Legal

Privacy Policy

Effective 24 August 2026 - Oris Intelligence Private Limited, operating Custelis

This policy has two parts, because Custelis plays two different roles with two different kinds of data. Read the section that applies to you: Part A covers you as a visitor, prospect, or account admin on custelis.com and app.custelis.com. Part B covers the employee monitoring data the Custelis product processes on behalf of a paying customer - if you're an employee whose employer uses Custelis, that's the section that describes you, and your employer (not Custelis) is who controls that data and answers your rights requests.

Who we are

Custelis is operated by Oris Intelligence Private Limited ("Custelis", "we", "us"), an ORIS ecosystem product. For any privacy question, write to privacy@custelis.com.

Registered office: [registered office address to be added]. Corporate Identification Number (CIN): [CIN to be added].

Part A - custelis.com visitors and account admins

What we collect

WhenWhatWhy
You submit the homepage email-capture formYour work email addressTo pass you into the signup flow you asked for
You create a workspaceOrganization name, your name, your work email, your password (stored hashed, never in plain text)To create your account and organization
You link ORIS Identity SSOYour ORIS Identity subject ID and the OAuth tokens needed to keep that session workingSingle sign-on across the ORIS ecosystem
You subscribe to a paid planBilling contact details and GST profile if you request an invoiceSubscription billing and tax-compliant invoicing
You contact supportWhatever you send usTo help you

We do not currently run any analytics or advertising trackers on custelis.com, and we do not sell, rent, or share your personal data with any third party for their own marketing purposes. See the Cookie Policy for exactly what, if anything, is set in your browser.

Payments

Custelis does not process or store your payment card details. Checkout is handled by Razorpay via the shared ORIS Billing platform; we receive confirmation that a payment succeeded, not your card number.

Who else sees this data

We share the minimum necessary with:

We do not transfer your personal data outside these purposes without telling you.

Your rights

Depending on where you're located, you have rights to access, correct, delete, or export your personal data, and to object to or restrict certain processing - under India's DPDP Act 2023, the EU/UK GDPR, and comparable US state privacy laws. To exercise any of these, write to privacy@custelis.com. We'll respond within the time your applicable law requires (30 days under DPDP Act practice absent a shorter statutory deadline).

Retention

We keep account and billing data for as long as your workspace is active, plus the period our own legal, tax, and audit obligations require after that. Ask privacy@custelis.com for account deletion at any time; we'll confirm what's deleted immediately and what's retained under a specific legal obligation, and for how long.

Part B - data the Custelis product processes for a customer

When an organization deploys Custelis on its employees' company-managed devices, that organization is the data controller (the "Data Fiduciary" under India's DPDP Act) for the activity, DLP, and device data collected. Custelis acts as its data processor - we process that data on the customer's instructions, under contract, and we don't use it for our own purposes.

If you're an employee at a company using Custelis: your employer decides what's monitored, for how long data is kept, and who can access it. To see exactly what's held about you, use the self-service transparency portal your employer's Custelis workspace gives you - it shows your own record counts and lets you raise access, correction, erasure, grievance, and nomination requests directly. If you'd rather go through a person, that request goes to your employer's compliance team first, since they're the ones who control the data and can act on it - we (Custelis) do not independently field or resolve data-principal requests from a customer's employees.

What the product is built to never capture, regardless of configuration: keystrokes, passwords or credentials, webcam or microphone recordings, or anything from a personal or BYOD device. This is enforced in code, not policy - see the DPDP section of the product page for the full mechanics.

Changes to this policy

If we make a material change, we'll update the effective date above and, for signed-in customers, post a notice in the product. Continued use after a change means you accept the update.

This page describes our current practices in plain language. It is not a substitute for formal legal advice about your own obligations, and the bracketed registration details above are placeholders pending completion by Oris Intelligence Private Limited's counsel - do not treat this page as final until they're filled in.