Privacy Policy

Plain words about your data.

This policy explains what Northstar Safety Systemz Private Limited ("Northstar", "we") collects, why, how it is protected, and the rights you have. It applies to the Axiomi platform at app.northstar-ehs.com, our mobile app, and this website.

Effective 4 August 2026 · Northstar Safety Systemz Private Limited, Chandigarh, India

1. The two roles we play

For workspace data — the safety records your organisation keeps in Axiomi (incidents, permits, training, health surveillance and so on) — your employer or the organisation that invited you is the data controller (the "Data Fiduciary" under India's Digital Personal Data Protection Act, 2023). Northstar processes that data only on their instructions, as their processor. Questions about why particular records about you exist in a workspace should go first to your organisation's Axiomi administrator.

For account and website data — your login identity, and information you send us through this website — Northstar is the controller.

2. What we collect

  • Account data: name, work email, role/title, department, password (stored only as a salted scrypt hash — we cannot see it), and optional multi-factor authentication enrolment.
  • Workspace records: whatever your organisation chooses to record in Axiomi. Some of this can include personal data (e.g. who reported an incident) and, in occupational-health modules, health-related data. Sensitive fields — names in medical records, medical findings, clinician notes, work restrictions — are encrypted with AES-256-GCM before they reach the database.
  • Technical data: server logs (IP address, timestamps, requested pages) kept for security and troubleshooting, and an activity trail of actions taken in your workspace, kept for auditability.
  • Website enquiries: what you submit through "Request a demo" or "Talk to sales" (name, company, email, phone, message).

We do not collect precise location, contacts, advertising identifiers, or anything from your device beyond what the app needs to work. Photos you attach to a report are uploaded only when you choose to attach them.

3. What we use it for

  • Providing and securing the service — authentication, authorisation, audit trails, backups, abuse prevention.
  • Operating your organisation's safety management system on its instructions.
  • Responding to enquiries you send us, and administering billing and contracts.
  • Improving reliability using aggregate, de-identified technical metrics.

We never sell personal data, never share it with advertisers, and show no ads. AI features (such as Ask Northstar) operate on your workspace's own data to serve your workspace; we do not use your data to train models for other customers.

4. Legal bases

Where the GDPR applies: performance of contract (providing the service), legitimate interests (security, service improvement), and consent where required. Under the DPDP Act: processing for the legitimate uses and consented purposes notified to you by your Data Fiduciary, and by us for the purposes above.

5. Who else touches the data (sub-processors)

ProviderPurpose
RenderCloud hosting & managed PostgreSQL database
Amazon Web Services (S3)Encrypted off-site backups
RazorpayPayment processing — card details go directly to Razorpay and never touch our servers
Microsoft 365Business email
ZohoBilling & customer relationship records

Each is bound by its own data-protection commitments; we list changes to this table here. Hosting is currently in the United States; on-premise deployment inside your own infrastructure is available where residency requirements demand it.

6. How long we keep it

Workspace records are retained as long as your organisation's subscription is active and per the retention rules it configures — safety law itself often sets minimums (for example, five-year record retention under OSHA and Indian Factories Act requirements). On contract termination, your organisation can export its data; we delete workspace data after a wind-down period stated in the service agreement. Server logs are kept for a short rolling window. Enquiry emails are kept as long as the conversation is live plus a reasonable business period.

7. Security

TLS for all traffic, AES-256-GCM field encryption for sensitive personal and health data at rest, scrypt password hashing, multi-factor authentication, SSO/SCIM, per-tenant tamper-evident audit chains, rate limiting and lockouts, and automated backups whose restorability is verified. The full picture is published on our Trust & Security page. If we ever become aware of a personal-data breach affecting you, we will notify affected organisations and authorities as the law requires.

8. Your rights

  • Under the DPDP Act (India): access to a summary of your personal data and processing, correction and erasure, grievance redressal, and the right to nominate. Requests about workspace records go to your organisation (the Data Fiduciary); we support them in fulfilling these.
  • Under the GDPR (where applicable): access, rectification, erasure, restriction, portability, and objection; and the right to complain to your supervisory authority.

For anything we control directly (your account, website enquiries), write to us at the address below and we will respond within the statutory time limits.

9. Cookies

The app uses one strictly-necessary session cookie to keep you signed in, and your language/theme preferences are stored on your device. No advertising or cross-site tracking cookies, no third-party analytics trackers.

10. Children

Axiomi is a workplace tool for professional use and is not directed at children. We do not knowingly process children's personal data.

11. Changes & contact

Material changes to this policy are announced in the changelog with an updated effective date. Contact — including DPDP grievances — is:

Grievance & privacy contact: Arpan Aggarwal, Northstar Safety Systemz Private Limited, Chandigarh, India · privacy@northstar-ehs.com