Overview
Worxley is designed to operate in compliance with the regulatory frameworks that apply to a business software platform operating in India. This page summarizes the frameworks we align with and where to go for more detail.
For the technical and administrative controls behind these commitments, see our Security page. For how we collect, use, and protect personal data, see our Privacy Policy.
Our Compliance Approach
Compliance at Worxley starts with a clear split of responsibility. Under the DPDP Act, every business using Worxley is a Data Fiduciary for the data it uploads — leads, contacts, deals, and customer records. We act as the Data Processor, handling that data strictly on your instructions.
This split is not just a legal formality — it shapes how the product is built. Every feature that touches customer data is designed so that your organization stays in control of it.
Digital Personal Data Protection Act, 2023 (DPDP Act)
We implement the obligations of a Data Processor and support your obligations as Data Fiduciary, including data subject rights, consent management, and cross-border transfer restrictions.
Information Technology Act, 2000 & 2008 Amendment
We maintain statutory reasonable security practices as defined under Section 43A of the IT Act and associated rules.
Payment and Settlement Systems Act, 2007
Payment collection features integrate exclusively with RBI-regulated payment gateways; we do not directly hold or settle customer funds.
Central Goods and Services Tax Act, 2017
Invoicing features support GST-compliant tax computation and disclosure for B2B transactions.
Data Residency
All Worxley infrastructure is hosted in India — specifically in the Mumbai (ap-south-1) region — on ISO 27001 and SOC 2 Type II certified data centre facilities. We do not host customer data outside India.
Data is replicated across geographically separated availability zones within India for high availability and disaster recovery, without any cross-border transfer.
Certifications & Independent Audits
Independent verification backs the commitments described on this page and on our Security page:
| Area | Standard / Cadence |
|---|---|
| Data centre hosting | ISO 27001 and SOC 2 Type II certified facilities (Mumbai, ap-south-1) |
| Penetration testing | Third-party test at least annually, and after any major architectural change |
| Security review | Reviewed quarterly by independent security firms |
For the full technical detail behind these controls — encryption standards, access control, incident response — see our Security page.
Sub-processor & Vendor Compliance
We maintain a strict vetting process for third-party vendors and sub-processors with access to customer data. Vendors sign Data Processing Agreements requiring security standards equivalent to our own, with 48-hour incident notification SLAs, before any customer data reaches them.
Your Compliance Responsibilities
As Data Fiduciary for the data you upload, some obligations stay with your organization even though we provide the tools to support them:
- Lawful basis: Confirming you have a valid basis (consent, contract, or otherwise) to collect and process the personal data you upload.
- Data subject requests: Responding to access, correction, or deletion requests from the individuals whose data you've uploaded — we give you the tools; the response is your organization's obligation.
- Internal access control: Configuring roles and permissions inside your Worxley account so only the right people on your team can see sensitive records.
- Retention decisions: Deciding how long customer records should be kept and removing data that's no longer needed.
Grievance & Regulatory Contact
If you believe your data rights have been violated or have a compliance-related concern, contact our Grievance Officer directly:
India
You also have the right to lodge a complaint with the Data Protection Board of India if you believe your data rights have been violated and we have not resolved your concern satisfactorily.