Digital Personal Data Protection (DPDP) compliance summary
How WebOptiva approaches India's Digital Personal Data Protection Act, 2023 for personal data collected through audits, reports, workspace accounts, and connected-domain telemetry.
Notice and purpose limitation
Personal data — such as a report recipient's email address, a workspace user's contact details, or a lead captured through an embedded audit widget — is collected only for the stated purpose: delivering the requested report, operating the account, or routing a captured lead to the tenant's configured CRM.
Purpose-limited collection
No secondary use without a documented basis
Consent capture on lead forms and embed widgets
Reasonable security safeguards
Account credentials use salted password hashing, one-time codes are HMAC-hashed at rest, and integration credentials are encrypted. Security events and audit findings are logged without persisting sensitive page content or exposed secrets.
Salted credential hashing
Encrypted third-party integration credentials
Security-event logging without sensitive-value persistence
Grievance redressal
Data principals may contact WebOptiva to request correction, erasure, or clarification about how their personal data is processed, consistent with DPDP data-principal rights.
Written grievance channel via the Contact page
Timely acknowledgment of data-principal requests
Escalation to account/security ownership for unresolved requests