Privacy Policy
Last updated: 4 August 2026
Sharnova Labs OPC Pvt. Ltd. ("Sharnova Labs", "we", "us" or "our") operates Sharnova Orbit ("Orbit", the "Service"), a workforce allocation governance and capacity intelligence platform. This Privacy Policy explains how we collect, use, disclose, store and protect personal data in connection with the Service, in accordance with the Digital Personal Data Protection Act, 2023 ("DPDPA"), the Digital Personal Data Protection Rules, 2025 ("DPDP Rules"), and the Information Technology Act, 2000. By accessing or using Orbit, you agree to the collection and use of information in accordance with this Policy. If you do not agree, please do not use the Service.
1. Definitions
- "Data Fiduciary" — an entity that, alone or with others, determines the purpose and means of processing personal data.
- "Data Processor" — an entity that processes personal data on behalf of a Data Fiduciary.
- "Data Principal" — the individual to whom personal data relates.
- "Data Protection Board" — the Data Protection Board of India established under the DPDPA.
- "Personal Data" — any data about an individual who is identifiable by or in relation to such data.
2. Who This Policy Covers
2.1 This Policy applies to two categories of individuals:
- Customer users — individuals at a customer organisation who access Orbit to plan, allocate and manage workforce capacity. For a customer user's own account and contact data (for example name, work email, login activity), Sharnova Labs is the Data Fiduciary.
- Data principals within customer workforce data — employees, contractors and project resources whose allocation, utilisation and bench data is entered into Orbit by a customer. For this category, Sharnova Labs acts solely as a Data Processor on the customer's instructions, and the customer organisation remains the Data Fiduciary responsible for its own legal basis to process that data, including under section 7(i) of the DPDPA (processing for employment purposes) where applicable.
3. Information We Collect
3.1 Account and contact information: full name, work email address, phone number and job title; company name, industry, country, company size and team size; information submitted through our contact and early-access forms.
3.2 Workforce and allocation data (processed on behalf of customers as Data Processor): employee names, roles, skills and reporting structures; project assignments, allocation percentages, timelines and bench status; approval workflows, utilisation metrics and capacity forecasts.
3.3 Usage and device data: log data such as IP address, browser type, device identifiers and access timestamps; product usage analytics, including pages viewed, features used and session duration; cookies and similar technologies — see our Cookie Policy.
4. How We Use Information
- To provide, operate and maintain the Service, including resource planning, capacity intelligence and approval workflows.
- To generate allocation and capacity-forecast outputs. These outputs are produced by rules-based and analytical processing configured for each customer's own data. Sharnova Labs does not use one customer's workforce data to train models or to generate outputs shared with, or applied to, any other customer.
- To respond to enquiries submitted via our website's contact and early-access forms.
- To send transactional communications, including onboarding, billing and service notices.
- To monitor, secure and improve the Service, including diagnosing technical issues and preventing fraud or abuse.
- To comply with applicable law, regulatory requirements and lawful requests from public authorities.
We do not sell personal data to third parties.
5. Legal Basis for Processing
5.1 For account and contact data of customer users, we process personal data on the basis of: (a) your consent, given under section 6 of the DPDPA at the time you submit information through our forms or register for the Service; and (b) the specific purpose for which you voluntarily provided the data, under section 7(a) of the DPDPA.
5.2 For workforce data entered by a customer, Sharnova Labs processes that data solely as a Data Processor acting on the customer's documented instructions. The customer, as Data Fiduciary, is responsible for establishing its own legal basis for processing — most commonly section 7(i) of the DPDPA (processing for employment purposes), or consent obtained directly from its own workforce.
5.3 We do not rely on any general "legitimate interest" standard, as the DPDPA does not recognise one. Where we process personal data without consent, we rely only on a specific ground enumerated in section 7 of the DPDPA.
6. Sharing and Disclosure
6.1 We disclose personal data only in the following circumstances:
- Sub-processors and service providers — including cloud infrastructure (Amazon Web Services), email delivery and analytics providers, bound by contractual confidentiality and data protection obligations. A current list of sub-processors is available on request by contacting us at contact@sharnovalabs.com, and we will give reasonable advance notice before adding a new sub-processor that will process customer data.
- Within a customer organisation — data entered into Orbit is visible to authorised users within that customer's account, according to their configured access controls.
- Legal and regulatory disclosure — where required by law, court order, or a lawful request from a government or regulatory authority.
- Business transfers — in connection with a merger, acquisition or sale of assets, subject to equivalent data protection commitments.
