โšก Express Shipping Same-day dispatch on orders placed before 2:00 PM IST

Last Updated: 02-09-2026
Effective For: Olatus Systems Private Limited (“Company,” “we,” “us,” or “our”)
Jurisdiction: India (with global accessibility)
Compliance Framework: Digital Personal Data Protection Act, 2023 (India) | General Data Protection Regulation (EU) 2016/679


๐Ÿ“‹ TABLE OF CONTENTS

  1. Introduction & Scope
  2. Key Definitions
  3. Who We Are: Data Fiduciary & Controller Information
  4. Lawful Basis for Processing
  5. Categories of Personal Data We Collect
  6. How and Why We Use Your Data
  7. Data Sharing & Third-Party Disclosures
  8. International Data Transfers
  9. Data Retention & Deletion
  10. Your Rights: DPDP Act & GDPR
  11. Consent Management & Withdrawal
  12. Cookies, Tracking & Analytics
  13. Children’s Privacy
  14. Security Measures
  15. Data Breach Notification
  16. Automated Decision-Making & Profiling
  17. Grievance Redressal & Contact
  18. Changes to This Policy
  19. Appendix: Data Processing Summary

1. INTRODUCTION & SCOPE

1.1 Welcome

Thank you for trusting Olatus Systems Private Limited with your personal data. This Privacy Policy (“Policy”) explains how we collect, use, store, protect, and share your personal information when you interact with our integrated platform, including:

โœ… eCommerce store (physical & digital products)
โœ… Learning Management System (LMS) & online courses
โœ… Community forum, blog, and user-generated content features
โœ… Membership subscriptions & recurring access plans
โœ… Mobile application and related services
(collectively, the “Services”)

1.2 Legal Framework & Compliance

This Policy is designed to comply with:

Where conflicts arise between legal frameworks, we apply the standard offering the highest level of protection to you.

1.3 Acceptance & Consent

By accessing or using our Services, you acknowledge that you have read, understood, and consent to the practices described in this Policy. If you do not agree, please discontinue use immediately.

๐Ÿ”น For Minors (Under 18): Use of our Services requires verifiable parental/guardian consent. Please review Section 13 for details.


2. KEY DEFINITIONS

TermDPDP Act DefinitionGDPR EquivalentOur Usage
Personal DataAny data about an individual who is identifiable by or in relation to such dataPersonal data: any information relating to an identified or identifiable natural personNames, contact details, purchase history, learning progress, forum posts, device identifiers
Data PrincipalThe individual to whom the personal data relatesData SubjectYou, the user of our Services
Data FiduciaryAny person who alone or with others determines the purpose and means of processing personal dataData ControllerOlatus Systems Private Limited
Data ProcessorAny person who processes personal data on behalf of a Data FiduciaryData ProcessorPayment gateways, cloud hosts, analytics providers, courier partners
ConsentFreely given, specific, informed, unconditional, and unambiguous indication of agreementFreely given, specific, informed, and unambiguous indication by clear affirmative actionYour opt-in during registration, checkout, or preference settings
ProcessingAny operation performed on personal data (collection, storage, use, sharing, deletion, etc.)Any operation performed on personal dataAll activities involving your data within our Services
Significant Data FiduciaryA Data Fiduciary notified by the Government based on volume/sensitivity of dataNot directly applicableWe assess our status annually; if designated, additional obligations apply

3. WHO WE ARE: DATA FIDUCIARY & CONTROLLER INFORMATION

Olatus Systems Private Limited
House No: 346, 1st Floor, Police Station, Zoo-Narengi Rd, opp. Barista Cafe and Geetanagar, Ambikagirinagar
Guwahati, Assam, 781024, India
๐Ÿ“ง Privacy Contact: support@olelectronics.com
๐Ÿ“ž Phone: +91 69001 05606
๐ŸŒ Website: www.olelectronics.com

3.1 Data Protection Officer (DPO) / Grievance Officer

As required under DPDP Act and GDPR (where applicable), we have designated:

Grievance Officer (DPDP Act)
Name: [Officer Name]
Email: support@olelectronics.com
Response Time: Within 15 days of receipt

Data Protection Officer (GDPR – if applicable)
Name: [DPO Name]
Email: support@olelectronics.com
Contact for EU/EEA users regarding GDPR rights

If you are in the EU/EEA and believe we are not a GDPR controller for your processing, please contact our DPO for clarification.

