OrixPrivacy
Privacy Policy
Effective date: 1 October 2026 · Last updated: 1 October 2026
1. Operator and contact
Orix is operated by AlphaMarkex LLP. Registered address: C/O Ravi Prakash Srivastava, 1429/1, Oro Dental Clinic, Mahuwaria, Mirzapur, Uttar Pradesh 231001, India. GSTIN: 09ACMFA9676Q1Z5. For privacy requests, data-protection questions and grievances, email support@orixhq.com. Customers may use these registered supplier details for statutory correspondence.
2. Data we process
Depending on the features used, Orix may process account name, email, phone number, company and billing details, client information, task/project records, invoices, payment references, profile information, uploaded business documents, authentication/session information, security logs, device/network information and optional analytics information. Orix does not intentionally require Aadhaar or identity-document uploads for ordinary workspace use.
3. Employee work-location and activity data
If an organisation enables Work Location Sharing, Orix may process location coordinates and related technical information while that feature is active. Orix may also process work-session/activity information when an organisation enables those features. The organisation controls these workplace features and is responsible for giving affected people an appropriate notice and lawful basis. Orix does not treat a device permission grant, by itself, as consent to start Orix location sharing.
4. Purposes
- create and secure accounts and workspaces;
- provide tasks, clients, invoices, meetings, collaboration and other requested features;
- process and reconcile payments;
- send service, security and account notices;
- prevent fraud, abuse and unauthorised access;
- maintain service reliability and security; and
- meet applicable contractual, accounting, tax and legal obligations.
5. Legal basis and consent
Orix uses the legal basis appropriate to the processing and applicable law. Where consent is required, Orix seeks a clear affirmative action and provides a practical withdrawal mechanism. Withdrawal does not affect processing that is necessary for a service already requested or otherwise permitted/required by law.
6. Customer organisations and service providers
For customer-entered employee/client information, the customer organisation determines many purposes and access rules, while Orix provides the hosted workspace. Orix may use hosting, database, authentication, email, analytics and payment providers to operate the service. Access is limited to what is reasonably necessary and providers are expected to maintain appropriate security and confidentiality controls.
7. Security
Orix uses HTTPS, role-based access controls, server-side authorisation, protected sessions, rate limiting, security headers, restricted administrative access and database controls appropriate to the service. No online service can guarantee absolute security. Suspected security incidents should be reported immediately to support@orixhq.com.
8. Data minimisation and sensitive identity information
Ordinary Orix onboarding does not require Aadhaar numbers or identity-document scans. Customers should not upload unnecessary sensitive identity information. Existing legacy identity fields are being retired and are not part of the normal Orix workflow.
9. Retention
Orix retains personal data only for as long as reasonably necessary for the stated purposes, active contractual/service needs, security, dispute resolution and applicable legal/accounting requirements. When retention is no longer required, data should be deleted or anonymised, subject to lawful retention requirements.
10. Requests, correction, erasure and grievances
Requests concerning access, correction, erasure, withdrawal of consent or grievances may be sent to support@orixhq.com. Include the account email, organisation and the specific request. Orix may verify identity before acting. Where a customer organisation controls the relevant data, Orix may direct the requester to that organisation or assist it with the request. Complaints are logged and handled within the timeline required by applicable law.
11. Children's data
Orix is a business-workspace service and is not intended for children. Organisations must not create accounts for children where doing so would breach applicable law.
12. International processing
Orix and its service providers may process information in jurisdictions where the service infrastructure or provider operates. Where applicable, Orix will apply required contractual, technical and legal safeguards and provide disclosures required by law.
13. Indian data-protection framework
Orix is designed to support applicable Indian privacy and data-protection requirements, including the Digital Personal Data Protection framework as its provisions and rules become applicable. This policy does not remove a customer's independent legal responsibilities as an employer or business.