Privacy Policy
Website: www.orderezee.com | Effective Date: September 05, 2026 | Last Updated: September 05, 2026OrderEzee Technologies Private Limited ("OrderEzee", "Company", "we", "us" or "our") respects the privacy of individuals whose personal data is processed through Ozie. This Privacy Policy ("Policy") explains how OrderEzee collects, receives, accesses, uses, processes, stores, shares, transfers, retains and protects personal data when individuals or businesses access or use Ozie and its associated applications, websites, dashboards, APIs, integrations, communication tools, artificial-intelligence-enabled services and related functionality (collectively, the "Services").
1. Introduction
Ozie ("Ozie", "Platform" or "App") is a business-to-business software-as-a-service ("B2B SaaS") platform owned and operated by OrderEzee Technologies Private Limited.
Ozie is primarily intended for businesses, including manufacturers, brands, distributors, wholesalers, retailers, dealers, sales teams and other commercial organisations, to digitise and automate business processes such as ordering, invoicing, inventory management, sales-force management, customer and channel communication, analytics and other commercial workflows.
This Privacy Policy should be read together with the Ozie Terms & Conditions and any applicable customer agreement, consent notice or other policy made available by OrderEzee. Where consent is required under applicable law, appropriate consent will be obtained before the relevant personal data is processed.
2. Scope of This Privacy Policy
This Privacy Policy applies to personal data processed through or in connection with:
- the Ozie mobile application;
- Ozie web applications and dashboards;
- www.orderezee.com;
- manufacturer and brand dashboards;
- distributor and wholesaler interfaces;
- retailer interfaces, including ORDERBOX;
- sales-force and field-force management modules;
- order, inventory and invoicing modules;
- customer-support systems;
- WhatsApp Business integrations;
- Meta and Facebook integrations;
- SMS, email and other communication integrations;
- payment-gateway and banking integrations;
- accounting, ERP and third-party software integrations;
- APIs and webhooks;
- AI-enabled functionality, including conversational and voice assistants;
- demonstrations, registrations and enquiries;
- analytics and reporting services; and
- any other OrderEzee product or service that refers to this Privacy Policy.
Third-party products or services connected with Ozie may be governed by their own terms and privacy policies.
3. Our Role in Processing Personal Data
Ozie operates as a B2B SaaS platform and may process personal data in different capacities depending upon the circumstances.
3.1 Data Processed for OrderEzee's Own Purposes
Where OrderEzee determines why and how personal data is processed — for example, account registration, billing, platform security, customer support, compliance and administration — OrderEzee acts in accordance with its obligations under applicable data-protection law.
3.2 Data Processed on Behalf of Business Customers
Business Customers may upload, collect, generate or otherwise process information relating to their retailers, distributors, wholesalers, dealers, customers, suppliers, employees, sales representatives, agents, or other business contacts through Ozie.
For such information, the relevant Business Customer generally determines the purpose for which the information is collected and used, and OrderEzee processes the information for the purpose of providing the Services and in accordance with the Business Customer's lawful and authorised instructions. The Business Customer is responsible for ensuring that it has an appropriate lawful basis, notice and/or consent, wherever required, to collect and process such personal data and to provide it to Ozie.
4. Information We May Collect or Process
Depending upon the Services used, we may collect or process the following categories of information:
4.1 Identity and Contact Information
This may include name, mobile number, email address, business address, organisation or company name, designation, profile information, authorised representative details, and information necessary to identify or communicate with a user.
4.2 Account and Authentication Information
This may include user ID, username, organisation ID, retailer, distributor or manufacturer identifier, account permissions and roles, authentication information, account settings, login information, and security and access records. Passwords and authentication credentials are protected using appropriate technical security measures and are not stored as readable plain-text passwords.
4.3 Business and Commercial Information
Depending upon functionality enabled by a Business Customer, Ozie may process GST and business-registration information, product catalogues, SKUs, product descriptions, inventory information, prices, schemes and offers, sales territories, customer and supplier records, retailer and distributor information, sales-force information, orders, invoices, returns and refunds, delivery information, digital ledger information, commercial records, sales information, and other business information uploaded to or generated through Ozie. Business Customers remain responsible for the accuracy and lawfulness of information they upload to the Platform.
