Overview
Worxley is a product of Acadyn Labs LLP ("we", "us", "our"), a limited liability partnership incorporated in India. We operate Worxley — an AI-first Customer Operations platform for Indian businesses, powered in part by our Worxley AI layer.
This Privacy Policy explains what personal data we collect when you use our platform, how we use and protect it, and what rights you have under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 (IT Act).
By accessing or using Worxley, you agree to the collection and use of information as described in this policy. If you are using Worxley on behalf of an organization, you represent that you have the authority to bind that organization to this policy.
Data We Collect
2.1 Account & Subscriber Data
When an organization subscribes to Worxley, we collect information from the account administrator, including: full name, business email address, mobile number, organization name and registered address, team size, GST number (for invoicing), and designation or role within the organization.
2.2 Customer Operations Data
Organizations using Worxley may upload lead, contact, and customer data including names, business contact details, communication history, deal values, and associated notes. This data is processed strictly on behalf of your organization (the Data Fiduciary) and is never used for any purpose other than operating your Worxley environment.
2.3 Usage & Technical Data
We automatically collect technical data when you use the platform: IP address, browser type and version, device type and operating system, pages visited and features used, session duration and timestamps, error logs, and API call logs. This data is used to operate, secure, and improve the platform.
2.4 Communications Data
If you contact our support team, we retain records of the conversation (email, chat transcript) to provide continuity of support and to improve our service quality.
How We Use Your Data
We use the data we collect for the following purposes, each with a legal basis:
| Purpose | Legal Basis |
|---|---|
| Providing and operating the Worxley platform | Contract performance |
| Sending transactional communications (receipts, alerts, service notices) | Contract performance |
| Responding to support requests and resolving issues | Contract performance |
| Detecting and preventing fraud, abuse, and security threats | Legitimate interest |
| Improving platform performance and developing new features | Legitimate interest |
| Complying with legal obligations (tax, regulatory, statutory filings) | Legal obligation |
| Sending marketing and product updates (only with explicit consent) | Consent |
We do not use your data to train any AI or machine learning model for commercial sale. Worxley AI, the AI layer built into Worxley, operates only on your organization's own CRM data, within your isolated environment.
Storage & Location
All Worxley data — including lead, contact, and deal records, and account information — is stored on servers physically located in India (Mumbai region). We do not transfer personal data outside India except where explicitly authorized by you and permitted under applicable Indian law.
Our infrastructure is hosted on ISO 27001-certified data centre facilities. Data is replicated across availability zones within India for redundancy and disaster recovery, without any cross-border transfer of personal data.
Sensitive fields — including billing information, payment details, and customer contact records — are encrypted at rest using AES-256 encryption. All data in transit is protected using TLS 1.3.
One exception, and only with your explicit action: if you connect a third-party app (Google, Zoom, WhatsApp Business, or a payment gateway) under Section 12, the specific data required by that feature is transmitted to that provider's infrastructure, which may be located outside India. This transfer only happens for accounts you personally connect, only for the data described in Section 12, and stops entirely when you disconnect. If you connect no apps, no Worxley data leaves India.
Data Retention
We retain personal data for as long as necessary to provide our services and meet our legal obligations. The following retention periods apply:
| Data Category | Retention Period | Basis |
|---|---|---|
| Account / subscriber data | Duration of subscription + 90 days | Contract |
| CRM data (leads, contacts, deals, notes) | Duration of subscription + 90 days, or as configured by your org | Contract / Configurable |
| Support communications | 2 years from last interaction | Operational |
| Usage / technical logs | 12 months rolling | Security and debugging |
| Connected-app credentials (OAuth tokens) | Until you disconnect the app — deleted immediately on disconnect | Contract / Consent |
When a subscription is terminated, we will delete or anonymize all non-statutory data within 90 days. Data subject to statutory retention periods will be held in a restricted, read-only archive until the applicable period expires, then permanently deleted.
Your Rights
Under the Digital Personal Data Protection Act, 2023, you have the following rights with respect to your personal data:
- Right to access: You may request a summary of the personal data we hold about you and how it is being used.
- Right to correction: You may request correction of inaccurate or incomplete personal data.
- Right to erasure: You may request deletion of your personal data, subject to statutory retention requirements that legally prevent deletion.
- Right to grievance redressal: You may raise a complaint with our Grievance Officer (details in Section 11) and receive a response within 30 days.
