1.Introduction & Identity of Controller
Welcome to Onsurity. This Privacy Policy explains how Onsurity Technologies Private Limited ("Onsurity", "we", "our", or "us") collects, uses, stores, shares, and protects personal data when you visit our website at www.onsurity.com, use the Onsurity platform, or interact with our services.
Onsurity Technologies Private Limited is a company incorporated under the Companies Act, 2013, with its registered office at:
19th Floor, Raheja Towers, MG Road,
Bengaluru, Karnataka 560 001
India
CIN: U74999KA2020PTC135291
Onsurity acts as the Data Fiduciary (controller) for personal data processed through our platform. For employee health insurance plans administered on behalf of employer clients, Onsurity acts as both Data Fiduciary and, in certain contexts, a Data Processor on behalf of the employer.
This policy applies to all individuals whose personal data we process, including visitors to our website, registered users, employer account holders, covered employees and their dependants, and job applicants. It is governed primarily by India's Digital Personal Data Protection Act, 2023 ("DPDPA") and, where applicable, the General Data Protection Regulation ("GDPR") for users based in the European Economic Area.
By using the Onsurity platform or submitting your information, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any part of this policy, please discontinue use of our services.
2.What Data We Collect
We collect personal data that you provide directly, that we generate through your use of our services, and that we receive from third parties who are authorised to share it with us. The categories of data we collect include:
2.1 Identity & Contact Data
- Full name, date of birth, gender
- Email address, mobile phone number
- Postal address (for policy documents and physical correspondence)
- Aadhaar number or other government-issued ID (where required for insurance KYC)
- PAN number (for tax and financial compliance)
2.2 Company & Employment Data
- Company name, GST number, company registration details
- Designation, department, date of joining
- Employee ID (as assigned by your employer)
- Salary band (where required for group insurance underwriting)
2.3 Health & Insurance Data
- Health declarations required for group health insurance enrolment
- Details of dependants (name, relationship, date of birth, health status) added to a policy
- Claims history, hospitalisations, and pre-existing condition disclosures
- Medical reports submitted as part of a claims process
Health data is classified as Sensitive Personal Data under Indian law. We process it only to the extent necessary to administer your insurance policy and handle claims, and we apply heightened security controls to it at all times.
2.4 Financial & Payment Data
- Billing name, billing address
- Bank account or UPI details (for premium deductions or refunds)
- Payment card type and last four digits (full card numbers are processed by our PCI-DSS-compliant payment gateway and are never stored on Onsurity systems)
- Premium payment history and invoice records
2.5 Usage & Technical Data
- IP address, browser type, device type, operating system
- Pages visited, time spent, referring URL, search terms used within the platform
- Login timestamps, session identifiers, and access logs
- Feature usage patterns (to improve product design)
2.6 Communication Data
- Content of support tickets, chat transcripts, and emails you send to us
- Feedback, survey responses, and NPS ratings
- Call recordings (where permitted by law and you have been notified)
2.7 Data We Do Not Collect
We do not collect biometric data, caste or ethnic origin, religious or political beliefs, or sexual orientation. We do not collect personal data from children under the age of 18 (see Section 11).
3.How We Use Your Data
We use personal data only for specific, clear purposes. Below is a summary of the primary purposes and the corresponding data categories used:
3.1 Service Delivery
- Creating and managing your Onsurity account
- Enroling you or your employees into group health insurance or other products
- Issuing and renewing policy documents
- Processing and settling health insurance claims
- Providing access to cashless hospitalisation at network hospitals
- Managing employee wellness benefit programmes
3.2 Billing & Payments
- Raising invoices, collecting premium payments, and processing refunds
- Reconciling payments against active policies
- Maintaining financial records as required under the Income Tax Act, 1961, and GST law
3.3 Customer Support
- Responding to queries, resolving complaints, and providing post-sale assistance
- Training our support teams on the basis of interaction patterns (using anonymised or aggregated data where possible)
3.4 Product Improvement & Analytics
- Understanding how features are used to improve product design
- Conducting internal research on aggregated, anonymised datasets
- A/B testing new features with opted-in users
3.5 Marketing & Communications (with consent)
- Sending product updates, newsletters, and promotional offers to users who have opted in
- Re-targeting campaigns on third-party advertising platforms using hashed identifiers
- Notifying you about new features or products that may be relevant to your business size and industry
You may withdraw your marketing consent at any time by clicking the "Unsubscribe" link in any email or by writing to privacy@onsurity.com. Withdrawal of marketing consent does not affect transactional communications that are necessary for your policy.
