norexıs← Back to login
Legal Document

Privacy Policy

Effective date: 14 June 2026Version: 1.0 — Draft for legal reviewJurisdiction: Kerala, India
Contents
1. Who We Are2. What We Collect3. How We Use It4. Legal Basis5. Data Sharing6. Retention7. Your Rights8. Security9. Children10. Changes11. Grievance Officer12. Contact

Summary: Norexis collects your mobile number and energy asset information solely to provide you with a unified energy management account. We do not sell your personal data. You may download, correct, or request deletion of your data at any time.

Section 01

Who We Are

Norexis is an energy account platform operated from Kerala, India. We provide consumers with a single account to manage their energy connections, usage history, and related documents.

"Norexis", "we", "us", and "our" refer to the platform operator. "You" refers to any individual who creates a Norexis account or uses our services.

This Privacy Policy is issued in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India.

Section 02

What We Collect

We collect only the personal data necessary to provide our services to you.

CategoryWhat We CollectWhy
ContactMobile numberAccount creation and authentication
ProfileDisplay name (optional, user-provided)Personalising your account
Energy accountsUtility consumer number, asset details you provideLinking and managing your energy accounts
Energy historyBill amounts, usage data, payment recordsYour energy dashboard and history
DocumentsDocuments you choose to uploadStoring proof of your energy assets
DeviceDevice token for push notificationsSending you bill and service alerts

We do not collect email addresses, home addresses, Aadhaar numbers, PAN numbers, or bank account details at this time.

Section 03

How We Use Your Data

We use your personal data only for the following purposes:

  • Creating and maintaining your energy account
  • Linking and displaying your energy assets and connections
  • Retrieving and displaying your utility bills
  • Computing and displaying energy usage insights and summaries
  • Verifying asset ownership when you request it
  • Sending notifications you have opted into
  • Storing documents you upload to your account vault
  • Maintaining your energy history record
  • Responding to your support requests
  • Complying with applicable laws

We do not use your personal data for automated decision-making that produces legal or similarly significant effects on you without human oversight.

Section 04

Legal Basis for Processing

We process your personal data on the following legal bases under the DPDP Act 2023:

  • Consent: You provide consent at registration by accepting these terms. You may withdraw consent at any time, subject to the effect described below.
  • Legitimate interest: Security monitoring and fraud prevention, to the extent not overridden by your interests.
  • Legal obligation: Where processing is required by applicable Indian law or regulatory authority.

Processing necessary to provide the core service (account management, bill retrieval, asset management) is disclosed in these terms. Only non-essential processing such as marketing communications requires a separate opt-in consent, which you may withdraw at any time without affecting your use of the platform.

Withdrawing consent to the core service processing will require account deletion, as such processing is necessary to provide the service.

Section 05

Who We Share Your Data With

We do not sell your personal data to any party.

We share your data only in the following circumstances:

  • Service providers: Third-party companies that process data on our behalf to provide our platform infrastructure, including cloud hosting, storage, messaging, and notification services. Each operates under a data processing agreement with us.
  • Utility providers:When you link a utility account, your account details are used to retrieve your billing information from that utility's systems. This is a retrieval process — we do not send your Norexis account data to the utility.
  • At your direction: When you choose to share your account information or documents with a third party using in-app sharing features, we share only what you have directed and only with the recipient you have chosen. Shared links are time-limited and you may revoke access.
  • Legal requirement: Where required by applicable Indian law, court order, or a competent regulatory authority.

Any future data sharing arrangements beyond the above will require your separate, explicit consent, which will be sought at that time with full disclosure of purpose and scope.

Section 06

How Long We Keep Your Data

We retain your personal data for as long as your account is active and as required by applicable law thereafter.

  • Account data: Retained for the life of your account and for the period required by law following account closure.
  • Energy history records: Your energy event history is maintained as a permanent, append-only record. This is a core feature of the service — the permanence of your energy history is what makes it verifiable. This is disclosed at registration.
  • Uploaded documents: Retained until you remove them from your account. Following removal, they are deleted from active storage within 90 days. A record that a document existed is retained for audit purposes.
  • Notification tokens: Retained until you log out or the token is replaced.

Following a verified account deletion request, your personally identifiable information will be removed or anonymised within 30 days, subject to any legal retention obligations.

Section 07

Your Rights

Under the DPDP Act 2023, you have the following rights as a data principal:

  • Right to access:Request a copy of all personal data we hold about you. Available via Account → Privacy & Data → Download My Data.
  • Right to correction: Request correction of inaccurate personal data. Available via your account settings.
  • Right to erasure: Request deletion of your account and personal data. We will process requests within 30 days as required by the DPDP Act. Note that energy history records are retained in anonymised form as described in Section 6.
  • Right to grievance redressal: Lodge a complaint with our Grievance Officer (Section 11) or with the Data Protection Board of India.
  • Right to nominate: Nominate a person to exercise your rights in the event of your death or incapacity. Contact the Grievance Officer to register a nomination.

To exercise any of these rights, use the tools in your account or contact us at grievance@norexis.in.

Section 08

How We Protect Your Data

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include encryption of sensitive data at rest and in transit, access controls, and regular security reviews.

Uploaded documents are stored in private, access-controlled storage. They are never publicly accessible. Any link you share to a document is time-limited and expires automatically.

No system is completely secure. If you suspect your account has been compromised, please contact us immediately at grievance@norexis.in.

If you discover a security vulnerability in our platform, please disclose it responsibly to grievance@norexis.in. We will acknowledge receipt within 48 hours.

Section 09

Children

Our platform is not directed at individuals under 18 years of age. We do not knowingly collect personal data from minors. If you believe a minor has created an account, please contact us at grievance@norexis.in and we will promptly investigate and, if confirmed, delete the account.

Section 10

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of material changes via in-app notice at least 14 days before they take effect.

Continued use of the platform after the effective date of a change constitutes your acceptance of the updated policy. If you do not accept the updated policy, you may request account deletion.

The date of the most recent update is shown at the top of this document. Prior versions are available on request from grievance@norexis.in.

Section 11

Grievance Officer

As required by the Digital Personal Data Protection Act 2023 and the Information Technology Act 2000, we have designated a Grievance Officer to address data-related complaints and queries.

Grievance Officer — Norexis

Name: Rosin Banu

Email: grievance@norexis.in

Response time: Within 30 days of receiving your complaint

Jurisdiction: Kerala, India

Please include your account identifier and a clear description of your concern when writing to us.

You also have the right to lodge a complaint with the Data Protection Board of India if you are not satisfied with our response.

Section 12

Contact

For privacy-related queries that are not formal complaints:

Norexis

Email: grievance@norexis.in

Website: norexis.in

Location: Kerala, India

This is a draft document pending formal legal review before public launch. Version 1.0 — 14 June 2026.

norexis. · Privacy Policy · Terms of Use · Grievance Officer: grievance@norexis.in

© 2026 Norexis. Kerala, India. DPDP Act 2023 compliant.