What we collect, and what we never do with it.
Oadbox builds and operates software that businesses run their operations on. That only works if the data inside it is treated as theirs. This policy explains what we collect on this website and in our products, why, and what you can ask us to do about it.
Last updated 5 August 2026
01Who this covers
This policy applies to visitors to oadbox.com and to people whose personal data we handle in the course of running our products — the staff at a customer organisation who log in, and the individuals whose records a customer stores.
For website visitors and enquiries, Oadbox is the data fiduciary: we decide what is collected and why. For data inside a customer's tenant, the customer is the data fiduciary and we act as a data processor on their instructions. If your details are in a product because you are a student, patient, employee or borrower of one of our customers, that organisation is the right first point of contact — but you can always write to us and we will route it.
02What we collect
We keep collection deliberately small. In practice it comes down to three things:
- Enquiries. When you use the contact form or email us, we receive your name, email address, company, phone number if you give one, and whatever you write in the message. The form on this site composes an email in your own mail client — nothing is posted to a server here.
- Account data. If your organisation becomes a customer, we hold the details needed to run your tenant: user names, work email addresses, phone numbers, roles and permissions, and a log of what changed and who changed it.
- Operational data. Our servers record standard technical information — IP address, browser and device type, timestamps, error traces — as part of keeping the services running and secure.
We do not buy contact lists, we do not run advertising trackers, and we do not build profiles of visitors for marketing.
03Why we use it
Every use falls into one of these:
- Replying to you, arranging a demo, and preparing a proposal.
- Providing, supporting and improving the products your organisation subscribes to.
- Keeping the services secure, available and auditable — including investigating incidents.
- Meeting statutory obligations such as invoicing, tax and record-keeping.
We rely on your consent for enquiries and marketing contact, and on the performance of our contract with your organisation for everything needed to actually run the product. You can withdraw consent for marketing contact at any time without affecting service.
04Who else touches it
We keep the list of third parties short, and each one processes data only to provide a service to us:
- Cloud infrastructure and storage providers, which host the applications and databases.
- Email, messaging and support tooling used to correspond with you.
- Payment and accounting providers, for subscription billing and statutory records.
We do not sell personal data, and we do not share it with anyone for their own marketing. We disclose data to authorities only where the law requires it, and we tell the affected customer unless we are legally barred from doing so.
05Where it is stored
Customer data is hosted on managed cloud infrastructure, with each organisation isolated in its own database schema rather than separated by a filter in application code. Data is encrypted in transit and at rest, and backed up so it can be restored to a point in time.
Our primary hosting region is in India. Where a service provider processes data outside India, we require contractual protections at least equivalent to those in this policy.
06How long we keep it
Enquiries are kept for as long as the conversation is live and for a reasonable period afterwards in case you come back to it. Customer data is kept for the life of the subscription and for a limited wind-down window after it ends, so that an export can still be produced. After that it is deleted from active systems, and backups age out on their own schedule.
Records we are required by law to retain — invoices and tax records in particular — are kept for the statutory period regardless of any deletion request.
07Security
Access to production systems is restricted to the engineers who operate them, protected by individual accounts and multi-factor authentication, and limited to support and maintenance work. Actions inside the products are recorded in immutable audit logs with field-level change tracking.
No system is perfectly secure. If a breach affects your data, we will notify the affected organisation and the relevant authority as required, with what we know and what we are doing about it.
08Your rights
Subject to the Digital Personal Data Protection Act, 2023 and other applicable law, you can ask us to:
- Confirm what personal data of yours we hold, and give you a copy.
- Correct anything inaccurate or incomplete.
- Erase data we no longer have a lawful reason to keep.
- Stop using your details for marketing contact.
- Nominate someone to exercise these rights on your behalf if you are unable to.
Write to us and we will respond within a reasonable period. Where the data sits inside a customer's tenant, we will pass the request to that organisation and support them in answering it.
09Children
This website is not directed at children, and we do not knowingly collect their data through it. Some products — school and hospital software in particular — hold records about minors, entered by the customer organisation in the course of its own duties. In those cases the organisation is responsible for obtaining the consents the law requires, and we process the data only on its instructions.
10Changes
If this policy changes materially, we will update the date at the top of this page and, where the change affects customers, tell them directly. Continued use after an update means the revised policy applies.
11Contact us
Questions, requests or complaints about privacy — including anything you would like escalated to our grievance officer — should go to the address below. If you are not satisfied with our response, you may raise the matter with the Data Protection Board of India.
Reach us at