Privacy Policy
iBytes Bits and Bots Private Limited (“iBytes”, “Company,” “we,” “us,” or “our”), the developer and operator of Aarya-Orion, a company incorporated under the laws of India (CIN U72900TN2020PTC136986) with its registered office at Plot No. 203, Flat No. T2, Anvaya Flats, Ram Nagar, 3rd Street, Velachery, Chennai, Tamil Nadu 600042, India, provides Aarya-Orion, an enterprise software-as-a-service platform for the oil and gas industry (the “Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard personal information when you visit https://aarya-orion.com/ or use the Service. Because the Service is provided primarily to businesses, “you” means individuals who register for, access, or use the Service on behalf of an organization, as well as visitors to our website.
Our role — controller vs. processor
For information about our own relationship with you (such as your account and billing details), we act as a “controller” (or “data fiduciary” under applicable Indian law). When our business customers upload or submit content to the Service, that content (“Customer Data”) may include personal information about their own users, employees, or customers. For Customer Data we generally act as a “processor” (or “service provider” / “data processor”) that processes the data on our customer’s behalf and under their instructions, as set out in the applicable subscription agreement and Data Processing Addendum (“DPA”). This Privacy Policy governs our activities as a controller; the DPA governs our processing of Customer Data.
1. Information we collect
We collect the following categories of information:
- Account and registration data: name, business email address, job title, company name, username, and password.
- Billing and payment data: billing contact, company address, and subscription details. Card and bank details are collected and processed by third-party payment providers like Stripe and Razorpay; we do not store full payment card numbers.
- Customer Data: content, files, records, engineering information, technical documents, and other information that you or your organization submit to the Service. Where Customer Data contains personal information, your organization is responsible for ensuring that it has the appropriate legal rights, permissions, and lawful basis to collect and submit such information to the Service. We process Customer Data only in accordance with our customer's instructions, the applicable subscription agreement, and the Data Processing Addendum (DPA).
- Usage and log data: IP address, browser and device information, pages viewed, features used, referring URLs, timestamps, and diagnostic data.
- Cookies and similar technologies: as described in Section 4.
- Communications and support data: information you provide when you contact us, request support, respond to surveys, or subscribe to communications.
We do not intentionally collect sensitive personal data (special categories of data) except where it is contained in Customer Data submitted by our customers, in which case we process it solely as a processor under the customer's instructions and the DPA.
2. How we use information
We use personal information to:
- provide, operate, maintain, and secure the Service;
- create and administer accounts and authenticate users;
- process subscriptions, invoicing, and payments;
- provide customer support and respond to inquiries;
- monitor, analyze, and improve the Service and develop new features;
- for administrative, security, and fraud-prevention purposes;
- detect, prevent, and address fraud, abuse, security incidents, and technical issues;
- comply with legal obligations and enforce our agreements; and
- (where permitted and subject to your rights) conduct limited business-to-business direct marketing.
We do not use personal information for automated decision-making that produces legal or similarly significant effects concerning individuals without human involvement, except where necessary for the performance of a contract or with your explicit consent (and subject to applicable safeguards).
We treat Customer Data as confidential information and use it only for delivering the Service unless otherwise instructed by the customer or required by law.
2.1 AI Processing
Certain features of Aarya-Orion use artificial intelligence, machine learning, engineering algorithms, rule-based systems, and computational models to assist users in engineering workflows. AI processing is performed solely for providing the contracted services requested by our customers. Customer Data is processed only in accordance with customer instructions and applicable agreements. Unless expressly authorized by the customer, Customer Data is not used to train publicly available artificial intelligence models or services.
AI-generated outputs are intended to assist qualified professionals and do not replace professional engineering judgment.
3. Legal bases for processing
Where the GDPR, UK GDPR, or Swiss data protection law applies, we rely on the following legal bases:
- performance of a contract (to provide the Service requested); our legitimate interests (to operate, secure, and improve the Service and to conduct limited B2B direct marketing), balanced against your rights; your consent (for marketing communications where required), which you may withdraw at any time; and compliance with legal obligations.
- Where the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) applies, we process personal data on the basis of consent or one of the permitted exceptions (including contractual necessity and legitimate interests where not overridden by the individual’s rights), and we provide the required transparency information at or before the time of collection.
- Where India’s Digital Personal Data Protection Act, 2023 applies, we process digital personal data on the basis of consent or for the legitimate uses permitted under that Act.
- In other jurisdictions we process personal information in accordance with applicable local law.
4. Cookies
We use only strictly necessary cookies — primarily authentication and session cookies that keep you signed in and help secure the Service. Because these cookies are essential to deliver the Service you request, they do not require your consent under most applicable laws, and we do not use advertising, marketing, or third-party analytics cookies. You can block or delete cookies through your browser settings, but the Service may not function properly without the essential ones. If you make a payment, third-party payment providers like Stripe and Razorpay may set their own cookies on their checkout pages to process the transaction and help prevent fraud; those cookies are governed by each provider's own privacy and cookie policies. Because we use only essential cookies, a separate cookie policy is not required, and this section serves as our cookie disclosure.