3.6 Legal Compliance & Fraud Prevention
- Meeting our obligations under IRDAI (Insurance Regulatory and Development Authority of India) regulations
- Complying with anti-money laundering (AML) and know-your-customer (KYC) requirements
- Detecting, investigating, and preventing fraud, identity theft, and other illegal activities
- Responding to lawful requests from government authorities, courts, or regulators
4.Legal Basis for Processing
Under India's DPDPA and, where applicable, the GDPR, we must have a lawful basis for each processing activity. Our primary legal bases are:
| Purpose | Legal Basis (DPDPA / GDPR equivalent) |
|---|---|
| Account creation and service delivery | Performance of contract / Consent |
| Insurance enrolment and claims processing | Legal obligation (IRDAI regulations) / Vital interests |
| Billing and financial record-keeping | Legal obligation (Income Tax, GST) |
| Customer support and complaint resolution | Legitimate interest / Contract |
| Product analytics and improvement | Legitimate interest (anonymised/aggregated) |
| Marketing communications | Consent (freely given, withdrawable) |
| Fraud detection and security | Legitimate interest / Legal obligation |
| Regulatory disclosures to IRDAI, courts | Legal obligation |
Where consent is the legal basis, you have the right to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal. Where processing is based on legitimate interests, you may object to it (see Section 7).
5.Data Sharing
We do not sell your personal data. We share it only with parties who need it to help us deliver our services, or where we are legally required to do so. The categories of recipients are:
5.1 Insurance Partners & Underwriters
We share policyholder data (identity, health declarations, employment details) with IRDAI-licensed insurance companies that underwrite the group health plans offered on our platform. These companies are independently regulated data fiduciaries and have their own privacy policies governing how they handle your information.
5.2 Third-Party Administrators (TPAs)
For cashless claims processing and hospital coordination, we share relevant claim and policy data with authorised TPAs who manage claim settlement on behalf of the insurer.
5.3 Payment Service Providers
Premium collections and refunds are handled by PCI-DSS-compliant payment gateway providers. We share only the information necessary to initiate and reconcile transactions. Full payment card data never passes through or is stored on Onsurity servers.
5.4 Cloud Infrastructure & Technology Vendors
Our platform is hosted on enterprise cloud infrastructure operated by reputable cloud service providers. These vendors act as data processors on our behalf and are bound by data processing agreements that prohibit them from using your data for their own purposes.
5.5 Analytics & Communication Tools
We use software tools for product analytics, email delivery, customer support, and engagement. Data shared with these tools is limited to what is necessary for the specific function and is governed by data processing agreements.
5.6 Your Employer (for Group Policies)
If you are an employee enrolled on a group policy purchased by your employer, your employer (as the policyholder) may view certain plan-level data such as enrolment status, premium due dates, and claims history summaries — as permitted under the terms of the group policy and applicable insurance regulations. Individual medical records are not shared with employers.
5.7 Legal & Regulatory Authorities
We disclose personal data to courts, law enforcement agencies, tax authorities, IRDAI, or other regulators when required by law or when we believe disclosure is necessary to protect our legal rights or to prevent imminent harm.
5.8 Corporate Transactions
In the event of a merger, acquisition, restructuring, or sale of assets involving Onsurity, personal data may be transferred to the acquiring entity. We will notify affected users prior to any such transfer and ensure the acquiring entity is bound by obligations no less protective than this policy.
6.Data Retention
We retain personal data for as long as necessary to fulfil the purposes described in this policy, unless a longer retention period is required or permitted by law. Our retention guidelines are:
- Active account data: Retained for the duration of your active relationship with Onsurity, plus a reasonable period thereafter to handle late queries or disputes (typically 12 months after account closure).
