Below is a detailed, website-ready Privacy Policy drafted for OrizerERP / Orizer InfoTech, covering ERP software, CRM, e-BIZ app, cloud/local deployment, customer data, employee/user access, integrations, support, analytics, security, and compliance.
Note: This is a business-ready draft, not a substitute for review by an Indian technology/privacy lawyer. You should replace the bracketed placeholders before publishing.
Effective Date: [28/10/2014]
Last Updated: [28/10/2025]
Welcome to OrizerERP, a business management and Enterprise Resource Planning (ERP) software platform provided by Orizer InfoTech ("OrizerERP", "Orizer", "Company", "we", "us", or "our").
OrizerERP provides ERP, CRM, manufacturing management, business analytics, e-BIZ applications, reporting, workflow management, and related software and technology services to businesses and organizations.
This Privacy Policy explains how we collect, use, store, process, protect, and disclose information when you:
By using our website, software, applications, or services, you acknowledge that you have read and understood this Privacy Policy.
This Privacy Policy applies to information processed through:
This Privacy Policy does not necessarily apply to third-party websites, applications, payment gateways, communication platforms, or other services that may be integrated with OrizerERP. Such third parties may maintain their own privacy policies.
Depending on how you interact with OrizerERP, we may collect different categories of information.
When a company or organization purchases or uses OrizerERP, we may collect:
Organizations using OrizerERP may create accounts for their employees, staff, administrators, or authorized users.
Information may include:
The customer organization is generally responsible for determining which employees/users receive access to its OrizerERP account and what permissions those users have.
OrizerERP is designed to manage business operations. Customers may enter information relating to their own customers, suppliers, employees, products, inventory, transactions, and business activities.
Depending on the modules used, this may include:
Such information may contain confidential business information belonging to the customer.
OrizerERP may process confidential business information provided by customers for the purpose of operating the customer's ERP environment.
This may include:
We treat customer business information as confidential and use it primarily to provide, maintain, support, secure, and improve the services.
Customers should not upload information that is unnecessary for the intended use of the software.
Users may be required to create or receive authentication credentials to access OrizerERP.
Users are responsible for:
Orizer will not knowingly ask users to disclose their password through unsolicited communication.
When you use our website, application, or online services, we may automatically collect certain technical information, where applicable, such as:
This information may be used to maintain system security, troubleshoot technical issues, improve performance, and prevent unauthorized access.
We may use information for the following purposes:
To:
We may use information provided during implementation to:
Information may be accessed where reasonably necessary to:
We may process technical and account information to:
We may use contact information to communicate regarding:
Where permitted by applicable law, we may also send information about new products, features, services, or business announcements.
We process personal information based on applicable legal grounds, contractual requirements, legitimate business purposes, consent where required, and other lawful bases available under applicable law.
For customers and users located in India, we intend to operate our services in accordance with applicable Indian privacy and data protection requirements, including the Digital Personal Data Protection Act, 2023, its applicable rules and regulations as they become effective, and other applicable laws.
Where applicable, customers may have additional obligations regarding the personal data they enter into OrizerERP.
In many ERP implementations, the customer organization determines:
Accordingly, depending on the applicable legal framework and circumstances, the customer may be responsible for determining the purposes and means of processing personal data.
Orizer generally acts as a technology/service provider processing information on behalf of the customer where applicable.
Customers are responsible for ensuring that information entered into OrizerERP is collected and processed lawfully and that appropriate notices, consents, permissions, and authorizations are obtained where required.
Unless otherwise agreed under a written contract:
Orizer does not claim ownership of customer business records merely because such information is stored or processed through OrizerERP.
Customers are responsible for the accuracy, legality, and authorization of information entered into the system.
Orizer retains ownership of:
We do not sell customer business data as a product.
We may disclose or provide access to information where reasonably necessary for:
We may use trusted third-party service providers for services such as:
Such providers may process information only to the extent necessary to provide their services to us or our customers and subject to applicable contractual or legal requirements.
Information may be shared when the customer or authorized user instructs us to do so.
We may disclose information where required or permitted by law, court order, government authority, regulatory requirement, or lawful governmental request.
Information may be disclosed where reasonably necessary to:
OrizerERP may integrate with third-party services, depending on the customer's configuration.
Examples may include:
When information is transferred to a third-party service through an integration, that third party may process the information according to its own terms and privacy policy.
Customers should review the applicable third-party policies before enabling such integrations.
OrizerERP may be deployed through different environments, including:
For cloud deployments, data may be stored on infrastructure operated by Orizer or its authorized infrastructure/service providers.
Where OrizerERP is installed on a customer's local infrastructure, the customer may have primary responsibility for:
Orizer may provide implementation and technical support according to the applicable service agreement.
We take reasonable technical and organizational measures designed to protect information against unauthorized access, alteration, disclosure, loss, misuse, or destruction.
Depending on the deployment and service configuration, security measures may include:
However, no electronic storage or transmission system can be guaranteed to be completely secure.
Customers are also responsible for maintaining appropriate security controls within their organization.
OrizerERP may allow administrators to assign access permissions based on:
Customers should regularly review user access and disable accounts belonging to employees or users who no longer require access.
Depending on the service plan, deployment model, and contractual arrangement, backup and recovery mechanisms may be provided by customer.
