Privacy & Data Protection Policy
This Privacy Policy describes how personal data and industrial operational telemetry are collected, processed, and safeguarded when using the website, platforms, and services operated by NRV DesignX Private Limited.
Corporate Identity & Legal Hierarchy
This Privacy Policy forms an integral part of and must be read together with the Df-OS Website Terms of Service. In the event of any conflict regarding the commercial supply, licensing, or operation of the Df-OS Platform, the bilateral Master Services Agreement (MSA) executed between the Company and the enterprise customer shall prevail.
Operated by NRV DesignX Private Limited — Noida (Corporate Office) & Dehradun (Registered Office).
1. Scope & Applicability
This Policy applies to all individuals and enterprise representatives accessing or using the website (https://df-os.com), applications, and services operated by NRV DesignX Private Limited (hereinafter referred to as “DesignX”, “Df-OS”, “Company”, “we”, “us”, or “our”).
This Policy governs the processing of personal data in compliance with applicable data protection laws, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 (“IT Act”), and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”) to the extent applicable.
B2B Scope: Df-OS is an enterprise industrial platform intended strictly for business users, manufacturing leaders, and industrial personnel. It is not designed or intended for consumers or children.
2. Data Protection Roles & DPDP Framework
Under the Indian Digital Personal Data Protection Act, 2023, legal roles and processing obligations are classified into two distinct operational models:
We act as a Data Fiduciary when determining the purpose and means of processing personal data for our own business activities, including when you browse our website, request a demonstration, register for whitepapers, or contact our sales team.
We act as a Data Processor when processing shopfloor machine logs, factory operational parameters, or IoT telemetry on behalf of enterprise customers. The enterprise customer is the Data Fiduciary who owns the data and issues processing instructions.
3. Consent & Choice
Where required by Applicable Law, we obtain your consent through affirmative, clear, and specific mechanisms at the time of collecting personal data for identified, lawful purposes.
Right to Withdraw Consent: You have the unconditional right to withdraw consent at any time. You can submit a withdrawal request by emailing our privacy team at legal@dfos.ai or support@dfos.ai.
4. Information We Collect
- Direct Business Information: Name, business email address, corporate telephone number, company designation, plant location, and communication details submitted during demo requests or contact forms.
- Machine Telemetry & Operational Parameters: System logs, PLC/SCADA signals, Edge gateway metrics (e.g. Hectos/X-Konnect), production counts, cycle times, and machine fault codes.
- Safety & Proximity Data: With explicit plant operator consent, localized proximity telemetry used solely for shopfloor safety and workforce dispatch.
- Technical Device Metadata: IP addresses, browser specifications, session timestamps, and system performance metrics.
5. How We Use Your Information
We use collected information solely for specified, lawful industrial purposes:
- Operating and maintaining the Df-OS industrial software platform.
- Executing root cause analyses, CAPA workflows, and factory dispatch.
- Responding to sales inquiries, demo bookings, and support tickets.
- Detecting and mitigating cybersecurity incidents and fraudulent activity.
6. AI Ethics & Public LLM Model Training Prohibition
In alignment with Clause 6.2(c) of our Terms of Service and enterprise industrial data privacy best practices, NRV DesignX Private Limited maintains a strict prohibition against utilizing proprietary customer data for public AI training.
Zero Public AI Training Guarantee: We explicitly warrant that neither personal data, employee records, nor customer-owned factory operational telemetry (including production recipes, machine signals, OEE logs, and downtime metrics) is ever used to train, fine-tune, or evaluate public third-party foundational Artificial Intelligence (AI), Machine Learning (ML), or Large Language Models (LLMs).
Vish AI Copilot models operating inside enterprise tenant environments utilize isolated, client-dedicated retrieval-augmented generation (RAG) and Bounded Autonomy architectures that do not leak metadata outside your enterprise boundary.
7. Industrial IoT & Factory Data Ownership
All telemetry and operational data generated within customer production environments—including machine cycle times, throughput figures, scrap parameters, and maintenance histories—remains the sole and exclusive property of the enterprise customer.
DesignX acts strictly as a Data Processor. We do not monetize, sell, broker, or exploit customer operational telemetry.
10. Sub-Processors & Cross-Border Data Transfers
Vetted Sub-Processors: We engage verified cloud hosting providers (e.g. ISO 27001 / SOC 2 Type II certified cloud regions) and security infrastructure vendors under binding Data Processing Addendums (DPAs).
Cross-Border Data Flows (Section 16, DPDPA 2023): Primary application data is hosted on secure cloud infrastructure located within India. Any cross-border data transfer strictly adheres to the transfer restrictions and negative-list notifications issued by the Central Government of India under Applicable Law.
11. Data Retention & 12. Enterprise Security Safeguards
Retention & Secure Deletion: Personal data is retained only for the duration required to fulfill business purposes or statutory obligations, after which it is securely anonymized or destroyed.
Multi-Layered Safeguards: We enforce end-to-end SSL/TLS encryption in transit, AES-256 encryption at rest, strict Role-Based Access Controls (RBAC), and continuous vulnerability assessments. Read our full Trust & Security Architecture.
13. Data Principal Rights Under DPDPA 2023
Under the Digital Personal Data Protection Act, 2023, you are entitled to exercise the following statutory rights regarding your personal data:
Request a summary of personal data processed, identities of all Data Processors shared with, and details of processing activities.
Request the correction of inaccurate or misleading data, updating of incomplete records, and erasure of personal data no longer necessary.
Access readily available grievance redressal mechanisms with guaranteed 24-hr acknowledgement and 15-day resolution timelines.
Nominate another individual to exercise data principal rights on your behalf in the event of death or legal incapacity.
To exercise any of these rights, please email our Grievance Desk at legal@dfos.ai. If your grievance remains unresolved, you have the right to escalate the matter to the Data Protection Board of India.
14. Grievance Redressal Officer & Corporate Offices
In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, the details of the designated Grievance Officer and corporate locations are set out below:
Designation: Grievance Officer
Corporate Entity: NRV DesignX Private Limited
Corporate Office: 3rd Floor, B-26 & 27, Sector 1, Noida, Gautam Buddha Nagar – 201 301, Uttar Pradesh, India
Registered Office: Nathanpur, Upper Nathanpur, Rural Dehradun, I.I.P., Dehradun – 248 005, Uttarakhand, India
Statutory Email: legal@dfos.ai
Operating Hours: Monday to Friday, 09:30 to 18:30 IST (excluding public holidays)
15. Breach Notification, 16. Children, 17. Updates & 18. Governing Law
Breach Notification: In the event of a verified personal data breach, we will notify affected Data Principals and relevant authorities (including CERT-In and the Data Protection Board of India) in compliance with statutory timelines.
Children's Privacy: Df-OS does not knowingly collect or process personal data of individuals under 18 years of age.
Governing Law & Jurisdiction: This Privacy Policy is governed by the laws of India. All disputes shall be subject to the exclusive jurisdiction of the competent courts at New Delhi, India.