Legal

Privacy Policy

Last updated 2 June 2026. This policy is prepared for OpsVision AI Systems Pvt. Ltd. (OVASPL) and should be reviewed by counsel before production use.

1. Who we are (data fiduciary)

OpsVision AI Systems Pvt. Ltd. (OVASPL, OpsVision, we, us, or our), a company incorporated in India, provides cloud security, compliance, cost-governance, incident, reporting, and AI-assisted operations software. For personal data processed through this website and our general business communications, OVASPL is the data fiduciary and can be contacted at hello@opsvision.ai; our registered office address is available on request to that inbox. For personal data inside the OpsVision platform, the customer is generally the data fiduciary and OVASPL acts as data processor — see section 5. This Privacy Policy explains how OVASPL collects, uses, stores, shares, and protects personal data when visitors use our website, email us, request a trial, or use the OpsVision platform.

2. Personal data we collect

Website visitors: when you browse our website, Amazon CloudFront (our content delivery network) automatically records standard access-log data — your IP address, browser user-agent string, the URL or resource requested, and a timestamp. If you email us: the "Contact sales" and "Start trial" buttons open your own email application addressed to hello@opsvision.ai; if you choose to email us, we receive your email address and whatever you include in your message. We do NOT operate a contact-form database, a marketing waitlist, or behavioural tracking-cookie profiling on this website. Platform customers: when you use the OpsVision platform we process account details, business contact information, organisation information, billing and procurement details, authentication metadata, product usage data, support communications, audit and security logs, cloud inventory metadata, security findings, compliance evidence, and cost and usage signals. Customers should not submit unnecessary personal data, secrets, credentials, or sensitive personal data into findings, prompts, support tickets, or evidence uploads.

3. Purposes of processing

Website access logs are used to operate and secure the site, prevent and investigate abuse, and maintain availability. Email you send us is used to respond to your enquiry, trial request, or support question. Platform data is used to provide and secure the contracted service: to create and administer accounts, connect customer-authorised cloud accounts, generate findings and reports, support approval workflows, improve product reliability, communicate with customers, comply with law, and enforce our agreements.

4. Lawful basis

Under India's Digital Personal Data Protection Act, 2023, we process personal data either with your consent or for the legitimate uses the Act permits. Website access logs and security logging are processed for the legitimate purpose of operating and protecting the website. Email correspondence is processed for the specific purpose for which you voluntarily provide it (to answer you). Platform personal data is processed on the customer's instructions under the customer contract. Where consent is the applicable basis, we rely on consent that has been given and may be withdrawn.

5. AI-assisted processing

OpsVision may use AI systems to classify findings, summarise evidence, prepare explanations, suggest remediation steps, draft reports, and assist support or onboarding. AI output may be incomplete, inaccurate, or unsuitable for a specific environment. Customers remain responsible for reviewing AI-assisted output and approving any action before execution.

6. Customer role (controller / processor)

Where applicable privacy law uses controller/processor or data fiduciary/data processor concepts, the customer is generally responsible for the personal data it submits to OpsVision, and OVASPL processes that data to provide the contracted service. Website, sales, billing, and support data may be processed by OVASPL for its own legitimate business purposes and legal obligations.

7. Data residency and cross-border transfer

The website's origin storage and its access logs are held in Amazon Web Services Asia Pacific (Mumbai), the ap-south-1 region in India. The website is delivered through Amazon CloudFront, a content delivery network with edge locations worldwide, so an individual request may be served from an edge location outside India even though the stored records remain in India. For the OpsVision platform, some subprocessors — including our cloud infrastructure provider (Amazon Web Services) and our AI provider, Anthropic (United States) — may process data outside India where required to provide the service, subject to contractual, technical, and organisational safeguards.

