Legal

Privacy Policy

Last updated on 20 September 2026

This privacy policy sets out how Opscale Technologies (OPC) Private Limited (One Person Company) ("Opscale", "we", "us") uses and protects any information that you give Opscale when you use this website (https://www.opscale.io), the Opscale application at https://app.opscale.io (including the signup page at https://app.opscale.io/signup and the dashboard), and the customer workspaces we host at {customer}.chat.opscale.io, {customer}.desktop.opscale.io and {customer}.control.opscale.io (together, the "Services"). Opscale is a One Person Company incorporated under the Companies Act, 2013, with its registered office at HD-037, WeWork Prestige Atlanta, 80 Feet Main Road, Koramangala 1A Block, Industrial Layout, Bengaluru, Karnataka 560034, India (GSTIN 29AACCO4519R2ZQ).

This policy is published in accordance with Section 43A of the Information Technology Act, 2000, Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (the "SPDI Rules") and Rule 3(1)(a) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and has been written to meet the standards of the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the rules made under it. The substantive provisions of the DPDP Act (sections 3 to 17) and of the DPDP Rules, 2025 have been notified but have not yet commenced as at the date of this policy; until they do, the IT Act and the SPDI Rules govern, and the DPDP rights and standards described in this policy are ones we apply voluntarily in advance of commencement. This policy applies to visitors of our website, to customers and their authorised users of the application, and to individuals who contact us. By using the Services, submitting the contact form or creating an account you agree to the practices described here. Opscale may change this policy from time to time by updating this page; see section 17. Our Terms and Conditions (/terms-and-conditions) and Cancellation and Refund Policy (/cancellation-and-refunds) form part of your relationship with us.

1. Who we are and our role

The entity responsible for your personal data (the "data fiduciary" under the DPDP Act and the "body corporate" under the SPDI Rules) is Opscale Technologies (OPC) Private Limited (One Person Company), HD-037, WeWork Prestige Atlanta, 80 Feet Main Road, Koramangala 1A Block, Industrial Layout, Bengaluru, Karnataka 560034, India. Email: business@opscale.io. Website: https://www.opscale.io.

We act in two different roles. For data about website visitors, prospects, account holders, billing and usage logs (sections 2, 3(a), 3(b) and 3(d)), Opscale decides the purposes and means of processing and is the data fiduciary. For content that you or your team give to your AI agents inside your workspace, including personal data of your own employees, customers or end-users ("Customer Content", section 3(c)), you are the data fiduciary and Opscale acts as a data processor on your instructions, solely to provide the Services you have subscribed to. You are responsible for giving any notices and obtaining any consents that your own end-users are entitled to before you place their data in your workspace.

2. Information we collect on the website (www.opscale.io)

  • Contact form: when you submit the contact form at /contact we collect your name, email address, company, subject and your message. The form is delivered to us through Formspree, a third-party form-processing service that may process submissions outside India.
  • Product analytics: we use PostHog to understand how the website is used. PostHog records page views, clicks and form-submission events, the page you came from (referrer), your device, browser and operating system information, an approximate location derived from your IP address, and identifiers stored in cookies or browser local storage that recognise your browser on later visits.
  • Server and hosting logs: the website is a static site hosted on Vercel. Vercel's infrastructure generates standard server logs (IP address, requested URL, time, user agent) for security and operational purposes.

3. Information we collect in the application (app.opscale.io and your workspace)

(a) Account data. When you sign up at https://app.opscale.io/signup we collect your name, work email address, company name, the agent departments you select (for example Engineering, Marketing, Sales, Operations, Finance or Customer Success), your timezone and, if you choose to supply one, your own OpenRouter API key.

(b) Authentication and billing data. We authenticate you through magic links sent to your work email; the transactional email is delivered through Amazon Simple Email Service (Amazon SES). Payments are collected through authorised third-party payment gateways such as Razorpay. We receive the transaction reference, amount, currency, date, payment status and the limited details needed to identify the payment method (for example the card network and last four digits, where the gateway provides them). Opscale does not receive or store full card numbers, CVV or expiry dates.

