Skip to content Skip to footer
0 items - $0.00 0
Cart

Privacy Policy

Privacy Policy
Tangerine Skies Private Limited (now merged into OFB Tech Limited)
1. Introduction

This Privacy Policy (“Policy“) is owned and operated by OFB Tech Limited, operating under the brand
name OfBusiness (“OfBusiness”, “Company”, “we”, “us”, “our”) including in respect of the businesses earlier
carried on by its erstwhile subsidiary Tangerine Skies Private Limited (now merged into OFB Tech
Limited). It governs the collection, use, storage, disclosure and other processing of personal data of users in
connection with the OfBusiness website, mobile applications and related products and services
(“Services“).

OfBusiness is committed to protecting and respecting the privacy of its users and implements reasonable
security practices and procedures in accordance with the Information Technology Act, 2000 and the
Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or
Information) Rules, 2011 (“SPDI Rules“), as well as the Digital Personal Data Protection Act, 2023
(“DPDPA“) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules“), to the extent applicable.

By accessing or using the Services, you (“user“, “you” or “Data Principal” under the DPDPA terminology)
acknowledge that you have read and understood this Policy.

1A. Notice Regarding Merged Entities and Succession of Businesses

Important Notice — Applicability to Businesses of Erstwhile Subsidiaries

OFB Tech Limited has, through a scheme of merger/amalgamation duly approved under applicable law,
merged its erstwhile subsidiaries into itself. As a result of such merger(s), OFB Tech Limited has succeeded
to all businesses, undertakings, assets, liabilities, rights, obligations and data processing activities that were
previously carried on by or vested in those merged entities (the “Merged Entities”).

This Policy therefore applies not only to personal data collected, processed or held by OFB Tech Limited in
its own right, but also to all personal data that was previously collected, processed or held by the Merged
Entities in connection with their respective businesses, which now vest in and are operated by OFB Tech
Limited.

Users who previously interacted with, registered on, or provided personal data to any of the Merged Entities
— whether through their respective websites, applications, platforms, or other channels — are hereby
informed that:

• OFB Tech Limited has succeeded to the role of Data Fiduciary (under the DPDPA) and body
corporate (under the SPDI Rules) in respect of all personal data previously collected by the Merged
Entities;

• all personal data previously collected by the Merged Entities shall continue to be processed by OFB
Tech Limited strictly for the same or compatible purposes for which it was originally collected,
unless fresh consent is obtained or a fresh notice is issued;

• this Policy supersedes and replaces any privacy policy, data protection notice or data processing
terms that were previously published by or on behalf of any Merged Entity, with effect from the
date of the relevant merger becoming effective; and

• your rights as a Data Principal under the DPDPA — including your right to access, correct, erase
and nominate — may now be exercised directly against OFB Tech Limited through the
grievance/DPO contact set out in Clause 16 of this Policy, irrespective of which Merged Entity
originally collected your data.

If you have any questions regarding how your personal data held by a Merged Entity has transitioned to
OFB Tech Limited, or if you wish to withdraw consent previously given to a Merged Entity, you may contact
our Grievance Officer/DPO at the details specified in Clause 16 below.

2. Applicable Laws
This Policy is framed, and OfBusiness processes personal data, in accordance with the following laws, as

amended from time to time:

     • Information Technology Act, 2000;

     • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal
Data or Information) Rules, 2011;

     • Digital Personal Data Protection Act, 2023;

     • Digital Personal Data Protection Rules, 2025.

References to the General Data Protection Regulation (EU) 2016/679 (“GDPR“) shall apply only to the
extent OfBusiness processes personal data of individuals located in the European Union and shall be
interpreted consistently with this Policy.

3. Definitions

Unless the context otherwise requires, terms used in this Policy shall have the meanings assigned to them
under the DPDPA and the SPDI Rules, including “personal data”, “Data Principal”, “Data Fiduciary”, “Data
Processor”, “processing”, “children”, and “personal data breach”.
The term “Merged Entities” refers to all erstwhile subsidiaries of OFB Tech Limited that have been merged
into OFB Tech Limited pursuant to a court-sanctioned or tribunal-approved scheme of
merger/amalgamation under applicable law, including the Companies Act, 2013.

4. Categories of Data Collected and Purposes

4.1 Personal Data Collected

OfBusiness may collect the following categories of personal data, including personal data originally collected
by the Merged Entities and now vesting in OFB Tech Limited:

• Registration and identity data: name, username, designation, email address, mobile number,
postal address, gender, country/state of residence.

