Privacy is a product principle at OCTYN, not just a legal requirement. This policy describes what we collect, why we collect it, how we protect it, and the choices you have when you use our website and cloud platform. By accessing or using OCTYN, you agree to the practices described here.
01 Our commitment
OCTYN is a cloud ERP platform built for Indian fuel stations and petroleum retailers. We handle sensitive financial and operational data every day — shift sales, reconciliation, payroll and more — so we design our systems around three commitments: collect only what we need, use it only for the purpose you expect, and secure it at every stage.
This policy covers all OCTYN products and services accessed through octynerp.com, including shift-wise operations and reconciliation, fuel purchase with OMC accounts, pricing and credit management, lubricants and non-fuel retail, GST-ready accounting and compliance, staff attendance and payroll, analytics and dashboards, and multi-station reporting.
02 Who we are
OCTYN is operated by Zenithyn Technologies Private Limited, an Indian technology company.
- Legal entity — Zenithyn Technologies Private Limited
- Website — www.octynerp.com
- Services — Cloud ERP for fuel stations: shift-wise operations & reconciliation, fuel purchase & OMC accounts, pricing & credit, lubricants & non-fuel retail, GST-ready accounting & compliance, staff attendance & payroll, analytics & dashboards, and multi-station reporting
- Jurisdiction — India
- Governing framework — IT Act 2000, the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011, and the Digital Personal Data Protection Act 2023
For privacy questions, write to [email protected].
03 Information we collect
What we collect depends on how you interact with OCTYN.
3.1 Information you give us directly
Account details — the account holder or business owner's name, business name and type, email, mobile number, business address, GSTIN, PAN (where applicable), and an encrypted password.
Business & financial data — invoices and billing records, customer and vendor details, employee and payroll data, bank details used for reconciliation, inventory and stock records, GST returns and tax data, and purchase/sales transactions processed through the platform.
Support & communication data — your name and email, the content of any request or complaint, chat and email correspondence, and survey or feedback responses.
Demo & enquiry data — the name, business name, size, location and requirement you share when you book a demo or fill a form.
3.2 Information we collect automatically
Device & technical data — IP address and approximate location, browser and version, operating system and device type, screen resolution, language and ISP.
Usage data — pages and features you visit, actions performed, time spent per module, forms submitted, and error or crash logs.
Cookies and browser storage — one preference cookie in the platform, the browser storage that keeps you signed in and remembers your settings, and cookieless analytics on the website, as detailed in our Cookie Policy.
3.3 Information from third parties
- GSTN portal — for GSTIN verification and e-invoicing
- Banking partners — for read-only bank feeds and reconciliation
- Payment gateways — for subscription payment processing
- Google / social sign-in — if you choose to sign in that way
- Referral partners — if a partner refers your account to us
04 How we use your information
4.1 To run the service
Create and manage your account, process invoices and GST returns, run payroll, sync and reconcile bank transactions, manage inventory and operations, and generate reports and dashboards.
4.2 To improve the platform
Understand how features are used, find and fix bugs, build new capabilities, and monitor uptime and performance.
4.3 To communicate with you
Send verification and account emails, product updates and release notes, GST filing reminders and compliance alerts, support responses, and billing receipts.
4.4 To meet legal obligations
Comply with GST and income-tax law, respond to lawful government requests, maintain required audit trails, and prevent fraud or unauthorised access.
4.5 For marketing (with consent)
Send newsletters and product tips, tell you about new modules and offers, run satisfaction surveys, and — only where you have consented — show relevant advertising.
05 Legal basis for processing
We process your data on one or more of the following bases:
- Contractual necessity — to deliver the services described in our Terms.
- Legal obligation — to comply with the IT Act, GST Act, Income Tax Act, Companies Act and applicable labour laws.
- Legitimate interests — to secure, improve and analyse the platform, where these interests do not override your rights.
- Consent — for marketing, non-essential cookies and certain data sharing, which you may withdraw at any time.
06 Data sharing & disclosure
OCTYN does not sell your personal data. We never trade, rent or monetise your information. We share data only in the limited situations below.
6.1 With service providers
We work with vetted providers who help us operate the platform. Each is contractually bound to use your data only for the agreed purpose and to maintain appropriate security.
| Partner type | Purpose | Data shared |
|---|---|---|
| Cloud infrastructure | Hosting & storage | Encrypted business data |
| Payment gateways | Subscription billing | Name, email, transaction amount |
| Email providers | Transactional email | Name, email address |
| AI document processing | Reading the purchase invoices you upload | Invoice documents |
| Analytics | Usage analytics | Anonymised usage data |
| GSTN portal | E-invoice & GST filing | GST transaction data |
| Banking partners | Bank feed integration | Read-only bank data |
6.2 With government & regulators
We may disclose information where required by a court order or statutory obligation, when requested by tax or law-enforcement authorities, or where necessary to protect the rights and safety of OCTYN and its users.
