Privacy Policy

Last updated: August 2026

NOMIRIS (OPC) PRIVATE LIMITED ("Nomiris", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website (www.nomiris.com) and use our services.

1. Information We Collect

1.1 Information You Provide

When you engage our services, fill out a form, or communicate with us, we may collect:

  • Name, email address, phone number, and business name
  • Billing and payment information (processed via our payment partners)
  • Advertising account credentials (accessed via platform permission models; we do not store passwords)
  • Business and marketing data necessary to perform our services
  • Communications you send to us (support requests, feedback, etc.)

1.2 Information Collected Automatically

When you visit our website, we automatically collect:

  • IP address (anonymized where required by law)
  • Browser type and version
  • Operating system
  • Referring URLs and exit pages
  • Pages viewed, time spent, and navigation patterns
  • Device identifiers and cookie information

1.3 Information from Third Parties

We may receive information about you from third-party sources, including advertising platforms (Google, Meta), analytics providers, and business partners, in connection with the services we provide.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing, managing, and optimizing digital marketing services
  • Communicating with you about your campaigns, account, and services
  • Processing payments and maintaining billing records
  • Analyzing website usage to improve our website and services
  • Sending service-related notices and marketing communications (with your consent where required)
  • Complying with legal obligations and protecting our rights
  • Detecting and preventing fraud or unauthorized access

3. Legal Basis for Processing

We process personal data based on the following legal grounds:

  • Contractual necessity: Processing required to perform our services under our agreement with you.
  • Legitimate interest: Processing necessary for our legitimate business interests, such as improving our services and preventing fraud, where those interests are not overridden by your rights.
  • Consent: Where you have given explicit consent for specific processing activities.
  • Legal obligation: Processing required to comply with applicable laws.

4. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Remember your preferences and settings
  • Analyze website traffic and usage patterns
  • Measure the effectiveness of our marketing campaigns
  • Provide personalized content and advertisements

You can control cookies through your browser settings. Disabling cookies may affect the functionality of our website.

5. Information Sharing and Subprocessors

We do not sell your personal information. We may share your information with the following categories of recipients:

  • Advertising platforms: Google Ads, Meta (Facebook/Instagram), and other platforms as directed by your campaign strategy.
  • Analytics providers: Google Analytics, Tag Manager, and similar tools for performance measurement.
  • Payment processors: Razorpay, Stripe, or other payment partners for billing purposes.
  • Subprocessors: Third-party agencies or contractors who assist in service delivery, bound by equivalent confidentiality and data protection obligations. A current list of subprocessors is available upon request.
  • Legal authorities: When required by law, regulation, or legal process.

6. Data Retention

We retain personal data for as long as necessary to fulfill the purposes outlined in this policy:

  • Client account data: Retained for the duration of the engagement plus twelve (12) months after termination, to support account handover and disputes.
  • Campaign data and work product: Retained for twelve (12) months after the end of the engagement, unless you request earlier deletion.
  • Website analytics: Retained for twenty-six (26) months in anonymized form.
  • Payment records: Retained for seven (7) years as required by Indian tax law.
  • Marketing communications: Retained until you withdraw consent.

Upon request, we will delete or anonymize your personal data within thirty (30) days, subject to our legal retention obligations.

7. Data Security

We implement appropriate technical and organizational measures to protect your data, including:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Role-based access controls with least-privilege principles
  • Multi-factor authentication for systems containing client data
  • Regular security assessments and vulnerability monitoring
  • Employee training on data protection and confidentiality
  • Incident response procedures for data breaches

While we strive to protect your data, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but will promptly notify affected parties in the event of a data breach as required by applicable law.

8. Your Rights

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data, subject to legal retention obligations.
  • Objection: Object to processing based on legitimate interests.
  • Restriction: Request restriction of processing in certain circumstances.
  • Portability: Request transfer of your data in a structured, machine-readable format.
  • Withdraw consent: Withdraw consent for processing at any time where processing is based on consent.

To exercise any of these rights, contact us at growth@nomiris.com. We will respond within thirty (30) days.

9. Healthcare and HIPAA Considerations

Nomiris provides marketing services to healthcare practices. When processing Protected Health Information ("PHI") on behalf of healthcare clients:

  • A Business Associate Agreement ("BAA") will be executed before any PHI is processed.
  • PHI is accessed only on a need-to-know basis by authorized personnel.
  • PHI is never stored on Nomiris systems beyond what is necessary for service delivery.
  • All PHI handling complies with HIPAA, HITECH, and applicable state privacy laws.
  • Clients are responsible for ensuring that patient consent covers marketing-related data processing.

10. International Data Transfers

As a company based in India, your data may be processed in India or in other countries where our subprocessors operate. We ensure that international data transfers are protected by appropriate safeguards, including standard contractual clauses where required by applicable law.

11. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified via email or a prominent notice on our website at least fifteen (15) days before they take effect. The "Last updated" date at the top of this page indicates when this policy was last revised.

13. Contact Us

If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact:

NOMIRIS (OPC) PRIVATE LIMITED
CIN: U73100KA2026OPC219618
Email: growth@nomiris.com
Website: www.nomiris.com