Legal
DPDP notice
This notice outlines how orbitGRC processes personal data under the Digital Personal Data Protection framework, particularly when acting on behalf of customers.
Role
Where orbitGRC acts as a Data Processor for customer data, the processing of personal data is governed by the contractual data-processing terms agreed with each customer organization. The customer remains the Data Fiduciary for that data.
Lawful processing
Lawful bases for processing personal data through orbitGRC are typically established via the customer’s contracts with its data principals and through the data-processing terms between the customer and orbitGRC. Specific lawful bases vary by use case and customer configuration.
Data Principal rights
Data principals are typically entitled to rights such as access, correction, erasure and grievance redressal in respect of their personal data. Such requests are normally handled by the customer in its role as Data Fiduciary, with orbitGRC providing reasonable processor assistance as set out in the customer’s contract.
Sub-processors
The list of orbitGRC sub-processors is maintained per the customer agreement and is available on request to authorized customer contacts.
Grievance
Submit grievances via the contact form at /contact.
Website analytics
This DPDP notice covers personal data processed by the orbitGRC platform on behalf of customers. The public marketing website at orbitgrc.in may separately use website analytics (including Google Analytics 4) to understand aggregate visitor behaviour. The website analytics path is governed by the website privacy notice at /legal/privacy rather than by customer data-processing terms.
Related pages
See also our privacy notice and security posture. For grievance follow-up or anything not covered above, use the contact page.