Privacy Policy

This Privacy Policy explains how Lalinx Pvt Ltd ("Lalinx", "we", "us"), registered office at C/o Jitender Yadave, Office No. 1, VPO Sarhoul, Sector 18, Palam Road, Gurgaon, Haryana 122015, India, collects and processes personal data in connection with the Opsore ITSM platform (the "Service") and the website opsore.com.

It is written to meet India's Digital Personal Data Protection Act, 2023 (DPDP Act) and, for customers and users in the EU/UK, the GDPR / UK GDPR.

Contact for all privacy matters: privacy@opsore.com (general support: support@opsore.com)

1. The Two Roles We Play

RoleWhenWhat Governs It
Data Fiduciary / ControllerData about our own website visitors, prospects, and customer account contacts (billing, admin)This Privacy Policy
Data ProcessorPersonal data inside Customer Data — tickets, requester details, asset records, user directories submitted by our customersOur Data Processing Agreement and the customer's instructions

If your personal data appears inside a ticket or record in an Opsore workspace operated by your employer or service provider, that organization controls the data — please direct requests to them; we will assist them in responding.

2. Data We Collect as Controller

  • Account & contact data: name, work email, phone (optional), company name, role — when you sign up, request a demo, or contact support.
  • Billing data: company billing address, GSTIN (if provided), transaction references. We do not store card numbers; payments are handled by our payment processor, Razorpay.
  • Usage & device data: IP address, browser type, pages visited, feature-usage events, log timestamps — collected automatically to secure and improve the Service.
  • Cookies: essential cookies for login/session only. If we introduce analytics cookies in future, they will be set only with your consent where required, and this policy will be updated first. We do not use advertising cookies.
  • Support communications: emails and messages you send to support@opsore.com.

We do not knowingly collect data from children under 18, and we do not process data for behavioral advertising.

3. Purposes and Legal Bases

PurposeLegal Basis (GDPR) / Ground (DPDP)
Providing and administering the ServiceContract performance / consent given at signup
Billing and accountingContract; legal obligation (tax law)
Security, fraud and abuse preventionLegitimate interest / legitimate use
Product improvement via aggregated analyticsLegitimate interest; consent for optional cookies
Service announcements and support repliesContract
Marketing emails to prospectsConsent; opt-out honored in every message
Compliance with law and lawful requestsLegal obligation

4. Sharing

We share personal data only with:

  • Sub-processors / service providers that host and operate the Service (see current list in DPA Annex 2) — hosting with Utho Cloud (utho.com), India region, email delivery via Zoho Mail (Zoho Corporation, India), payment processing via Razorpay (India). Each is bound by a data protection contract.
  • Professional advisers (accountants, lawyers) under confidentiality.
  • Authorities where required by applicable law, court order, or to protect rights and safety.
  • A successor entity in a merger or acquisition, with notice to you.

We do not sell personal data.

Our website may contain links to third-party sites; their privacy practices are their own, and this policy does not cover them.

5. International Transfers

Our primary hosting region is India — Utho Cloud, Delhi NCR data center. Customer Data is stored and processed in India by default. Where data is transferred outside your country (including outside India or the EEA), we use lawful transfer mechanisms — for EEA/UK data, Standard Contractual Clauses with sub-processors.

6. Retention

  • Account and billing records: for the life of the account plus the period required by Indian tax/company law (generally 8 years for financial records).
  • Support tickets with us: 24 months after closure.
  • Server and security logs: 180 days (rolling), as required by the CERT-In Directions of 28 April 2022; logs are stored within India.
  • Customer Data (processor role): per the DPA — exportable for 30 days after termination, deleted within 60 days thereafter.

7. Security

We protect personal data with encryption in transit (TLS 1.2+) and at rest (disk-level and database-level encryption), role-based access control with MFA for administrative access, logical separation of customer workspaces, and regular backups. See our security documentation for details.

8. Your Rights

Under the DPDP Act (India): access a summary of your personal data and processing; correction and erasure; grievance redressal; nominate a person to exercise rights on your behalf. You may also complain to the Data Protection Board of India.

Under GDPR (EEA/UK): access, rectification, erasure, restriction, portability, objection, and withdrawal of consent; complaint to your local supervisory authority.

To exercise rights, email privacy@opsore.com with the subject "Privacy request". We respond within 30 days (or sooner where law requires). We may verify your identity first.

Grievance Officer (DPDP Act & IT Act, 2000 / IT Rules, 2021):

Name: Amit Kumar

Address: Lalinx Pvt Ltd, C/o Jitender Yadave, Office No. 1, VPO Sarhoul, Sector 18, Palam Road, Gurgaon, Haryana 122015, India

Email: grievance@opsore.com (or support@opsore.com)

Grievances are acknowledged within 24 hours and resolved within 15 days of receipt.

9. Breach Notification

If a personal data breach affects you, we will notify affected individuals and the Data Protection Board of India as required by the DPDP Act, and report covered cyber incidents to CERT-In within the mandated timeline. Where we act as processor, we notify the affected customer without undue delay per the DPA.

10. Changes

We may update this policy from time to time. Material changes will be announced by email or in-app notice at least 15 days before they take effect. The "Effective date" above always reflects the current version.