6.3 In a business transfer
If OCTYN is involved in a merger, acquisition or sale of assets, your data may transfer to the acquiring entity under the same protections described here. We will notify you before any such transfer.
6.4 With your consent
We share information with other parties — for example, giving your CA firm access to your account — only when you have authorised it.
07 Storage & retention
7.1 Where your data lives
Your records are stored in India: OCTYN's database is hosted in Mumbai. Some data is processed outside India: the purchase-invoice files you upload are read by AI on Cloudflare's global network, and an invoice it cannot read reliably may be sent to a second AI provider in the United States; the emails OCTYN sends go through our email provider in the United States. Our cloud and database services are provided by established platforms whose data centres maintain recognised security certifications such as ISO 27001 and SOC 2; these certifications are held by those infrastructure providers. The full list of providers that process your business data is in our Data Processing Agreement.
7.2 How long we keep it
| Data type | Retention period | Reason |
|---|---|---|
| Account & profile | Account life + 5 years | Legal & audit |
| GST & tax records | 8 years from filing | GST Act |
| Payroll & employee records | 8 years | Labour law |
| Financial transactions | 8 years | Income Tax Act |
| Support communication | 3 years | Service improvement |
| Marketing data | Until opt-out or 2 years | Consent-based |
| Website usage logs | 12 months | Security monitoring |
After the applicable period, data is securely deleted or anonymised.
08 Data security
8.1 Technical measures
Encryption — traffic between your browser and OCTYN is protected in transit with TLS (HTTPS), and data stored at rest is encrypted using AES-256 by our cloud infrastructure providers.
Access controls — role-based access, optional multi-factor authentication, automatic session timeout, and IP restrictions for enterprise accounts.
Infrastructure — regular penetration testing, automated threat detection, continuous monitoring, and DDoS/firewall protection.
Backups — automated daily backups stored in geographically separate locations, with periodic restoration tests.
8.2 Organisational measures
- Least-privilege data access for staff
- Regular security training for the team
- Confidentiality agreements with employees and contractors
- A formal incident-response plan
8.3 Breach notification
If a breach affects your data, we will notify you within 72 hours of becoming aware of it, inform the relevant authorities as required, describe what happened, and advise on protective steps.
09 Cookies
The platform sets one preference cookie and keeps your sign-in session and settings in browser storage; the website uses cookieless analytics. We use no advertising or tracking cookies. Every item is listed by name in our dedicated Cookie Policy.
10 Your rights
Subject to applicable law, you can:
- Access a copy of the personal data we hold about you (within 30 days).
- Correct inaccurate or incomplete information — much of it directly in account settings.
- Delete your personal data, except where retention is legally required (e.g. GST and tax records).
- Port your data in a structured, machine-readable format such as CSV or Excel.
- Withdraw consent for consent-based processing, without affecting prior lawful processing.
- Object to direct marketing at any time via the unsubscribe link or your settings.
To exercise any right, email [email protected] with the subject "Data Rights Request". We may verify your identity before acting and will respond within 30 days.
11 Children's privacy
OCTYN is built for business use by adults and is not directed at anyone under 18. We do not knowingly collect data from minors. If you believe a minor has registered, contact [email protected] and we will remove the information.
12 Third-party links & integrations
Our platform links to third-party services such as the GSTN portal, banking partners and payment gateways. This policy applies only to OCTYN. We are not responsible for the privacy practices of external services — please review their policies before using them.
13 Changes to this policy
We may update this policy to reflect changes to our services or the law. For material changes we will update the "Last updated" date, email you where the change affects your rights, and display a notice in-product. Continued use after an update means you accept the revised policy.
14 Grievance officer
In line with the IT Act 2000 and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, OCTYN has appointed a Grievance Officer for data-related concerns. You can reach the Grievance Officer at [email protected].
15 Governing law
This policy is governed by the laws of the Republic of India, with exclusive jurisdiction in the courts of India. Applicable laws include the IT Act 2000, IT Rules 2011, the Digital Personal Data Protection Act 2023, the GST Act 2017 and the Income Tax Act 1961.
16 Contact us
For any question about this policy or how OCTYN handles your data, reach our privacy team:
- Email — [email protected]
- Web — octynerp.com/contact-us
- Response time — within 30 days