Df-OS Logo
Statutory Compliance • DPDP Act 2023 & IT Act 2000

Privacy & Data Protection Policy

This Privacy Policy describes how personal data and industrial operational telemetry are collected, processed, and safeguarded when using the website, platforms, and services operated by NRV DesignX Private Limited.

Effective & Last Updated: August 2026
Entity: NRV DesignX Private Limited
Read alongside: Terms of Service

Corporate Identity & Legal Hierarchy

This Privacy Policy forms an integral part of and must be read together with the Df-OS Website Terms of Service. In the event of any conflict regarding the commercial supply, licensing, or operation of the Df-OS Platform, the bilateral Master Services Agreement (MSA) executed between the Company and the enterprise customer shall prevail.

Operated by NRV DesignX Private Limited — Noida (Corporate Office) & Dehradun (Registered Office).

Section 01

1. Scope & Applicability

This Policy applies to all individuals and enterprise representatives accessing or using the website (https://df-os.com), applications, and services operated by NRV DesignX Private Limited (hereinafter referred to as “DesignX”, “Df-OS”, “Company”, “we”, “us”, or “our”).

This Policy governs the processing of personal data in compliance with applicable data protection laws, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 (“IT Act”), and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”) to the extent applicable.

B2B Scope: Df-OS is an enterprise industrial platform intended strictly for business users, manufacturing leaders, and industrial personnel. It is not designed or intended for consumers or children.

Section 02

2. Data Protection Roles & DPDP Framework

Under the Indian Digital Personal Data Protection Act, 2023, legal roles and processing obligations are classified into two distinct operational models:

DesignX as Data Fiduciary

We act as a Data Fiduciary when determining the purpose and means of processing personal data for our own business activities, including when you browse our website, request a demonstration, register for whitepapers, or contact our sales team.

DesignX as Data Processor

We act as a Data Processor when processing shopfloor machine logs, factory operational parameters, or IoT telemetry on behalf of enterprise customers. The enterprise customer is the Data Fiduciary who owns the data and issues processing instructions.

Section 04

4. Information We Collect

  • Direct Business Information: Name, business email address, corporate telephone number, company designation, plant location, and communication details submitted during demo requests or contact forms.
  • Machine Telemetry & Operational Parameters: System logs, PLC/SCADA signals, Edge gateway metrics (e.g. Hectos/X-Konnect), production counts, cycle times, and machine fault codes.
  • Safety & Proximity Data: With explicit plant operator consent, localized proximity telemetry used solely for shopfloor safety and workforce dispatch.
  • Technical Device Metadata: IP addresses, browser specifications, session timestamps, and system performance metrics.
Section 05

5. How We Use Your Information

We use collected information solely for specified, lawful industrial purposes:

  • Operating and maintaining the Df-OS industrial software platform.
  • Executing root cause analyses, CAPA workflows, and factory dispatch.
  • Responding to sales inquiries, demo bookings, and support tickets.
  • Detecting and mitigating cybersecurity incidents and fraudulent activity.
Section 06 — Industrial AI Safeguards

6. AI Ethics & Public LLM Model Training Prohibition

In alignment with Clause 6.2(c) of our Terms of Service and enterprise industrial data privacy best practices, NRV DesignX Private Limited maintains a strict prohibition against utilizing proprietary customer data for public AI training.

Zero Public AI Training Guarantee: We explicitly warrant that neither personal data, employee records, nor customer-owned factory operational telemetry (including production recipes, machine signals, OEE logs, and downtime metrics) is ever used to train, fine-tune, or evaluate public third-party foundational Artificial Intelligence (AI), Machine Learning (ML), or Large Language Models (LLMs).

Vish AI Copilot models operating inside enterprise tenant environments utilize isolated, client-dedicated retrieval-augmented generation (RAG) and Bounded Autonomy architectures that do not leak metadata outside your enterprise boundary.

Section 07

7. Industrial IoT & Factory Data Ownership

All telemetry and operational data generated within customer production environments—including machine cycle times, throughput figures, scrap parameters, and maintenance histories—remains the sole and exclusive property of the enterprise customer.

