Privacy & DataProtection Policy.
How Oryntic Labs Private Limited collects, safeguards, and respects your personal data, proprietary source code, and commercial specifications across our engineering services and software platforms.
Zero Data Sale
Never monetized or traded
ISO 27001 Controls
Enterprise security hygiene
AI Model Isolation
Code never trains public LLMs
Mutual NDAs
Signed before first call
Introduction & Corporate Identity
Entity details, commitment to privacy, and fundamental data principles.
Welcome to Oryntic Labs Private Limited ("Oryntic Labs", "Company", "we", "us", or "our"). We are an incorporated technology enterprise in India under the Companies Act, 2013 (CIN: U62011MP2026PTC085165; GSTIN: 23AAFCO2495P1ZX), operating engineering centers in Gurugram, Haryana and Rewa, Madhya Pradesh.
At Oryntic Labs, transparency, confidentiality, and data protection are foundational to how we design, build, and deploy software. Whether you are exploring our marketing website (www.orynticlabs.com), engaging our software engineering and staff augmentation practices, or utilizing our proprietary platforms—including OryAI, OryCMS, and PerformX—we treat your personal and commercial data with strict technical and organizational safeguards.
Scope of this Privacy Policy
Who this policy covers across our website, products, and services.
This Privacy Policy applies to all interactions with Oryntic Labs, covering:
- Visitors and users of our public website and subdomains
- Prospective clients submitting enquiries, scoping requests, or RFPs
- Clients contracting our custom software engineering or advisory services
- Subscribers and users of proprietary platforms: OryAI, OryCMS, and PerformX
- Professionals hired via our Staff Augmentation practice
- Job candidates, contractors, and business partners communicating with us
Where a formal Master Services Agreement (MSA), Statement of Work (SOW), Non-Disclosure Agreement (NDA), or custom Data Processing Addendum (DPA) is executed between Oryntic Labs and a client, the terms of that signed contract shall prevail in the event of any operational conflict with this general policy.
Information We Collect
Directly provided details, project documentation, and automated technical data.
A. Information You Provide Voluntarily
When communicating with us via our contact forms, scheduling consultations, or entering into commercial engagements, you may submit:
- Contact Details: Full name, professional work email, phone / WhatsApp number, company name, job title, and geographic location.
- Project Briefs & Documentation: Software architecture specifications, technical requirements, uploaded RFP files, decks, wireframes, and business goals.
- NDA & Contractual Records: Signatory names, business addresses, authorized corporate representatives, and confidentiality terms.
- Billing & Commercial Information: Corporate billing address, GSTIN / VAT numbers, invoicing contacts, purchase orders, and payment records. We do not store raw credit/debit card numbers; payments are processed securely through certified gateway partners.
B. Automatically Collected Technical Data
When browsing our website or interacting with our web platforms, standard technical diagnostic data is logged automatically:
- Device & Network Data: Internet Protocol (IP) address, browser family and version, operating system, screen resolution, and hardware architecture.
- Usage & Navigation Metrics: Referral URLs, pages visited, time spent per section, button interactions, diagnostic error logs, and session durations.
- Security & Authentication Tokens: Cryptographic session tokens, CSRF validation cookies, and verification flags to safeguard against unauthorized requests.
How We Use Your Information
Operational purposes, contract fulfillment, system reliability, and communication.
We process your personal and project information strictly for transparent, lawful purposes:
Consultation & Scoping
Reviewing your project brief, understanding requirements, and preparing scoped technical roadmaps or architectural proposals.
Confidentiality & NDAs
Executing bilateral Non-Disclosure Agreements before discussing proprietary product logic or proprietary datasets.
Software Delivery
Building, testing, deploying, and maintaining custom web platforms, mobile applications, data pipelines, and cloud systems.
Platform Access
Provisioning and administering tenant accounts on OryAI, OryCMS, and PerformX, including role-based workspace permissions.
Billing & Compliance
Issuing formal invoices, processing milestone payments, and complying with statutory tax, GST, and corporate accounting laws.
Security & Fraud Defense
Monitoring server health, preventing distributed denial-of-service (DDoS) attempts, and safeguarding intellectual property.
Client Intellectual Property & AI Model Isolation
Guarantees that your source code, data, and prompts never train public AI models.
Our AI Isolation Guarantee
For all client projects and users of our OryAI agentic ecosystem, we adhere to strict architectural isolation:
- No Public LLM Training: Client proprietary source code, private database schemas, user prompts, and knowledge base documents are never used to train, retrain, or fine-tune public foundational models (such as commercial OpenAI, Anthropic, or open-source community weights).
- Client Ownership of IP: All code, algorithms, custom-trained weights, models, and digital assets developed under client work orders remain the 100% exclusive intellectual property of the client upon settlement of contractual dues.
- Private Vector & RAG Silos: Vector embeddings, indexed knowledge bases, and retrieval-augmented generation (RAG) stores are logically or physically isolated per client environment with granular access control tokens.
Legal Bases for Processing (DPDP Act & GDPR)
Statutory compliance under India's DPDP Act 2023 and international standards.
In accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India and global regulations such as the General Data Protection Regulation (GDPR), we process personal data under one or more recognized legal grounds:
1. Consent
When you voluntarily submit a message, tick our NDA request box, or opt in to receive WhatsApp/SMS status updates. You can withdraw your consent at any time.
2. Performance of Contract
Where processing is required to execute a service proposal, fulfill contract milestones, deploy software, or support an active platform license.
3. Statutory Legal Obligations
Where retention or reporting is mandated by Indian laws, including the Companies Act, Income Tax Act, Goods and Services Tax (GST) laws, and cybersecurity directives.
