Data Protection
Internal governance for responsible and secure personal-data handling
Effective Date: 01 January 2020
1. Purpose
This policy establishes how Web Apps Services governs personal data across its website, client engagements, workforce, vendors, applications and support operations.
It is intended to promote lawful, fair, transparent, secure and accountable processing.
2. Scope
This policy applies to founders, employees, contractors, consultants and authorized service providers who process personal data for Web Apps Services or on behalf of a client.
It covers digital personal data and related records in production, development, testing, support, backups and archives.
3. Core Data-Protection Principles
Process personal data only for a specific, lawful and communicated purpose.
Collect only data reasonably necessary for that purpose.
Keep data accurate and enable correction where required.
Retain data only for an approved period and dispose of it securely.
Apply security controls proportionate to sensitivity, volume and risk.
Maintain evidence of notices, consent where used, vendors, requests, incidents and decisions.
4. Data Inventory and Classification
A process is available to record the data category, source, purpose, people affected, system, owner, access roles, recipient, location, retention period and deletion method.
The data is classified as Public, Internal, Confidential or Restricted.
5. Notice, Consent and Purpose Control
While collecting it is informed and described the data, purpose, rights and contact route.
When consent is the processing basis, it is recorded when, how and for what purpose it was obtained and make withdrawal reasonably accessible.
6. Data Collection and Minimization
We do not use real personal data in development or demonstrations where synthetic or masked data is sufficient.
We do not copy client datasets into unapproved devices, drives, messaging systems or AI tools.
We review forms, logs, analytics and integrations periodically for unnecessary collection.
7. Access Control
We use named accounts, strong authentication and least-privilege access.
We use multi-factor authentication for administrative, cloud and source-control access where supported.
We review privileged access periodically and remove access promptly when roles end.
We keep production access limited, logged and separately controlled from development.
We store secrets in approved secret-management or protected configuration systems, not source code.
8. Secure Development and Operations
We apply secure design, code review, dependency management, validation and authorization checks.
We encrypt data in transit and use encryption at rest where appropriate to the risk and platform.
We maintain backups, recovery procedures, monitoring and security logging appropriate to the service.
We provide patch supported systems and address material vulnerabilities according to risk.
We separate client tenants and enforce authorization before retrieval, API access or AI processing.
9. Vendors and Data Processors
Before onboarding any sub processor we ensure that the data processor should address documented instructions, confidentiality, security, incident support, rights requests, return/deletion and audit information as per the agreed contractual agreement.
10. Client Data
Where Web Apps Services processes personal data for a client, the client generally determines purpose and lawful basis while Web Apps Services follows documented instructions.
A project-specific data-processing addendum should define categories, purpose, duration, security, subprocessors, international processing, requests, incident notification and deletion.
Unlawful or unsafe instructions must be escalated.
11. AI and Automated Processing
Do not submit confidential, personal or client data to unapproved public AI services.
Assess provider retention, training use, data location, access and deletion options before approval.
Minimize or redact personal data before AI processing wherever practicable.
Use human review for material decisions and approval for sensitive automated actions.
Log model/provider versions, purpose and material safeguards for production AI features.
12. Retention and Secure Disposal
Each data category have an approved retention period based on purpose, contract and legal obligations.
Project closure have trigger review of working files, credentials, test data, backups and vendor copies.
Disposal has secure deletion, cryptographic erasure, anonymization or physical destruction appropriate to the medium.
13. Individual Rights and Grievances
Requests concerning access information, correction, completion, erasure, consent withdrawal, grievance handling or nomination are logged, identity-verified, routed to the responsible contact and answered within the applicable period.
Responses records the search performed, decision, action and any lawful reason for refusal or retention.
14. Personal Data Breach Response
Immediately report suspected loss, unauthorized access, disclosure, alteration, ransomware or credential compromise.
Contain the event, preserve evidence, revoke exposed access and assess affected data, people and systems.
Notify management, relevant clients and advisers without undue internal delay.
Determine legally required notices to affected persons, the Data Protection Board of India, or other authorities based on applicable law and facts.
Document the timeline, impact, decisions, remediation and lessons learned.
15. International Processing
Cross-border processing documented and reviewed against applicable Indian restrictions, client commitments, provider locations and contractual safeguards.
16. Training and Confidentiality
Personnel with access to personal or client data must receive role-appropriate privacy, security and incident-reporting guidance and remain subject to confidentiality obligations.
Additional training are followed significant policy, system or threat changes.
17. Monitoring, Exceptions and Enforcement
Compliance will be reviewed through access reviews, project checks, vendor reviews, incident analysis and periodic audits.
Exceptions require documented scope, risk, compensating controls, owner and expiry date.
Violations may result in access removal, contractual action or other appropriate measures.
18. Policy Review
The management review this document at least annually and after material legal, service, provider or incident changes.
Superseded versions should be retained as controlled records.
Let's create something great together.
Tell us about your website, web application, AI tool, automation platform, or custom business solution.