Legal · Oronzo LLP
Privacy Policy
Effective date: · Last updated:
This Privacy Policy is published in accordance with Rule 3 and Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011("SPDI Rules"), Section 43A of the Information Technology Act, 2000, and the Digital Personal Data Protection Act, 2023 ("DPDP Act"). It describes how Oronzo LLP("Oronzo", "we", "us", "our") collects, processes, stores, transfers, discloses, retains, and protects Personal Data of Users ("you", "Data Principal").
1. Who We Are (Data Fiduciary)
Oronzo LLP is a Limited Liability Partnership incorporated under the Limited Liability Partnership Act 2008 (LLPIN [LLPIN: AAA-1234]), with its registered office at WeWork, K. Raheja Mindspace, Survey No. 64, Building No. 9, Madhapur, Shaikpet, Hyderabad – 500081, Telangana, India. For the purposes of the DPDP Act 2023, Oronzo acts as the "Data Fiduciary" in respect of Personal Data collected directly from Users on its website oronzo.io and its products (Curex24, Curex24 Clinic, F-Cube, Oronzo Desk, Retro Board, and future products).
Where you, as an enterprise customer, use our products to process Personal Data of your own customers, patients, or employees, you are the Data Fiduciary and Oronzo is a Data Processor acting on your documented instructions under a separate Data Processing Agreement.
2. Scope & Applicability
This Policy applies to Personal Data of:
- Visitors to oronzo.io and any sub-domain;
- Registered users of Curex24, Curex24 Clinic, F-Cube, Oronzo Desk, and Retro Board;
- Prospective customers who fill in a contact form or download materials;
- Job applicants who submit information through our careers channels.
This Policy does not apply to (a) personal data processed by you about identifiable individuals when you act as a Data Fiduciary using our products; (b) third-party websites linked from our Platform; or (c) information you make publicly available.
3. Definitions
- "Personal Data" means any data about an individual who is identifiable by or in relation to such data (Section 2(t), DPDP Act).
- "Sensitive Personal Data or Information (SPDI)" includes passwords, financial information, health condition data, sexual orientation, biometric information, and medical records, as defined in Rule 3 of the SPDI Rules 2011.
- "Data Principal" means the individual to whom the Personal Data relates.
- "Processing" means any operation performed on Personal Data including collection, recording, organisation, storage, retrieval, use, disclosure, transmission, and erasure.
- "Consent Manager" means a person registered with the Data Protection Board of India under Section 6(7) of the DPDP Act, who enables a Data Principal to give, manage, review, and withdraw consent.
4. Personal Data We Collect
4.1 Data You Provide
- Identity & contact data: name, email address, phone number, postal address, designation.
- Account data: username, hashed password, profile picture, language preference.
- Billing data: billing name, billing address, GSTIN (for business customers), invoices. Card numbers are processed and tokenised by PCI-DSS compliant payment partners and are never stored in cleartext on Oronzo systems.
- Communications: support tickets, chat transcripts, feedback, survey responses.
- Product-specific data (see Section 17 for details).
4.2 Data Collected Automatically
- Log & device data: IP address, browser type and version, operating system, device identifiers, time-zone, referrer URL, pages viewed, clickstream data.
- Cookies & similar technologies: see Section 15.
- Security telemetry: authentication events, anomaly detection signals, audit logs.
4.3 Data Received from Third Parties
We may receive data from identity providers (e.g., Google, Microsoft sign-in), payment processors, KYC vendors, public registries, fraud-detection vendors, and recruitment portals.
4.4 Sensitive Personal Data
Certain products process SPDI such as health records, prescriptions, and financial information. SPDI is processed only with your explicit consent and subject to the heightened safeguards under Rule 5 of the SPDI Rules 2011 and Section 8(5) of the DPDP Act 2023.