(c) Customer Content. Your AI agents process the content you and your team provide inside your private, isolated hosted workspace: chat messages, files, documents, code, data pulled from integrations you connect (for example GitHub, Slack, Linear, HubSpot, Notion, QuickBooks or Intercom) and the credentials, tokens or API keys you supply to connect those integrations. Agents act only within the permissions you grant.

(d) Usage and technical logs. We record technical events generated by your workspace and the dashboard, such as login events, agent runs, errors, IP addresses, timestamps and resource usage, to operate, secure, monitor and tune the Services.

4. Sensitive personal data or information

Some of the information above is "sensitive personal data or information" under Rule 3 of the SPDI Rules, in particular integration credentials and API keys you supply, and financial information relating to your payments. Customer Content may also contain sensitive personal data of your end-users. By creating an account and supplying such information you consent, in writing within the meaning of Rule 5(1) of the SPDI Rules, to our collection and use of it for the purposes in section 5. You may decline to provide sensitive information (for example, you are never required to supply your own OpenRouter key or to connect any integration), and you may withdraw consent at any time under section 13; if you do so we may be unable to provide some or all of the Services. We do not publish sensitive personal data, and we require every recipient listed in section 7 to keep it confidential.

5. Purposes and lawful basis

We process personal data only for the purposes below and rely on the following lawful bases: your consent (Rule 5 of the SPDI Rules and, once in force, section 6 of the DPDP Act); the voluntary provision of personal data by you for the purpose of receiving the Services you have requested (a "legitimate use" under section 7(a) of the DPDP Act, once in force), which we refer to below as "contract"; and compliance with legal obligations (section 7(b) and (c) of the DPDP Act, once in force).

  • To respond to enquiries submitted through the contact form and to follow up on your interest in our Services (basis: consent and voluntary provision of data).
  • To create and secure your account, authenticate you through magic links, and provision your workspace, typically within a few minutes and in any case within 24 hours of payment (basis: contract).
  • To operate your AI agents and process Customer Content on your instructions, including passing prompts and content to large language model providers via OpenRouter (basis: contract; for Customer Content we act as your processor).
  • To collect subscription fees, issue invoices, process refunds under /cancellation-and-refunds and maintain accounting records (basis: contract and legal obligation, including GST and company law).
  • To provide support, human-in-the-loop review checkpoints, and continuous monitoring and tuning of your agents (basis: contract).
  • To monitor security, detect abuse or fraud, maintain logs, investigate incidents and comply with directions of the Indian Computer Emergency Response Team (CERT-In) (basis: legal obligation and legitimate use).
  • To measure and improve the website and the Services through analytics (basis: your voluntary use of the website, subject to the opt-out described in section 6).
  • To send you service notices about your account, billing, security or changes to our terms and policies (basis: contract).
  • To send you marketing communications about Opscale only where you have agreed to receive them or have contacted us about our Services; you may opt out at any time as described in section 15.
  • To comply with applicable law, court orders and lawful requests from government agencies, and to establish or defend legal claims.

We do not use Customer Content or your inputs and outputs to train or fine-tune any AI model unless you give us your written opt-in. When requests are made through our OpenRouter account, each model provider processes data under OpenRouter's and its own data-use terms, as described in section 7; we do not knowingly enable provider-side training on your data. If you supply your own OpenRouter API key, the retention and training settings of your own OpenRouter account apply and are your responsibility. We do not sell, rent or lease your personal information to anyone.

6. Cookies and analytics, and how to opt out

Cookies are small text files placed on your device by a website; local storage identifiers work in a similar way. Our website uses cookies and local storage for two purposes: (i) strictly necessary storage needed for the site and application to function, such as keeping you signed in to the dashboard; and (ii) analytics, through PostHog, which stores a pseudonymous identifier that recognises your browser and records page views, clicks and events so that we can see which pages are used and how the site performs. PostHog data is hosted in the United States. We do not use advertising cookies and we do not serve targeted advertising.

