Privacy Policy
We believe you deserve to know exactly how your information is handled. This policy describes what we collect, why, and how.
About This Policy
Orysin (“Orysin”, “we”, “us”, “our”) operates the website at orysin.in and related services. This Privacy Policy describes how we collect, use, store, and protect personal information when you visit our website or submit an enquiry through our submission form.
We are committed to handling your personal information responsibly. This Policy is written to comply with the Information Technology Act, 2000 (“IT Act”) and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), which are currently operative under Indian law.
The Digital Personal Data Protection Act, 2023 (“DPDPA”) received Presidential assent on 11 August 2023. Its operative provisions, and the DPDP Rules made under it, are expected to come into force as and when notified by the Central Government. We are building our practices in anticipation of full commencement and will update this Policy when those provisions become operative.
Please read this Policy before submitting information to us. By using our website or submitting an enquiry, you acknowledge that you have read and understood this Policy.
Who We Are
Orysin is a product studio and technology consultancy that helps founders evaluate and develop technology products. Our website is at https://www.orysin.in.
For privacy-related matters, contact us at: legal.orysin@gmail.com with the subject line Privacy / Data Request.
What Information We Collect and Why
When you submit an enquiry through our website, we may collect the following categories of information:
Full name
To identify you and address correspondence appropriately.
Work email address
To respond to your enquiry and communicate with you about potential or existing services.
Phone number (optional)
To contact you regarding your enquiry if you choose to provide it. Phone numbers may constitute sensitive personal data under Rule 3 of the SPDI Rules.
Project description / enquiry message
To understand your idea, question, or challenge so we can assess how we may be able to help.
Category of enquiry
To route and prioritise your submission appropriately.
Referral code or name (optional)
To attribute referrals and, where applicable, to acknowledge referrers.
Consent record
We record whether you have agreed to our Privacy Policy and Idea Submission & Confidentiality Terms, along with a timestamp and policy version. This is stored as part of your submission record.
We also collect the following through our website infrastructure:
Website analytics data
Aggregate, anonymised website usage metrics collected through Vercel Analytics. See Section 7 for details.
We do not collect:
- Payment card details through the submission form
- Government identification numbers
- Biometric information
- Health or medical information
- Religious beliefs, political opinions, or caste information
How We Use Your Information
We use the information you submit to:
- Respond to your enquiry
- Evaluate whether we can help with what you have described and, if so, determine an appropriate approach
- Communicate with you about potential or existing services
- Provide services you have engaged us for under a separate agreement
- Attribute referrals where applicable
- Improve our website and submission process (using aggregated, anonymised analytics only)
- Comply with applicable legal obligations
What we do not do
- We do not use submitted idea descriptions to train artificial intelligence models.
- We do not send your submission to external AI services for automated processing.
- We do not publish your submitted ideas publicly or display them as case studies without your separate written authorisation.
- We do not sell your personal information.
- We do not use your information for advertising or marketing by third parties.
How Your Information Flows
When you submit the form on our website, your submission passes through the following infrastructure. We describe this accurately because we believe you are entitled to understand which systems handle your information.
Supabase (database)
Your submission is stored in a PostgreSQL database hosted by Supabase, Inc., a US-based cloud infrastructure provider. Your submission data is stored in this database. Access is restricted to authorised Orysin personnel.
Resend (email delivery)
Your submission details are transmitted through Resend, Inc., an email delivery service, to an Orysin-controlled email mailbox. Resend processes the data solely to deliver this notification email. Resend does not receive or store your idea submission independently of this delivery function.
Orysin mailbox and authorised personnel
The submission notification arrives in an Orysin-controlled email mailbox. Only authorised Orysin personnel with access to that mailbox and to the Supabase database may view your submission.
Vercel (hosting and analytics)
Our website is hosted on Vercel, Inc. Vercel's infrastructure processes web requests in the ordinary course of hosting. Vercel Analytics collects aggregate, anonymised website usage data as described in Section 7. Vercel is not part of the idea-submission delivery chain beyond hosting the website itself.
We do not use Google Analytics or any other third-party advertising or behavioural tracking technology on our website.
Your client IP address is collected by our server-side infrastructure for the purpose of rate limiting (preventing spam and abuse). It is not stored in our submission database.