4.4 Transaction Information
We may process order history, invoice information, transaction amounts, payment status, payment references, refunds, reconciliation information, and credit or financing information where an enabled service requires it. Payment processing is undertaken by authorised third-party payment gateways, banks or financial institutions. Ozie does not ordinarily store complete payment-card numbers, CVVs, UPI PINs, internet-banking passwords or equivalent payment-authentication credentials.
4.5 Sales-Force and Field Activity Information
Where enabled by a Business Customer, Ozie may process information relating to authorised sales or field personnel, including name and employee information, attendance and activity information, assigned territory, retailer/customer visits, order activity, field reports, photographs uploaded through the App, timestamps, travel or route information, and device location information where location functionality is enabled. Location information is collected only where the relevant feature requires it and subject to applicable device permissions and legal requirements. Business Customers using employee-monitoring or location functionality are responsible for providing appropriate notices and obtaining required permissions or consent from their personnel.
5. Device Permissions
Certain Ozie features may request access to device functionality. Depending upon the functionality used, this may include access to:
- Camera: For uploading invoices, documents, field-visit photographs, product images, KYC documents or other authorised business records.
- Photos / Media / Files: For uploading or downloading authorised business documents and media.
- Location: For field-force, visit verification, route, territory, attendance, delivery or other location-enabled functionality.
- Microphone: Where voice input, voice-assistant or voice-communication functionality is enabled.
- Notifications: For order alerts, transaction updates, business communications, security alerts and other platform notifications.
Permissions may generally be managed through the user's device settings. Disabling a permission may prevent the relevant feature from functioning correctly.
6. Technical and Usage Information
When Ozie is accessed, we may automatically receive or generate technical information such as IP address, device type, operating system, browser type, application version, device or application identifiers, login timestamps, session information, security logs, feature usage, diagnostic information, crash information, and network and performance information. We use this information primarily to operate, secure, troubleshoot and improve the Services.
7. How We Use Personal Data
Subject to applicable law, information processed through Ozie may be used to:
- create and administer accounts;
- authenticate users;
- provide and operate the Services;
- facilitate orders and commercial transactions;
- manage product catalogues and inventory;
- generate or facilitate invoices;
- facilitate returns, refunds and deliveries;
- enable sales-force and field-force functionality;
- provide business analytics and reports;
- enable authorised communications;
- provide customer support;
- process subscriptions and billing;
- integrate authorised third-party services;
- prevent fraud and misuse;
- investigate suspicious activity;
- maintain platform and information security;
- diagnose technical issues;
- improve product performance and functionality;
- maintain audit and transaction records;
- enforce contractual terms;
- comply with applicable laws and lawful governmental requests;
- establish, exercise or defend legal claims; and
- fulfil other purposes disclosed at the time information is collected.
8. WhatsApp Business Communications
Ozie may enable Business Customers to communicate with their customers, retailers, distributors or other authorised recipients through the WhatsApp Business Platform and related Meta technologies. Ozie is a technology-enablement platform and does not grant a Business Customer an independent right to contact an individual through WhatsApp.
8.1 Recipient Consent
Business Customers using WhatsApp functionality through Ozie are responsible for ensuring that recipients have:
- provided the mobile number being used for the communication; and
- provided any opt-in, permission or consent required under applicable law and applicable WhatsApp/Meta policies.
The recipient should understand which business will communicate with them and the nature of communications they have agreed to receive.
8.2 Transactional and Marketing Communications
Where applicable, Ozie may facilitate different categories of WhatsApp communication, including:
- Transactional / Utility Communications: Order confirmations, invoice notifications, payment information, delivery updates, service notifications, and account-related communications.
- Marketing / Promotional Communications: Product promotions, offers, schemes, campaigns, product launches, and promotional announcements.
Where required, appropriate consent or opt-in for marketing communications must be obtained separately or in a manner that clearly informs the recipient that marketing messages will be received. Consent to receive transactional communications should not automatically be treated as unrestricted consent to receive promotional communications.
8.3 WhatsApp Templates
Business-initiated communications may be sent only through message formats or templates permitted or approved by WhatsApp/Meta where such approval is required.
