Loading…
Version 2026-09-27 · Effective 27 September 2026
This Privacy Policy explains how Otlo collects, uses, shares, and protects personal data for individual Users and across Communities, Events, and Brand pages, and how you can exercise your rights.
Otlo processes personal data to create and secure User accounts, power profiles and networks, and deliver community management, event participation, and brand engagement features.
Otlo is committed to full compliance with applicable data-protection and privacy rules of competent legal bodies for Users as data principals, including obligations under India’s Digital Personal Data Protection Act, 2023 (DPDP) and other laws that apply to Otlo’s processing of User, Community, Event, and Brand-related personal data.
User account and profile data may include phone number, name, username, photo, bio, keywords, work details, social links, city/state, date of birth, gender (where provided), platform status, and connection relationships.
Community data may include membership, roles, join applications, form responses, invites, announcements, and moderation actions linked to User identities.
Event data may include RSVPs, registration answers, guest lists, host/team roles, chat participation metadata, and feedback responses linked to attending Users.
Brand data may include business profile fields, follower relationships (Users who follow a Brand), and operator roles tied to a business page.
Technical and preference data may include session cookies, device signals needed for security, notification permission state, and location settings a User enables.
We use personal data to authenticate Users, operate profiles and networks, run Communities, Events, and Brands, personalise discovery (such as city-based Explore results), send notifications Users allow, prevent abuse, and meet legal obligations.
Sensitive or voluntary fields (for example gender or precise location) are collected only where the product flow discloses purpose to the User and records consent or another lawful basis where required.
Your User profile is the primary identity surface on Otlo. Depending on relationship and visibility rules, other Users may see your name, username, photo, city, bio, work summary, interests, and social links you choose to publish.
Otlo processes connection requests, accepts, withdrawals, and disconnects so Users can manage who is in their network. Connection-related notices may be delivered according to your notification settings.
You can update profile fields, location preferences, notification permissions, and account status in Settings. Account disablement and deletion are User rights-supporting controls subject to legal retention and fraud-prevention needs.
Otlo’s User privacy compliance includes purpose limitation for onboarding data, recorded platform Terms and Privacy acceptance, optional permission consents, and pathways to request access, correction, or deletion under applicable law.
When a User joins a Community, operators with appropriate roles may see membership details and application answers needed to admit and manage members.
Community operators must use join-form and membership data only for the Community purpose disclosed to applicants, and must not export or misuse User member data outside Otlo except as allowed by law and their own notices.
Otlo provides tools for policy acknowledgement, role-based access, and ownership transfer so Community administration stays accountable to Users and to law.
Hosts and authorised event team members may access guest and registration information required to run the Event, including capacity, RSVP status, and form answers submitted by Users.
Event chat and feedback features process messages and responses only for Users who are granted access under event rules.
If an Event is linked to a Community or Brand, relevant organisers may receive attendance context consistent with that link and their permissions.
Public Brand profile fields you publish (name, logo, description, industry tags, socials) may be visible to visiting Users and followers.
Brand administrators can see operational data needed to manage the page. Follower lists and engagement signals are processed to power follow/unfollow and discovery features for Users.
Brand operators must ensure published information does not unlawfully disclose third-party personal data of Users or others.
Otlo shares a User’s personal data with other Users only as needed for the features that User uses (for example, showing a profile to a Community they join or to a connection).
Otlo may use infrastructure and messaging providers as processors under contracts that require confidentiality and security. Otlo does not sell User personal data.
Otlo may disclose information when required by law, legal process, or to protect User rights, safety, and platform integrity.
Otlo retains personal data for as long as needed to provide the service to the User, resolve disputes, enforce policies, and meet legal retention duties. Account disablement and deletion flows are available in Settings, including a grace window before permanent deletion where applicable.
Otlo applies technical and organisational measures appropriate to the risk, including access controls and secure transport.
Subject to applicable law, Users may request access, correction, withdrawal of consent (where processing is consent-based), or deletion. Use in-app Settings or Otlo support to raise a request. Otlo will respond in line with legal timelines for data principals.
If User data is processed in more than one region, Otlo uses safeguards consistent with applicable transfer rules.
Otlo is not directed at children where local law requires parental consent without verification. Age gates and DOB collection support compliance with age-related requirements protecting young Users.
We may update this Privacy Policy when products or laws change. The version identifier and effective date above will be revised, and Otlo may request renewed acceptance from Users when required.