1. Purpose and scope
This Data Protection document describes Opsivel's intended governance approach for personal data and Customer Data processed through its products and services. It is designed to complement the Privacy Policy and applicable commercial agreements.
Where a customer determines the purposes and means of processing and Opsivel processes data only on the customer's instructions, the customer may act as Data Fiduciary and Opsivel as Data Processor under the DPDP framework. Where Opsivel determines the purposes and means of its own processing, Opsivel may act as Data Fiduciary.
Definitions
Customer means the hotel, resort, company or other organisation that uses or purchases Opsivel services. Authorised User means an individual who is authorised by the Customer to access or use the applicable Opsivel service. References to the Customer include the organisation using the services, while references to an Authorised User refer to an individual user acting on behalf of that organisation.
2. Applicable Indian framework
Opsivel's data-protection framework is designed around applicable Indian requirements, including the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 to the extent applicable, and the Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025.
The DPDP Act and Rules have a phased commencement. The core provisions of the Act are scheduled to commence eighteen months after 13 November 2025, while the Rules contain corresponding staged dates. Opsivel should therefore operate its controls in a way that supports both currently applicable requirements and the future DPDP obligations.
3. Governance and accountability
Opsivel will assign appropriate responsibility for privacy, security and data-protection matters within the organisation. Personnel with access to personal data or Customer Data should receive appropriate instructions and access only to information needed for their role.
Where a customer agreement requires a dedicated Data Protection Officer or other named contact, the applicable contractual document will identify that person or function.
4. Data classification
Opsivel should classify information according to sensitivity and operational impact. Categories may include public information, internal business information, personal data, confidential customer information, credentials and security-sensitive information.
Access, storage, sharing and retention controls should be proportionate to the classification.
5. Data minimisation and purpose limitation
Opsivel aims to collect and process only data reasonably necessary for identified purposes. Customer workflows should avoid collecting personal information that is not required for the service.
Where the purpose changes materially, the applicable notice, contract or customer instruction should be reviewed before new processing begins.
6. Role-based access control
Access should be granted on a least-privilege and need-to-know basis. Where technically feasible, administrative access should be limited, authenticated using appropriate controls and logged.
Customers are responsible for managing their own user access and permissions within the platform. Opsivel is responsible for the controls applicable to its own personnel and systems.
7. Authentication and credential security
Opsivel should use appropriate authentication controls for administrative and user access. Credentials, tokens and secrets must not be exposed in public repositories or insecure channels.
Users and customer administrators are responsible for safeguarding their credentials and promptly reporting suspected compromise.
8. Encryption and secure transmission
Where appropriate to the service architecture, data should be protected using encryption in transit and at rest. Sensitive credentials and secrets should be stored using secure mechanisms designed to prevent unauthorised disclosure.
Specific encryption standards and architecture may vary by component and should be documented internally rather than promised broadly on a public page unless actually implemented.
9. Secure development and change management
Opsivel should use reasonable secure-development practices, code review, dependency management, environment separation, testing and controlled deployment processes appropriate to the maturity and risk of the service.
Material changes to security-sensitive components should be evaluated for privacy and security impact.
10. Logging, monitoring and auditability
Systems should maintain appropriate logs and monitoring to support security, troubleshooting, abuse detection and accountability. Logs should be protected against unauthorised alteration and retained only for as long as necessary for their purpose and applicable obligations.
11. Backups and disaster recovery
Where backups are used, they should be protected with access controls and appropriate security measures. Restoration procedures should be tested to the extent appropriate to the service. Recovery objectives and backup retention should be documented internally and may be specified contractually for enterprise customers.
12. Sub-processors and service providers
Opsivel may use third-party providers for hosting, cloud infrastructure, communications, analytics, monitoring, support, email, authentication, payment processing or other operational functions.
Where those providers process personal data on behalf of Opsivel or a customer, Opsivel should conduct appropriate diligence and impose contractual confidentiality, security and processing controls appropriate to the role and risk.
13. Customer Data processing
Customer Data will be processed only for purposes authorised by the applicable customer agreement or documented instructions, except where processing is required by applicable law.
Opsivel should not sell Customer Data. Any product analytics or aggregated reporting using Customer Data should be designed to avoid identifying individuals and should be covered by the applicable agreement and privacy notices.
14. International processing and transfers
Some technology providers may operate infrastructure outside India. Where cross-border processing occurs, Opsivel will use legally permitted arrangements and safeguards appropriate to the applicable requirements.
Opsivel will monitor Government notifications and other applicable legal requirements concerning restricted jurisdictions or transfer conditions under the DPDP framework.
15. Retention and deletion
Opsivel will support retention and deletion processes appropriate to the purpose and contractual arrangement. Customer-controlled data should be deleted or returned in accordance with the applicable contract, subject to legally required retention, backup schedules and technical limitations.
Where data is deleted from active systems, residual copies may persist temporarily in protected backups until their normal expiry cycle.
16. Personal-data breach management
Opsivel should maintain an incident-response process covering detection, assessment, containment, investigation, remediation, documentation and notification.
The DPDP Act and Rules include obligations concerning personal-data breaches. The final operational timelines and notification process must be implemented in accordance with the provisions applicable at the time and the customer's contractual requirements.
17. Data Principal and customer requests
Where Opsivel processes Customer Data as a Data Processor, it will provide reasonable assistance to the customer in responding to legally valid data-principal requests, subject to the scope of the service, applicable law, security requirements and reasonable costs where contractually permitted.
Where Opsivel is itself the Data Fiduciary, individuals may exercise applicable rights through the privacy contact identified in the Privacy Policy.
18. Employee and contractor obligations
Personnel and contractors with access to protected information should be subject to confidentiality obligations and appropriate security practices. Access should be revoked promptly when no longer required.
19. Physical and infrastructure security
Where Opsivel relies on third-party cloud or hosting providers, infrastructure security controls may be provided through those providers and their facilities. Opsivel should evaluate relevant provider controls and configure services to reduce avoidable exposure.
Physical security commitments should reflect the actual hosting architecture rather than generic claims.
20. Security testing and vulnerability management
Opsivel should maintain reasonable processes for identifying and addressing vulnerabilities in systems, dependencies and configurations. The timing and depth of testing should be risk-based and proportionate to the service.
21. Customer security responsibilities
Customers are responsible for configuring their use of Opsivel securely, including user permissions, account administration, device security, credential management, lawful data collection, appropriate notices and the content entered by their users.
Customers should not use the service for prohibited or unnecessarily high-risk processing without written agreement and appropriate safeguards.
22. Data protection agreements
For enterprise or customer-controlled personal-data processing, Opsivel may enter into a Data Processing Addendum or similar agreement covering processing instructions, confidentiality, security, sub-processors, breach notification, assistance with data-principal requests, deletion or return, audits and other applicable requirements.
Where a signed DPA conflicts with this public document, the signed DPA will govern the contractual relationship.
23. No absolute security guarantee
Opsivel cannot guarantee that any system or transmission will be completely immune from compromise. The objective of these controls is to reduce risk, detect incidents, limit impact and support appropriate response and recovery.
24. Contact
Questions regarding data protection or security can be sent to hello@opsivel.com. Opsivel should insert its final legal entity details and any formally designated privacy or security contact before publication.