8.4 Opt-Out
Recipients may request that marketing communications stop at any time through mechanisms made available by the sending business, including instructions contained in messages where applicable. Business Customers using Ozie must honour valid opt-out, block and withdrawal requests. OrderEzee may restrict or suspend use of communication functionality where it reasonably believes that the functionality is being used for spam, unsolicited bulk communication, deceptive messaging or other activity contrary to applicable law or platform policies.
9. Meta and Facebook Integrations
Ozie may integrate with services provided by Meta Platforms, Inc. and its affiliates, including Facebook and WhatsApp. Where a Business Customer chooses to connect an authorised Meta account or asset with Ozie, we may receive or process information made available through the applicable Meta APIs and authorised permissions.
Depending upon the functionality authorised, this may include:
- business profile information;
- Facebook Page information;
- Meta Business Account information;
- WhatsApp Business Account information;
- phone-number information;
- account identifiers;
- message-related metadata;
- message delivery/read status;
- authorised business assets;
- API access credentials or tokens; and
- other information made available under the permissions granted by the Business Customer.
OrderEzee will use information obtained through Meta integrations only for authorised functionality, platform operation, security, support and other purposes permitted by applicable law and applicable Meta terms and policies. OrderEzee does not sell personal data obtained through Meta, Facebook or WhatsApp integrations. OrderEzee will not knowingly use data obtained through Meta APIs for purposes materially inconsistent with the purpose for which the applicable access or permission was granted.
Users or Business Customers may disconnect relevant integrations or revoke permissions through the applicable Meta service, where such functionality is available. Revoking access may prevent certain Ozie functionality from continuing to operate.
10. Communications
Ozie may process communications including email, WhatsApp messages, support chats, customer-support tickets, feedback, surveys, complaints, enquiries, and authorised voice communications. Such information may be processed to provide the relevant service, resolve enquiries, maintain service quality, investigate disputes and comply with applicable legal obligations.
11. AI, Automation and Voice-Enabled Services
Ozie may provide artificial-intelligence, machine-learning, conversational AI, automation and voice-enabled functionality, including services such as AI assistants and automated business agents.
Depending upon the feature used, information submitted to these services may be processed by automated systems to interpret user requests, retrieve authorised business information, generate responses, facilitate orders or workflows, provide business insights, automate customer interactions, or perform other functionality requested by the user or Business Customer.
AI-generated responses may occasionally be incomplete, inaccurate or inappropriate for a particular business decision. Users should independently verify material commercial, financial, legal or operational information before relying upon AI-generated output. Where third-party AI or technology service providers are used, information will be shared only to the extent reasonably required to provide the relevant functionality and subject to appropriate contractual, security and privacy safeguards where applicable.
Ozie does not intend AI functionality to make legally significant decisions about individuals without appropriate human involvement where such involvement is required by applicable law.
12. Payment and Financial Services
Ozie may integrate with third-party payment gateways, banks, financial institutions, lending institutions, and other regulated financial-service providers.
Where a payment, credit or financing service is offered through a third party, the applicable third party is responsible for its own regulated service and may separately collect and process personal data under its own privacy policy and terms. OrderEzee does not represent itself as a bank, payment system operator or lender merely because such third-party services are integrated into Ozie.
13. Third-Party Integrations
Ozie may integrate with third-party applications and services such as accounting software (e.g., Tally, BUSY), ERP systems, payment gateways, banking services, messaging platforms, cloud infrastructure, analytics services, customer-support systems, and other authorised business software. When a Business Customer activates an integration, information may be exchanged between Ozie and the selected service as reasonably necessary to provide the requested functionality. Third-party providers are responsible for their own privacy practices. Business Customers should review the privacy policies and terms of third-party services before enabling an integration.
14. Cookies and Similar Technologies
OrderEzee's websites and web applications may use cookies and similar technologies for authentication, security, session management, user preferences, analytics, performance, and service improvement. Where required by applicable law, consent will be obtained for non-essential cookies or similar technologies.
