Privacy

Privacy Policy

How ORIGAT collects, processes, secures and shares information across the ORIGAT trust, risk and compliance platform.

Information we collect

We collect account details of platform users (name, work email, role, organisation), the business information your organisation submits about entities it onboards (company registration, tax identifiers, banking details, documents and contracts), and technical data such as log timestamps, IP address and device information needed to secure the service.

How we use information

Information is used to provide onboarding, verification, monitoring, scoring and contract functionality; to run verification checks against official and authorised data sources on your instruction; to send operational alerts such as expiry notifications; to maintain audit trails; and to support, secure and improve the platform.

Verification and third-party sources

To confirm identifiers such as PAN, GST, CIN, MSME registration and bank accounts, we transmit the minimum necessary data to authorised verification providers and official registries. Results are stored with the entity record so your team retains evidence of what was checked and when.

Legal basis and roles

Where your organisation uploads information about its own customers, vendors or partners, your organisation is the controller of that information and ORIGAT acts as a processor under your instructions and our agreement with you. For our own account, billing and website data, ORIGAT is the controller.

Sharing

We do not sell personal information. We share it only with verification and infrastructure providers engaged to deliver the service under contractual confidentiality and security obligations, and where required by law or to protect our legal rights.

Security

We apply encryption in transit and at rest, role-based access control, least-privilege administrative access, environment separation, audit logging and regular review of access and dependencies. Access to customer data by our staff is restricted to what is required for support and operations.

Retention

Entity records, verification results and audit trails are retained for as long as your organisation maintains its account, and afterwards only for the period needed to meet legal, tax and audit obligations. On termination, data is deleted or returned in line with your agreement.

Your rights

Subject to applicable law, you may request access, correction, deletion, restriction or a copy of your personal information, and object to certain processing. If your information was submitted through a customer of ORIGAT, we will direct your request to that organisation.

International transfers

Where information is processed outside your country, we rely on appropriate safeguards such as contractual data protection terms with our providers.

Changes and contact

We will update this policy as the platform evolves and will indicate the effective date of any material change. For any privacy question or request, contact info@origat.tech.

Questions about this policy? Email info@origat.tech.