3.2 Representative for EU/EEA Users (GDPR Art. 27)

If we do not have an establishment in the EU but process data of EU residents, our appointed representative is:

[Representative Name/Entity]
[Address in EU]
Email: support@olelectronics.com

(If not applicable, this section will state: “Not applicable: Olatus Systems Private Limited has an establishment in the EU / does not target EU residents.”)


4. LAWFUL BASIS FOR PROCESSING

We process your personal data only when we have a valid legal basis. Below is our mapping of processing activities to lawful bases:

Processing ActivityDPDP Act BasisGDPR Legal BasisExplanation
Account registration & authenticationConsent / Legitimate UseConsent (Art. 6(1)(a)) / Contract (Art. 6(1)(b))Necessary to create and manage your Account
Order processing & fulfillmentConsent / Contractual necessityContract (Art. 6(1)(b))Required to deliver products/services you purchase
Payment processingConsent / Legal obligationContract (Art. 6(1)(b)) / Legal obligation (Art. 6(1)(c))To complete transactions and comply with financial regulations
Course enrollment & LMS accessConsent / ContractContract (Art. 6(1)(b))To provide educational services you subscribed to
Community participation (forum/blog)ConsentConsent (Art. 6(1)(a)) / Legitimate interests (Art. 6(1)(f))To enable user interaction and content sharing
Personalization & recommendationsConsent / Legitimate UseLegitimate interests (Art. 6(1)(f))To improve user experience and content relevance
Marketing communicationsExplicit ConsentConsent (Art. 6(1)(a))Only sent if you opt-in; easy opt-out always available
Security, fraud prevention & complianceLegitimate Use / Legal obligationLegitimate interests (Art. 6(1)(f)) / Legal obligation (Art. 6(1)(c))To protect our Services, users, and comply with law
Analytics & service improvementConsent / Legitimate UseLegitimate interests (Art. 6(1)(f)) / Consent (Art. 6(1)(a))Aggregated, anonymized data used to enhance functionality
Legal claims & dispute resolutionLegal obligationLegal obligation (Art. 6(1)(c)) / Legitimate interests (Art. 6(1)(f))To defend rights, comply with court orders, or resolve disputes

๐Ÿ”น Special Category Data: We do not intentionally collect sensitive personal data (e.g., health, biometrics, religious beliefs) unless explicitly required for a specific Service (e.g., accessibility accommodations). Such processing requires explicit consent and additional safeguards.


5. CATEGORIES OF PERSONAL DATA WE COLLECT

We collect data directly from you, automatically via technology, and from third parties. Below is a comprehensive inventory:

5.1 Data You Provide Directly

CategoryExamplesWhen CollectedPurpose
Identity & ContactFull name, email, phone, mailing address, profile photoRegistration, checkout, support requestsAccount creation, order fulfillment, communication
AuthenticationPassword (hashed), security questions, 2FA detailsAccount setup, loginSecure access to your Account
Transaction DataOrder history, payment method (tokenized), billing address, GSTINCheckout, subscription managementProcess payments, issue invoices, manage refunds
Learning Data (LMS)Course enrollments, progress, quiz scores, certificates, forum posts in coursesCourse access, assessmentsDeliver education, track completion, issue credentials
Community ContentForum posts, blog comments, reviews, uploaded files, profile bioForum/blog participationEnable community interaction, moderate content
PreferencesLanguage, currency, notification settings, cookie preferencesAccount settings, cookie bannerPersonalize experience, respect communication choices
Support CommunicationsHelp tickets, chat logs, email correspondenceCustomer support interactionsResolve issues, improve service quality
Verification DocumentsGovernment ID, address proof (for high-value orders or age verification)KYC checks, fraud preventionComply with legal requirements, prevent fraud

5.2 Data Collected Automatically

CategoryExamplesTechnology UsedPurpose
Device & TechnicalIP address, browser type, OS, device model, unique identifiersServer logs, analytics SDKsSecurity, compatibility, troubleshooting
Usage & BehavioralPages visited, time spent, click patterns, course completion ratesCookies, pixels, session recording (opt-in)Improve UX, personalize content, detect abuse
Location DataApproximate location (IP-based) or precise location (with permission)Geolocation APIs, IP geolocationLocalize content, calculate shipping, comply with regional laws
Cookie & Tracking DataSession IDs, preference cookies, advertising identifiersFirst-party & third-party cookies, local storageMaintain sessions, remember preferences, measure ad performance