15. Sharing and Disclosure of Information
OrderEzee does not sell personal data. We may disclose information where reasonably necessary to:
- Service Providers and Sub-Processors: Provide cloud hosting, infrastructure, messaging, communications, analytics, customer support, security, payment or other technology services.
- Business Customer Administrators: Allow authorised administrators of a Business Customer to manage users and information associated with their organisation.
- Authorised Integrations: Provide functionality specifically enabled by a Business Customer or user.
- Professional Advisers: Obtain legal, accounting, audit, insurance or professional advice subject to appropriate confidentiality obligations.
- Corporate Transactions: Facilitate a merger, acquisition, restructuring, financing, investment, sale of assets or similar corporate transaction, subject to applicable legal safeguards.
- Legal and Regulatory Requirements: Respond to lawful orders, regulatory requirements, governmental requests or legal proceedings or to protect the rights, property or security of OrderEzee, its customers, users or others.
We endeavour to limit disclosure to information reasonably necessary for the relevant purpose.
16. International Processing and Data Transfers
Certain technology, cloud, communications or integration providers used in providing the Services may process information using infrastructure located outside India. Where personal data is transferred or processed outside India, OrderEzee will take measures reasonably required under applicable law and will comply with restrictions on cross-border processing or transfers applicable from time to time.
17. Information Security
OrderEzee implements reasonable technical and organisational safeguards designed to protect personal data against unauthorised access, disclosure, alteration, misuse, destruction or loss. Depending upon the relevant system and risk, measures may include:
- role-based access controls;
- authentication controls;
- encryption in transit and/or at rest where appropriate;
- network and application-security controls;
- access logging;
- monitoring;
- backups;
- vulnerability management;
- restricted administrative access;
- security reviews; and
- contractual confidentiality obligations.
No internet-based or electronic system can, however, be guaranteed to be completely secure. Users are responsible for maintaining the confidentiality of their login credentials and should immediately notify OrderEzee of suspected unauthorised account access.
18. Personal Data Breaches
Where OrderEzee becomes aware of a personal-data breach affecting information for which it has relevant legal responsibility, OrderEzee will investigate the incident and take reasonable measures to contain, mitigate and remediate it. Where notification is required under applicable law, OrderEzee will notify the relevant authority and/or affected individuals in accordance with the applicable legal requirements and prescribed timelines.
Where OrderEzee processes affected information on behalf of a Business Customer, OrderEzee may notify and reasonably assist that Business Customer in addressing the incident.
19. Data Retention
Personal data is retained only for as long as reasonably necessary for the purposes for which it was processed, including:
- provision of Services;
- contractual obligations;
- transaction records;
- accounting and taxation requirements;
- dispute resolution;
- fraud prevention;
- security;
- regulatory obligations; and
- legal claims.
Retention periods may vary according to the nature of the information and applicable legal requirements. Information may be deleted, anonymised or securely archived when it is no longer required, subject to applicable legal, contractual, backup and technical requirements.
20. Data Principal / User Rights
Subject to applicable law and the capacity in which OrderEzee processes the relevant information, individuals may have rights relating to their personal data, including the ability to:
- request information about personal-data processing;
- request access where applicable;
- request correction or updating of inaccurate information;
- request completion of incomplete information;
- request deletion or erasure where legally available;
- withdraw consent where processing is based upon consent;
- raise a grievance; and
- exercise other rights available under applicable data-protection law.
Requests may be submitted to: grievances@orderezee.com. Where OrderEzee processes information solely on behalf of a Business Customer, we may refer the request to the relevant Business Customer or reasonably assist that Business Customer in responding. We may request reasonable information to verify the identity and authority of a person making a request.
21. Withdrawal of Consent
Where processing is based upon consent, consent may be withdrawn through the mechanism made available for the relevant Service or by contacting us. Withdrawal will not ordinarily affect processing lawfully undertaken before withdrawal. Certain Services may no longer be available where the information concerned is necessary to provide them.
22. Data Deletion
Users may request deletion of eligible personal data by emailing: grievances@orderezee.com with the subject line: PERSONAL DATA DELETION REQUEST. The request should contain sufficient information to identify the relevant account and information.
