Legal · Privacy

Privacy Policy

What we collect, why we collect it, who can see it, and how to exercise your rights.

Effective 2026-10-05 Version 2026-10-01 WorkTrack Pro

Who we are, and who is responsible

WorkTrack Pro ("we", "us") operates this service. Our registered address is available on request and our contact address is support@example.com.

WorkTrack Pro is a multi-tenant platform. The shop or organisation that created your record — the "tenant" — decides what to enter about you and why. For that information the tenant is the data fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDPA"), and we process it on the tenant's instructions as a data processor.

For information about you as a user of this website — your account, your billing relationship, support requests you send directly to us — we are the data fiduciary.

The short version If you are a customer of one of the shops using this platform, address your request to that shop first. They hold your record; we only process it for them.

What we process

Depending on how the service is used, the following categories may be processed:

  • Account data — name, email address, phone number, password hash, role and branch assignment.
  • Tenant data — shop name, business type, address, GST/PAN and other details the tenant chooses to record.
  • Customer records — contact details, identity document references, work history and payment history entered by a tenant.
  • Documents — files uploaded by a tenant to support a job, such as forms, scans and certificates.
  • Communications — Telegram messages, WhatsApp messages, email content and support tickets, where those integrations are switched on.
  • Transaction data — amounts, dates, method, payment references and verification status. We do not store full card numbers or CVVs; card payments are handled by the payment provider.
  • Technical data — IP address, user agent, timestamps, page views and security events recorded in logs.
Please do not enter sensitive data unless it is necessary The DPDPA restricts processing of certain personal data, including financial information, health information, biometric information and anything revealing a religious or philosophical belief or sexual orientation. Do not enter such data unless you have a lawful basis, have given any required notice, and have recorded consent where consent is the basis relied upon.

Why we process it

Under the DPDPA, personal data may be processed for a lawful purpose on the basis of consent, or without consent for certain "legitimate uses" such as data you have voluntarily provided to a specified purpose, or processing necessary for a contract.

  • To provide, secure and support the service you or your organisation signed up for.
  • To process subscriptions, invoices and payment verification.
  • To send the reminders, notifications and updates you or your organisation have asked for.
  • To prevent fraud, abuse, unauthorised access and other harmful activity.
  • To meet accounting, tax and other legal obligations that apply to us.
  • To answer support, privacy and grievance requests.

We do not sell personal data. We do not use tenant business records to train third-party AI models; where an AI feature is enabled, only the specific content you submit is sent to the configured provider to generate that response.

Who can see your data

  • Your tenant's staff. Access is role-based and scoped to the tenant. Staff only see the shops they are assigned to.
  • The platform administrator. A small number of operators can access the system to maintain it. Access is restricted, logged and auditable.
  • Sub-processors. Hosting, email delivery, payment gateways, messaging networks and, if enabled, the AI provider.

Sub-processors are given only what they need to perform their function. Each shop's bot tokens and gateway keys are encrypted at rest and are not visible to other tenants or to shop staff.

Sharing and international transfers

We share personal data only with:

  • the tenant that the record belongs to;
  • service providers acting on our instructions under a written agreement;
  • payment providers, to complete a payment you initiate;
  • messaging networks (Telegram, WhatsApp, email) when you use those channels;
  • authorities, where disclosure is required by applicable law.

If personal data is transferred outside India, we take reasonable steps to ensure a standard of protection comparable to that under the DPDPA, as required by the applicable rules.

Security

We apply layered controls rather than relying on any single measure:

  • Tenant scoping enforced in application middleware on every query.
  • Passwords stored only as salted hashes; sessions invalidated on logout.
  • Secrets encrypted at rest using Laravel's application-level encryption.
  • CSRF protection on all state-changing forms, and validation on every input.
  • Role and permission checks on the platform administration panel.
  • An append-only audit log of sensitive changes, including user, IP and before/after values.
  • Telegram actions restricted to explicitly approved chat IDs.
  • Installer and upgrade entry points are single-use and must be deleted after setup.

No system connected to the internet can be guaranteed completely secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authority as required by law.

Retention

We keep personal data only as long as needed for the purposes described here.

  • Tenant business records are retained until the tenant deletes them or the account is closed.
  • After account closure we retain a limited set of records for the period required by accounting, tax and dispute-resolution obligations, then delete or anonymise them.
  • Security and audit logs are kept for a shorter, defined period.
  • Backup copies age out on the hosting provider's backup cycle.

Tenants can request export or deletion of their records through the contact details below.

Your rights

Subject to applicable law, you may ask for:

  • Summary information about the personal data held about you and how it has been used.
  • Correction or updating of data that is inaccurate or incomplete.
  • Erasable deletion where the data is no longer necessary and retention is not required by law.
  • Withdrawal of consent at any time, where consent was the basis for processing — without affecting processing already carried out.
  • Grievance redressal through the channels below.
  • Nomination rights, where applicable under the DPDPA.

We may need to verify your identity before acting on a request, and may decline where a lawful exception applies — for example where disclosure would reveal another person's personal data or breach a legal obligation. If we decline, we will tell you why.

Nominate someone else Where permitted, you may nominate another individual to exercise your rights on your behalf in the event of your death or incapacity.

Cookies and tracking

The public pages of this site set no advertising or tracking cookies. Signed-in areas use a strictly necessary session cookie to keep you authenticated; disabling it will sign you out. We do not run third-party advertising trackers or cross-site profiling on this site.

Changes to this policy

We update this policy when the service or the law changes. The version and effective date at the top of this page show the current text. Where a change is material, we will give notice through the service or by email before it takes effect.

Contact

Privacy officer
Privacy Officer · privacy@example.com
General contact
support@example.com
Post
Available on request

This document is a working template prepared for this deployment. It should be reviewed against your actual data flows, sub-processors, retention periods and contracts by a qualified professional before you rely on it.