4. Legitimate Interests
To defend our infrastructure from cyber threats, secure our systems against unauthorized access, optimize performance, and manage business operations responsibly.
Data Sharing & Third-Party Disclosures
Vetted infrastructure partners, strict confidentiality, and zero data brokerage.
We do not sell, trade, or broadcast personal information. Third-party disclosures occur solely in strictly controlled scenarios:
- Cloud Infrastructure & Tooling Providers: We utilize Tier-1 cloud providers (such as Amazon Web Services, Google Cloud Platform, and Microsoft Azure) to host platform infrastructure, databases, and continuous deployment environments. All vendors are subject to data protection agreements and ISO/SOC-2 certifications.
- Communication & Transactional Services: Secure transactional email systems, messaging APIs (e.g., Twilio/WhatsApp Business API for client communication), and certified payment gateways bound by strict non-disclosure obligations.
- Statutory & Law Enforcement Requests: We disclose information only if strictly compelled by a lawful order from a court of competent jurisdiction or government authority having direct legal remit under applicable Indian law.
Data Security & ISO 27001 Safeguards
End-to-end encryption, role-based access, and continuous vulnerability monitoring.
We employ enterprise-grade technical and organizational measures aligned with ISO/IEC 27001 standards to protect data against unauthorized disclosure, loss, alteration, or compromise:
Encryption in Transit & at Rest
Transport Layer Security (TLS 1.3) across all endpoints and AES-256 bit encryption for databases, persistent disks, and archival storage.
Principle of Least Privilege
Internal access to client source code and databases is restricted strictly to assigned engineers via Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA).
Automated Backups & Redundancy
Daily snapshots, geo-redundant storage with point-in-time recovery capabilities, and encrypted off-site archives.
Continuous Audits & CI/CD Checks
Automated dependency security auditing, static code analysis (SAST), vulnerability patching, and strict Git repository protections.
Data Retention & Secure Deletion
Clear retention timelines, project archiving, and contractual erasure.
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy or required by contractual, legal, or accounting mandates:
- Enquiry & Lead Records: Retained for 24 months from last interaction to provide context if discussions resume, unless deletion is requested earlier.
- Client Project Code & Databases: Maintained during active engineering and warranty periods. Following handover, staging databases are decommissioned per project agreement.
- Statutory Invoices & Corporate Records: Retained for a minimum of 7 to 8 years in compliance with Section 128 of the Indian Companies Act, 2013 and Goods & Services Tax rules.
When retention periods expire, data is securely destroyed via cryptographic erasure or non-recoverable electronic file shredding.
Your Statutory Privacy Rights
Access, correction, erasure, data portability, and withdrawal of consent.
Depending on your jurisdiction (including under India's DPDP Act and GDPR), you have specific statutory rights concerning your personal information:
| Right | What it Means |
|---|---|
| Right to Access | Request a copy of the personal data we hold about you and details on how it is processed. |
| Right to Rectification | Request correction of inaccurate, incomplete, or outdated information. |
| Right to Erasure | Request deletion of your personal records (Right to be Forgotten) where statutory retention is not mandated. |
| Right to Data Portability | Obtain your provided data in a structured, commonly used, machine-readable format (JSON/CSV). |
| Right to Withdraw Consent | Revoke consent for optional updates or communications at any time without penalty. |
| Right to Grievance Redressal | Lodge a formal enquiry or complaint with our designated Data Grievance Officer. |
To exercise any of these rights, email us directly at support@orynticlabs.com. We acknowledge all requests within 48 hours and process them within 30 days.
International Data Transfers
Cross-border engineering operations with Standard Contractual Clauses.
Oryntic Labs delivers engineering solutions to clients globally across North America, Europe, the United Kingdom, the Middle East, and Asia-Pacific. While our core engineering offices are in India, data transfers across national borders are protected by:
- Execution of Standard Contractual Clauses (SCCs) approved by international privacy bodies.
- Comprehensive Data Processing Agreements (DPAs) stipulating technical confidentiality.
- Data residency options: Enterprise clients may specify regional data storage on AWS (e.g., us-east-1, eu-central-1, ap-south-1) to satisfy local regulatory mandates.
Children's Privacy Protection
Strict enterprise and adult focus (18+).
Our website, services, and proprietary software products are designed strictly for businesses, technology practitioners, and individuals who are at least 18 years of age. We do not knowingly solicit or collect personal information from minors. If you believe a minor has submitted personal information through our platform, contact us immediately at support@orynticlabs.com, and we will promptly purge the data from our repositories.
Grievance Officer & Official Inquiries
Designated point of contact for regulatory, legal, and privacy matters.
In compliance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, the details of our designated Grievance Officer and corporate legal team are provided below:
Legal & Grievance Officer
Registered Office
Oryntic Labs Private Limited
Ward 14, Main Stand, Mangawan, Rewa, Madhya Pradesh 486111, India
Corporate Hub: 6th Venture X, Landmark, Sector 67, Gurugram, Haryana 122101, India
Updates to this Privacy Policy
Notification procedure for future policy amendments.
We may amend this Privacy Policy periodically to reflect emerging engineering capabilities, new product releases, or legislative updates under Indian and international privacy statutes. When changes occur, we update the "Last Revised" timestamp at the top of this document. For significant changes, we will provide additional notice through banner notifications on our platforms or direct email communications to active account holders.
Last revised: September 2026 · Version 2.4 · Oryntic Labs Private Limited.
Have questions about data handling or mutual NDAs?
We sign Non-Disclosure Agreements before your kickoff call, ensuring total protection for your architecture, business concept, and data pipelines.