7. Data Storage and Cross-Border Transfer
7.1 Orbit is hosted on Amazon Web Services (AWS). Customer and workforce data is stored on infrastructure located in India where offered, and secured using encryption in transit (TLS) and at rest.
7.2 Under section 16 of the DPDPA, personal data may be transferred outside India to any country or territory, except where the Central Government has, by notification, restricted such transfer. As at the date of this Policy, no such restriction has been notified. Where we transfer personal data outside India, we apply contractual and technical safeguards consistent with our obligations under the DPDPA, and we will comply with any country-specific restriction the Central Government notifies in the future.
8. Data Retention
8.1 We retain personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law.
8.2 Customer workforce data is retained for the duration of the customer's active subscription. Following termination or expiry of a customer's subscription, we will delete or anonymise the corresponding customer data within ninety (90) days, except where a longer period is required to comply with a legal obligation, resolve a dispute or enforce our agreements.
8.3 Account and contact data of customer users is retained for as long as the individual's account remains active, and for a reasonable period thereafter for administrative, legal and security purposes.
9. Data Security
We implement reasonable security practices and procedures, including encryption, role-based access control, network security controls, logging and periodic security reviews, to protect personal data against unauthorised access, alteration, disclosure or destruction. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. Personal Data Breach Notification
10.1 If we become aware of a personal data breach affecting personal data processed in connection with the Service, we will notify the Data Protection Board of India in accordance with Rule 7 of the DPDP Rules, without delay upon becoming aware of the breach, and with further particulars (including the circumstances of the breach, remedial measures taken, and findings as to its cause) within seventy-two (72) hours, or such extended period as the Board may allow.
10.2 Where a breach is likely to result in harm to data principals, we will notify affected data principals without delay, in a concise, clear and plain manner, describing the nature, extent and timing of the breach, its likely consequences, the measures we have implemented to mitigate risk, safety measures the data principal may take, and a contact point for further information.
10.3 Where personal data affected by a breach forms part of a customer's workforce data, we will also promptly notify the affected customer so that it may fulfil any notification obligations it bears as Data Fiduciary.
10.4 Separately, we will report cyber security incidents to the Indian Computer Emergency Response Team (CERT-In) within the period required by the directions issued under section 70B(6) of the Information Technology Act, 2000, and retain system logs for a rolling period of one hundred and eighty (180) days within Indian jurisdiction.
11. Your Rights
11.1 Subject to applicable law, you may have the right to: obtain a summary of the personal data we hold about you; request correction or updating of inaccurate or incomplete personal data; request erasure of personal data that is no longer necessary for the purpose for which it was collected; withdraw consent at any time, without affecting the lawfulness of processing before withdrawal; nominate another individual to exercise these rights on your behalf in the event of death or incapacity; and register a grievance regarding the processing of your personal data.
11.2 To exercise any of these rights, contact us at contact@sharnovalabs.com. We may request information reasonably necessary to verify your identity before acting on a request. We will respond to grievances within a maximum of ninety (90) days of receipt, consistent with Rule 14 of the DPDP Rules. If your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India under section 13 of the DPDPA.
11.3 Where personal data forms part of a customer's workforce records, requests should first be directed to the relevant customer organisation, as it is the Data Fiduciary for that data.
12. Significant Data Fiduciary Status
As at the date of this Policy, Sharnova Labs has not been notified by the Central Government as a Significant Data Fiduciary under section 10 of the DPDPA. If we are so notified in the future, we will comply with the applicable additional obligations, including appointment of a Data Protection Officer based in India, periodic data protection impact assessments and audits, and any applicable data localisation requirements.
13. Children's Privacy
Orbit is a business-to-business workforce management platform and is not directed at, or intended for use by, individuals under 18 years of age. We do not knowingly collect personal data from children.
14. Grievance Officer and DPDPA Contact
In accordance with the Information Technology Act, 2000 and the DPDPA, the following individual serves as both our Grievance Officer under the IT Act and our contact point for data-principal requests and grievances under the DPDPA:
Grievance Officer: Munmun Banerjee
Sharnova Labs OPC Pvt. Ltd.
Email: contact@sharnovalabs.com
Registered Office: 512/3 Parnashree Pally, LP-140/22/3/1, Parnasree Pally, Kolkata – 700060, West Bengal, India
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in applicable law. We will notify you of material changes via the Service or by email at least thirty (30) days before they take effect, and the "Last updated" date above will be revised accordingly.
16. Governing Law and Jurisdiction
This Policy is governed by the laws of India. Any dispute arising out of or in connection with this Policy is subject to clause 25 (Governing Law and Dispute Resolution) of our Terms of Service.
17. Contact
Questions about this Policy may be directed to contact@sharnovalabs.com.