Skip to the main content
India · Digital Personal Data Protection Act, 2023

DPDP Act 2023 compliance

What OctaPages has in place under India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 — each item is checked against the running service. For the data a business keeps in its own workspace, the business is the Data Fiduciary and we are its Data Processor.

26/30

in place

In place Being builtChecked against the service on 30 September 2026

Notice and consent

4/5
  • A clear privacy notice

    Our Privacy Policy lists what we collect, why, who sees it, how long we keep it and how to exercise your rights, in plain language.

    DPDP Act §5 · Rule 3See it →
  • The notice in English and Hindi

    Every legal page is available in both languages from the language switch at the top of the page.

    DPDP Act §5(3)See it →
  • Consent recorded when an account is created

    Sign-up records that you accepted the Terms and Privacy Policy, with the date and the version you accepted.

    DPDP Act §6
  • Withdrawing consent is as easy as giving it

    You can delete your account from Settings → Privacy at any time; data used on the basis of consent is then erased.

    DPDP Act §6(4)See it →
  • Age confirmation at sign-up

    The service is for adults and our terms say so; an explicit age confirmation, with a verifiable parental consent path, is being added.

    DPDP Act §9 · Rule 10

Your rights

6/6
  • Right to access

    Download a copy of your data at any time: Settings → Privacy → Download my data.

    DPDP Act §11See it →
  • Right to correction

    Correct your name, contact details and photo in Settings → Profile; businesses edit their listings themselves.

    DPDP Act §12See it →
  • Right to erasure

    Delete your account from Settings → Privacy. Your name, email, phone and photo are removed.

    DPDP Act §12See it →
  • Right to nominate

    Nominate someone to exercise your rights if you die or cannot act, through the data rights request form.

    DPDP Act §14See it →
  • A request form answered within 30 days

    Anything the settings don't cover can be requested on the Data Rights page; each request becomes a tracked case with a reference number.

    DPDP Rules, 2025See it →
  • A named Grievance Officer

    Complaints are acknowledged within 24 hours and resolved within 15 days; you can then go to the Data Protection Board of India.

    DPDP Act §13 · IT Rules 2021See it →

Security safeguards

5/7
  • Encryption in transit

    Every page and API call is served over HTTPS only.

    DPDP Act §8(5)
  • Passwords never stored

    Passwords are kept as one-way argon2id hashes; two-step verification is available for every account.

    DPDP Act §8(5)
  • A separate database for every business

    Each business's workspace has its own database; automated tests on every change prove one business cannot reach another's data.

    DPDP Act §8(5)
  • Encrypted, verified backups

    A workspace is backed up with its own encryption key and the backup is test-restored before anything is deleted.

    DPDP Act §8(5)
  • Staff actions are logged

    Every staff decision about a business or an account is recorded in an audit log with who, what and when.

    DPDP Act §8(5)
  • Breach response runbook

    Our policy commits to telling affected people and the Data Protection Board without delay; the written runbook and response drills are being completed.

    DPDP Act §8(6) · Rule 7
  • Independent security testing

    An external vulnerability assessment and penetration test is planned before the paid plugins launch widely.

    DPDP Act §8(5)

Only what is needed, only as long as needed

5/5
  • No visitor tracking

    Listing visits are counted without any IP address, cookie or identifier of the visitor; crawlers are not counted.

    DPDP Act §4, §8(7)
  • Hidden photo data removed

    Uploaded photos are re-encoded and their hidden data, including GPS location, is removed.

    DPDP Act §8
  • Essential cookies only

    No advertising, analytics or tracking cookies.

    DPDP Act §6See it →
  • Data is erased when its purpose ends

    Retention sweeps delete old visit counts, error reports and rejected photos; a deleted workspace's backup is kept 30 days (1 month), then erased with its files.

    DPDP Act §8(7) · Rule 8See it →
  • Field-team location and photos are deleted on schedule

    In Octa Field, location points, photo files and tracking events are deleted every night once they pass the retention your business chose (never longer than its plan allows); the day's summary and each visit's record stay. Location is collected only between Start day and End day.

    DPDP Act §8(7) · Rule 8See it →

Processors and transfers

6/7
  • A Data Processing Addendum for businesses

    For the customer data a business keeps in its workspace, we act only on its behalf, under published terms.

    DPDP Act §8(2)See it →
  • A published list of sub-processors

    Hosting, storage, email, payments and WhatsApp providers are named in the Privacy Policy and the Data Processing Addendum.

    DPDP Act §8(2)See it →
  • Terms for service providers (resellers)

    When a business uses the service through a reseller, our Reseller Data Processing Addendum sets what the reseller may do with its data, how it is reached (a visible, removable member, every visit recorded) and what happens when the relationship ends. The automated tests on every change check that a reseller cannot reach another reseller's clients.

    DPDP Act §8(2)See it →
  • A dedicated sub-processors page

    Every provider that handles businesses' data, what it does and where, on one page we update before a new one starts.

    DPDP Act §8(2) · GDPR art. 28(2)See it →
  • Data hosted in a permitted country

    Our servers are in Germany (European Union), which is not a restricted country under the Act.

    DPDP Act §16See it →
  • Signed data protection terms with every sub-processor

    Provider data processing agreements are being collected and filed.

    DPDP Act §8(2)
  • Customer consent records inside the CRM

    The WhatsApp CRM keeps each customer's opt-in and opt-out for offers, with how and when it was given and a history of every change; a STOP reply opts out at once, and marketing broadcasts skip anyone without an opt-in. Check it on a contact's WhatsApp consent tab.

    DPDP Act §6 (for businesses)

This page describes our own processing and is reviewed whenever the service changes. It is not legal advice, and our policies are being reviewed by counsel.

Questions about your data: [email protected] · Grievance Officer