OrderEzee will verify and process valid requests subject to applicable law, contractual requirements, transaction and accounting obligations, fraud and security requirements, dispute or legal-claim preservation, backup retention, and other lawful retention requirements. Deletion of information required for an active Business Customer account may affect the availability of Services.
23. Meta / Facebook Data Deletion
A user or Business Customer seeking deletion of information received through an authorised Facebook or Meta integration may:
- remove or revoke the applicable Ozie integration through the relevant Meta/Facebook account settings where available; and/or
- submit a deletion request to grievances@orderezee.com with the subject: META/FACEBOOK DATA DELETION REQUEST.
The request should provide sufficient information for OrderEzee to identify the relevant integration or account. Eligible information will be deleted or de-identified subject to applicable legal, security, fraud-prevention and retention obligations. Further instructions may also be provided through OrderEzee's dedicated Data Deletion page.
24. WhatsApp Opt-Out
Recipients who no longer wish to receive marketing or promotional WhatsApp communications should use the opt-out mechanism provided by the sending business or communicate their request to that business.
Where OrderEzee receives a valid opt-out request relating to communications directly controlled by OrderEzee, we will take reasonable steps to honour it. Business Customers using Ozie's WhatsApp functionality are independently responsible for maintaining and respecting recipient consent and opt-out preferences applicable to their communications.
25. Business Customer Responsibilities
Business Customers using Ozie are responsible for ensuring that personal data uploaded to or processed through Ozie has been collected and used lawfully. Without limiting the foregoing, Business Customers must:
- provide appropriate privacy notices where required;
- obtain valid consent where required;
- maintain evidence of consent where appropriate;
- use personal data only for legitimate and authorised purposes;
- ensure reasonable accuracy of uploaded information;
- restrict platform access to authorised personnel;
- protect account credentials;
- honour applicable data-subject requests;
- respect communication opt-outs;
- comply with WhatsApp/Meta messaging requirements;
- avoid unsolicited bulk messaging or spam;
- comply with applicable marketing and telecommunications laws; and
- refrain from using Ozie to process information unlawfully.
OrderEzee may restrict or suspend access where it reasonably believes the Services are being used in violation of applicable law, this Privacy Policy, applicable platform policies or contractual terms.
26. Prohibited Use of Communication Services
Ozie's communication functionality must not be used to:
- send unsolicited bulk communications;
- spam recipients;
- contact recipients without required permission;
- mislead recipients regarding the identity of the sender;
- impersonate another person or organisation;
- conduct fraudulent or deceptive activities;
- circumvent messaging-platform restrictions;
- artificially manipulate messaging activity;
- engage in unlawful automated activity; or
- send content prohibited under applicable law or applicable third-party platform policies.
Use of automated functionality must remain consistent with applicable WhatsApp, Meta and other third-party platform requirements.
27. Children
Ozie is a B2B business platform and is not designed or intended for use by children. Business Customers should not intentionally upload children's personal data unless the relevant functionality legitimately requires such processing and all requirements under applicable law, including any applicable parental or guardian consent requirements, have been satisfied. If OrderEzee becomes aware that children's personal data has been processed without an appropriate lawful basis, reasonable steps may be taken to delete or otherwise appropriately address such information.
28. Applicable Data-Protection Law
OrderEzee intends to process personal data in accordance with applicable Indian laws, including, as and to the extent applicable and brought into force from time to time:
- the Digital Personal Data Protection Act, 2023 ("DPDP Act");
- the Digital Personal Data Protection Rules, 2025;
- the Information Technology Act, 2000;
- applicable rules and regulations made thereunder; and
- other applicable privacy, cybersecurity, electronic-communications and information-technology requirements.
This Privacy Policy will be interpreted in accordance with applicable law as amended from time to time.
29. Changes to This Privacy Policy
OrderEzee may update this Privacy Policy periodically to reflect changes to Ozie functionality, changes to integrations, changes in technology, legal or regulatory developments, or changes to our privacy and security practices.
The updated version will be made available through Ozie and/or www.orderezee.com with a revised "Last Updated" date. Where a material change requires additional notice or consent under applicable law, OrderEzee will take appropriate steps to provide such notice or obtain such consent.
