Data Protection & Confidentiality
Privacy Policy
At ODC Standards Certifications, we prioritize the confidentiality and protection of your personal and organizational data. This Privacy Policy details how we collect, process, store, and protect your information.
1. Information We Collect
We collect information necessary to provide certification, audit, training, and assessment services, as well as to process enquiries and manage client relationships:
- Personal & Contact Information: Name, business email, telephone number, job designation, organization name, and billing address.
- Certification & Audit Data: Company profiles, management system documentation, audit scope, process manuals, and audit evaluation reports.
- Transaction & Payment Details: Billing records, invoice history, payment reference numbers, and transaction IDs (payment details are processed securely via PCI-DSS compliant payment gateways such as Razorpay).
- Technical Data: IP address, browser type, operating system, pages visited, and session analytics collected via standard web cookies.
2. How We Collect Information
Information is collected through direct interactions and automated site technologies:
- When you complete enquiry, application, or feedback forms on our website.
- When you communicate with our certification teams via email, phone, or written correspondence.
- During audit planning, site assessments, and document reviews.
- Automatically via web analytics tools (e.g., Google Analytics, Hotjar, Clarity) when navigating our site.
3. Purpose & Use of Collected Information
ODC Standards Certifications uses your data solely for legitimate business and audit purposes:
- To deliver management system certification, auditing, and assessment services.
- To issue ISO certificates, maintain certification validity registers, and update accreditation records.
- To process service payments and generate GST-compliant invoices.
- To respond to customer enquiries, provide technical support, and send important certification updates or surveillance reminders.
- To ensure regulatory and accreditation compliance under ISO/IEC 17021-1 standards.
4. Data Confidentiality & Security
Confidentiality is a core pillar of our ISO certification principles. We implement strict administrative, technical, and physical security controls to safeguard your data against unauthorized access, loss, alteration, or disclosure.
- Website data transmissions are encrypted using SSL (Secure Sockets Layer) technology.
- Audit records and client documents are accessible only to authorized personnel and qualified auditors bound by strict non-disclosure agreements (NDAs).
5. Data Sharing & Disclosure
We do NOT sell, rent, trade, or commercialize your personal or corporate data to any third party. Information may be shared only under the following strictly defined conditions:
- Accreditation Bodies: Where required for accreditation verification, audit oversight, or mandatory certificate directory entries.
- Payment Processors: With secure, PCI-DSS compliant banking partners and payment gateways (such as Razorpay) for transaction execution.
- Legal & Statutory Requirements: When compelled by law, court order, or government regulation.
6. Cookie Policy
Our website uses cookies to enhance user navigation, measure website traffic, and improve service delivery. You can choose to accept or decline cookies through your web browser settings. Disabling cookies may affect certain interactive features of our site.
7. Data Retention & Your Rights
Client and audit records are retained for the duration mandated by accreditation rules, tax laws, and ISO audit standards. You have the right to request access to your stored personal information, request corrections, or request data deletion where not restricted by mandatory accreditation or legal retention requirements.
8. Policy Updates
We reserve the right to modify this Privacy Policy as necessary to reflect changes in legal requirements or operational practices. Any updates will be posted on this page with immediate effect.