5. Purposes & Lawful Basis for Processing
In accordance with Sections 4 to 7 of the DPDP Act, we process Personal Data only for lawful purposes for which the Data Principal has given consent or where processing is for "certain legitimate uses" permitted under Section 7 of the DPDP Act.
| Purpose | Lawful Basis |
|---|---|
| Account creation, authentication, service delivery | Consent / Performance of contract |
| Processing of payments, billing, taxation | Performance of contract / Legal obligation |
| Customer support & service notices | Consent / Legitimate use |
| Marketing communications & product announcements | Consent (opt-in) |
| Security, fraud detection, abuse prevention | Legitimate use / Compliance with law |
| Compliance with statutory and regulatory obligations | Legal obligation |
| Analytics & product improvement | Consent / Anonymised processing |
6. Notice, Consent & Withdrawal
In compliance with Sections 5 and 6 of the DPDP Act, every request for consent is preceded by, or accompanied by, a clear and plain-language notice describing (a) the Personal Data sought, (b) the specified purpose, (c) the manner in which Data Principal rights can be exercised, and (d) the manner of grievance redressal.
Consent so given is free, specific, informed, unconditional, and unambiguous. You may at any time withdraw consent through your account settings or by writing to compliance@oronzo.io. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal, and may limit our ability to continue providing the relevant service.
You may also manage consent through a Consent Manager registered with the Data Protection Board of India, as and when such facility is made available by Oronzo.
7. Children & Persons with Disabilities
In accordance with Section 9 of the DPDP Act, Oronzo shall not process Personal Data of a child (a person below 18 years of age) without verifiable consent of the parent or lawful guardian, and shall not undertake (a) processing that is likely to cause any detrimental effect on the well-being of a child, or (b) tracking, behavioural monitoring, or targeted advertising directed at children. Personal Data of a person with a disability who has a lawful guardian shall be processed only with the consent of such guardian.
Our products are not directed at children. If we become aware that we have collected Personal Data from a child without verifiable parental consent, we will take prompt steps to delete such data.
9. Sub-Processors & Third Parties
Oronzo engages reputable sub-processors who provide infrastructure and ancillary services. Categories include:
- Cloud infrastructure (e.g., AWS, GCP, Microsoft Azure data centres in India where available);
- Email & transactional messaging (e.g., Amazon SES, MSG91, Twilio);
- Payment processing (e.g., Razorpay, Stripe, Cashfree);
- Analytics & observability (e.g., Google Analytics 4, PostHog, Sentry);
- Customer support (e.g., Intercom, Zendesk);
- KYC/identity (e.g., Digio, Karza) where required for F-Cube or Curex24 Clinic.
A current list of material sub-processors is available on request from compliance@oronzo.io.
10. Cross-Border Transfers
Personal Data is primarily processed on infrastructure located in India. Where data is transferred outside India (for example to use a sub-processor not yet present in India), such transfer is undertaken in accordance with Section 16 of the DPDP Act and any restrictions notified by the Central Government from time to time. Standard contractual clauses, data processing agreements, and (for healthcare data) applicable sector-specific safeguards are used to protect such transfers.
11. Data Retention & Erasure
We retain Personal Data only for as long as is necessary for the purposes set out in Section 5, or for such longer period as required to comply with a legal obligation, accounting requirement (e.g., 8 years under the Companies Act / Income-Tax Act), regulatory record-keeping (e.g., under PMLA), or to establish, exercise, or defend legal claims.
- Active account data: retained while the account is active and for up to 180 days after closure, then erased or anonymised.
- Billing & tax records: retained for at least 8 financial years as required under Indian tax laws.
- Health records on Curex24: retained for the period required under the Indian Medical Council regulations and the Clinical Establishments Act (typically 3 years from the last consultation, subject to longer periods for minors and specified conditions).
- Server & security logs: typically 180 days, subject to the CERT-In Directions of 28 April 2022 which require certain logs to be maintained for 180 days within Indian jurisdiction.
12. Security Safeguards
Oronzo implements "reasonable security practices and procedures" within the meaning of Section 43A of the IT Act 2000 read with Rule 8 of the SPDI Rules 2011, aligned with internationally accepted standards including ISO/IEC 27001 and the NIST Cybersecurity Framework. Measures include:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256 or equivalent);
- Strict role-based access controls and principle of least privilege;
- Multi-factor authentication for all privileged production access;
- Periodic vulnerability assessments, penetration tests, and code reviews;
- Network segmentation, firewall protection, and intrusion detection;
- Encrypted, geographically segregated backups with documented restoration drills;
- Mandatory privacy & security training for personnel;
- Documented incident response and business-continuity plans.
