1. About the DPDPA#
The Digital Personal Data Protection Act, 2023 ("DPDPA") is India's comprehensive law governing the processing of digital personal data. It establishes rights for Data Principals (the individuals whose data is processed), obligations for Data Fiduciaries (organisations that decide why and how personal data is processed), and a regulator — the Data Protection Board of India ("DPB") — to enforce compliance.
This notice explains how SyncHQ Pro complies with the DPDPA. It supplements our Privacy policy; in case of any conflict between this notice and the Privacy policy regarding Indian Data Principals, this notice controls.
2. Our role as Data Fiduciary#
Pavidha Technologies Pvt Ltd, headquartered in Dindigul, Tamil Nadu, India, operates the SyncHQ Pro platform. When you sign up directly with us, DECISYN is the Data Fiduciary for your personal data.
When your employer or service provider invites you into a SyncHQ Pro workspace as a staff member, the workspace owner is the Data Fiduciary for your data; DECISYN acts as a Data Processor on their behalf and follows their lawful instructions, subject to our security and compliance baselines.
3. Personal data we process#
The DPDPA applies to all digital personal data. We process the following categories of personal data of Indian Data Principals:
- Identity data — name, work email, mobile number, role.
- Business data — company name, GSTIN, address.
- Customer & staff data — names, contact details, addresses, work history, performance metrics (where applicable).
- Financial data — invoices, payments, tokenized payment-method references.
- Communication data — content of SMS / WhatsApp / email sent through the platform.
- Location data — IP-derived approximate location, plus precise GPS for staff who explicitly enable on-clock tracking.
- Device & usage data — device type, browser, pages viewed, telemetry.
The Privacy policy Section 2 contains the complete enumeration.
4. Lawful basis under Sections 6 & 7#
The DPDPA permits processing of personal data only with consent (Section 6) or for certain "legitimate uses" (Section 7). We rely on:
- Section 6 — Consent for marketing emails, optional analytics, optional location tracking, and any processing outside the strict needs of the contract.
- Section 7(a) — Voluntary provision for personal data you provide for a specified purpose (e.g., creating an account, configuring your workspace).
- Section 7(b) — Compliance with judgments / law for legal-process responses.
- Section 7(g) — Employment-related for processing of staff personal data necessary for employment.
- Section 7(i) — Public interest in legitimate business activity for security, fraud prevention, and platform stability.
You may withdraw consent at any time via Settings > Privacy > Consent management. Withdrawal does not affect lawful processing before withdrawal but stops future processing where consent is the basis.
5. Purposes of processing#
- Provide, operate, maintain, and improve the platform.
- Authenticate users and protect accounts.
- Deliver service communications (SMS / WhatsApp / email) you initiate.
- Process payments and reconcile invoices.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal, tax, accounting, and regulatory obligations applicable in India.
- Provide AI-assisted features only as the user initiates and only with the inputs required by that feature.
6. Retention and erasure#
Personal data is retained only as long as needed for the purposes set out above, or as required by Indian law (e.g., 7-year retention for financial records under tax law). The privacy policy retention schedule applies.
Under Section 8(7) of the DPDPA, personal data must be erased once the specified purpose is no longer being served, unless retention is required by law. On account deletion you may request immediate erasure subject only to statutory retention obligations.
7. International transfers (Section 16)#
Section 16 of the DPDPA empowers the central government to restrict cross-border transfers of personal data by notification. Until a restriction is notified, transfers are permissible.
SyncHQ Pro primarily processes data in Microsoft Azure's India region. Limited transfers occur to the following sub-processors located outside India, each under a Data Processing Agreement aligned with the Standard Contractual Clauses (SCCs):
| Sub-processor | Region | Purpose |
|---|---|---|
| OpenAI | USA | AI feature responses (anonymised prompts only) |
| Anthropic | USA | AI feature responses (anonymised prompts only) |
| Stripe | USA / global | Card payments |
| Twilio | USA / global | SMS & voice notifications |
| Google Maps Platform | USA / global | Geocoding & route optimisation |
| Vercel | USA / global | Marketing website CDN edge |
All customer data is hosted in our primary region; we notify you in advance of any change. Razorpay (UPI / India-domestic payments) operates entirely within India.
