DPDP Act 2023 compliance
What OctaPages has in place under India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 — each item is checked against the running service. For the data a business keeps in its own workspace, the business is the Data Fiduciary and we are its Data Processor.
26/30
in place
Notice and consent
4/5A clear privacy notice
Our Privacy Policy lists what we collect, why, who sees it, how long we keep it and how to exercise your rights, in plain language.
DPDP Act §5 · Rule 3See it →The notice in English and Hindi
Every legal page is available in both languages from the language switch at the top of the page.
DPDP Act §5(3)See it →Consent recorded when an account is created
Sign-up records that you accepted the Terms and Privacy Policy, with the date and the version you accepted.
DPDP Act §6Withdrawing consent is as easy as giving it
You can delete your account from Settings → Privacy at any time; data used on the basis of consent is then erased.
DPDP Act §6(4)See it →Age confirmation at sign-up
The service is for adults and our terms say so; an explicit age confirmation, with a verifiable parental consent path, is being added.
DPDP Act §9 · Rule 10
Your rights
6/6Right to access
Download a copy of your data at any time: Settings → Privacy → Download my data.
DPDP Act §11See it →Right to correction
Correct your name, contact details and photo in Settings → Profile; businesses edit their listings themselves.
DPDP Act §12See it →Right to erasure
Delete your account from Settings → Privacy. Your name, email, phone and photo are removed.
DPDP Act §12See it →Right to nominate
Nominate someone to exercise your rights if you die or cannot act, through the data rights request form.
DPDP Act §14See it →A request form answered within 30 days
Anything the settings don't cover can be requested on the Data Rights page; each request becomes a tracked case with a reference number.
DPDP Rules, 2025See it →A named Grievance Officer
Complaints are acknowledged within 24 hours and resolved within 15 days; you can then go to the Data Protection Board of India.
DPDP Act §13 · IT Rules 2021See it →
Security safeguards
5/7Encryption in transit
Every page and API call is served over HTTPS only.
DPDP Act §8(5)Passwords never stored
Passwords are kept as one-way argon2id hashes; two-step verification is available for every account.
DPDP Act §8(5)A separate database for every business
Each business's workspace has its own database; automated tests on every change prove one business cannot reach another's data.
DPDP Act §8(5)Encrypted, verified backups
A workspace is backed up with its own encryption key and the backup is test-restored before anything is deleted.
DPDP Act §8(5)Staff actions are logged
Every staff decision about a business or an account is recorded in an audit log with who, what and when.
DPDP Act §8(5)Breach response runbook
Our policy commits to telling affected people and the Data Protection Board without delay; the written runbook and response drills are being completed.
DPDP Act §8(6) · Rule 7Independent security testing
An external vulnerability assessment and penetration test is planned before the paid plugins launch widely.
DPDP Act §8(5)
Only what is needed, only as long as needed
5/5No visitor tracking
Listing visits are counted without any IP address, cookie or identifier of the visitor; crawlers are not counted.
DPDP Act §4, §8(7)Hidden photo data removed
Uploaded photos are re-encoded and their hidden data, including GPS location, is removed.
DPDP Act §8Data is erased when its purpose ends
Retention sweeps delete old visit counts, error reports and rejected photos; a deleted workspace's backup is kept 30 days (1 month), then erased with its files.
DPDP Act §8(7) · Rule 8See it →Field-team location and photos are deleted on schedule
In Octa Field, location points, photo files and tracking events are deleted every night once they pass the retention your business chose (never longer than its plan allows); the day's summary and each visit's record stay. Location is collected only between Start day and End day.
DPDP Act §8(7) · Rule 8See it →
Processors and transfers
6/7A Data Processing Addendum for businesses
For the customer data a business keeps in its workspace, we act only on its behalf, under published terms.
DPDP Act §8(2)See it →A published list of sub-processors
Hosting, storage, email, payments and WhatsApp providers are named in the Privacy Policy and the Data Processing Addendum.
DPDP Act §8(2)See it →Terms for service providers (resellers)
When a business uses the service through a reseller, our Reseller Data Processing Addendum sets what the reseller may do with its data, how it is reached (a visible, removable member, every visit recorded) and what happens when the relationship ends. The automated tests on every change check that a reseller cannot reach another reseller's clients.
DPDP Act §8(2)See it →A dedicated sub-processors page
Every provider that handles businesses' data, what it does and where, on one page we update before a new one starts.
DPDP Act §8(2) · GDPR art. 28(2)See it →Data hosted in a permitted country
Our servers are in Germany (European Union), which is not a restricted country under the Act.
DPDP Act §16See it →Signed data protection terms with every sub-processor
Provider data processing agreements are being collected and filed.
DPDP Act §8(2)Customer consent records inside the CRM
The WhatsApp CRM keeps each customer's opt-in and opt-out for offers, with how and when it was given and a history of every change; a STOP reply opts out at once, and marketing broadcasts skip anyone without an opt-in. Check it on a contact's WhatsApp consent tab.
DPDP Act §6 (for businesses)