- Insurance policy records: Retained for a minimum of 7 years from the date of policy expiry or the settlement of the last claim under that policy, in accordance with IRDAI guidelines and the Limitation Act, 1963.
- Financial and billing records: Retained for 7 years from the end of the relevant financial year, as required under the Income Tax Act, 1961, and GST law.
- Health and claims data: Retained for 7 years from the date of the last claim settlement, or longer if required by the insurer or applicable regulation.
- KYC records: Retained for a minimum of 5 years from the end of the business relationship, as required by anti-money laundering guidelines.
- Marketing consent records: Retained for 3 years after the most recent interaction to demonstrate compliance, and deleted upon verified withdrawal of consent.
- Technical logs and analytics data: Typically retained for 12–24 months in identifiable form, then aggregated or deleted.
- Deleted account data: Upon verified account deletion request, personal identifiers are removed or pseudonymised within 30 days, subject to the retention obligations above.
When data is no longer required and no legal retention obligation applies, we securely delete or anonymise it so that it can no longer be attributed to you.
7.Your Rights
Under India's DPDPA and, for EEA residents, the GDPR, you have rights in relation to your personal data. We are committed to facilitating these rights promptly and without undue friction.
7.1 Right of Access
You have the right to request a copy of the personal data we hold about you, information about the purposes for which it is processed, and the categories of recipients with whom it has been shared. We will provide this information within 30 days of a verified request.
7.2 Right to Correction & Rectification
You have the right to request correction of inaccurate personal data and completion of incomplete data. You can update most of your profile information directly within the Onsurity platform. For data that cannot be self-corrected (e.g., policy records), please contact us at privacy@onsurity.com.
7.3 Right to Erasure (Right to be Forgotten)
You may request deletion of your personal data where it is no longer necessary for the purposes for which it was collected, where you have withdrawn consent and there is no other legal basis for processing, or where you have objected to processing based on legitimate interests and your interests override ours. We will action erasure requests within 30 days, subject to legal retention obligations.
7.4 Right to Data Portability
Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, machine-readable format (e.g., CSV or JSON) and to transmit it to another service provider.
7.5 Right to Object
You may object to processing based on legitimate interests at any time. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims. You may object to direct marketing at any time without providing reasons, and we will stop immediately.
7.6 Right to Restrict Processing
In certain circumstances (e.g., while the accuracy of data is being contested, or during the assessment of an objection), you may request that we restrict processing to storage only.
7.7 Right to Withdraw Consent
Where processing is based on your consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing that took place before withdrawal.
7.8 Right to Complain
If you believe we have not handled your personal data lawfully, you have the right to lodge a complaint with India's Data Protection Board (once constituted under the DPDPA). EEA residents may also complain to the data protection authority in their country of residence.
To exercise any of the rights above, email us at privacy@onsurity.com with the subject line "Data Rights Request". We may ask you to verify your identity before acting on the request. We will respond within 30 days; complex requests may take up to 60 days, and we will notify you if an extension is needed.
8.Cookies Policy
Our website uses cookies and similar tracking technologies to provide core functionality, personalise your experience, and analyse how the site is used.
8.1 What Are Cookies?
Cookies are small text files placed on your device by your browser when you visit a website. They allow the website to recognise your device and remember information about your visit.
8.2 Types of Cookies We Use
- Strictly necessary cookies: Essential for the platform to function. These include session authentication tokens and CSRF protection cookies. They cannot be disabled without breaking core functionality.
- Functional cookies: Remember your preferences (e.g., language, saved filters) so you do not have to re-enter them on each visit.
- Analytics cookies: Help us understand aggregate traffic patterns and feature usage. Data collected is pseudonymised and used solely for internal product improvements.
- Marketing cookies: Placed by advertising networks to measure campaign effectiveness and serve relevant ads. These are activated only with your explicit consent.
8.3 Managing Cookies
You can manage cookie preferences through the consent banner shown on your first visit to our site, or at any time through the Cookie Settings link in our footer. You can also instruct your browser to refuse all cookies or alert you when cookies are being sent — however, some parts of our service may not function correctly without cookies.