30. Grievance Redressal
Questions, complaints or grievances relating to privacy or personal-data processing may be submitted to:
Entity: OrderEzee Technologies Private Limited
Email: grievances@orderezee.com
Website: www.orderezee.com
We will endeavour to acknowledge and resolve grievances in accordance with applicable legal requirements. Where a grievance relates primarily to personal data controlled by a Business Customer, OrderEzee may coordinate with or refer the matter to the relevant Business Customer.
31. Contact Us
Platform / Brand: Ozie
Website: www.orderezee.com
Privacy & Grievance Email: grievances@orderezee.com
32. Related Policies
Users may also refer to the following documents available through the OrderEzee website:
- Privacy Policy
- Terms & Conditions
- Data Deletion Policy
- Grievance Redressal Policy
These documents should be read together with this Privacy Policy where applicable.
33. Acknowledgement
By accessing or using Ozie, you acknowledge that this Privacy Policy has been made available to you and describes how personal data may be processed in connection with the Services. Where applicable law requires consent for a particular processing activity, such processing will be based upon the appropriate consent or other lawful basis permitted by applicable law.
Consent Matrix
Annexure AThis matrix details mandatory versus optional consent modules collected during registration, platform operation, and integration execution.
| Activity / Feature | Purpose | Type | Withdrawal Permitted |
|---|---|---|---|
| Account Registration & Auth | Create and maintain business user account | Mandatory | No (requires account deletion) |
| Acceptance of Terms of Use | Contractual formation | Mandatory | No |
| Privacy Policy Acceptance | Processing of personal & business data | Mandatory | No (requires account deletion) |
| Payment & Invoicing Processing | Subscription settlements, invoices & ledgers | Mandatory | No |
| WhatsApp Transactional Updates | Order and delivery confirmations via Meta APIs | Conditional (Customer Opt-in) | Yes |
| WhatsApp Marketing Campaigns | Promotional offers, launches and schemes | Optional | Yes (Opt-out anytime) |
| Field-Force Location & Visits | Route tracking, attendance and visit verification | Consent-based / Operational | Yes (Via Device Settings) |
| Camera & Media Permissions | Upload invoices, KYC & field photographs | Optional | Yes (Via Device Settings) |
| Microphone Access | Voice commands, assistant & voice search | Optional | Yes (Via Device Settings) |
| AI Insights & Assistant | Personalized business forecasting & automation | Optional | Yes |
| Essential Cookies | Security and session functionality | Mandatory | No |
| Analytics Cookies | Performance improvement tracking | Optional | Yes |
Data Retention Schedule
Annexure BSubject to statutory mandates and the DPDP Rules 2025, datasets are retained under the following schedules:
| Category | Retention Baseline Period | Legal / Operational Basis |
|---|---|---|
| User Account Records | Duration of active commercial relationship + 5 years | Limitation Act, 1963 / Contractual claim defense |
| Orders, Invoices & Ledgers | 8 years | Companies Act, 2013 / Income Tax compliance |
| GST & Tax Records | As prescribed by GST statutes (approx. 72 months) | Statutory Taxation compliance |
| Customer Support & Enquiries | 3 years | Quality assurance and dispute resolution |
| Authentication & Access Logs | 2 years | CERT-In Directions / IT Act cybersecurity logs |
| Field-Force Geo-Logs | 12 months (or as configured by Business Customer) | Operational verification & payroll auditing |
| Backup Archives | Up to 180 days (rolling purge) | Disaster recovery & business continuity |
Cookie Notice
Annexure COur platform uses cookies and localized storage mechanisms. Essential cookies (identifying sessions and validating account logins) are strictly required for platform operability. Functional and analytical cookies (such as measuring application performance and dashboard latency) are optional and can be toggled through your browser settings or directly via the account settings panel of Ozie.
Information Security Framework
Annexure DOur technical infrastructure incorporates modern defense-in-depth protocols:
- Cryptographic Controls: Data in transit is protected using TLS 1.3 encryption; stored databases and sensitive commercial attachments are secured using AES-256 standards.
- Access Governance: Granular role-based access controls (RBAC) are enforced alongside mandatory multi-factor authentication (MFA) across all administrative portals.