No method of transmission or electronic storage is fully secure; while we strive to protect your Personal Data, we cannot guarantee absolute security.
13. Breach Notification
In the event of a Personal Data breach, Oronzo will notify the Data Protection Board of India and affected Data Principals in accordance with Section 8(6) of the DPDP Act 2023 and any rules made thereunder. Cybersecurity incidents that fall within the scope of the CERT-In Directions dated 28 April 2022 will be reported to CERT-In within six (6) hours of becoming aware of, or being notified of, such incidents.
14. Your Rights as a Data Principal
Subject to applicable law, you have the following rights:
- Right to information (Section 11, DPDP Act) — to obtain a summary of Personal Data being processed and the processing activities undertaken.
- Right to correction and erasure (Section 12) — to request correction, completion, updating, or erasure of inaccurate or no-longer-necessary Personal Data.
- Right to grievance redressal (Section 13) — to a readily available means of registering a grievance with Oronzo (see Section 18) and to escalate to the Data Protection Board of India.
- Right to nominate (Section 14) — to nominate another individual to exercise your rights in the event of death or incapacity.
- Right to withdraw consent — at any time, with the same ease with which consent was given.
- Right to portability and access (SPDI Rules 2011) — to access and receive a copy of SPDI held about you.
- Right to grievance under the IT Rules 2021 — for content-related complaints to be acknowledged within 24 hours and resolved within 15 days.
To exercise any right, please write to compliance@oronzo.io with sufficient information to identify you. We may seek additional verification before acting on a request to prevent unauthorised disclosure. We will respond within the timelines prescribed by Applicable Law.
16. Marketing Communications
Marketing emails, SMS, WhatsApp messages, and push notifications are sent only with your opt-in consent and comply with TRAI's Telecom Commercial Communications Customer Preference Regulations, 2018 (TCCCPR). You may unsubscribe at any time via the link in the message or by updating your communication preferences in your account.
17. Product-Specific Notes
17.1 Curex24 & Curex24 Clinic (Healthcare)
Health data, prescriptions, and consultation records constitute SPDI and are processed in line with the Telemedicine Practice Guidelines 2020 and the National Digital Health Mission's Health Data Management Policy. Such data is shared only with the treating Registered Medical Practitioner, the relevant pharmacy or diagnostic partner where you have requested fulfilment, and with regulators where required by law.
17.2 F-Cube (Financial Technology)
Financial information is processed in line with the SPDI Rules and any contractual obligations of partner banks, NBFCs, or payment aggregators. KYC documentation is retained for the period required under the PMLA / RBI Master Directions applicable to the partner entity.
17.3 Oronzo Desk & Retro Board (SaaS)
Customer-uploaded content is treated as confidential information of the customer and is accessed by Oronzo personnel only for support, security, or as required by law.
18. Grievance Officer
In compliance with Section 8(10) of the DPDP Act 2023, Rule 5(9) of the SPDI Rules 2011, and Rule 3(2) of the IT Rules 2021, Oronzo has designated the following officer to receive and resolve grievances:
Palla Chetana Reddy — Grievance Officer, Oronzo LLPOronzo LLP, WeWork, K. Raheja Mindspace, Survey No. 64, Building No. 9,
Madhapur, Shaikpet, Hyderabad – 500081, Telangana, India
Grievances: grievance@oronzo.io
Privacy & compliance: compliance@oronzo.io
Grievances will be acknowledged within forty-eight (48) hours and resolved within fifteen (15) days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
19. Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated by updating the "Last updated" date above and, where appropriate, by email or prominent in-product notice at least seven (7) days before they take effect. Your continued use of the Platform after the effective date constitutes acceptance of the revised Policy.
20. Contact Us
For any questions about this Privacy Policy or our data handling practices, please contact:
Oronzo LLPWeWork, K. Raheja Mindspace, Survey No. 64, Building No. 9,
Madhapur, Shaikpet, Hyderabad – 500081, Telangana, India
General: hello@oronzo.io
Privacy: compliance@oronzo.io