DPDPA & GDPR Compliance
A plain-language summary of how WhizzGate is built and operated to align with the Digital Personal Data Protection Act, 2023, the EU General Data Protection Regulation, and the security principles behind them.
Section 1Controller vs. processor
Understanding who is responsible for what is central to data protection. On WhizzGate:
| Data | Data Fiduciary / Controller | Processor |
|---|---|---|
| Society & administrator account data | WhizzGate | Our sub-processors |
| Resident, staff & visitor data | The Society | WhizzGate |
For resident and visitor data, we process only on the documented instructions of the Society and do not use that data for our own purposes.
Section 2Core principles we follow
- Lawfulness & transparency — clear notice and a valid basis (consent or a permitted legitimate use) for every processing activity.
- Purpose limitation — data is used only for the community-operations purposes it was collected for.
- Data minimisation — we collect the least data needed to run the Services.
- Accuracy — Users can review and correct their data.
- Storage limitation — data is retained only as long as necessary or legally required.
- Integrity & confidentiality — encryption, access control and tenant isolation by design.
- Accountability — audit logs and documented processes evidence our compliance.
Section 3Digital Personal Data Protection Act, 2023 (India)
The DPDP Act governs the processing of digital personal data in India. WhizzGate does not just describe compliance — the platform ships the tooling to operate it:
- Notice & consent management — societies publish itemised privacy notices, and residents give, review and withdraw consent from within the app; every consent is recorded.
- Data-principal request workflow — access, correction, export and erasure requests are raised and fulfilled through a tracked in-product workflow, not ad-hoc email.
- Processing registry — a maintained record of processing purposes, sub-processors and retention policies.
- Breach / incident register — security incidents are logged and managed, supporting notification to the Data Protection Board of India and affected Data Principals.
- Audit trail — sensitive actions are audit-logged and exportable, evidencing accountability.
- Grievance officer — a designated contact who responds within statutory timelines (see the Privacy Policy).
- Children's data — no tracking, behavioural monitoring or targeted advertising directed at children.
- Data localisation-ready — primary processing on infrastructure in India, with safeguards for any permitted cross-border transfer.
Section 4General Data Protection Regulation (EU/EEA)
Where the GDPR applies to a Society or its Users, WhizzGate supports compliance by providing:
- A lawful-basis framework (contract, consent, legal obligation, legitimate interests).
- Full data-subject rights: access, rectification, erasure, restriction, portability and objection.
- Privacy by design and by default across the platform.
- A Data Processing Agreement with Standard Contractual Clauses for international transfers.
- Breach notification to the relevant supervisory authority within 72 hours.
- Records of processing activities and support for Data Protection Impact Assessments.
Section 5Data Processing Agreement
Societies that require a Data Processing Agreement (DPA) — setting out our obligations as processor, the sub-processor list, security measures and transfer safeguards — can request one at hello@whizzact.com. The DPA forms part of our contract with the Society.
Section 6Sub-processors
We engage a limited set of sub-processors to deliver the Services, each bound by contract to appropriate confidentiality and security obligations. Typical categories include:
| Category | Purpose |
|---|---|
| Cloud hosting | Application and database hosting, backups. |
| Payment gateway — Cashfree Payments | Processing maintenance and other payments (PCI-DSS compliant). |
| Messaging providers | SMS, email and push notification delivery. |
The current, named sub-processor list is available on request and referenced in the DPA. We give notice of material changes so Societies can object.
Section 7Security controls
- TLS encryption in transit and encryption at rest.
- Per-society tenant isolation and role-based access control.
- Hashed credentials, signed & expiring public links, and rate limiting.
- Audit logging, least-privilege staff access and regular backups.
- Secure development practices and dependency monitoring.
Section 8Breach response
We maintain an incident-response process to detect, contain and remediate security incidents. In the event of a personal-data breach, we notify the relevant authority (the Data Protection Board of India, and supervisory authorities under the GDPR within 72 hours) and affected parties as required, and support the controlling Society in meeting its own obligations.
Section 9Exercising data rights
If your data is controlled by WhizzGate, contact hello@whizzact.com. If it is controlled by your Society (most resident and visitor data), your Society is the first point of contact and we assist as its processor. Full details are in our Privacy Policy.
Section 10Talk to our privacy team
Data Protection Officer: hello@whizzact.com · Grievance Officer: hello@whizzact.com. For DPA requests or a security questionnaire, email hello@whizzact.com.