Why Octech
Security & Compliance at Octech
We hold your consumers' data to the highest standards of security, privacy, and legal compliance.
01 DPDP Act, 2023 Compliance
Octech (Octecxh Digital Labs Pvt. Ltd.) operates in full compliance with the Digital Personal Data Protection (DPDP) Act, 2023. All consumer personal data collected through Octech-managed programmes is processed under explicit, informed consent and handled for the minimum purposes necessary to operate the respective programme.
- Personal data is collected only after obtaining verifiable, affirmative consent from the data principal.
- Data is used solely for the stated purpose of the programme or service and is not sold, rented, or profiled beyond those objectives.
- Data principals retain the right to withdraw consent, request correction, or request erasure at any time.
- Data is retained only for the period required to operate the programme and is securely deleted thereafter.
- Third-party processors engaged by Octech are contractually required to adhere to equivalent data protection standards.
02 ISO 27001:2022 Certified Security
Octech's infrastructure, processes, and team practices are certified to the ISO 27001:2022 information security management standard. Octech's controls span the full programme lifecycle — from design and data capture to delivery and post-campaign deletion.
- Access controls and role-based permissions govern all programme data environments.
- Data in transit and at rest is encrypted using industry-standard protocols.
- Periodic internal security audits and vulnerability assessments (VAPT) are conducted across campaign infrastructure.
- Employees complete security awareness training and operate under confidentiality obligations when handling personal data.
- Vendor and processor security assessments are performed prior to engagement.
03 Data Breach Response
In the event of a personal data breach, Octech follows a documented incident response process consistent with DPDP Act obligations:
- Affected data principals will be notified promptly where required by law or where the breach poses a material risk.
- The Data Protection Board of India will be informed in accordance with statutory timelines.
- All incidents are logged, investigated, and remediated with root-cause corrective actions.
- Clients and partners whose programme data is affected will be informed without undue delay.
04 Exercise Your Data Rights
As a data principal under the DPDP Act, 2023, you have the following rights with respect to personal data processed by Octech:
- Right to access — Request a summary of personal data held about you.
- Right to correction — Request correction of inaccurate or incomplete data.
- Right to erasure — Request deletion of your personal data where we no longer have a lawful basis to retain it.
- Right to withdraw consent — Withdraw consent to processing at any time.
- Right to grievance redressal — Raise a complaint with our Grievance Officer.
To exercise any of these rights, please email our Grievance Officer at grievance@octech.in with the subject line "Data Rights Request". We will acknowledge your request within 48 hours and resolve it within 30 days.
05 Grievance Officer / Data Protection Contact
In accordance with the DPDP Act, 2023, Octech has appointed a designated contact for all data protection matters:
- Name: Grievance Officer, Octech
- Email: grievance@octech.in
- Entity: Octecxh Digital Labs Pvt. Ltd., India
- Response time: Within 30 days of receipt of complaint
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India once the Board is constituted and operational under the DPDP Act, 2023.
06 Related Policies
This page should be read alongside our full Privacy Policy, Cookies Policy, and Terms and Conditions.