5.3 Data from Third Parties

SourceData ReceivedPurpose
Payment ProcessorsTransaction confirmation, fraud scores, tokenized payment referencesComplete purchases, prevent fraud
Social Login Providers (Google, Facebook, etc.)Name, email, profile picture (as permitted by you)Simplify registration, enable social features
Courier & Logistics PartnersDelivery status, address validation, proof of deliveryFulfill orders, resolve shipping issues
Analytics & Marketing PartnersAggregated behavior, campaign attribution (with consent)Measure performance, optimize marketing
Identity Verification ServicesKYC validation results (not raw documents)Comply with anti-fraud regulations

โš ๏ธ We do not sell your personal data to third parties for monetary consideration. Data shared with processors is strictly for Service delivery under contractual safeguards.


6. HOW AND WHY WE USE YOUR DATA

We process your personal data only for specified, explicit, and legitimate purposes:

6.1 Core Service Delivery

โœ… Create, manage, and secure your Account
โœ… Process orders, deliver products (physical/digital), and manage subscriptions
โœ… Provide access to courses, track progress, and issue certificates
โœ… Enable community features: forum discussions, blog comments, reviews
โœ… Respond to support requests and resolve technical issues

6.2 Personalization & Experience Enhancement

โœ… Recommend products, courses, or content based on your interests
โœ… Remember preferences (language, currency, notifications)
โœ… Customize dashboards and learning paths
โœ… Send relevant, non-marketing service updates (e.g., course reminders, order status)

6.3 Communication (With Consent)

โœ… Send transactional emails: order confirmations, password resets, policy updates
โœ… Deliver marketing communications only if you opt-in: newsletters, promotions, new course alerts
โœ… Provide survey invitations to improve our Services (optional participation)

6.4 Security, Compliance & Legal Obligations

โœ… Detect, prevent, and investigate fraud, abuse, or security incidents
โœ… Verify identity for high-risk transactions or age-restricted content
โœ… Comply with tax, accounting, consumer protection, and data protection laws
โœ… Respond to lawful requests from public authorities (with legal validation)

6.5 Analytics & Service Improvement

โœ… Analyze aggregated, anonymized usage patterns to improve platform performance
โœ… Conduct A/B testing on features (with opt-out where required)
โœ… Measure course effectiveness and content engagement (in anonymized form)

๐Ÿ”น No Automated Profiling for Significant Decisions: We do not use your data for automated decision-making that produces legal or similarly significant effects (e.g., credit scoring, employment decisions) without your explicit consent and right to human intervention.


7. DATA SHARING & THIRD-PARTY DISCLOSURES

We share your data only in the following circumstances, with appropriate safeguards:

7.1 Service Providers (Data Processors)

We engage trusted third parties to perform specific functions under strict data processing agreements (DPAs) compliant with DPDP Act and GDPR:

CategoryExamplesData SharedSafeguards
Payment ProcessingRazorpay, Stripe, PayPalTokenized payment references, transaction amount, billing emailPCI-DSS compliance; no raw card data stored by us
Cloud InfrastructureAWS, Google Cloud, AzureEncrypted user data, logs, backupsISO 27001 certification; data residency options
Email & CommunicationSendGrid, Mailgun, AWS SESEmail address, name, transactional contentEncryption in transit; opt-out mechanisms
Analytics & UXGoogle Analytics (GA4), Hotjar (opt-in), MixpanelAggregated behavior, device info, session recordings (anonymized)IP anonymization; data retention limits; DPA in place
Courier & LogisticsDelhivery, Blue Dart, India PostName, shipping address, phone, order detailsPurpose-limited use; no marketing use
Customer SupportZendesk, FreshdeskSupport tickets, chat logs, account info (for context)Access controls; audit logs; retention policies
Identity VerificationSignzy, Karza (India); Onfido (global)Name, ID number, document images (encrypted)Minimal data collection; secure deletion post-verification

7.2 Legal & Regulatory Disclosures

We may disclose personal data if required by law or to:

We challenge overly broad requests and notify you (unless legally prohibited) when permissible.

7.3 Business Transfers

In the event of a merger, acquisition, restructuring, or sale of assets:

7.4 With Your Explicit Consent

We may share data for purposes not listed above only with your prior, specific, and informed consent, which you may withdraw at any time.

