Privacy Policy

Last Updated: July 13, 2026 | Publisher: Onyxio Quantum Systems Pvt Limited

1. Introduction & Trademark Notice

Onyxio™ ("we," "our," or "us") is committed to protecting the privacy and security of your data. This Privacy Policy explains how we collect, use, process, and safeguard the information you provide when using our Deterministic Archival and Retention System (DARS) via onyxio.cloud.

Trademark Notice: Onyxio® and Onyxio Cloud™ are registered trademarks and proprietary assets of Onyxio Quantum Systems Private Limited. All rights reserved.

2. Data Roles

  • Data Fiduciary: Our customers (you) act as the Data Fiduciary. You determine the purpose and means of data processing.
  • Data Processor: Onyxio acts as the Data Processor, providing the infrastructure and tools to store, seal, and retrieve your documents in accordance with your instructions.

3. Information We Collect

To provide our archival services, we collect:

  • Account Information: Name, business email, phone number, and billing information.
  • Third-Party Authentication Data: If you log in via enterprise Identity Providers (e.g., Google SSO, Microsoft Entra ID), we collect basic profile data authorized by the provider.
  • Archival Data: The documents, metadata, and files you upload to our platform.
  • Usage Data: Logs of access, timestamps, IP addresses, and actions performed (e.g., "Seal Document" events) to maintain an audit trail.
  • Technical Data: Browser type, operating system, and device information to optimize platform performance.

4. How We Use Your Data

We process your information for the following purposes:

  • Service Delivery: To facilitate the archival, integrity-sealing, and retrieval of your documents.
  • Security & Compliance: To monitor for unauthorized access, verify document integrity, and meet regulatory requirements under the DPDP Act.
  • Communication: To provide service updates, security alerts, and customer support.
  • Billing: To process subscriptions and manage payments.

5. Single Sign-On (SSO) & Third-Party Authentication

Onyxio supports enterprise authentication via Google and Microsoft. We explicitly declare our data handling practices for these APIs to comply with their respective developer policies:

Google API Services (OAuth)

  • Data Accessed: We request only non-sensitive, basic profile scopes (openid, userinfo.email, and userinfo.profile).
  • Data Usage: Strictly for identity verification and secure session management. We do not use Google data for advertising or AI training.
  • Limited Use: Onyxio's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Microsoft Entra ID (formerly Azure AD)

  • Data Accessed: We request basic Microsoft Graph API read permissions (e.g., User.Read) to access your verified organizational email address and name.
  • Data Usage: This data is utilized solely to map your enterprise identity to your Onyxio tenant, ensuring secure role-based access control (RBAC).
  • Data Sharing: We do not share, sell, or expose Microsoft enterprise user data to external third parties.

6. Data Residency and Sovereignty

In line with our commitment to data sovereignty, all personal data processed by Onyxio is stored exclusively within the borders of India (Mumbai Region - ap-south-1). We do not transfer your personal data to jurisdictions that do not provide adequate protection, ensuring full compliance with Indian data regulations.

7. Data Security Safeguards

We employ industry-leading security measures, including:

  • Encryption: All data is encrypted at rest (AES-256) and in transit (TLS 1.3).
  • Immutable Integrity: Our 'Seal Document' architecture ensures that your archived data is tamper-evident.
  • Access Control: Strict role-based access control (RBAC) to ensure only authorized personnel can manage your archives.

8. Your Rights (Data Principal Rights)

Under the DPDP Act, you have the right to:

  • Access: Request confirmation of what personal data we process.
  • Correction: Request the correction of inaccurate or incomplete information.
  • Erasure: Request the deletion of data, subject to legal and regulatory retention requirements.
  • Grievance Redressal: You may raise concerns or complaints through our dedicated support channel at privacy@onyxio.cloud.

9. Data Retention and Deletion

We retain your data only for as long as your subscription is active or as required by law. Upon termination of your account, you may request a secure export of your data. Following the contractually defined retention period, all data is permanently purged from our systems using secure wiping protocols.

10. Third-Party Sharing

We do not sell your personal data. We only share information with third-party service providers (e.g., cloud infrastructure providers like AWS) under strict data processing agreements to ensure they adhere to our privacy and security standards. This explicitly excludes the sale or unauthorized sharing of data obtained via Identity Providers like Google or Microsoft.

11. Cookies and Tracking Technologies

onyxio.cloud utilizes strictly necessary cookies to maintain secure user sessions, manage enterprise authentication flows, and ensure platform stability. We do not use third-party advertising or cross-site tracking cookies. You can manage cookie preferences through your browser settings, though disabling strictly necessary cookies will prevent access to the archival platform.

12. Data Breach Notification Protocol

In the event of a verified personal data breach or unauthorized access to our multi-tenant or hybrid storage infrastructure, Onyxio maintains a strict incident response protocol. We will notify affected Data Fiduciaries without undue delay and report the incident to the Data Protection Board of India as mandated by the DPDP Act. Notifications will include the nature of the breach, potential consequences, and the mitigation measures deployed.

13. Approved Sub-Processors

To deliver our services—particularly for clients operating in highly regulated sectors such as pharmaceuticals—we engage vetted third-party sub-processors, such as cloud hosting providers and payment gateways. We maintain strict Data Processing Agreements (DPAs) with each entity, ensuring they adhere to the same stringent security, encryption, and data residency standards (ap-south-1) outlined in this policy to support long-term document retention safely. A complete, up-to-date list of our authorized sub-processors is available to active clients upon request.

14. Children's Privacy

The Onyxio platform is designed exclusively for enterprise and business use. We do not knowingly collect, process, or store personal data from individuals under the age of 18. If we become aware that we have inadvertently collected such data, we will take immediate steps to securely delete it from our systems.

15. Policy Updates

We may update this policy periodically to reflect changes in technology or law. Significant changes will be communicated via your registered email or through a notification on the Onyxio dashboard.

16. Contact Us

For any privacy-related inquiries, data access requests, or complaints, please contact our Data Protection Office:

Email: privacy@onyxio.cloud

Address:
Onyxio Quantum Systems Private Limited
WeWork DLF Forum
Cybercity, Phase III
Gurugram, Haryana 122002
India