• Business and financial data: company name, date of incorporation, GST number, billing
address, turnover, operating locations, website details, company type, contact details of authorised
representatives.

• Transaction and usage data: details of products/services requested or purchased, tenders
searched, usage frequency, preferences, interaction logs, device identifiers, IP address, browser
type, and cookies/online identifiers.

• Communications data: information shared through calls with customer care, chat, SMS,
WhatsApp, emails and other communications, including call recordings where permitted by law.

• Location data: approximate or precise location derived from devices, IP address or other
identifiers, where permitted by applicable law.

4.2 Purposes of Processing

OfBusiness processes personal data for the following specified purposes:

• Providing, operating and improving the Services requested by you, including credit assessment,
underwriting, fulfilment and support.

• Managing your account and authenticating your identity.

• Communicating with you regarding your account, transactions, updates to the Services, and
material changes to this Policy or other terms.

• Sending you product notifications, service-related communications, and where permissible,
marketing and promotional communications regarding OfBusiness and third-party offerings,
subject to your preferences.

• Personalising content and user experience, including recommendations and targeted content.

• Detecting, investigating and preventing fraud, abuse, security incidents and other unlawful or
prohibited activities.

• Complying with legal obligations, regulatory requirements, law enforcement requests, and
court/authority orders.

• Analytics, research and business intelligence to improve Services, including through anonymised
or aggregated data.

• Continuing to serve users who were previously customers, registered users or data principals of
the Merged Entities, in connection with the businesses and services acquired by OFB Tech Limited
pursuant to the mergers.

5. Legal Basis and Consent

5.1 Consent
Where processing is based on consent under the DPDPA, OfBusiness shall obtain your consent in a manner
that is free, specific, informed, unconditional and unambiguous, signified by a clear affirmative action.
Consent shall be limited to such personal data as is necessary for the specified purpose, in line with the
principle of data minimisation.

5.2 Withdrawal of Consent
You may withdraw your consent at any time by using the settings provided on the website/app or through
the communication link provided in the consent notice, in a manner that is comparable in ease to the
manner in which consent was given.
Upon withdrawal, OfBusiness shall cease processing your personal data for the relevant purpose, unless
such processing is required to comply with legal obligations or for other legitimate uses permitted under
Section 7 of the DPDPA.

5.3 Legitimate Uses Without Consent
OfBusiness may process personal data without consent for legitimate uses specified under the DPDPA,
including but not limited to: compliance with law, performance of legal obligations, responding to medical
emergencies, and any other notified legitimate uses.

6. Children’s Data

OfBusiness does not knowingly process personal data of children (individuals below 18 years of age) without
verifiable consent of a parent or lawful guardian, as required under Section 9 of the DPDPA.
OfBusiness shall not undertake tracking or behavioural monitoring of children or targeted advertising
directed at children.

7. Rights of Data Principals

Subject to applicable law, you have the following rights in relation to your personal data, including personal
data previously held by the Merged Entities and now vesting in OFB Tech Limited:

• Right to access information: to obtain a summary of your personal data being processed, the
processing activities, and the identities/types of Data Fiduciaries and Data Processors with whom
your personal data has been shared.

• Right to correction and erasure: to request correction, completion, updating or erasure of your
personal data where it is inaccurate, incomplete or no longer necessary for the purposes for which
it was collected, subject to legal retention requirements.

• Right to grievance redressal: to register complaints with the designated Grievance Officer/DPO
and to escalate to the Data Protection Board of India if not satisfied with the resolution.

• Right to nominate: to nominate another person to exercise your rights under the DPDPA in the
event of your death or incapacity, in the manner specified by OfBusiness.

You may exercise these rights — including in relation to personal data originally collected by any Merged
Entity — through your account settings or by contacting the Grievance Officer/DPO using the details
provided in Clause 16 below.

8. Duties of Data Principals

You are required under the DPDPA to:

• not impersonate another individual while providing personal data;

• not suppress any material information while providing personal data;

• not register frivolous or false grievances or complaints; and

• furnish only such information that is verifiably authentic while exercising your rights.

9. Disclosure and Sharing of Personal Data

OfBusiness may share your personal data with:

• its group entities, affiliates and subsidiaries for the purposes set out in this Policy;

• service providers and Data Processors (including cloud service providers, IT support, analytics
providers, KYC agencies, payment gateways) engaged under valid contracts that impose
confidentiality and data protection obligations, with OfBusiness remaining responsible for their
actions;

• governmental authorities, regulators, law enforcement agencies or courts where disclosure is
required by applicable law or order;

• prospective or actual purchasers, transferees or successors in connection with any merger,
acquisition, restructuring or sale of business or assets, subject to confidentiality obligations.