You can opt out of analytics at any time by: blocking or deleting cookies and site data for opscale.io in your browser settings (most browsers let you refuse all or third-party cookies and clear local storage); using a content-blocking browser extension that blocks analytics scripts; or writing to business@opscale.io asking us to exclude your identifier from analytics. Refusing analytics cookies does not affect your ability to use the website or the application; refusing strictly necessary storage may prevent you from signing in.

7. Who we share information with

We share personal data with the following recipients. Those in the first seven bullets are our service providers (data processors) bound by contracts restricting their use of the data to providing services to us, except that, where you supply your own OpenRouter API key, OpenRouter acts under your own account and terms rather than ours; the tools in the last bullet are independent services you choose to connect and are not our processors.

  • Amazon Web Services (AWS), Mumbai region (ap-south-1): hosting of the application, dashboard and all customer workspaces, and storage of Customer Content and logs.
  • Vercel: hosting and content delivery for the marketing website, including server logs.
  • OpenRouter and the underlying model providers it routes to (which may include Anthropic, OpenAI, Google, MiniMax and others): processing of prompts, Customer Content and agent instructions to generate agent responses. If you supply your own OpenRouter API key, requests are made under your OpenRouter account and OpenRouter's terms.
  • Formspree: receipt and forwarding of contact-form submissions.
  • PostHog (hosted in the USA): website product analytics as described in section 6.
  • Amazon SES: delivery of magic-link sign-in emails and other transactional emails.
  • Razorpay and any other authorised payment gateway we use: collection of subscription payments and processing of refunds. The gateway handles your card or bank details under its own privacy policy and the PCI DSS security standard; Opscale does not store full card details. Razorpay's privacy policy is available at https://razorpay.com/privacy/.
  • Third-party tools you choose to connect to your agents (for example GitHub, Slack, Linear, HubSpot, Notion, QuickBooks or Intercom): data flows to and from these tools only because you connected them and only within the permissions you granted; each is governed by its own terms and privacy policy.

We may also disclose personal data (a) to government agencies mandated under law, on a written request, for the purpose of verifying identity or for the prevention, detection, investigation or prosecution of offences, as permitted by Rule 6 of the SPDI Rules; (b) where required by a court order or applicable law; (c) to our professional advisers, auditors and insurers under confidentiality obligations; and (d) to a successor entity if Opscale is merged, acquired or sells its business, in which case we will notify you by email before your data becomes subject to a different privacy policy. Any third party receiving personal data from us is prohibited from disclosing it further except as permitted above.

8. International transfers

Your account data, Customer Content and workspace logs are stored in India, on AWS in the Mumbai region. However, some processing necessarily takes place outside India: the marketing website is served by Vercel and contact-form submissions are handled by Formspree, both of which may process data outside India; PostHog analytics data is hosted in the United States; and prompts and Customer Content sent to your agents are transmitted through OpenRouter to model providers that may process the data outside India, including in the United States. Where you connect a third-party integration, data is exchanged with that provider wherever it operates.

In accordance with Rule 7 of the SPDI Rules, we transfer information abroad only where it is necessary to perform our contract with you or where you have consented, and only to recipients that are contractually required to provide the same level of data protection as that required under Indian law. By using the Services you consent to these transfers. The DPDP Act, once in force, permits transfers to any country other than those the Central Government may restrict by notification; if a country we rely on is restricted, we will stop the transfer or obtain your fresh consent. Customers in the European Union or United Kingdom who need a data processing agreement for their end-user data may request one at business@opscale.io.

9. How AI agents use your data

Your agents are powered by third-party large language models accessed through the OpenRouter API. Each time an agent acts, the relevant instructions and Customer Content are sent to the selected model provider and the response is returned to your workspace. Agents can only read and act on the data and integrations you connect, within the permissions you set in the dashboard, and you may revoke those permissions at any time. AI outputs may be inaccurate or incomplete; you must review them before relying on them, and decisions taken by agents remain under your control. Your workspace is private and containerised, and Customer Content is not shared with other Opscale customers.