Third-Party Service Providers
We engage the following infrastructure and service providers who process personal data in connection with delivering our services. These providers act as service providers or data processors on our behalf. We do not authorise them to use your data for their own marketing or advertising purposes beyond what is necessary to provide services to us.
| Provider | Function | Privacy info |
|---|---|---|
| Supabase, Inc. | Database infrastructure | supabase.com/privacy |
| Resend, Inc. | Email delivery | resend.com/legal/privacy-policy |
| Vercel, Inc. | Website hosting and analytics | vercel.com/legal/privacy-policy |
We recommend reviewing these providers' own privacy documentation for information about their processing practices, including data storage locations. We do not make specific claims about the physical location of data centres used by these providers beyond what is stated in their own published documentation.
Vercel Analytics
We use Vercel Analytics to understand how visitors use our website in aggregate. Based on Vercel's published documentation, Vercel Analytics is designed to be privacy-friendly. It does not use cookies, does not fingerprint individual users, and does not track users across different websites. It collects aggregate metrics such as page views, referring sources, general geographic regions, and device types.
We also use Vercel Speed Insights, which collects Core Web Vitals performance metrics to help us understand website performance.
We do not use Google Analytics, Facebook Pixel, or any other advertising or cross-site behavioural tracking technology.
If Vercel's data collection practices materially change, we will review and update this section accordingly.
Data Retention
We do not currently operate an automated deletion schedule for submission data. Submissions are retained in our database and email systems until we delete them manually or as part of our operational processes.
We retain submission data for as long as:
- it is reasonably necessary to respond to and process your enquiry;
- a potential or existing client relationship is active or may reasonably be anticipated;
- retention is required or permitted by applicable law; or
- it is required for internal administrative or legal purposes.
We are in the process of establishing a formal retention schedule. We intend to implement a review process under which inactive submissions will be periodically reviewed for deletion or anonymisation.
If you wish to request deletion of your personal data, please contact us as described in Section 11. We will consider your request and delete or anonymise your data where we are not required to retain it. We cannot guarantee immediate deletion from all backup or archival systems.
Data Security
We implement reasonable security measures, including:
- Encrypted database connections
- Access controls limiting submission access to authorised personnel
- Rate limiting and spam protection on our submission forms
- CSRF (cross-site request forgery) protection
- Input validation and sanitisation
No method of internet transmission or electronic storage is completely secure. We cannot guarantee absolute security of your data and make no warranty to that effect. In the event of a data breach or security incident that materially affects your personal information, we will take appropriate steps in accordance with applicable law.
Your Rights
Currently operative rights (IT Act and SPDI Rules 2011)
Under the IT Act and SPDI Rules currently in force, you have the right to:
- Review the personal information we hold about you;
- Correct inaccurate personal information; and
- Withdraw consent for the use of your information — noting that withdrawal may affect our ability to respond to your enquiry or provide services.
Anticipated rights under the DPDPA 2023 (not yet fully operative)
When the operative provisions of the DPDPA come into force, you will have additional rights as a “Data Principal”, including rights of correction, erasure, grievance redressal, and nomination of an authorised representative. We will update this Policy when those provisions become operative and we will facilitate the exercise of those rights at that time.
To exercise your current rights, contact us using the details in Section 11.
Grievance and Privacy Contact
Under Rule 5(9) of the SPDI Rules, we have designated a point of contact for privacy-related grievances.
Grievance Contact
Name: Chakradhar Kale
Designation: Privacy & Grievance Contact, Orysin
Email: legal.orysin@gmail.com
Subject line: Privacy / Data Request
We will acknowledge your grievance within a reasonable time and endeavour to resolve it within 30 days of receipt.
Children
Our services are not directed at persons under 18 years of age. We do not knowingly collect personal information from persons under 18. If you believe a person under 18 has submitted information to us, please contact us and we will take appropriate steps.
Cross-Border Transfer
Some of our service providers — including Supabase, Resend, and Vercel — are headquartered outside India. In the ordinary course of providing their services, your data may be transferred to and processed in countries other than India.
Cross-border transfer restrictions under the DPDPA are expected to come into force as notified by the Central Government. When those provisions become operative, we will review and update our practices and this section accordingly.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date at the top of this page and increment the version number.
We encourage you to review this Policy periodically. Your continued use of our website or services after a material change constitutes acknowledgement of the updated Policy.
Governing Law
This Privacy Policy is governed by the laws of India. Any dispute arising in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Tirupati, Chittoor District, Andhra Pradesh, India.