๐Ÿšซ We do NOT:


8. INTERNATIONAL DATA TRANSFERS

8.1 Primary Data Location

8.2 Transfers Outside India (DPDP Act Compliance)

Where personal data is transferred outside India: โœ… We ensure the recipient country has been notified by the Indian Government as having adequate data protection standards, OR
โœ… We implement prescribed safeguards, such as:

8.3 Transfers Outside EU/EEA (GDPR Compliance)

For EU/EEA users, transfers outside the European Economic Area rely on: โœ… Adequacy Decisions: Transfers to countries deemed adequate by the European Commission
โœ… Standard Contractual Clauses (SCCs): EU-approved clauses with supplementary measures
โœ… Derogations: Explicit consent, contract necessity, or important reasons of public interest (used sparingly)

8.4 Your Right to Know

You may request details about international transfers involving your data by contacting support@olelectronics.com.


9. DATA RETENTION & DELETION

We retain personal data only as long as necessary for the purposes outlined in this Policy, or as required by law.

9.1 Retention Periods by Data Category

Data CategoryRetention PeriodLegal Basis / Reason
Account Identity & ContactDuration of Account + 3 years after last activityContractual necessity; legitimate interest in re-engagement
Transaction & Order Records8 years from transaction dateIndian GST/Income Tax Act requirements
Payment References (Tokenized)13 months (PCI-DSS requirement)Payment card industry security standards
LMS Progress & CertificatesLifetime of course access + 2 yearsContractual obligation; user request for records
Forum/Blog ContributionsIndefinitely (unless deleted by user or moderator)Legitimate interest in community archive; user control
Support Tickets3 years from resolutionLegitimate interest in service improvement; legal defense
Marketing Consent RecordsUntil consent withdrawn + 1 yearProof of consent per DPDP Act/GDPR accountability
Security Logs (IP, login attempts)12 monthsLegitimate interest in fraud prevention and security
Analytics (Aggregated/Anonymized)Indefinitely (non-personal)Legitimate interest in service improvement

9.2 Deletion & Erasure Procedures

You may request deletion of your personal data at any time:

  1. Self-Service: Delete your Account via Account Settings โ†’ “Delete Account” (triggers automated erasure workflow)
  2. Manual Request: Email support@olelectronics.com with subject “Data Erasure Request” and verification details
  3. Verification: We will confirm your identity before processing to prevent unauthorized deletion

9.3 Exceptions to Deletion

We may retain certain data despite a deletion request where:

๐Ÿ”น Right to Be Forgotten (GDPR): EU/EEA users may request erasure under Article 17. We assess requests case-by-case, balancing your rights against our legitimate interests or legal obligations.


10. YOUR RIGHTS: DPDP ACT & GDPR

You have enforceable rights regarding your personal data. Below is a consolidated overview:

10.1 Rights Under DPDP Act, 2023 (India)

RightDescriptionHow to Exercise
Right to AccessObtain confirmation whether we process your data and access to such dataEmail support@olelectronics.com with “Access Request” + ID verification
Right to CorrectionRequest correction of inaccurate or incomplete personal dataUse Account Settings โ†’ “Edit Profile” or email correction request
Right to ErasureRequest deletion of personal data when no longer necessary or consent withdrawnAccount deletion feature or email “Erasure Request”
Right to Grievance RedressalLodge a complaint with our Grievance Officer regarding data processingContact support@olelectronics.com; escalation to Data Protection Board of India if unresolved
Right to NominateNominate another individual to exercise your rights in case of death or incapacitySubmit written nomination to support@olelectronics.com with verification

10.2 Rights Under GDPR (EU/EEA Users)

RightDescriptionHow to Exercise
Right of Access (Art. 15)Receive a copy of your personal data and processing detailsSubmit “GDPR Access Request” to support@olelectronics.com
Right to Rectification (Art. 16)Have inaccurate data corrected without undue delayAccount Settings or email correction request
Right to Erasure / “Right to Be Forgotten” (Art. 17)Request deletion under specific conditions (e.g., consent withdrawn, data no longer necessary)Email “GDPR Erasure Request” with justification
Right to Restriction (Art. 18)Limit processing while accuracy is verified or objection is assessedEmail “Restriction Request” specifying grounds
Right to Data Portability (Art. 20)Receive your data in a structured, machine-readable format and transmit to another controllerRequest “Data Portability Export” in JSON/CSV format
Right to Object (Art. 21)Object to processing based on legitimate interests or direct marketingUse unsubscribe links or email “Objection Request”
Rights re: Automated Decision-Making (Art. 22)Not be subject to decisions based solely on automated processing producing legal/significant effectsContact support@olelectronics.com to request human review

