This policy explains what Northstar Safety Systemz Private Limited ("Northstar", "we") collects, why, how it is protected, and the rights you have. It applies to the Axiomi platform at app.northstar-ehs.com, our mobile app, and this website.
For workspace data — the safety records your organisation keeps in Axiomi (incidents, permits, training, health surveillance and so on) — your employer or the organisation that invited you is the data controller (the "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023). Northstar processes that data only on their instructions, as their processor. Questions about why particular records about you exist in a workspace should go first to your organisation's Axiomi administrator.
For account and website data — your login identity, and information you send us through this website — Northstar is the controller.
We do not collect precise location, contacts, advertising identifiers, or anything from your device beyond what the app needs to work. Photos you attach to a report are uploaded only when you choose to attach them.
We never sell personal data, never share it with advertisers, and show no ads. AI features (such as Ask Northstar) operate on your workspace's own data to serve your workspace; we do not use your data to train models for other customers.
Where the GDPR applies: performance of contract (providing the service), legitimate interests (security, service improvement), and consent where required. Under the DPDP Act: processing for the legitimate uses and consented purposes notified to you by your Data Fiduciary, and by us for the purposes above.
| Provider | Purpose |
|---|---|
| Render | Cloud hosting & managed PostgreSQL database |
| Amazon Web Services (S3) | Encrypted off-site backups |
| Razorpay | Payment processing — card details go directly to Razorpay and never touch our servers |
| Microsoft 365 | Business email |
| Zoho | Billing & customer relationship records |
Each is bound by its own data-protection commitments; we list changes to this table here. Hosting is currently in the United States; on-premise deployment inside your own infrastructure is available where residency requirements demand it.
Workspace records are retained as long as your organisation's subscription is active and per the retention rules it configures — safety law itself often sets minimums (for example, five-year record retention under OSHA and Indian Factories Act requirements). On contract termination, your organisation can export its data; we delete workspace data after a wind-down period stated in the service agreement. Server logs are kept for a short rolling window. Enquiry emails are kept as long as the conversation is live plus a reasonable business period.
TLS for all traffic, AES-256-GCM field encryption for sensitive personal and health data at rest, scrypt password hashing, multi-factor authentication, SSO/SCIM, per-tenant tamper-evident audit chains, rate limiting and lockouts, and automated backups whose restorability is verified. The full picture is published on our Trust & Security page. If we ever become aware of a personal-data breach affecting you, we will notify affected organisations and authorities as the law requires.
For anything we control directly (your account, website enquiries), write to us at the address below and we will respond within the statutory time limits.
The app uses one strictly-necessary session cookie to keep you signed in, and your language/theme preferences are stored on your device. No advertising or cross-site tracking cookies, no third-party analytics trackers.
Axiomi is a workplace tool for professional use and is not directed at children. We do not knowingly process children's personal data.
Material changes to this policy are announced in the changelog with an updated effective date. Contact — including DPDP grievances — is:
Grievance & privacy contact: Arpan Aggarwal, Northstar Safety Systemz Private Limited, Chandigarh, India · privacy@northstar-ehs.com