- Security Assessments: Periodic external vulnerability assessments and penetration testing (VAPT) evaluate platform resiliency against unauthorised access.
- Credential Security: Passwords and API secret keys are securely hashed using modern cryptographic algorithms and are never stored in readable plain-text format.
Data Principal Rights Request Procedure
Annexure ETo exercise rights under the DPDP Act (such as Access, Correction, Erasure, or Grievance Redressal), Data Principals may follow this procedure:
- Step 1 (Submission): Send a formal written email to grievances@orderezee.com specifying the nature of the request.
- Step 2 (Identity Verification): Confirm account ownership via OTP verification or authorised company identity documentation.
- Step 3 (Processing & Response): OrderEzee will evaluate statutory applicability and fulfill the request within the turnaround windows below.
| Request Type | Acknowledgment Window | Resolution Window |
|---|---|---|
| Data Correction / Updating | Within 3 business days | Within 15 business days |
| Consent Withdrawal | Within 3 business days | Within 7 business days |
| Account / Personal Data Deletion | Within 3 business days | Within 30 business days (subject to statutory retention) |
| Meta / Facebook Data Deletion | Within 3 business days | Within 15 business days |
Categories of Personal Data Processed
Annexure FThe following mapping outlines our specific processing categories:
| Data Category | Sample Elements | Processing Purpose | Legal Basis | Classification |
|---|---|---|---|---|
| Identity Data | Name, User ID, Designation | Account creation & operations | Contract / Consent | Confidential |
| Contact Data | Phone, Email, Business Address | Communications & notifications | Contract / Consent | Confidential |
| Commercial & Financial | GSTIN, Invoices, Ledgers, Txn IDs | Order processing, invoicing & tax compliance | Contract / Legal Obligation | Restricted |
| Sales-Force & Geo-Data | GPS Location, Route, Visit logs | Field-force management & attendance | Consent / Legitimate Interest | Confidential |
| Integration Metadata | Meta Page IDs, WhatsApp tokens | Social & omnichannel messaging | Consent / Integration Auth | Restricted |
| Technical / Audit Logs | IP Address, Device ID, Access Logs | Security monitoring & fraud prevention | Statutory Requirement | Confidential |
Third-Party Sub-Processors
Annexure GOur approved sub-processors and external integrations are limited to verified providers that facilitate our core SaaS functionality:
- Amazon Web Services (AWS): Cloud hosting, database clusters, secure storage, and disaster recovery.
- Meta Platforms, Inc. (WhatsApp Cloud API): Omnichannel messaging, transactional updates, and WhatsApp Business integrations.
- Payment Gateways & Banks (e.g., Razorpay): Payment processing, checkout infrastructure, and settlement management.
- ERP & Accounting Providers (e.g., Tally, BUSY): Seamless two-way synchronisation of business transactions, invoices, and stock data.
- Telephony & SMS Partners: OTP verification, transactional alerts, and carrier-grade customer communication.
AI Governance & Responsible AI Principles
Annexure HOur deployment of AI, automated business agents, and voice assistants follows these core directives:
- Human-in-the-Loop: AI features operate as advisory tools; material financial, operational, and commercial commitments require human confirmation.
- Model Insulation: Proprietary Business Customer data and uploaded invoices are isolated and are not utilised to train public large-language models.
- Transparency: Automated responses, conversational agents, and machine-generated forecasts are visibly identified within the user interface.
- Prohibited Use: AI conversational features may not be used to produce malicious, fraudulent, defamatory, or deceptive content.
Privacy by Design & Data Governance
Annexure IIn adherence to the DPDP Act 2023 and DPDP Rules 2025, OrderEzee embeds privacy safeguards across all engineering lifecycles:
- Privacy by Default: Non-essential tracking and optional marketing opt-ins are turned off by default upon platform provisioning.
- Data Minimisation: Features are architected to request only the exact device permissions (Camera, Location, Mic) required to execute the user-initiated action.
- Privacy Impact Assessments (PIA): System architecture modifications or third-party integrations undergo internal privacy audits prior to production deployment.
- Workforce Training: Internal engineering, customer support, and operations teams undergo regular privacy compliance and data-handling governance workshops.