Legal · Compliance

Compliance framework

The Indian law this product operates under, what the software does for you, and what stays your responsibility as the shop.

Effective 2026-10-03 Version 2026-10-01

Applicable law

This deployment is operated from India and is built for shops operating under Indian law. The framework that matters day to day is:

  • Digital Personal Data Protection Act, 2023 — consent, purpose limitation, the rights of a Data Principal, and the duties of a Data Fiduciary and Data Processor.
  • Information Technology Act, 2000 and the Information Technology (Reasonable Security) Rules, 2011 — reasonable security practices for personal data, plus obligations for intermediaries.
  • CERT-In directions of 28 August 2022 — incident reporting timelines, log retention and related operational requirements for qualifying systems.
  • Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020 — seller identity, published pricing, grievance officer and refund policy.
  • Payments — the payment gateways we redirect to are regulated by the Reserve Bank of India; we never hold card numbers, so we stay outside the cardholder data environment.
This page is a summary, not legal advice It describes what the software does and which obligations a shop still owns. It has not been written by a lawyer and does not substitute for advice on your own data flows, contracts and filings.

Information Technology Act and reasonable security

The 2011 Rules require a body corporate that holds personal data to implement reasonable security practices and a governance structure. In software terms that means:

  • access limited to people who need it, with roles defined per shop;
  • every record tied to a shop, and every query scoped to that shop;
  • credentials encrypted at rest rather than stored in plain configuration files;
  • protection against unauthorised access and tampering, with tamper-evident logging of sensitive changes;
  • a published grievance officer and contact route.

See the privacy policy for the detailed control list.

DPDPA 2023

For shops that collect customer documents — identity proofs, forms, scanned certificates — the Act is the central piece of law. The platform implements the mechanics:

  • Purpose limitation. Fields and work types are configurable, so a shop collects only what its chosen service actually needs.
  • Consent that is recorded. Sign-up captures an affirmative consent against a specific policy version, with the timestamp, IP address and user agent, in a privacy_consents record. Consent is never inferred from silence or a pre-ticked box.
  • Notice at collection. The notice is shown before the account is created and links to this policy set.
  • Rights. Access, correction, erasure, withdrawal of consent, grievance redressal and nomination are described in the DPDPA rights page, with a named privacy officer and grievance officer.
  • No children's data without verifiable parental consent. Sign-up is restricted to adults, and the policy states the restriction plainly.

The shop remains the Data Fiduciary for its own customer records. This platform is a Data Processor for those records and a Data Fiduciary for your account, billing and support data.

CERT-In directions

The CERT-In directions of 28 August 2022 apply to certain system operators and to entities of significant size. Where they apply, they require, among other things:

  • reporting cyber-security incidents to CERT-In within six hours of noticing them, or being brought to notice of them;
  • enabling and continuously operating a security incident reporting platform;
  • retaining logs for 180 days inside the country, with integrity checks on them;
  • synchronising system clocks with an NTP source, and maintaining a list of asset owners; annual reporting.
What the software does Sensitive changes are written to an append-only audit log with the acting user, IP address and before/after values, and failed sign-in attempts and access denials are recorded. That gives you the evidence trail the directions expect. Deciding when an incident is reportable, running the six-hour clock and filing with CERT-In remain a human, documented process — the platform cannot make that call for you.

If you operate a shop that falls within scope, set your security contact and log retention period from the Super Admin settings so they appear on your published policies.

Consumer protection and e-commerce rules

Where a shop takes payment for services through this platform, the Consumer Protection (E-Commerce) Rules, 2020 require, among other things:

  • clear display of the name and contact details of the seller / service provider;
  • fair and transparent pricing, with the applicable taxes shown before payment;
  • a published grievance officer and a working grievance channel;
  • a published return, refund and cancellation policy;
  • no misleading claims about goods or services.

The platform supports these by publishing, from your own configured identity:

  • the operator's legal entity, registered address, GSTIN and contact channels on every public page and policy;
  • a payments and refunds policy that explains manual UPI/QR verification and refund timelines;
  • a grievance officer with an email address shown in the footer and on the DPDPA rights page.

Payments and card data

Card and UPI payment details are entered on and handled by the payment gateway, never by this application. The platform stores only what is needed to reconcile: amount, currency, time, method, gateway reference, status and — for manual UPI, QR and bank transfers — the reference number the customer supplies and the verification decision.

Because no cardholder data is stored, processed or transmitted by this application, the shop stays outside the cardholder data environment and does not take on its PCI DSS obligations. Your obligations sit with the payment service provider and with the contract you have with them.

Card details, CVVs, OTPs and banking passwords are never requested by this platform, by its support, or by the person who administers it. Report any such request as fraud.

Manual transfer evidence

A bank or UPI transfer cannot be confirmed by an API, so the customer submits two additional data points with it. Both are personal or financial information, and both are handled as described here:

  • Transaction reference (UTR). Stored so a payment can be matched to a statement row. Each reference is accepted once only — a unique database constraint enforces this, so one transfer cannot be claimed against two subscriptions. A repeated submission is refused rather than paid out again.
  • Screenshot of the bank's confirmation. Accepted as an image, re-decoded on upload so a renamed file cannot smuggle in another type, and written outside the public web root. It is not served as a static file and has no public URL. Only the platform administrator verifying that specific payment can open it, through an authenticated route.

Confirmation is a human decision, made by matching the reference against the platform's bank statement. The submitted screenshot is supporting evidence for that decision; it is never treated as sufficient on its own, and uploading one never activates a subscription.

Rejected attempts are marked with a reason rather than deleted, so a disputed payment keeps an audit trail, and the decision records who made it and when.

GST and invoicing

A receipt is issued for every successful payment and is available in the billing history. Where GST applies, the invoice states the taxable value, the rate and amount of tax, the supplier's GSTIN and the customer's GSTIN where the customer has provided one.

Ensure the entity name, registered address and GSTIN configured in the Super Admin settings match your registrations exactly — invoices quoting inconsistent details are the most common cause of a rejected input claim.

Records, retention and audit

  • Business records stay under the shop's control until the shop deletes them or the account is closed.
  • Consent records, with policy version, timestamp, IP and user agent, are retained as evidence of lawful processing.
  • Security and audit logs support incident investigation and any regulatory enquiry.
  • Backups age out on the hosting provider's cycle; nothing is silently retained forever.

Your responsibilities as a shop

Software cannot discharge these for you. A shop using WorkTrack Pro remains responsible for:

  • having a lawful basis, and giving the notice, before collecting a customer's data;
  • not collecting data beyond what the specific service needs, and not collecting prohibited categories without a lawful basis;
  • obtaining verifiable parental consent before handling a child's data;
  • answering a customer's access, correction or erasure request — this platform gives you the records to do so;
  • telling us to delete data of a customer whose services have ended, when asked;
  • keeping staff access to a minimum, and closing accounts of staff who leave;
  • deciding whether an incident is reportable, and meeting any CERT-In or police reporting deadline that applies to your business.

Contact

Operator
Registered address
Available on request
General
Privacy officer
Privacy Officer ·
Grievance officer