Skip to content
Opsivel
  • Home
  • Platform
  • Solutions
  • About
  • Contact
Book a Demo
Legal

Data Protection

This document explains how Opsivel approaches data protection when operating its website and when providing B2B hospitality software that may process customer-controlled personal data.

Last updated: 24 August 2026

1. Purpose and scope

This Data Protection document describes Opsivel's intended governance approach for personal data and Customer Data processed through its products and services. It is designed to complement the Privacy Policy and applicable commercial agreements. Where a customer determines the purposes and means of processing and Opsivel processes data only on the customer's instructions, the customer may act as Data Fiduciary and Opsivel as Data Processor under the DPDP framework. Where Opsivel determines the purposes and means of its own processing, Opsivel may act as Data Fiduciary.

Definitions

Customer means the hotel, resort, company or other organisation that uses or purchases Opsivel services. Authorised User means an individual who is authorised by the Customer to access or use the applicable Opsivel service. References to the Customer include the organisation using the services, while references to an Authorised User refer to an individual user acting on behalf of that organisation.

2. Applicable Indian framework

Opsivel's data-protection framework is designed around applicable Indian requirements, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 to the extent applicable, and the Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025. The DPDP Act and Rules have a phased commencement. The core provisions of the Act are scheduled to commence eighteen months after 13 November 2025, while the Rules contain corresponding staged dates. Opsivel should therefore operate its controls in a way that supports both currently applicable requirements and the future DPDP obligations.

3. Governance and accountability

Opsivel will assign appropriate responsibility for privacy, security and data-protection matters within the organisation. Personnel with access to personal data or Customer Data should receive appropriate instructions and access only to information needed for their role. Where a customer agreement requires a dedicated Data Protection Officer or other named contact, the applicable contractual document will identify that person or function.

4. Data classification

Opsivel should classify information according to sensitivity and operational impact. Categories may include public information, internal business information, personal data, confidential customer information, credentials and security-sensitive information. Access, storage, sharing and retention controls should be proportionate to the classification.

5. Data minimisation and purpose limitation

Opsivel aims to collect and process only data reasonably necessary for identified purposes. Customer workflows should avoid collecting personal information that is not required for the service. Where the purpose changes materially, the applicable notice, contract or customer instruction should be reviewed before new processing begins.

6. Role-based access control

Access should be granted on a least-privilege and need-to-know basis. Where technically feasible, administrative access should be limited, authenticated using appropriate controls and logged. Customers are responsible for managing their own user access and permissions within the platform. Opsivel is responsible for the controls applicable to its own personnel and systems.

7. Authentication and credential security

Opsivel should use appropriate authentication controls for administrative and user access. Credentials, tokens and secrets must not be exposed in public repositories or insecure channels. Users and customer administrators are responsible for safeguarding their credentials and promptly reporting suspected compromise.

8. Encryption and secure transmission

Where appropriate to the service architecture, data should be protected using encryption in transit and at rest. Sensitive credentials and secrets should be stored using secure mechanisms designed to prevent unauthorised disclosure. Specific encryption standards and architecture may vary by component and should be documented internally rather than promised broadly on a public page unless actually implemented.

9. Secure development and change management

Opsivel should use reasonable secure-development practices, code review, dependency management, environment separation, testing and controlled deployment processes appropriate to the maturity and risk of the service. Material changes to security-sensitive components should be evaluated for privacy and security impact.

10. Logging, monitoring and auditability

Systems should maintain appropriate logs and monitoring to support security, troubleshooting, abuse detection and accountability. Logs should be protected against unauthorised alteration and retained only for as long as necessary for their purpose and applicable obligations.

11. Backups and disaster recovery

Where backups are used, they should be protected with access controls and appropriate security measures. Restoration procedures should be tested to the extent appropriate to the service. Recovery objectives and backup retention should be documented internally and may be specified contractually for enterprise customers.

