This Policy explains what personal data ORR collects, how and why we use it, who we share it with, how long we keep it, and the rights you have. We process personal data lawfully, and only for the purposes described here. It is written to reflect obligations under major data-protection regimes, including the EU/UK GDPR, India’s Digital Personal Data Protection Act, 2023 and the DPDP Rules, and US state privacy laws such as the CCPA/CPRA. By using the ORR website or contacting us, you acknowledge this Policy.
Who we are
The data controller / data fiduciary responsible for your personal data is ORR (“ORR”, “we”, “us”), a business-structuring consultancy operating in India.
For any privacy matter, or to raise a grievance about how we handle your data, contact contact@orrhq.com.
Scope of this policy
This Policy applies to personal data we process about: visitors to and users of our website; people who contact us or submit an enquiry; prospective clients; and clients and their personnel during an engagement.
Our website may link to third-party websites and services. This Policy does not cover those third parties, who operate under their own privacy policies.
Where we process personal data on behalf of a client during an engagement, we generally do so as a processor / on behalf of the client as data fiduciary. Clause 14 explains this.
Definitions
“Personal data” means information relating to an identified or identifiable individual.
“Processing” means any operation performed on personal data.
“Controller” / “data fiduciary” means the party that determines the purposes and means of processing.
“Processor” means a party that processes personal data on a controller’s behalf.
“Data principal / data subject / consumer” means the individual to whom personal data relates.
Terms not defined here have the meaning given in the applicable law.
Personal data we collect
We collect only what we need. We do not collect special-category / sensitive personal data through the website, and we ask that you do not submit it through the enquiry form.
| Category | What it includes | Source |
|---|---|---|
| Enquiry data | Name, email address, and the message / description you submit through the contact form (including what you tell us about your idea or business). | You, directly |
| Communications | Correspondence and records of our exchanges when you contact us by email or otherwise. | You, directly |
| Client engagement data | Business, commercial, operational, and contact information provided during an engagement, which may include personal data about your personnel or contacts. | You / your organisation |
| Technical & log data | IP address, browser and device type, referring pages, and access times, from standard web-server and hosting logs. | Automatic |
| Cookie / analytics data | Only where cookies or analytics are in use — see clause 07. | Automatic |
The enquiry form is for a name, an email, and a short description of your business. Please do not submit special-category or sensitive personal data, financial account details, government identifiers, or confidential third-party information through it. We do not knowingly collect more personal data than is necessary for the purposes in clause 06.
The Structure Brief
The Structure Brief is a self-assessment tool. The answers you select are used to generate your assessment within your own browser. Those answers are not, in themselves, transmitted to or collected by ORR.
Personal data reaches ORR only if you then choose to contact us or submit the enquiry form — for example, to share or discuss your result. At that point, the enquiry data described in clause 04 is processed as set out in this Policy.
The Structure Brief produces general, informational output based on the inputs you provide. It is not advice. See the Disclaimer.
Why we use your data & our lawful basis
We use personal data for the purposes below. Where a law such as the GDPR requires a lawful basis, the applicable basis is shown. Under India’s DPDP Act, we rely on your consent or, where available, a permitted legitimate use (such as processing data you have voluntarily provided for the purpose for which you provided it).
| Purpose | Lawful basis (where required) |
|---|---|
| Respond to your enquiry and correspond with you | Consent, and/or steps at your request prior to a contract; legitimate interests in responding to enquiries |
| Provide and administer our services under an engagement | Performance of a contract; legitimate interests in operating our business |
| Operate, secure, and improve the website | Legitimate interests in a secure, functioning website |
| Keep records and comply with legal, tax, and regulatory obligations | Legal obligation; legitimate interests |
| Establish, exercise, or defend legal claims | Legitimate interests; legal obligation |
Where our basis is consent, you may withdraw it at any time (clause 12); withdrawal does not affect processing carried out before withdrawal. Where our basis is legitimate interests, you may object as described in clause 12.
Cookies & similar technologies
Strictly necessary technologies required to serve and secure the website may operate without consent.
Our website loads fonts from Google Fonts; doing so may transmit your IP address to Google as part of serving those fonts. [To remove this transmission, self-host the fonts.]
Where we use non-essential cookies or analytics, we will request your consent where the law requires, and you will be able to accept, reject, or manage them. [If/when analytics or non-essential cookies are added, describe them here and deploy a compliant consent banner. If none are used, state that plainly.]
You can control cookies through your browser settings. Blocking some cookies may affect how the website functions.