For information on managing cookies in your browser, refer to your browser's help documentation. Useful third-party guides are available at aboutcookies.org.
8.4 Do Not Track
Some browsers transmit a "Do Not Track" signal. Because there is currently no industry consensus on how to respond to such signals, our platform does not alter its behaviour in response to them. You can use the cookie consent banner to opt out of non-essential tracking.
9.Data Security
We implement layered technical and organisational security measures proportionate to the sensitivity of the data we process. Our key controls include:
- Encryption in transit: All data transmitted between your browser or device and our servers is encrypted using TLS 1.2 or higher.
- Encryption at rest: Sensitive data — including health data, payment records, and identity documents — is encrypted at rest using AES-256 or equivalent standards.
- Access controls: Access to personal data is restricted on a strict need-to-know basis using role-based access controls (RBAC). All access is logged and periodically reviewed.
- Multi-factor authentication (MFA): Enforced for all internal staff and administrator accounts accessing production systems.
- Vulnerability management: Regular penetration testing, automated vulnerability scanning, and patch management processes are in place.
- Incident response: We maintain a documented data breach response plan. In the event of a breach affecting your rights and freedoms, we will notify the relevant regulator within the timeframe required by law and notify affected individuals without undue delay.
- Vendor security: Third-party vendors with access to personal data are required to meet our security standards and sign data processing agreements before being given access.
- Employee training: All Onsurity employees handling personal data receive mandatory data protection training at onboarding and annually thereafter.
While we apply robust security measures, no internet-based system is completely immune to threats. We encourage you to use a strong, unique password for your Onsurity account and to notify us immediately at security@onsurity.com if you suspect any unauthorised access.
10.Cross-Border Transfers
Onsurity primarily stores and processes personal data within India. However, some of our technology and service vendors operate servers in other countries, including the United States, Singapore, and member states of the European Union.
Where personal data is transferred outside India, we ensure adequate protections are in place, including:
- Transfers to countries or territories notified by the Government of India as providing adequate data protection under the DPDPA.
- Standard contractual clauses or equivalent data transfer mechanisms ensuring the recipient provides a level of protection equivalent to the DPDPA.
- Binding contractual commitments from the recipient to apply appropriate technical and organisational security measures.
Sensitive health and financial data is processed and stored within India wherever technically feasible, in accordance with IRDAI data localisation requirements for insurance records.
11.Children's Data
Onsurity's platform and services are designed for use by businesses and adult individuals. We do not knowingly collect personal data directly from children under the age of 18.
Dependants under 18 (such as children of employees enrolled as beneficiaries under a group health policy) may have their data processed as part of an insurance policy administered by an adult policyholder or employer. In such cases, the adult account holder or employer is responsible for ensuring that appropriate consent or other lawful basis exists for the processing of the minor's data.
If you believe we have inadvertently collected personal data from a child without appropriate authorisation, please contact us at privacy@onsurity.com and we will delete it promptly.
12.Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or the way we process your personal data, please contact our privacy team:
Privacy Officer — Onsurity Technologies Private Limited
Email: privacy@onsurity.com
Post: Privacy Officer, Onsurity Technologies Private Limited, 19th Floor, Raheja Towers, MG Road, Bengaluru, Karnataka 560 001
Response time: We aim to acknowledge your query within 2 business days and resolve it within 30 days.
We also maintain a Grievance Redressal Policy in accordance with the DPDPA and IRDAI guidelines. If you are not satisfied with our response to a privacy query, you may escalate to our Grievance Officer using the contact details in that policy.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will notify you by email (at the address associated with your account) or by displaying a prominent notice on our platform at least 30 days before the changes take effect.
The "Last updated" date at the top of this page indicates when the policy was most recently revised. We encourage you to review this policy periodically to stay informed about how we are protecting your data.
Your continued use of our services after a revised policy takes effect constitutes your acceptance of the updated terms. If you do not agree with the revised policy, you should discontinue use of our services and may request deletion of your account.
This policy was last reviewed by Onsurity's legal and compliance team on 01-Jan-2026 and is effective from that date. Onsurity Technologies Private Limited is registered with the IRDAI as a licensed insurance intermediary.