Last Updated: February 11, 2026

Privacy Policy

This Privacy Policy (“Policy”) describes how personal and telemetry data is collected, processed, and safeguarded when using the website, applications, products, and services operated by NRV DesignX Private Limited.

1. Scope & Applicability

This Policy applies to the access and use of the website, platforms, and services operated by NRV DesignX Private Limited (hereinafter referred to as “DesignX”, “Df-OS”, “Digital Factory Operating System”, “Vish”, “we”, “us”, or “our”). We are committed to protecting the privacy and security of the personal data of our individual users and enterprise customers (“you” or “your”).

This Policy describes the types of information that are collected and recorded by us, the purposes for which such information is processed, including through our services, products, and platforms (collectively, the “Services” or “Df-OS”), and explains how such information is used, shared, stored, and protected in compliance with applicable laws, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 (“IT Act”), and other applicable data protection rules.

This Policy applies to all individuals who access or use the Services or otherwise interact with us. It does not apply to personal data collected or processed by third-party applications, websites, or systems not owned or controlled by DesignX.


2. Data Protection Roles & Frameworks

Under the Indian Digital Personal Data Protection Act, 2023 (DPDP Act), data roles are explicitly divided depending on the nature of interaction:

DesignX as Data Fiduciary

We act as a Data Fiduciary when determining the purpose and means of processing personal data for our own business activities. This includes when you browse our website, sign up for a demo, register an account, or contact our sales and support teams.

DesignX as Data Processor

We act as a Data Processor when processing telemetry, shopfloor machine logs, factory operational parameters, or IoT device metrics on behalf of our enterprise customers. In these scenarios, the enterprise customer is the Data Fiduciary who owns the data and controls its processing instructions.

We strictly process customer-owned data on the instructions of the respective Data Fiduciary (the enterprise customer) and do not use it for independent commercial or advertising purposes.



4. Information We Collect

We collect information to provide, maintain, and optimize our Digital Factory Operating System. The information we collect falls into the following categories:

  • Information You Provide Voluntarily: This includes name, professional email address, telephone numbers, company details, job title, and communications when you request a demo, fill out forms, register an account, or submit customer support tickets.
  • Shopfloor & IoT Device Data: Depending on the configuration of Df-OS by your organization, we process device telemetry, system logs, hardware identifiers, machine performance metrics, and operational metadata generated from factory machines, IoT sensors, Edge gateways (e.g., Hectos), and applications.
  • Location and Safety Data: With explicit, informed user consent (only where necessary for safety, workforce mapping, or localized operations), we may process geographical coordinates and proximity telemetry.

5. How We Use Your Information

We use the collected information solely for specified, legitimate, and lawful purposes in connection with Df-OS:

  • Provide, operate, and maintain Df-OS software platforms.
  • Improve, personalize, optimize, and expand the functionality of Df-OS.
  • Perform system analytics to monitor shopfloor performance and reliability.
  • Provide user support, address security alerts, and send system updates.
  • Detect, prevent, and mitigate cybersecurity incidents, fraud, or misuse.
  • Comply with applicable statutory regulations and legal disclosures.

6. Industrial IoT & Factory Data Ownership

Data generated within our customers' production environments—including machine cycles, line speeds, production volumes, quality parameters, and maintenance logs—remains the sole and exclusive property of the respective enterprise customer.

We act strictly as a data processor for such information. We do not monetize, sell, or use customer operational data for any independent or commercial purposes. We may compile anonymized, aggregated, and de-identified metrics that do not reference any specific individual or customer to monitor infrastructure reliability and enhance our software modules in compliance with applicable laws.


7. Location Information

To coordinate and verify site operations or ensure worker safety inside a facility, some Df-OS mobile modules may request permission to access location data.

We collect and process location coordinates only with your explicit permission and strictly when necessary for the execution of the requested Service. We do not access location telemetry in the background unless explicitly required for safety-monitoring features and approved by the user. Disabling location services in your device settings will stop this collection, though it may limit the functionality of localized safety alerts or routing modules.


8. Log Files & Cookies

Log Files: Df-OS follows a standard procedure of using server log files. The technical details collected include Internet Protocol (IP) addresses, browser types, Internet Service Providers (ISP), timestamps, and navigation tracking. This data is not linked to any personally identifiable information offline; it is collected for auditing, security logging, and optimizing performance.

Cookies and Web Beacons: We use cookies to enhance website navigation, manage sessions, and remember user preferences. You can configure your web browser to refuse or block cookies, though some portions of our web platform may not operate correctly without them.


9. Third-Party Data Processing

We do not sell, trade, or otherwise transfer your personal data to outside parties for promotional purposes. We may share limited personal and telemetry data with verified third-party partners and sub-processors who assist us in operating our platform, carrying out hosting services (e.g. secure cloud infrastructure), conducting data analytics, or providing security controls.

All such sub-processors are bound by strict contractual obligations and confidentiality requirements to ensure they process data solely under our instructions and maintain security standards aligned with this Policy.


10. Data Retention & Deletion

We retain your personal data only for as long as is reasonably necessary to fulfill the specific purposes outlined in this Policy, including providing Df-OS, complying with legal or tax regulations, resolving disputes, and executing agreements.

For data where we act as a Data Processor, we retain information in accordance with the timelines and terms specified in the agreement with the respective Data Fiduciary (the enterprise customer). Upon the expiration of the retention timeline or direct request by the customer, we securely delete, destroy, or anonymize the data in accordance with industry-standard practices.


11. Security Safeguards

We implement appropriate and robust technical and organizational measures designed to secure personal and industrial telemetry data. These safeguards include, but are not limited to:

  • Data encryption in transit (via SSL/TLS) and at rest (using AES-256).
  • Strict Role-Based Access Controls (RBAC) to ensure only authorized personnel access data.
  • Regular vulnerability assessments, penetration testing, and security code reviews.
  • Secure OT-to-IT cloud connections using encrypted APIs and gateway credentials.

While we strive to match industry-standard protocols to protect your information, no transmission method over the internet or physical storage system can be guaranteed 100% secure.


12. Grievance Redressal & Contact Information

Under the DPDP Act 2023, you have the right to register grievances, seek correction of personal details, or request erasure of personal data. DesignX has appointed a designated Grievance Officer to address queries or complaints regarding this Privacy Policy and our processing of your information.

Contact Details

NRV DesignX Private Limited

Block B-26 & 27, 3rd floor, Sector-1,

Noida, Uttar Pradesh - 201301, India


13. Data Breach Notification

In the event of a personal data breach or unauthorized system exposure, we will evaluate the impact and notify affected users and/or relevant regulatory authorities (such as the Data Protection Board of India or CERT-In) in compliance with the timelines and procedures prescribed by applicable laws.


14. Children's Privacy

Df-OS is an enterprise industrial platform intended strictly for use by working professionals. We do not knowingly collect, store, or process information from children under the age of 18 years, or individuals with legal disabilities. If a parent or guardian becomes aware that a child has provided us with personal information, they should contact us immediately so we can take steps to remove such records.


15. Updates to this Policy

This Policy is effective from February 11, 2026, and supersedes all prior versions. We may periodically update our data practices to reflect security advancements or regulatory changes.

We will notify you of any material changes by posting the updated Privacy Policy directly on our website or applications. We encourage you to review this page periodically to stay informed about how we protect your personal and industrial information.


16. Governing Law & Jurisdiction

Any legal claim, dispute, or interpretation arising under this Privacy Policy shall be governed by and construed in accordance with the laws of India.

All disputes arising out of or in connection with the access, usage, or security of the Services shall be subject to the exclusive jurisdiction of the courts located in Delhi, India.