1. Introduction & Dual Legal Capacities
This Privacy Policy explains how Werkora Technology (Sole Proprietorship of Abhishek Kumar, GSTIN: 09FKRPK3676J1Z9, registered at 50, Block Z, Sector 12, Noida, Gautam Buddha Nagar, Uttar Pradesh - 201301, India, "Werkora", "we", "us", or "our") collects, processes, stores, and protects personal data in compliance with India's Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
Under Indian law, Werkora acts in two distinct legal capacities:
- Data Fiduciary: When we collect account credentials, contact information, billing records, and usage telemetry from workspace owners and administrators.
- Data Processor: When tenant organizations input personal data of factory floor workers, shop managers, contractors, and supplier representatives into the ERP software. In this capacity, we process personal data strictly on the documented instructions of the tenant under our Data Processing Agreement (DPA).
2. Categories of Personal Data Collected
| Category | Elements | Legal Purpose |
|---|---|---|
| Account Identity | Name, work email, phone number, salted scrypt password hash | Authentication, workspace invitations, access control |
| Workforce & Labor | Worker name, employee code, phone, wage rates, shift attendance | Factory production planning, work order steps, wage calculation |
| Commercial Contacts | Contact person name, company phone, email, dispatch address, GSTIN | Order fulfillment, dispatch documents, tax invoicing |
| Security Telemetry | IP address, user agent, consent timestamp, request path | CERT-In security logging, abuse prevention, rate limiting |
3. Legal Grounds for Processing
We process personal data under Section 4 of DPDPA on the following grounds:
- Affirmative Consent: When you register for an account, agree to these terms, or authorize invitations.
- Contractual Necessity: To deliver the ERP software, calculate available-to-promise inventory, and execute dispatch workflows.
- Statutory Compliance: To maintain mandatory tax invoice records under Section 36 of the CGST Act, 2017 and maintain 180-day cybersecurity incident logs under CERT-In Directions.
4. Rights of Data Principals (DPDPA 2023)
Under Sections 11–13 of the DPDP Act, 2023, you and your authorized employees have the following rights:
- Right to Access: View all personal data held in your account profile and access audit logs through workspace Settings.
- Right to Correction & Erasure: Edit profile information or request permanent account erasure via workspace Settings.
- Right of Grievance Redressal: Submit grievances regarding data handling directly to our designated Grievance Redressal Officer.
- Right to Nominate: Nominate an individual to exercise rights on your behalf in the event of death or incapacity.
5. Statutory Data Retention Schedules
Personal and business data are retained in accordance with statutory minimums under Indian law:
- Tax & Commercial Invoices: Retained for 8 years following the end of the financial year pursuant to Section 128(5) of the Companies Act, 2013 and Section 36 of the CGST Act, 2017.
- Cybersecurity & Access Logs: Retained securely within Indian jurisdiction for 180 days pursuant to CERT-In Directions No. 20(3)/2022-CERT-In.
- Tenant Operational Data: Preserved during the active subscription period, with a 30-day export window following cancellation, followed by permanent cryptographic purge.
6. Cybersecurity & Incident Response (CERT-In)
Werkora implements strict security safeguards including AES-256 encrypted database backups, salted scrypt password hashing, encrypted TLS 1.3 in transit, and multi-tenant row isolation.
In accordance with CERT-In Cybersecurity Directions, our Incident Response Team actively monitors security events. In the event of a reportable cybersecurity incident or personal data breach, Werkora follows its formal Incident Response Plan to notify the Indian Computer Emergency Response Team (CERT-In) and the Data Protection Board of India (DPBI) within statutory windows.
7. Payment Gateway & Financial Security (Razorpay)
Commercial subscriptions and digital payments are processed through our authorized payment aggregator, Razorpay Software Private Limited.
Werkora does not store, process, or transmit raw credit card numbers, debit card numbers, PINs, or CVV codes on our servers. All payment transactions are executed within Razorpay's encrypted, PCI-DSS Level 1 certified checkout environment. Werkora receives only tokenized transaction identifiers, payment status confirmations, and masked bank/card metadata necessary for statutory GST tax invoicing and audit compliance.
8. Statutory Grievance Redressal Officer
In compliance with Section 12 of the Digital Personal Data Protection Act, 2023 and Rule 5(9) of the Information Technology Rules, 2011, Werkora has appointed a dedicated Data Protection Grievance Redressal Officer:
Data Protection Grievance Officer
Werkora Technology (Proprietor: Abhishek Kumar)
Email: support@werkora.in
Postal Address: 50, Block Z, Sector 12, Noida, Gautam Buddha Nagar, Uttar Pradesh - 201301, India
Statutory Timelines: Acknowledgment within 48 hours · Resolution within 30 days.
9. Updates to this Policy
We may revise this Privacy Policy to reflect statutory rule changes or new feature deployments. The latest version and effective date will always be posted on this page.