10.3 Exercising Your Rights: Process & Timeline

  1. Submit Request: Email support@olelectronics.com with:
    • Subject line: “[Right Type] Request” (e.g., “Access Request”, “Erasure Request”)
    • Full name, registered email, and Account ID (if applicable)
    • Specific details of your request
    • Copy of government-issued ID for verification (secure upload link provided upon request)
  2. Verification: We will verify your identity within 3 Business Days to prevent unauthorized access.
  3. Response Timeline:
    • DPDP Act: We respond within 15 days (extendable by 15 days with notice)
    • GDPR: We respond within 30 days (extendable by 60 days for complex requests)
  4. No Fee: Requests are free unless manifestly unfounded or excessive (we will justify any fee).
  5. Appeals: If unsatisfied with our response:
    • India: Escalate to the Data Protection Board of India (dpb.gov.in)
    • EU/EEA: Lodge a complaint with your national Data Protection Authority (list: edpb.europa.eu)

11. CONSENT MANAGEMENT & WITHDRAWAL

11.1 How We Obtain Consent

11.2 Withdrawing Consent

You may withdraw consent at any time, free of charge:

โš ๏ธ Effect of Withdrawal:

11.3 Consent Records

We maintain auditable records of:


12. COOKIES, TRACKING & ANALYTICS

12.1 What Are Cookies & Similar Technologies?

Cookies, pixels, local storage, and SDKs help us:

12.2 Cookie Categories & Consent

CategoryPurposeDurationConsent Required?
Strictly NecessaryEnable core functions: login, cart, security, load balancingSession to 1 yearโŒ No (legitimate interest)
Preference / FunctionalRemember language, currency, accessibility settings1โ€“2 yearsโŒ No (contractual necessity)
Analytics / PerformanceMeasure traffic, user behavior, feature usage (aggregated)13โ€“26 monthsโœ… Yes (DPDP/GDPR)
Marketing / TargetingPersonalize ads, retargeting, campaign attribution13โ€“24 monthsโœ… Yes (explicit opt-in)
Social Media PluginsEnable sharing, embedded content (e.g., YouTube, Twitter)Varies by providerโœ… Yes (when activated)

12.3 Managing Cookies

12.4 Analytics & Privacy by Design

๐Ÿ”น Third-Party Cookies: We minimize reliance on third-party cookies. Where used (e.g., payment fraud detection), processors are contractually bound to DPDP/GDPR-compliant practices.


13. CHILDREN’S PRIVACY

13.1 Age Restrictions

13.2 Parental Consent Process (For Users 13โ€“17)

If a minor (13โ€“17) wishes to use our Services:

  1. Parent/guardian registers the Account and provides consent via:
    • Signed consent form (uploaded securely), OR
    • Verified email confirmation + government ID match
  2. Parent receives dashboard access to monitor activity, manage preferences, and request data deletion
  3. Minor’s data is flagged in our systems for enhanced protection and limited processing

13.3 Under 13: Zero Tolerance

13.4 Educational Content Safeguards


14. SECURITY MEASURES

We implement technical and organizational measures to protect your data against unauthorized access, alteration, disclosure, or destruction:

14.1 Technical Safeguards

โœ… Encryption: Data encrypted in transit (TLS 1.3+) and at rest (AES-256)
โœ… Access Controls: Role-based access, multi-factor authentication (MFA) for staff, principle of least privilege
โœ… Secure Development: OWASP-aligned practices, regular penetration testing, code reviews
โœ… Monitoring & Logging: Real-time threat detection, audit trails for data access, SIEM integration
โœ… Backup & Recovery: Encrypted, geographically redundant backups; tested disaster recovery plans

14.2 Organizational Safeguards

โœ… Staff Training: Mandatory data protection training for all employees and contractors
โœ… Data Processing Agreements (DPAs): Legally binding contracts with all processors requiring DPDP/GDPR compliance
โœ… Privacy by Design: Data protection impact assessments (DPIAs) for new features involving high-risk processing
โœ… Incident Response: Dedicated team and playbook for data breach containment, investigation, and notification

14.3 Limitations

โš ๏ธ No method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security. You are responsible for safeguarding your password and device.


