Privacy policy
What we hold about you, why we hold it, where it sits, and what you can make us do with it.
1. Who holds your data
OMLINUX, operated by PwTech of Rajkot, Gujarat, India. We are the data fiduciary for your account and billing records. For whatever you store on a server you rent from us, you are the fiduciary and we are the processor — we do not look inside it except to operate the service, fix a fault, or where the law requires it.
2. What we collect
- Account details you give us: name, email address, phone number, company name and billing address.
- Tax and identity details where they apply: GSTIN, PAN, and any identity document you upload for verification.
- Billing records: what you ordered, what you were invoiced, what you paid and when.
- Technical records generated by using the service: IP addresses, server and access logs, resource usage.
- What you send us: support tickets, chat messages, emails and anything attached to them.
We never see your card number. Card payments are handled on the payment provider's own systems; we receive only the result of the transaction and a reference.
3. Why we hold it
- To provide and operate the service you bought, and to support it when something breaks.
- To invoice you, take payment, and meet our own tax and accounting obligations.
- To send you service notices — maintenance, incidents, renewals, invoices. These are not marketing and you cannot unsubscribe from them while you hold a service.
- To detect and stop abuse of our network.
We do not sell your data, and we do not share it with anyone for their own marketing.
4. Where it is held
Services run in one of four facilities: our own in Rajkot, and rented racks in Ahmedabad, Navi Mumbai and Helsinki. If your service runs in Helsinki, the data on it is held in Finland, inside the European Union — the datacentres page names the operator and the country of every site, and your service page tells you which one you are on.
Our public website is served through Cloudflare, which sees the IP address and request details of visitors as traffic passes through it.
5. Security — what we actually do
Traffic to this site and to your client area is encrypted in transit with TLS. Passwords are stored hashed, never in a readable form, and the credentials our platform holds for third-party systems are encrypted at rest. Access to customer records is limited to the people who need it to do their job.
6. Cookies
This website sets two cookies, both strictly functional: a session cookie that keeps you signed in, and a CSRF token that stops another site from submitting our forms on your behalf. There is no analytics, no advertising pixel and no third-party tracker on these pages — you can confirm that in your browser's developer tools, which is why there is no cookie banner to click through.
7. Support and AI assistance
Support conversations are stored against your account so that whoever picks up your next ticket can see the history. Where an automated assistant answers first, it currently runs on hardware we operate rather than a third-party AI service. If that ever changes, we will say so here before it does.
8. Who else touches it
Payment providers, to take payment. The operators of the facilities our servers sit in. Communication providers, to deliver email and messages to you. Cloudflare, in front of this website. Each gets only what it needs to do that job, and none is permitted to use your data for anything else.
We disclose data to a public authority only where we are legally obliged to, and we tell you when we are permitted to tell you.
9. How long we keep it
Account and support records last as long as your account does. Invoices, tax records and the transactions behind them are kept for as long as Indian tax and company law requires, which is longer than your account may last. Data on a server you cancel is deleted when the service is decommissioned, so take your copy before you cancel.
10. Your rights
Under India's Digital Personal Data Protection Act, 2023 you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to erase it where we are not required to keep it, and nominate someone to exercise these rights if you cannot. If you are in the European Union — which you may be if your service is in Helsinki — you have equivalent rights under the GDPR, and we will handle your request on the same terms.
Ask by email or by raising a ticket, and we will answer. We do not employ a data protection officer; your request reaches the people who run the company.
11. Children
Our services are sold to businesses and adults. We do not knowingly collect data about anyone under 18, and we will delete it if we discover we have.
12. Changes, and how to reach us
If we change this policy materially we will update the date above and tell existing customers by email. Questions, complaints and data requests go to [email protected]. If we cannot resolve a complaint you may take it to the Data Protection Board of India.