10. Retention

We keep personal data only for as long as it is needed for the purposes in section 5 or as required by law, and we do not retain sensitive personal data for longer than lawfully required, as Rule 5(4) of the SPDI Rules demands. In particular:

  • Contact-form submissions: retained for no longer than 12 months after our last correspondence with you, unless you become a customer, in which case the account retention period below applies; you may ask us to delete them at any time under section 13.
  • Account data, Customer Content and workspace configuration: retained for the life of your subscription. When your subscription ends (cancellation takes effect at the end of the current monthly billing period, as set out at /cancellation-and-refunds), we retain your workspace data for 30 days so that you can request an export by emailing business@opscale.io, as described in section 8 of our Terms and Conditions, after which we delete or anonymise your workspace and Customer Content from our active systems; residual copies in backups are removed in our ordinary backup rotation, subject to the legal exceptions below. You may request earlier deletion under section 13.
  • Security, access and system logs: retained for at least 180 days within India, as required by the CERT-In Directions of 28 April 2022 issued under Section 70B of the Information Technology Act, 2000, after which they are deleted or anonymised.
  • Billing records, invoices and payment references: retained for 8 years from the end of the financial year to which they relate, being the longer of the periods required by section 128 of the Companies Act, 2013 and section 36 of the Central Goods and Services Tax Act, 2017.
  • Analytics data in PostHog: retained in line with the retention period configured in our PostHog account and for no longer than 12 months from collection; you can prevent further collection as described in section 6.
  • Data needed to resolve a dispute, enforce our agreements or comply with a legal obligation: retained until that need ends.

11. Security practices

We maintain reasonable security practices and procedures as required by Rule 8 of the SPDI Rules and in anticipation of Section 8(5) of the DPDP Act, comprising managerial, technical, operational and physical controls proportionate to the data we handle. These controls include: hosting on AWS in an isolated, containerised workspace for each customer; encryption of data in transit using TLS on all pages of the website and application; password-less sign-in through single-use, emailed magic links; storage of integration credentials and API keys in a form not exposed to other customers; role-based access limited to personnel who need it; logging and monitoring of access; and contractual security obligations imposed on every processor listed in section 7. Payment card data is handled exclusively by our PCI DSS-compliant payment gateway. We do not, however, guarantee that the transmission of information over the internet is completely secure, and you are responsible for keeping your email account and any credentials you connect to your workspace secure.

12. Personal data breaches

If we become aware of a personal data breach affecting you, we will inform you without delay at your registered email address, describing the nature, extent and timing of the breach, its likely consequences, the measures we have taken or propose to take, the steps you can take to protect yourself, and the contact details of the person who can answer your questions. We report cyber security incidents to CERT-In within 6 hours of noticing them, as required by the CERT-In Directions of 28 April 2022, and, once the relevant provisions of the DPDP Act and rules commence, we will intimate the Data Protection Board of India without delay and provide it with a detailed report within 72 hours of becoming aware of the breach.

13. Your rights and how to exercise them

Under the SPDI Rules and, in anticipation of the DPDP Act, you have the following rights in respect of the personal data for which Opscale is the data fiduciary:

  • Access: to obtain a summary of the personal data we hold about you, the processing activities we carry out, and the identities of the processors and other fiduciaries with whom it has been shared.
  • Correction and completion: to have inaccurate or incomplete data corrected or updated. Account details can be edited in the dashboard; other corrections can be requested by email.
  • Erasure: to have your personal data deleted where it is no longer needed for the purpose for which it was collected, unless retention is required by law.
  • Withdrawal of consent: to withdraw any consent you have given, as easily as you gave it, without affecting the lawfulness of processing before withdrawal. We will stop the relevant processing within a reasonable time; withdrawing consent needed to run the Services may mean we cannot continue to provide them.
  • Grievance redressal: to have any complaint about our handling of your personal data addressed by our Grievance Officer (section 19).
  • Nomination: to nominate another individual who may exercise these rights on your behalf in the event of your death or incapacity.