12. Sub-processors and service providers

Opsivel may use third-party providers for hosting, cloud infrastructure, communications, analytics, monitoring, support, email, authentication, payment processing or other operational functions. Where those providers process personal data on behalf of Opsivel or a customer, Opsivel should conduct appropriate diligence and impose contractual confidentiality, security and processing controls appropriate to the role and risk.

13. Customer Data processing

Customer Data will be processed only for purposes authorised by the applicable customer agreement or documented instructions, except where processing is required by applicable law. Opsivel should not sell Customer Data. Any product analytics or aggregated reporting using Customer Data should be designed to avoid identifying individuals and should be covered by the applicable agreement and privacy notices.

14. International processing and transfers

Some technology providers may operate infrastructure outside India. Where cross-border processing occurs, Opsivel will use legally permitted arrangements and safeguards appropriate to the applicable requirements. Opsivel will monitor Government notifications and other applicable legal requirements concerning restricted jurisdictions or transfer conditions under the DPDP framework.

15. Retention and deletion

Opsivel will support retention and deletion processes appropriate to the purpose and contractual arrangement. Customer-controlled data should be deleted or returned in accordance with the applicable contract, subject to legally required retention, backup schedules and technical limitations. Where data is deleted from active systems, residual copies may persist temporarily in protected backups until their normal expiry cycle.

16. Personal-data breach management

Opsivel should maintain an incident-response process covering detection, assessment, containment, investigation, remediation, documentation and notification. The DPDP Act and Rules include obligations concerning personal-data breaches. The final operational timelines and notification process must be implemented in accordance with the provisions applicable at the time and the customer's contractual requirements.

17. Data Principal and customer requests

Where Opsivel processes Customer Data as a Data Processor, it will provide reasonable assistance to the customer in responding to legally valid data-principal requests, subject to the scope of the service, applicable law, security requirements and reasonable costs where contractually permitted. Where Opsivel is itself the Data Fiduciary, individuals may exercise applicable rights through the privacy contact identified in the Privacy Policy.

18. Employee and contractor obligations

Personnel and contractors with access to protected information should be subject to confidentiality obligations and appropriate security practices. Access should be revoked promptly when no longer required.

19. Physical and infrastructure security

Where Opsivel relies on third-party cloud or hosting providers, infrastructure security controls may be provided through those providers and their facilities. Opsivel should evaluate relevant provider controls and configure services to reduce avoidable exposure. Physical security commitments should reflect the actual hosting architecture rather than generic claims.

20. Security testing and vulnerability management

Opsivel should maintain reasonable processes for identifying and addressing vulnerabilities in systems, dependencies and configurations. The timing and depth of testing should be risk-based and proportionate to the service.

21. Customer security responsibilities

Customers are responsible for configuring their use of Opsivel securely, including user permissions, account administration, device security, credential management, lawful data collection, appropriate notices and the content entered by their users. Customers should not use the service for prohibited or unnecessarily high-risk processing without written agreement and appropriate safeguards.

22. Data protection agreements

For enterprise or customer-controlled personal-data processing, Opsivel may enter into a Data Processing Addendum or similar agreement covering processing instructions, confidentiality, security, sub-processors, breach notification, assistance with data-principal requests, deletion or return, audits and other applicable requirements. Where a signed DPA conflicts with this public document, the signed DPA will govern the contractual relationship.

23. No absolute security guarantee

Opsivel cannot guarantee that any system or transmission will be completely immune from compromise. The objective of these controls is to reduce risk, detect incidents, limit impact and support appropriate response and recovery.

24. Contact

Questions regarding data protection or security can be sent to hello@opsivel.com. Opsivel should insert its final legal entity details and any formally designated privacy or security contact before publication.
Opsivel

Opsivel is a hospitality operations platform that brings guest requests, service teams, mobility, bookings and reporting into one place.

Explore

  • Home
  • Platform
  • Solutions
  • About
  • Contact

Legal

  • Terms & Conditions
  • Privacy Policy
  • Data Protection

Get started

See how Opsivel can simplify your property's operations.

Book a Demo

© 2026 Opsivel. All rights reserved.