15. DATA BREACH NOTIFICATION

15.1 Our Commitment

In the event of a personal data breach likely to result in risk to your rights and freedoms:

โœ… DPDP Act: We will notify the Data Protection Board of India and affected Data Principals within 72 hours of becoming aware, as required.
โœ… GDPR: We will notify the relevant supervisory authority within 72 hours and affected data subjects without undue delay if high risk exists.

15.2 What We Include in Notifications

15.3 Your Role

If you suspect unauthorized access to your Account:

  1. Immediately change your password and enable MFA
  2. Review Account activity for suspicious actions
  3. Contact support@olelectronics.com with details
  4. Monitor financial statements if payment data was involved

16. AUTOMATED DECISION-MAKING & PROFILING

16.1 Our Approach

We use limited automated processing to enhance your experience:

16.2 Your Rights

You have the right to: โœ… Opt Out: Disable personalized recommendations in Account โ†’ Preferences
โœ… Request Human Intervention: For decisions significantly affecting you (e.g., account suspension), email support@olelectronics.com
โœ… Understand Logic: Request a plain-language explanation of automated decision criteria

๐Ÿšซ We do NOT use:


17. GRIEVANCE REDRESSAL & CONTACT

17.1 Primary Contacts

PurposeContactResponse Time
General Privacy Inquiriessupport@olelectronics.com3 Business Days
Exercising Data Rightssupport@olelectronics.com (subject: “[Right] Request”)15 Days (DPDP) / 30 Days (GDPR)
Grievance Officer (DPDP Act)support@olelectronics.com15 Days
Data Protection Officer (GDPR)support@olelectronics.com30 Days
Security Incidentssupport@olelectronics.comImmediate acknowledgment
Support & Account Helpsupport@olelectronics.com1 Business Day

17.2 Escalation Path (If Unresolved)

  1. Internal Review: Contact Grievance Officer/DPO with reference to initial request
  2. Regulatory Complaint:
  3. Judicial Remedy: You retain the right to seek legal remedy in competent courts.

17.3 Physical Address for Notices

Olatus Systems Private Limited
Attn: Grievance Officer / Data Protection Officer
House No: 346, 1st Floor, Police Station, Zoo-Narengi Rd, opp. Barista Cafe and Geetanagar, Ambikagirinagar
Guwahati, Assam, 781024, India

For secure document submission, we provide an encrypted upload portal upon request.


18. CHANGES TO THIS POLICY

18.1 Updates & Notification

18.2 Your Continued Use

18.3 Historical Versions

Archived versions of this Policy are available upon request at support@olelectronics.com.


19. APPENDIX: DATA PROCESSING SUMMARY

19.1 Quick Reference: Data Flows by Service

ServiceData CollectedPrimary PurposeLegal BasisRetention
eCommerceName, address, payment token, order historyFulfill orders, prevent fraudContract, Legal obligation8 years (tax)
Digital ProductsEmail, download logs, license keysDeliver access, prevent piracyContract, ConsentDuration of license + 2 years
LMS / CoursesProgress, assessments, certificates, forum postsDeliver education, issue credentialsContract, ConsentLifetime access + 2 years
Forum / BlogUsername, posts, comments, reportsEnable community, moderate contentConsent, Legitimate interestIndefinite (user-deletable)
MembershipsSubscription status, access logs, billingManage recurring access, personalizeContract, ConsentDuration of membership + 3 years
Mobile AppDevice ID, crash logs, location (opt-in)Ensure functionality, improve UXConsent, Legitimate interest12โ€“24 months
MarketingEmail, preferences, engagement metricsSend relevant promotions (opt-in only)Explicit ConsentUntil withdrawal + 1 year

19.2 Third-Party Processor Register (Excerpt)

Full register available at [privacy.olelectronics.com/processors]

ProcessorRoleLocationSafeguards
RazorpayPayment processingIndiaPCI-DSS, DPDP-compliant DPA
AWSCloud hostingIndia (Mumbai)ISO 27001, SOC 2, DPA
Google Analytics (GA4)Web analyticsGlobal (EU-US DPF certified)IP anonymization, SCCs, 14-month retention
DelhiveryLogisticsIndiaPurpose-limited DPA, data minimization
SendGridTransactional emailUSA (EU-US DPF)Encryption, DPA, opt-out enforcement