Who we share data with
We do not sell your personal data, and we do not share it for cross-context behavioural advertising. We share personal data only with:
- Service providers who process data on our behalf, under contract and appropriate safeguards — including our form-submission provider (our enquiry form is delivered using Formspree, which processes form submissions on our behalf), our website hosting and email providers, and font / content-delivery providers described in clause 07;
- Professional advisers (such as lawyers, accountants, and insurers) where necessary;
- Authorities and other parties where required by Applicable Law, court order, or to establish, exercise, or defend legal claims; and
- A successor in the event of a reorganisation, merger, or sale of the business, subject to this Policy.
Each processor is permitted to use your data only for the purposes we specify and is required to protect it. [Maintain an internal, current list of processors and their locations.]
International transfers
ORR and some of its service providers may be located in, or transfer personal data to, countries other than yours. Where we transfer personal data across borders, we do so in accordance with Applicable Law.
For transfers subject to the GDPR, we rely on an adequacy decision or appropriate safeguards such as the Standard Contractual Clauses. For transfers of data subject to India’s DPDP Act, we transfer only as permitted under that Act and any restrictions the Government of India may notify. [Confirm your transfer mechanisms and any localisation requirements that apply.]
You may request information about the safeguards we use by contacting us (clause 16).
How long we keep data
We keep personal data only for as long as necessary for the purpose it was collected, including to meet legal, tax, accounting, or reporting requirements, and to establish or defend legal claims.
Indicatively: enquiry data from prospects who do not become clients is retained for [e.g. 12–24 months]; client engagement records are retained for [e.g. the engagement plus 6–7 years, per applicable limitation and tax rules]. When no longer needed, data is deleted or anonymised.
How we protect data
We implement reasonable technical and organisational measures appropriate to the risk, designed to protect personal data against unauthorised access, loss, misuse, or alteration. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping any credentials you hold confidential.
Where a personal-data breach is likely to result in a risk to individuals, we will notify the relevant authority and affected individuals as and where required by Applicable Law.
Your rights
Depending on where you are and the law that applies, you may have some or all of the following rights. We will respond within the timeframe required by Applicable Law, after verifying your identity.
| Right | What it means |
|---|---|
| Access | Obtain confirmation of, and a copy of, the personal data we hold about you, and a summary of our processing. |
| Correction | Have inaccurate or incomplete personal data corrected or completed. |
| Erasure / deletion | Request deletion where there is no overriding lawful reason for us to keep it. |
| Restriction / objection | Restrict or object to certain processing, including processing based on legitimate interests. |
| Portability | Receive certain data in a structured, commonly used, machine-readable format (GDPR). |
| Withdraw consent | Withdraw consent at any time where processing is based on consent. |
| Nominate (DPDP) | Nominate another individual to exercise your rights in the event of death or incapacity. |
| Grievance (DPDP) | Have your grievance addressed through our grievance-redressal process (clause 16). |
| Opt-out / non-discrimination (CCPA) | Opt out of any sale or sharing (we do neither) and not be discriminated against for exercising your rights. |
| Complain | Lodge a complaint with your supervisory authority — the relevant EU/UK authority, the Data Protection Board of India, or the applicable US regulator. |
To exercise a right, contact us using the details in clause 16. We may need information to verify your identity, and may decline or charge a reasonable fee for manifestly unfounded or excessive requests, to the extent Applicable Law permits.
Children’s data
Our website and services are directed to businesses and adults, not to children. We do not knowingly collect personal data from children.
Where India’s DPDP Act applies, we will not process the personal data of a person under 18 without verifiable consent of a parent or lawful guardian, and will not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided us with personal data, contact us and we will delete it.
When we act as a processor
During an engagement we may process personal data on your instructions and on your behalf. In that case you are the controller / data fiduciary and remain responsible for that data, including for the lawfulness of the instructions you give and the notices and consents required from the individuals concerned.
We will process such data only on your documented instructions, apply appropriate security, assist you with data-subject requests and breach obligations as required, and enter into a data-processing agreement where Applicable Law requires one. A data-processing agreement is available on request.
Changes to this policy
We may update this Policy from time to time. The current version, with its effective date, is always available on this page. Where changes are material, we will take reasonable steps to bring them to your attention. Continued use of the website after changes take effect indicates your awareness of the updated Policy.
Contact & grievance redressal
To exercise a right, ask a question, or raise a grievance about how we handle personal data, contact contact@orrhq.com.
We will acknowledge and respond to grievances within the period required by Applicable Law. If you are not satisfied, you may escalate to the competent supervisory authority, including the Data Protection Board of India (for DPDP matters) or your relevant EU/UK supervisory authority.
This Privacy Policy is provided for transparency about ORR’s data practices and does not itself constitute legal advice.