Disclosure of sensitive personal data or information (where applicable) to third parties shall be in
accordance with Rule 6 of the SPDI Rules, including obtaining prior consent or contractually authorised
disclosure, save where required by law.

10. Cross-Border Transfer of Personal Data

Personal data collected by OfBusiness — including personal data of users of the Merged Entities now vesting
in OFB Tech Limited — may be stored and processed in India or in other jurisdictions, subject to applicable
law. Any such transfer shall comply with Section 16 of the DPDPA and any restrictions or conditions notified
by the Central Government, including restrictions on transfer to certain countries or entities.


Where required, OfBusiness will implement appropriate contractual and technical safeguards to protect
personal data transferred outside India, consistent with applicable Indian law.

11. Data Security

OfBusiness uses reasonable security practices and procedures, including:

• 128-bit encryption and TLS protocols for data in transit;

• logical and physical access controls, authentication and authorisation mechanisms;

• encryption, obfuscation, masking or use of virtual tokens for securing personal data, as appropriate;

• monitoring and logging of access to detect, investigate and remediate unauthorised access;

• business continuity and disaster recovery measures to ensure integrity and availability of personal
data.

OfBusiness implements reasonable security practices in accordance with Rule 8 of the SPDI Rules and the
security safeguard obligations under Section 8 of the DPDPA and the DPDP Rules. These safeguards apply
equally to personal data transitioned from the Merged Entities.

12. Data Breach Notification

In the event of a personal data breach, OfBusiness shall:

• implement remedial measures to contain and investigate the breach;

• notify the Data Protection Board of India without undue delay and provide a more detailed report
within prescribed timelines, in accordance with Section 8(6) of the DPDPA and the DPDP Rules;

• inform affected users, through their registered contact details, of such breach and recommended
steps to mitigate potential harm.

13. Data Retention

OfBusiness retains personal data — including personal data transitioned from the Merged Entities — only
for as long as necessary for the purposes for which it was collected, or as required under applicable law,
including prescribed minimum retention periods under the DPDP Rules and sectoral regulations.

Logs and related records required for security and regulatory purposes shall be retained for at least the
minimum period mandated by applicable law. Thereafter, personal data may be anonymised or securely
deleted, subject to any legal obligation to retain it for a longer period.

14. Cookies and Tracking Technologies

OfBusiness uses cookies and similar technologies (such as pixels, tags, SDKs and web beacons) to enable
core functionality, remember user preferences, enhance user experience, and for analytics and security
purposes.

You may manage or disable cookies through your browser settings; however, some features of the Services
may not function properly if cookies are disabled.

15. User Controls and Preferences

You may control your preferences in relation to:

• marketing and promotional communications (opt-in/opt-out);

• product notifications and alerts;

• language preferences for notices and communications in English or other languages specified in
the Eighth Schedule to the Constitution of India, where available, in accordance with the DPDPA.

16. Grievance Redressal and DPO Details

In compliance with the SPDI Rules and the DPDPA, OfBusiness designates the following contact for all
grievances, including grievances relating to personal data previously held by the Merged Entities:

Grievance Officer / Data Protection Officer (DPO)
Name: Mr. Bhuvan Kumar Gupta
Designation: Director and Grievance Officer / Data Protection Officer
Email: contact@ofbusiness.com
Address: 6th Floor, Tower A, Global Business Park, M.G. Road, Gurgaon – 122001, India

You may contact the Grievance Officer/DPO with any questions, concerns or grievances regarding the
processing of your personal data. OfBusiness shall endeavour to resolve grievances within a reasonable
time, not exceeding 90 days, in accordance with the DPDPA and DPDP Rules.

If you are not satisfied with the response, you may lodge a complaint with the Data Protection Board
of India as per the procedure prescribed under the DPDPA.

17. Changes to This Policy

OfBusiness may modify this Policy from time to time to reflect changes in legal or regulatory requirements,
technology, or our data processing practices. Any material changes will be notified to you by way of
prominent notice on the website/app or by email to your registered address, prior to such changes
becoming effective.

Your continued use of the Services after the effective date of the revised Policy shall constitute your
acceptance of the updated Policy.

18. Severability and No Waiver

If any provision of this Policy is held invalid or unenforceable under applicable law, such provision shall be
severed, and the remaining provisions shall continue in full force and effect.

Failure or delay by OfBusiness in exercising any right under this Policy shall not constitute a waiver of such
right.