Legal · Data protection
Your rights under the DPDPA, 2023
A practical guide to what the Digital Personal Data Protection Act, 2023 gives you, and how to use it.
About this notice
This notice explains your rights under the Digital Personal Data Protection Act, 2023 ("DPDPA") and the rules made under it, in relation to personal data processed through this platform.
WorkTrack Pro is used by many independent shops. This creates two roles:
- The shop using the service (the tenant) is normally the Data Fiduciary — it decides which of your data to collect and why. Example: a cyber café that records your phone number to process a PAN application.
- is normally a Data Fiduciary only for the account, billing and support data you give directly to us, and a Data Processor when handling a shop's records on its instructions.
The principles we follow
Personal data must be processed only for a lawful purpose, on a basis permitted by the DPDPA, and in a way that a reasonable person would consider fair in the circumstances.
Concretely, the platform is built so that a shop can:
- Collect only what it needs. Fields are configurable, so data can be limited to the purpose at hand.
- Keep it accurate. Records can be corrected and versioned through status history.
- Keep it no longer than necessary. Records are deleted on request or when the account closes, subject to legal retention duties.
- Keep it secure. Tenant scoping, role-based access, encrypted credentials and an audit log are built in rather than optional.
- Dispose of it safely. Deletion removes the record; residual copies age out of backups on the hosting provider's schedule.
Your rights
As a Data Principal — a person whose personal data is processed — you have these rights:
Summary information
You may ask for a summary of your personal data being processed and of its processing activity, in a plain, clear and accessible format.
Correction and updation
You may require your data to be corrected, completed, updated or erased if it is not accurate, or if it is no longer needed for the purpose it was collected for.
Erasure
You may require erasure of personal data that is no longer necessary for the purpose it was collected for — subject to the exceptions in section 08.
Withdrawal of consent
Where processing is based on your consent, you may withdraw it at any time, for the future. Withdrawal does not affect the lawfulness of processing already carried out.
Grievance redressal
You may raise a grievance about how your data has been handled, using the channel in section 09.
Nomination
You may nominate another person to exercise your rights on your behalf, including in the event of your death or in circumstances you choose.
Consent
Where we rely on consent, it must be:
- Free to give — not forced by making the service conditional on unrelated processing.
- Specific — given for a stated purpose, not a blanket permission covering everything.
- Informed — given after you understand what is being collected and why.
- Unambiguous — an affirmative act by you, not pre-ticked boxes or silence.
- Capable of being withdrawn — as easily as it was given.
Consent is not required where the DPDPA permits processing without it (see section 05), and is not required for data you have voluntarily provided for a specified purpose.
Withdrawing consent will not result in you being denied a service you asked for, or being treated differently, where the withdrawal concerns processing that was not necessary for that service.
Where a shop has collected your data without a lawful basis, ask it to stop — and use section 09 if it does not.
Processing without your consent
The DPDPA allows processing without consent in certain cases, including where you have voluntarily provided personal data yourself for a specified purpose, and where processing is necessary for certain legitimate uses — such as fulfilling a contract with you, or complying with a legal obligation.
Some processing is also permitted for reasonable purposes set out in the Act, such as fraud prevention, network security, and recovering a debt owed to you.
We do not use your personal data for automated decision-making that produces legal effects about you without human involvement.
How to make a request
- Identify who holds the data. Name the shop, or tell us it is data you gave directly to .
- Tell us what you want. A summary, a correction, an erasure, a withdrawal of consent, or a grievance — and which record it relates to.
- Send it to the privacy contact in section 11, or through the shop's own published contact.
- Confirm your identity when we ask (see section 07).
- Wait for the response. We aim to acknowledge within 7 days and to give a substantive response within 30 days. If we need longer for a complex request we will tell you, with a reason and a revised date.
Verification
Before acting on a request we must be satisfied that it genuinely comes from you. We may ask for:
- the account email or phone number associated with the record;
- a limited piece of information only you would know about the record;
- proof of identity or authority, such as a nominee's or representative's authorisation.
We collect only what is needed to verify you, we do not keep a copy of identity documents beyond the verification step unless the law requires it, and we will destroy any copy promptly.
If verification fails we will decline and explain why. If a request would reveal another person's personal data, we will redact that part rather than refuse the whole request where we reasonably can.
Limits on your rights
The DPDPA permits refusal in defined situations. Examples include where:
- compliance would reveal another person's personal data, or the identity of the person who gave us information in confidence;
- compliance would result in disclosure of a commercial secret, intellectual property or an invention whose disclosure would harm you or someone else;
- the data is being used for statistical, research or archiving purposes and compliance would seriously impede those purposes;
- the request is frivolous or vexatious, or has already been answered in substance;
- the data is required to be retained by law, for the exercise of a legal claim, or for enforcing a contractual obligation;
- compliance would compromise the sovereignty and integrity of India, public order, or the prevention, investigation or prosecution of an offence.
If we refuse, we will tell you the reasons and explain that you may prefer to use the grievance process.
Grievance redressal
Every Data Fiduciary must have a grievance officer. You may raise a grievance with either the shop that collected your data, or with us for data held in your account, billing or support history.
If you are not satisfied with our response, you may prefer to escalate. Under the DPDPA you may raise the matter with the Data Protection Board of India established under the Act, and you may also pursue any other remedy available to you under law. You may also complain to the shop's own grievance officer in the first instance.
Children's data
Verifiable parental consent is required before processing the personal data of a child (under 18), and tracking behaviour, behavioural monitoring and targeted advertising directed at children are not permitted.
Tenants must not collect children's personal data through this platform unless they hold verifiable parental consent and comply with these restrictions. If you believe a child's data has been collected improperly, contact the grievance officer with the details.