Skip to content

Legal

DPDP notice

This notice outlines how orbitGRC processes personal data under the Digital Personal Data Protection framework, particularly when acting on behalf of customers.

Role

Where orbitGRC acts as a Data Processor for customer data, the processing of personal data is governed by the contractual data-processing terms agreed with each customer organization. The customer remains the Data Fiduciary for that data.

Lawful processing

Lawful bases for processing personal data through orbitGRC are typically established via the customer’s contracts with its data principals and through the data-processing terms between the customer and orbitGRC. Specific lawful bases vary by use case and customer configuration.

Data Principal rights

Data principals are typically entitled to rights such as access, correction, erasure and grievance redressal in respect of their personal data. Such requests are normally handled by the customer in its role as Data Fiduciary, with orbitGRC providing reasonable processor assistance as set out in the customer’s contract.

Sub-processors

The list of orbitGRC sub-processors is maintained per the customer agreement and is available on request to authorized customer contacts.

Grievance

Submit grievances via the contact form at /contact.

Website analytics

This DPDP notice covers personal data processed by the orbitGRC platform on behalf of customers. The public marketing website at orbitgrc.in may separately use website analytics (including Google Analytics 4) to understand aggregate visitor behaviour. The website analytics path is governed by the website privacy notice at /legal/privacy rather than by customer data-processing terms.

Related pages

See also our privacy notice and security posture. For grievance follow-up or anything not covered above, use the contact page.