Backup frequency, retention, restoration procedures, storage location, and recovery commitments may vary according to the customer's agreement.
Customers using local installations should maintain appropriate independent backups of their business data.
Orizer shall not be responsible for data loss caused by circumstances outside its reasonable control, including customer-side hardware failure, unauthorized deletion, malware, improper configuration, third-party infrastructure failure, or failure to maintain required backups, except to the extent otherwise agreed in writing.
We retain information only for as long as reasonably necessary for:
The actual retention period may vary depending on:
When information is no longer required, it may be deleted, anonymized, archived, or otherwise securely disposed of, subject to applicable legal and contractual requirements.
Subject to the customer's agreement and applicable technical limitations, customers may request:
Requests may be subject to verification, contractual terms, applicable charges, technical limitations, and legal retention requirements.
Customers should maintain their own appropriate backups before requesting account closure or deletion.
Our website and online services may use cookies or similar technologies to:
Users may be able to control cookies through their browser settings.
Disabling certain cookies may affect the functionality of parts of our website.
We may collect aggregated or technical information about how users interact with our website, applications, or services.
This may include:
We may use aggregated or anonymized information for:
Where information is anonymized so that individuals cannot reasonably be identified, it may be used for legitimate business and analytical purposes.
We may send service-related communications that are necessary for providing our services.
Where permitted by applicable law, we may also send marketing communications regarding:
Recipients may request to opt out of non-essential marketing communications.
Service, security, contractual, billing, and other essential communications may continue where necessary.
OrizerERP is intended primarily for businesses and professional users.
Our services are not intentionally designed to collect personal information directly from children.
If we become aware that personal information has been collected from a child in circumstances where such collection is not legally permitted, we will take appropriate steps as required by applicable law.
Depending on our infrastructure, cloud providers, service providers, integrations, and customer configuration, information may be processed or stored in locations outside the customer's state or country.
Where cross-border transfer of personal data occurs, we will seek to comply with applicable legal requirements and contractual obligations.
Customers should contact Orizer if they have specific data residency or geographic storage requirements.
Users of OrizerERP are responsible for:
If Orizer becomes aware of a security incident involving customer or personal data, we will assess the incident and take reasonable steps appropriate to the circumstances.
Where required by applicable law or contractual obligations, we may notify affected customers, users, regulators, or other relevant parties.
Customers are responsible for promptly informing Orizer of suspected unauthorized access, data disclosure, compromised credentials, or other security incidents affecting their OrizerERP environment.
Depending on applicable law and the circumstances, individuals may have rights relating to their personal information, which may include:
Where the personal information is controlled by a customer organization, requests may need to be directed to that organization first.
If you have a privacy-related question, concern, or grievance regarding Orizer's processing of personal information, you may contact our designated privacy/grievance contact.
Name: [ORIZER INC]
Designation: [Designation]
Company: Orizer InfoTech
Email: [[email protected]]
Phone: [Phone Number]
Address: [Registered Office Address]
We will review and respond to privacy-related requests in accordance with applicable law and our internal procedures.
If Orizer undergoes a merger, acquisition, restructuring, sale of assets, investment, or other corporate transaction, information may be transferred as part of the transaction, subject to applicable law.
Where required, appropriate contractual and legal protections will be applied to information transferred as part of such transaction.
All intellectual property rights relating to OrizerERP, including but not limited to:
remain the property of Orizer or its applicable licensors unless expressly agreed otherwise in writing.
This Privacy Policy does not grant any intellectual property license.
We may update this Privacy Policy from time to time to reflect:
When we make material changes, we may update the "Last Updated" date and, where appropriate, provide additional notice.
We encourage customers and users to periodically review this Privacy Policy.
Although we take reasonable measures to protect information, no internet transmission, software system, server, database, or electronic storage method can be guaranteed to be completely secure.
Accordingly, Orizer cannot guarantee absolute security of information.
Customers should maintain appropriate organizational, technical, and administrative safeguards for their own systems and users.
Our website or applications may contain links to third-party websites or services.
Orizer is not responsible for the privacy practices, content, security, or policies of third-party websites.
Users should review the privacy policies of third-party websites before providing personal information.
Orizer provides technology for customers to manage their business information.
The customer is responsible for:
Orizer is not responsible for the customer's independent decisions regarding collection or use of personal data.
This Privacy Policy shall be governed by and interpreted in accordance with the applicable laws of India.
Subject to applicable law and contractual agreements, disputes relating to this Privacy Policy shall be subject to the jurisdiction of the appropriate courts having jurisdiction over [Vapi, Gujarat, India].
If you have questions regarding this Privacy Policy, our data practices, or privacy-related matters, please contact us.
Website: www\.orizer.in
Email: info@orizer.in
Privacy Email: info\@orizer.in
Phone: [Phone Number]
Registered Office: [vapi – Gujarat - INDIA]
Location: Vapi, Gujarat, India
By accessing or using OrizerERP products and services, you acknowledge that you have read and understood this Privacy Policy and agree to the processing of information as described herein, subject to applicable law and the terms of your agreement with Orizer.
Last Updated: [28/10/2025]
This version is structured for a professional ERP company's website, rather than a generic app privacy policy. Before publishing, I recommend replacing the placeholders and having a lawyer review the DPDP Act, customer-data/controller-processor language, breach obligations, retention, and jurisdiction clauses.