Legal · Privacy

Privacy Policy

Last updated: 16 September 2026

Orditia India Private Limited (“Orditia,” “we,” “our,” “us”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you visit www.orditia.com or engage with us for consulting services. It is designed to align with the Digital Personal Data Protection Act, 2023 (DPDP Act), and, where applicable, the EU General Data Protection Regulation (GDPR) and the U.S. HIPAA Privacy and Security Rules.

1. Who we are

Orditia India Private Limited is a company registered in India, with its registered office at F.No 2225 Tower B, Cander Crescent, Lingampally, Hyderabad, Telangana, India. For the purposes of the DPDP Act, we act as a Data Fiduciary when we determine the purposes and means of processing personal data, and as a Data Processor when we process personal data on behalf of a client under contract.

2. What information we collect

  • Information you provide directly. When you submit our contact form or otherwise contact us, we collect your name, work email, company name (optional), your message, and any interest tag captured in the URL (e.g. ?interest=audit).
  • Technical information. When you visit our website, our infrastructure providers (Cloudflare and Cloudflare Pages) may automatically log your IP address, user-agent string, and request timestamps for security and abuse-prevention purposes.
  • Client engagement data. During a client engagement, we may process personal data that our client provides to us under a Data Processing Agreement (DPA). This data is handled only on the client's documented instructions.

We do not use cookies for advertising, and we do not currently run third-party analytics on this site.

3. Why we process your data (lawful basis / purpose)

  • To respond to your inquiry and to schedule follow-up conversations (contractual necessity / your consent under §6 DPDP Act).
  • To operate and secure our website (legitimate interests).
  • To meet legal, tax, and regulatory obligations.
  • To deliver contracted services to our clients (per client DPA).

4. How we protect your data

We apply security controls aligned to ISO/IEC 27001 and SOC 2 Trust Services Criteria, including:

  • Encryption of personal data in transit (TLS 1.2+) and at rest.
  • Access on a minimum-necessary, need-to-know basis.
  • Multi-factor authentication on all administrative systems.
  • Audit logging of access to systems that hold personal data.
  • For engagements involving Protected Health Information, HIPAA Security Rule §164.312 controls and Business Associate Agreements with our sub-processors.

5. Where your data is stored

By default, personal data is stored and processed in India (AWS ap-south-1 or Azure Central India). For clients with U.S. or EU footprints, we can host in-region (us-east-1, eu-west-1, etc.) to satisfy applicable data-residency requirements. Cross-border transfers, where they occur, are performed only under mechanisms permitted by the DPDP Act and, where relevant, EU Standard Contractual Clauses.

6. How long we keep your data

Inquiries submitted through this website are retained for up to 24 months to allow for follow-up, then deleted or anonymized unless a client engagement is under way. Client engagement data is retained for the period specified in the applicable Statement of Work or DPA.

7. Who we share your data with

We do not sell personal data. We share it only with:

  • Sub-processors that help us operate the website (e.g. Cloudflare for hosting and CDN; a form-processing provider such as Formspree, once configured) under contractual data-protection obligations.
  • LLM and cloud infrastructure providers used within a specific client engagement, only under the client's authorization and with BAAs where PHI is involved.
  • Regulators, courts, and law-enforcement agencies where legally required.

8. Your rights as a Data Principal

Under the DPDP Act you have the right to:

  • Access the personal data we hold about you.
  • Correct or update inaccurate or incomplete data.
  • Erase your personal data, subject to applicable retention obligations.
  • Withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
  • Nominate another individual to exercise these rights in the event of death or incapacity.
  • Lodge a complaint with the Data Protection Board of India.

To exercise any of these rights, please use our contact form. We will respond within the timeframe required by applicable law.

9. Children's data

This website is not directed at children under 18, and we do not knowingly collect personal data from children.

10. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date above will reflect any changes. Material changes will be flagged on the homepage or by direct notice where feasible.

11. Contact us

Questions or complaints about this Privacy Policy? Please use our contact form and mark your submission as “Privacy”. Formal notices should be addressed to the Grievance Officer at our registered office.