- Right to nominate: You may nominate another individual to exercise your rights on your behalf in case of incapacity or death, as permitted under the DPDP Act.
If a business has entered your contact or deal details into their Worxley account, some of these rights must be exercised through that business (as the Data Fiduciary), not directly with us. We will refer such requests appropriately.
To exercise any right, email: privacy@worxley.com. We will respond within 30 days. For complex requests, we may extend this by an additional 30 days with notice.
Children's Data
Worxley is a business-to-business platform intended for use by organizations and their employees. We do not knowingly collect or process personal data from individuals under the age of 18. If you believe a minor's data has been submitted to our platform, please contact us immediately at privacy@worxley.com and we will delete it promptly.
Policy Changes
We may update this Privacy Policy from time to time to reflect changes in law, our practices, or our platform. When we make material changes, we will:
- Send an email notification to the account administrator at least 30 days before the change takes effect
- Display a prominent in-app notice when you log in
- Update the "Last updated" date at the top of this page
Your continued use of Worxley after the effective date of a revised policy constitutes your acceptance of the changes. If you do not agree, you may terminate your subscription before the changes take effect.
Contact Us
If you have questions about this Privacy Policy or wish to exercise your data rights, you may contact us through the following:
India
You also have the right to lodge a complaint with the Data Protection Board of India if you believe your data rights have been violated and we have not resolved your concern satisfactorily.
Third-Party Integrations & Connected Apps
Worxley can connect to external services so that work done in the CRM appears in the tools you already use. Every connection is optional and per-user: nothing is connected by default, each person connects their own account from Configuration → System → Marketplace, and no data is exchanged with a provider until they do.
11.1 Google Services
If you connect a Google account, we request the narrowest scopes that support each feature. We collect your Google account email address and account ID, solely to display which account is linked and to confirm the connection is still valid.
| Feature | What we do with Google data |
|---|---|
| Google Calendar | Create, update and delete calendar events for meetings you schedule in the CRM. We never read your existing calendar events. |
| Gmail | Send an email you have composed in the CRM from your own address. The scope we request cannot read, search, or delete anything in your mailbox. |
| Google Tasks | Create, update and delete tasks that mirror your CRM tasks. We never read your other tasks. |
| Google Sheets | Write data you have chosen to export into a spreadsheet. We never read your other spreadsheets. |
Retention. We store the OAuth access and refresh tokens for the connection, encrypted at rest with AES-256-GCM, plus the account email and ID. Tokens are kept only while the connection is active and are deleted as soon as you disconnect. We do not keep copies of your Google emails, calendar entries, tasks, or spreadsheets — only the identifier of the record we created, so it can later be updated or removed.
Revoking access. You can disconnect at any time from Configuration → System → Marketplace → Apps. Disconnecting revokes the token with Google and deletes the stored credentials. You may also revoke access independently at any time from your Google Account permissions page at myaccount.google.com/permissions.
11.2 Other Connected Services
- Zoom: creates, updates and deletes meetings for CRM meetings you schedule, and reads your Zoom account email and ID to identify the connection. Where enabled, we store the link to a completed meeting recording so it can be opened from the CRM record. Credentials are encrypted at rest and deleted on disconnect.
- WhatsApp Business (Meta): where your organization configures it, message content and recipient phone numbers are sent to Meta in order to deliver the message, and delivery status is returned to the CRM.
- Razorpay and Cashfree: payment collection. Transaction and payer details necessary for the payment are shared with the gateway. We do not store full card numbers on our servers.
- Exotel (cloud telephony): where your organization configures it, we place calls through Exotel using your own Exotel account. The caller and recipient phone numbers are sent to Exotel to connect the call, and we store the resulting call metadata — direction, duration, status, timestamp — and, where your organization has enabled recording, the link to the recording held by Exotel. Your Exotel API credentials are encrypted at rest and are never shown again once saved.
- Your own email server (custom SMTP): your organization may configure Worxley to send email through its own mail server instead of ours. In that case the message, its recipients, and your SMTP credentials are used only to deliver that email. Credentials — including the app password — are encrypted at rest, are never returned to the browser after saving, and are deleted when you remove the configuration.
Each of these services processes data under its own privacy policy, in addition to this one. Data is only shared with a provider your organization or you have actively connected, and only to deliver the feature you have asked for. We do not sell data received from any connected service, and we do not use it for advertising or to train generalised AI models.