5. How we share information
We do not sell personal information. We do not “share” personal information for cross-context behavioral advertising as defined under California law. We share information only as follows:
- Service providers / subprocessors: vendors that host, process, or support the Service, including Amazon Web Services (AWS) for cloud hosting, third-party payment providers like Stripe and Razorpay for payment processing, and Amazon SES for transactional email delivery. Support inquiries are handled via our business email (privacy@i-bytes.com). These providers are bound by confidentiality and data-protection obligations. A current list of subprocessors is maintained and available through our Trust Center or upon request; material changes will be notified in accordance with the DPA where applicable.
- Within your organization: administrators of your organization's account may access and manage your use of the Service.
- Legal and safety: where required to comply with law or lawful requests, or to protect the rights, safety, and property of the Company, our users, or others.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Privacy Policy.
- With your consent or at your direction.
6. International data transfers
We may transfer, store, and process information in countries other than your own, including India (where the Company is established) and locations used by our subprocessors (including AWS regions). Where we transfer personal information out of the EEA, UK, or Switzerland, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, supplemented by technical and organizational measures as needed. Where UAE PDPL or other local laws impose additional requirements for cross-border transfers, we implement the required safeguards or obtain the necessary authorizations.
7. Data retention
We retain personal information only for as long as necessary to fulfil the purposes described in this Policy, to comply with legal, accounting, or reporting obligations, to resolve disputes, and to enforce our agreements. Typical retention periods (subject to longer retention where legally required):
- Account and registration data: for the duration of the subscription/account plus a reasonable period thereafter (generally up to 7 years for contractual and tax records).
- Billing and payment records: as required by applicable tax and accounting laws (typically 7 years).
- Usage and log data: generally 12–24 months, unless needed longer for security or legal purposes.
- Support and communications data: generally 3 years after the last interaction, unless a longer period is required.
- Customer Data: retained in accordance with your organization’s subscription agreement and the DPA.
- On termination we delete or return Customer Data as described in the DPA.
- We may retain de-identified or aggregated data indefinitely.
8. Security
We implement appropriate administrative, technical, physical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, and destruction. These measures may include, as appropriate, encryption of data in transit and at rest, role-based access controls, authentication mechanisms, application of the principle of least privilege, security monitoring and logging, backup and recovery procedures, vulnerability management, and periodic reviews of our security practices. While we implement and continually improve safeguards designed to protect personal information, no method of electronic transmission or storage can be guaranteed to be completely secure. Accordingly, we cannot guarantee absolute security. Security of information also depends in part on the security of the computer, device, or network you use and the measures you take to protect your credentials. Please take appropriate steps to protect your User IDs and passwords. In the event of a personal-data breach that is likely to result in a risk to individuals’ rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals, in accordance with applicable law (including the 72-hour notification window under the GDPR where it applies).
9. Your privacy rights
Depending on where you live, you may have some or all of the following rights, subject to applicable law and any relevant exemptions:
- EEA / UK / Swiss residents access, rectification, erasure, restriction of processing, data portability, objection to processing (including for direct marketing), withdrawal of consent, and the right to lodge a complaint with a supervisory authority.
California residents (CCPA / CPRA) know and access the personal information we collect, use, and disclose; request deletion; request correction; opt out of the “sale” or “sharing” of personal information; limit the use of sensitive personal information (where applicable); and not be discriminated against for exercising your rights. We do not sell or share personal information as those terms are defined under California law.
- UAE residents access, rectification, erasure, restriction, objection, withdrawal of consent, and the right to lodge a complaint with the UAE Data Office.
Indian residents (DPDP Act, 2023) access, correction, erasure, data portability (where applicable), and grievance redressal.
- Other jurisdictions you may have similar rights under applicable local law.
- To exercise your rights, contact us at contact@i-bytes.com . We will respond within the timeframes required by applicable law (generally one month under the GDPR, 30 days under UAE PDPL, and within the periods set by other applicable laws) and may need to verify your identity.
- If you are an individual whose personal information was submitted to the Service by one of our business customers, please direct your request to that customer (the controller / data fiduciary); we will assist them as their processor.
10. Intended audience
The Service is an enterprise platform intended solely for businesses in the oil and gas and energy sectors and the professional users authorized by those businesses. It is not directed to, marketed to, or intended for consumers or anyone under 18, and we do not knowingly collect personal information from individuals under 18. If you believe someone under 18 has provided us with personal information, contact us and we will take appropriate steps to delete it.
11. Third-party links and services
The Service may link to or integrate with third-party websites and services we do not control. Their privacy practices are governed by their own policies, and we are not responsible for them.
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date. Where required by law, we will provide additional notice (for example by email or in-product notice) of material changes. Your continued use of the Service after the effective date of changes constitutes acceptance of the updated Policy, except where applicable law requires a different form of consent or notice for certain processing activities.
13. Contact us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us at:
iBytes Bits and Bots Private Limited
Plot No. 203, Flat No. T2, Anvaya Flats, Ram Nagar, 3rd Street, Velachery, Chennai, Tamil Nadu 600042, India
Email: privacy@i-bytes.com
For privacy-specific inquiries you may also write to the same address marked “Privacy”.