  • Relevant parties in connection with a merger, acquisition, restructuring, or business transfer

We seek to ensure that third parties receiving personal data provide appropriate safeguards and process information only for authorized purposes.

7. Data Processors and Service Providers

Octonomus may engage third-party providers to support our technology and business operations.

These may include providers supporting:

  • Cloud infrastructure
  • Website hosting
  • Analytics
  • Cybersecurity
  • Communications
  • Customer relationship management
  • Forms and enquiry management
  • Business operations
  • Technical support

Where appropriate, contractual, technical, and organizational safeguards will be used to protect personal data.

8. Data Security

Security is an important part of how we operate as a technology and cybersecurity company.

We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, disclosure, alteration, loss, destruction, or other unauthorized processing.

Depending on the nature and sensitivity of the information, measures may include:

  • Access controls
  • Authentication mechanisms
  • Encryption
  • Secure infrastructure
  • Security monitoring
  • Logging
  • Vulnerability management
  • Backup and recovery
  • Secure development practices
  • Incident response procedures
  • Third-party security controls

The DPDP Rules specify reasonable security safeguards including encryption, access controls, logging and monitoring, backups, contractual safeguards with processors, and appropriate technical and organizational measures. 

No digital environment can be guaranteed to be completely secure. We therefore continuously review and improve our security practices.

9. Personal Data Breaches

Octonomus maintains procedures for identifying, assessing, containing, and responding to personal data breaches.

Where applicable, we will follow the notification and response requirements prescribed under relevant data protection laws.

The DPDP Rules establish requirements concerning notification of certain personal data breaches to affected Data Principals and the Data Protection Board of India. 

10. Data Retention

We retain personal data only for as long as reasonably necessary for the purpose for which it was collected, unless a longer period is required or permitted by law.

Retention may depend on:

  • The purpose for which information was collected
  • The nature of the business relationship
  • Legal and regulatory requirements
  • Security requirements
  • Accounting requirements
  • Dispute resolution
  • Contractual obligations

When personal data is no longer required, we take reasonable steps to securely delete, anonymize, or otherwise dispose of it.

11. International Data Processing

Octonomus is based in India and may work with clients, technology providers, and business partners located in other countries.

As a result, personal data may be processed or stored outside India where necessary for legitimate business purposes.

Where applicable, we will implement appropriate contractual, technical, and organizational safeguards for international processing and transfers and comply with applicable legal requirements.

12. Cookies and Similar Technologies

Our website may use cookies and similar technologies to:

  • Enable essential functionality
  • Maintain security
  • Remember preferences
  • Understand website usage
  • Measure performance
  • Improve user experience
  • Support relevant communications where applicable

Where consent is required, we will provide appropriate mechanisms to manage cookie preferences.

You may also manage cookies through your browser settings. Disabling certain cookies may affect website functionality.

13. Analytics and Third-Party Technologies

We may use third-party technologies for website analytics, performance monitoring, security, communications, forms, and other business purposes.

Such technologies may process technical or personal information in accordance with their own terms and privacy practices.

Where appropriate, we seek to use providers that maintain reasonable security and privacy safeguards.

14. AI and Personal Data

Octonomus provides AI-related technology and may use artificial intelligence and automated technologies in appropriate business and operational contexts.

Where personal data is processed through AI-enabled systems, we seek to apply appropriate safeguards relating to:

  • Privacy
  • Security
  • Confidentiality
  • Purpose limitation
  • Human oversight
  • Transparency
  • Responsible use

We do not intentionally use personal data for unrelated AI purposes without an appropriate legal basis, authorization, or applicable notice.

15. Children's Personal Data

Our corporate website is primarily intended for businesses, organizations, and professional users.

We do not intentionally seek to collect children’s personal data through ordinary website enquiries.

Where the DPDP framework applies to children’s personal data, Octonomus will implement the applicable safeguards and requirements.

The DPDP Rules establish specific requirements relating to verifiable parental consent and processing of children’s personal data.

16. Your Data Protection Rights

Subject to applicable law and the commencement of relevant provisions, individuals may have rights relating to their personal data, including:

Access

Request information about personal data being processed and relevant processing activities.

Correction

Request correction of inaccurate or incomplete personal data.

Erasure

Request deletion of personal data where applicable.

Withdrawal of Consent

Withdraw consent where processing is based on consent.

Grievance Redressal

Raise concerns regarding the processing of personal data.

Nomination

Exercise applicable nomination rights under the DPDP framework.

Requests may be submitted to: support@octonomus.com

We may take reasonable steps to verify the identity of the requester before responding to certain requests.

17. Exercising Your Rights

To submit a privacy or data protection request, contact:

support@octonomus.com

Please include sufficient information to help us understand your request.

Where applicable, we will provide mechanisms through which individuals can exercise their rights and raise grievances.

We may request additional information where reasonably necessary to verify identity and protect against unauthorized requests.

How can we help?