8. Section 11 — Right to information#
You have the right to obtain from us:
- Confirmation of whether we are processing your personal data;
- A summary of the personal data we are processing about you;
- The identities of all Data Fiduciaries and Data Processors with whom we have shared your data, along with a description of the categories shared;
- Any other information related to such processing as may be prescribed.
Submit your request via Settings > Privacy > Data rights or by emailing privacy@servicesynchq.com. We respond within 30 days.
9. Section 12 — Right to correction and erasure#
You have the right to request the correction, completion, updating, or erasure of your personal data. We will:
- Correct or update inaccurate or incomplete data within 30 days.
- Erase data we no longer need, unless retention is required by law.
- Notify our sub-processors of any correction or erasure that affects them.
Some data must be retained for statutory reasons (e.g., tax records). In those cases we restrict further processing and erase as soon as the statutory period ends.
10. Section 13 — Right of grievance redressal#
If you are dissatisfied with how we have processed your personal data or responded to a DPDPA request, you may file a grievance with our Grievance Officer (see Section 15). We will acknowledge the grievance within 7 working days and resolve it within 30 days.
11. Section 14 — Right to nominate#
You have the right to nominate another individual who may exercise your DPDPA rights in the event of your death or incapacity. To register a nominee, sign in and go to Settings > Privacy > Nominee, or contact privacy@servicesynchq.com with the nominee's name, relationship, and consent.
12. Consent and Consent Manager#
Where we rely on consent under Section 6, we obtain it in plain language at the time of collection. You can review and withdraw consent at any time from Settings > Privacy > Consent management.
If the DPDPA Consent Manager framework is operational at your time of use, we will integrate with registered Consent Managers so you can manage consents across the providers participating in the framework.
13. Children's data (Section 9)#
SyncHQ Pro is designed for business use by adults. We do not knowingly process the personal data of children (under 18). If a child's personal data has been provided to us, contact privacy@servicesynchq.com and we will delete it after reasonable verification.
For tenants who operate services that may involve children's data (e.g., school-uniform services), the tenant — as the Data Fiduciary for that data — must obtain verifiable parental consent before processing.
14. Breach notification (Section 8(6))#
If we become aware of a personal data breach affecting your data, we will notify both the Data Protection Board of India and you "as soon as practicable" — for SyncHQ Pro that means within 72 hours of confirmation. The notice will include the nature of the breach, the data affected, the steps you can take, and the steps we are taking to mitigate.
15. Grievance Officer#
In accordance with the DPDPA Section 10 and the IT Rules 2011 / Intermediary Guidelines 2021, DECISYN has appointed a Grievance Officer:
Grievance Officer
DECISYN Privacy Office
First point of contact for all DPDPA grievances. Empowered to investigate, decide, and direct remediation across DECISYN's data-processing operations.
To file a grievance, email the Grievance Officer with: (1) your name and registered account email; (2) a clear description of the issue; (3) any prior tickets or correspondence; (4) the outcome you are seeking. We will acknowledge within 7 working days and resolve within 30 days.
16. Escalation to the Data Protection Board#
If you are dissatisfied with the Grievance Officer's response, or if no response is received within 30 days, you may escalate to the Data Protection Board of India under Section 27 of the DPDPA. The DPB's official notification, contact channel, and complaint form are published by the Government of India on the Ministry of Electronics and Information Technology (MeitY) portal.
17. Contact#
- Grievance Officer (DPDPA, primary): grievance@servicesynchq.com
- Privacy & data-rights requests: privacy@servicesynchq.com
- Legal: legal@servicesynchq.com
Postal address: Pavidha Technologies Pvt Ltd, Dindigul, Tamil Nadu, India.