8. Sharing and subprocessors

OVASPL does not sell personal data. We may share information with hosting and cloud infrastructure providers (Amazon Web Services), our AI provider (Anthropic), payment and billing providers, support tools, security monitoring providers, professional advisers, and authorities where legally required. Subprocessors are expected to handle data under confidentiality, security, and data-protection obligations.

9. Security

We use reasonable technical and organisational measures intended to protect information, including access controls, encryption in transit, cloud security controls, logging, least-privilege access, and approval-gated workflows for modifying actions. Several of the website's transport-security controls are externally checkable — see our Trust page (/trust) for commands you can run yourself. No system is perfectly secure, and customers must configure their own cloud roles, users, integrations, and approval policies responsibly.

10. Retention

Website access logs are retained for 90 days and then deleted. Email correspondence is retained for as long as needed to handle your request and to keep a reasonable business record. Platform data is retained for as long as needed to provide the service and to meet legal, tax, security, and contractual obligations, and is then deleted or returned in line with the customer agreement. Where a fixed period is not stated above, retention varies by data type, account status, and contractual requirements rather than a single fixed term.

11. Your rights and how to make a request (DSR)

Under India's Digital Personal Data Protection Act, 2023, and subject to identity verification, you may ask us to: (a) access a summary of the personal data we hold about you and how we process it; (b) correct, complete, or update it; (c) erase it where it is no longer needed for the purpose it was collected and no law requires us to keep it; (d) nominate another individual to exercise your rights in the event of death or incapacity; and (e) have a grievance about our handling of your data redressed. How to make a request: email privacy@opsvision.ai, state which right you want to exercise, and include enough detail for us to locate your data (for website data, the approximate date and the email address or context you used to contact us). To protect your data we may ask you to verify your identity before we act, and we may decline or pause a request where the law allows — for example where acting would infringe another person's rights or a legal obligation we are subject to. For personal data held inside a customer's OpsVision workspace the customer is the data fiduciary, so we will route your request to, or coordinate with, that organisation. We do not charge a fee to make a request. We will acknowledge your request promptly and aim to respond within 30 days; where the law sets a shorter timeline we follow it, and if a complex request needs longer we will tell you why. If you are not satisfied with our response you may escalate to the Grievance Officer in section 12.

12. Grievance Officer

In accordance with India's Digital Personal Data Protection Act, 2023, our Grievance Officer can be reached at privacy@opsvision.ai. You may contact the Grievance Officer with any question or complaint about how your personal data is handled, and we will respond within the timelines required by applicable law.

13. Data Protection Officer

OVASPL has not been notified as a Significant Data Fiduciary under the Digital Personal Data Protection Act, 2023, and is therefore not required to appoint a Data Protection Officer. The Grievance Officer contact in section 12 is the point of contact for data-protection queries. If our status changes, we will update this policy.

14. Children's data

The OpsVision website and platform are intended for businesses and their personnel. We do not direct the service to children (individuals under the age of 18) and we do not knowingly collect their personal data. If you believe a child has provided us personal data, contact privacy@opsvision.ai and we will delete it.

15. Cookies and local storage

This website does not set advertising, analytics, or tracking cookies, and it does not use third-party trackers, tag managers, or behavioural profiling. In a fresh-session browser test of our public pages (home, pricing, and contact) on 2 June 2026, no cookies were set at all. The only data we store in your browser is a single local-storage value named "theme" that records your light or dark display preference. It is written only if you switch the theme, it stays on your device, it is not a cookie, and it is not sent to us or shared with anyone. Clearing your browser's site data removes it and the page simply falls back to its default appearance. The OpsVision platform (app.opsvision.ai) is a separate, authenticated application governed by the customer agreement; any strictly necessary cookies it uses to keep you signed in are described to customers within the product and are never used for advertising or cross-site tracking.

16. Changes and contact

We may update this Privacy Policy as the product, law, or business changes. Material changes will be reflected by updating the date on this page. General questions can be sent to hello@opsvision.ai; privacy requests and grievance communications should be sent to privacy@opsvision.ai.