To exercise any right, email business@opscale.io from your registered email address, quoting your registered email and company name so that we can verify your identity, or write to the address in section 19. We will acknowledge your request within 48 hours with a reference number and respond within 30 days, and in every case within the time limit required by applicable law (which, under the DPDP Act, will not exceed 90 days). If your request is a complaint, the grievance timelines in section 19 apply. If you are not satisfied with our response after exhausting this process, you may, once the relevant provisions of the DPDP Act are in force, complain to the Data Protection Board of India. If your request concerns personal data contained in Customer Content of one of our customers, we will refer your request to that customer, who is the data fiduciary for that data, and assist them in responding.

14. Children

The Services are intended for business use by persons aged 18 years or older acting on behalf of a company or other organisation. They are not directed at children and we do not knowingly collect personal data from anyone under 18. By signing up you represent that you are at least 18 years old and are authorised to bind the entity on whose behalf you are acting. If we learn that we have collected personal data from a person under 18, we will delete it. We do not carry out tracking, behavioural monitoring or targeted advertising directed at children.

15. Marketing communications and controlling your information

We will only send you marketing emails about our Services if you have agreed to receive them or have enquired about our Services through the contact form. Every marketing email includes a way to unsubscribe, and you may also opt out, or change your mind about any use of your data for marketing, at any time by emailing business@opscale.io. Service notices about your account, security, billing or policy changes are not marketing and will continue while you hold an account. We will not sell, distribute or lease your personal information to third parties unless we have your permission or are required by law to do so.

17. Changes to this policy

We may update this policy from time to time to reflect changes in the Services, our processors or the law. The date at the top of this page shows when it was last revised. For material changes, such as a new purpose of processing or a new category of processor, we will notify account holders by email at their registered address before the change takes effect, and where the law requires it we will ask for your fresh consent. Continued use of the Services after the effective date of a non-material change constitutes acceptance of the revised policy. We also remind account holders of this policy, our Terms and Conditions (/terms-and-conditions) and our other policies at least once a year.

18. Governing law

This policy and any dispute arising out of it are governed by the laws of India, including the Information Technology Act, 2000, the SPDI Rules, 2011 and, once its relevant provisions commence, the Digital Personal Data Protection Act, 2023. The courts at Bengaluru, Karnataka have exclusive jurisdiction, without prejudice to your right to approach the Data Protection Board of India (once the relevant provisions of the DPDP Act empowering it to hear complaints commence) or any other authority with statutory jurisdiction.

19. Contact us and Grievance Officer

In accordance with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and Rule 4 of the Consumer Protection (E-Commerce) Rules, 2020, and in anticipation of Section 8(9) and 8(10) of the Digital Personal Data Protection Act, 2023, the name and contact details of our Grievance Officer and data protection contact are:

  • Name and designation: Anub Sinha, Founder and Director
  • Legal entity: Opscale Technologies (OPC) Private Limited (One Person Company)
  • Address: HD-037, WeWork Prestige Atlanta, 80 Feet Main Road, Koramangala 1A Block, Industrial Layout, Bengaluru, Karnataka 560034, India
  • Email: business@opscale.io
  • Support hours: Monday to Friday, 10:00 to 18:00 IST (excluding Indian public holidays)

You may raise any question, request or complaint about this policy or our handling of your personal data by email, or by post to the address above. We will acknowledge every complaint by email within 48 hours of receipt with a reference number, respond substantively within 5 business days, act on complaints about unlawful content within the timelines required by the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 where they apply to us, and resolve all complaints within 30 days of receipt. Further ways to reach us are listed at /contact.

Business and contact details

Legal name
Opscale Technologies (OPC) Private Limited
Registered address
HD-037, WeWork Prestige Atlanta80 Feet Main Road, Koramangala 1A BlockIndustrial Layout, BengaluruKarnataka 560034, India
Support hours
Monday to Friday, 10:00 to 18:00 IST
GSTIN
29AACCO4519R2ZQ
CIN
U74999KA2017OPC099577
Grievance Officer
Anub Sinha, Founder & Director