All topics In production
Overview
WareShare processes personal data of Indian residents (host owners, tenant procurement leads, staff users). The DPDP Act 2023 sets out specific obligations for how that data is collected, processed, stored and deleted. Our DPDP programme is built into the platform — not a policy document — so the controls are auditable end-to-end.
Data principal rights
Right to access
Self-serve data export from /settings/privacy returns every personal data record we hold within 24 hours.
Right to correction
Inline editing on the user profile flows back to all downstream services within 5 minutes via the identity event bus.
Right to erasure
Account deletion request triggers a 30-day grace period, then a hard purge across identity, marketplace, billing and audit logs (audit retains a tombstone with no PII).
Right to grievance
Designated Grievance Officer (Section 8) named on /grievance with 7-day SLA on initial response and 30-day on resolution.
Consent management
Granular consent
Marketing, analytics and host-data-sharing tracked separately. Withdrawal is one click and propagates within 60 seconds.
Consent ledger
Every grant / withdrawal is hashed, timestamped and signed; admins can produce the consent trail for any user on demand.
Notice in plain language
Privacy notice is rendered in English + Hindi, version-controlled, and shown again whenever the policy changes.
Data lifecycle
Data residency
All personal data processed in Azure India regions (Hyderabad, Pune). No cross-border transfer for Indian principals unless contractually required.
Retention
Active accounts: indefinite. Closed accounts: 90-day retention for dispute resolution, then purge. Audit logs: 7 years (statutory).
Encryption
AES-256 at rest, TLS 1.3 in transit. Database-level encryption keys rotated quarterly via Azure Key Vault.
Breach response
Detection window
Production telemetry alerts fire within 5 minutes of an integrity or access anomaly. On-call engineer paged immediately.
CERT-In notification
6-hour notification to CERT-In as required under Section 70B; affected data principals notified within 72 hours.
Runbook
Documented incident-response runbook covers triage, containment, regulator filing, and customer comms. Tabletop drill every quarter.
Artifacts & references
Public docs link directly. Confidential artifacts available under NDA — request via enterprise sales.