DesignX acts strictly as a Data Processor. We do not monetize, sell, broker, or exploit customer operational telemetry.

Section 08 & 09

8. Location Data & 9. Log Files & Cookies

Location Telemetry: Processed only with explicit user permission for localized safety-monitoring modules and never tracked in the background without authorization.

Cookies & Log Files: We use standard server logs (IP addresses, timestamps, browser types) and essential, preference, and analytics cookies. You may manage cookie preferences at any time via your browser settings.

Section 10

10. Sub-Processors & Cross-Border Data Transfers

Vetted Sub-Processors: We engage verified cloud hosting providers (e.g. ISO 27001 / SOC 2 Type II certified cloud regions) and security infrastructure vendors under binding Data Processing Addendums (DPAs).

Cross-Border Data Flows (Section 16, DPDPA 2023): Primary application data is hosted on secure cloud infrastructure located within India. Any cross-border data transfer strictly adheres to the transfer restrictions and negative-list notifications issued by the Central Government of India under Applicable Law.

Section 11 & 12

11. Data Retention & 12. Enterprise Security Safeguards

Retention & Secure Deletion: Personal data is retained only for the duration required to fulfill business purposes or statutory obligations, after which it is securely anonymized or destroyed.

Multi-Layered Safeguards: We enforce end-to-end SSL/TLS encryption in transit, AES-256 encryption at rest, strict Role-Based Access Controls (RBAC), and continuous vulnerability assessments. Read our full Trust & Security Architecture.

Section 13 — Statutory Rights

13. Data Principal Rights Under DPDPA 2023

Under the Digital Personal Data Protection Act, 2023, you are entitled to exercise the following statutory rights regarding your personal data:

1. Right to Access & Summary (Sec 11)

Request a summary of personal data processed, identities of all Data Processors shared with, and details of processing activities.

2. Right to Correction & Erasure (Sec 12)

Request the correction of inaccurate or misleading data, updating of incomplete records, and erasure of personal data no longer necessary.

3. Right to Grievance Redressal (Sec 13)

Access readily available grievance redressal mechanisms with guaranteed 24-hr acknowledgement and 15-day resolution timelines.

4. Right to Nominate (Sec 14)

Nominate another individual to exercise data principal rights on your behalf in the event of death or legal incapacity.

To exercise any of these rights, please email our Grievance Desk at legal@dfos.ai. If your grievance remains unresolved, you have the right to escalate the matter to the Data Protection Board of India.

Section 14

14. Grievance Redressal Officer & Corporate Offices

In accordance with the Information Technology Act, 2000 and the DPDP Act, 2023, the details of the designated Grievance Officer and corporate locations are set out below:

Designation: Grievance Officer

Corporate Entity: NRV DesignX Private Limited

Corporate Office: 3rd Floor, B-26 & 27, Sector 1, Noida, Gautam Buddha Nagar – 201 301, Uttar Pradesh, India

Registered Office: Nathanpur, Upper Nathanpur, Rural Dehradun, I.I.P., Dehradun – 248 005, Uttarakhand, India

Statutory Email: legal@dfos.ai

Operating Hours: Monday to Friday, 09:30 to 18:30 IST (excluding public holidays)

Statutory Resolution Timeline: In accordance with Clause 22 of our Terms of Service, we acknowledge grievances within 24 hours of receipt and resolve them within 15 days.
Section 15–18

15. Breach Notification, 16. Children, 17. Updates & 18. Governing Law

Breach Notification: In the event of a verified personal data breach, we will notify affected Data Principals and relevant authorities (including CERT-In and the Data Protection Board of India) in compliance with statutory timelines.

Children's Privacy: Df-OS does not knowingly collect or process personal data of individuals under 18 years of age.

Governing Law & Jurisdiction: This Privacy Policy is governed by the laws of India. All disputes shall be subject to the exclusive jurisdiction of the competent courts at New Delhi, India.

NRV DesignX Private Limited — Legal & Compliance Division
Review Terms of Service