Legal

Privacy policy

Effective 29 September 2026

This policy explains how OpsMeld (“OpsMeld”, “we”, “us”) handles personal data when you visit opsmeld.com, use our products (Vantage ITSM and Expense Agent), or work with us on a consulting engagement. It is written to meet India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and to reflect the principles of the EU General Data Protection Regulation for customers who rely on it.

01Who we are

OpsMeldis a business based in India. It is in the process of being incorporated. Until incorporation is complete, the website and services are provided by OpsMeld’s founder, who is responsible for the personal data described in this policy. We will update this policy with the registered company name and address once they are issued.

You can reach us about anything in this policy at privacy@opsmeld.com.

02Our role: fiduciary or processor

Where we decide why and how data is used (for example, enquiries you send us, website requests, and the administrator account for your organisation), we act as the data fiduciary (controller).

Where we handle data on a customer’s behalf (for example, tickets, assets, employee records, and expense claims that a customer stores in Vantage ITSM or Expense Agent), the customer is the data fiduciary and we act as its data processor. We process that data only on the customer’s documented instructions. If you are an employee or end user of one of our customers, please direct privacy requests to that organisation first; we will support them in responding.

03Personal data we collect

When you contact us or visit the website

  • Name, work email, company, and anything else you include in an email or enquiry.
  • Standard web server logs kept by our hosting provider, such as IP address, browser type, requested page, and time of request. The marketing website does not use analytics or advertising trackers.

When your organisation uses our products

  • Account data: name, work email, role, department, and a salted hash of your password (never the password itself).
  • Content your organisation enters: tickets, comments, attachments, asset and configuration records, change and problem records, employee onboarding details, expense claims, receipts, and advance requests.
  • Audit data: which user performed which action and when, and the IP address of certain requests, kept for security and accountability.
  • Email content, where your organisation connects a mailbox so that emails become tickets.
  • For Expense Agent, reference data read from your Microsoft Dynamics 365 Business Central company (employees, vendors, accounts, dimensions) and messages exchanged with the agent in Microsoft Teams.

When we deliver consulting work

  • Business contact details of your project team, and any personal data contained in systems we are given access to for the engagement.

04How we use personal data

  • To provide, secure, and support the products and services you or your organisation have asked for.
  • To create and manage accounts, authenticate users, and prevent misuse such as brute-force login attempts.
  • To respond to enquiries and to communicate about the service, including security and billing notices.
  • To keep audit trails and to investigate incidents.
  • To meet legal, tax, and accounting obligations.

We do not sell personal data, and we do not use customer content to train general-purpose AI models.

Grounds for processing. We process data where you have given consent, where it is needed to provide a service you requested, for the legitimate uses permitted under section 7 of the DPDP Act, or where the law requires it. Where we rely on consent, you can withdraw it at any time by writing to us; this does not affect processing that took place before withdrawal.

05AI features

Some product features use AI models to assist users. In each case a person reviews the result before it is acted on.

  • Vantage ITSM email triage (optional). If your organisation enables it, the sender, subject, and the first part of an inbound email are sent to the Google Gemini API to classify the email and suggest a category and priority. It is off unless an administrator configures it.
  • Expense Agent. Receipt images and chat messages are processed to extract expense details and to understand requests, using the AI provider the customer configures (Anthropic, OpenAI, or Google). Extracted values are shown to the employee for confirmation, and nothing is posted to Business Central until it has been approved.

The providers used for these features are listed on our subprocessors page.

06Who we share data with

  • Service providers who host, store, or transmit data for us, bound by contract to use it only for that purpose. The current list is on our subprocessors page.
  • Systems you connect, such as your Microsoft 365 tenant or Business Central company, when you configure an integration.
  • Authorities where disclosure is required by law or to protect rights and safety.
  • A successor business if OpsMeld is involved in a merger or acquisition, subject to this policy.

OpsMeld personnel can access customer workspaces and platform usage records only where needed to operate, support, or secure the service, and such access is limited to authorised staff.

07International transfers

Some of our service providers store or process data outside India, including in the United States. Where we transfer data, we do so only to countries not restricted by the Government of India under the DPDP Act and under contracts that require appropriate protection. Customers who need data kept within their own infrastructure can run Vantage ITSM on-premises.

08How long we keep data

  • Enquiry emails: for as long as needed to respond and follow up, then up to 24 months.
  • Customer content: for the life of the subscription. After it ends, we delete it within 90 days unless the customer asks for earlier deletion or the law requires us to keep it.
  • Audit and security logs: for the life of the workspace, so that customers retain a complete record.
  • Invoices and accounting records: for the period required by Indian tax and company law.

09How we protect data

We use technical and organisational measures appropriate to the risk, including workspace isolation enforced in the database, role-based access control, hashed passwords, signed and expiring session tokens, encrypted connections, and rate limiting on sign-in. Details are on our security page. If a personal data breach occurs, we will notify affected customers and the Data Protection Board of India as the DPDP Act requires.

10Your rights

Subject to applicable law, you can ask us to:

  • give you a summary of the personal data we hold about you and how it is processed;
  • correct, complete, or update your personal data;
  • erase personal data that is no longer needed, or that you have withdrawn consent for;
  • nominate another person to exercise your rights in the event of your death or incapacity;
  • address a grievance about how your data has been handled.

Write to privacy@opsmeld.com. We will verify your identity and respond within 30 days. If your data sits in a customer’s workspace, we will pass your request to that customer.

11Grievance officer

If you are not satisfied with our response, you can write to our grievance officer at grievance@opsmeld.com. This address is monitored by the person responsible for data protection at OpsMeld.

We will acknowledge a grievance within 48 hours and aim to resolve it within 30 days. If it remains unresolved, you may approach the Data Protection Board of India.

12Children

Our website and products are intended for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18.

13Cookies

We use only the cookies needed to keep you signed in to our products. See our cookie policy.

14Changes to this policy

We will update the effective date above when we change this policy, and notify customers of material changes by email or in the product before they take effect.