Last Updated: June 12, 2026 | Effective Date: June 12, 2026
1. Introduction & Scope
DCW Webtech Solutions ("we," "us," or "our") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, share, and protect your information when you:
- Visit our website (www.dcwwebtech.com) or any of our subdomains
- Use our software products (CRM, ERP, HRMS platforms)
- Utilize our communication services (WhatsApp Business API, SMS Gateway, RCS)
- Engage our custom development or mobile app development services
- Contact us via email, phone, WhatsApp, or contact forms
- Subscribe to our newsletters or marketing communications
- Attend our webinars, events, or training sessions
This policy applies to all data subjects including website visitors, registered users, clients, prospects, employees, and business partners.
Compliance Framework: We comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, General Data Protection Regulation (GDPR) for EU residents, and applicable data protection laws in jurisdictions where we operate.
2. Information We Collect
We collect different categories of information depending on your interaction with us:
2.1 Personal Information (Directly from You)
| Category | Examples | Purpose |
| Identity Data | Name, job title, company name, organization type | Account creation, service delivery, communication |
| Contact Data | Email address, phone number, WhatsApp number, postal address | Communication, support, invoicing |
| Account Data | Username, password, account preferences, subscription details | Authentication, account management |
| Financial Data | Bank account details, UPI ID, GST number, PAN, billing address | Payment processing, invoicing, tax compliance |
| Technical Data | IP address, browser type, device information, OS, login times | Security, analytics, troubleshooting |
| Usage Data | Pages visited, features used, session duration, click patterns | Product improvement, user experience |
| Communication Data | Emails, chat logs, support tickets, call recordings (with consent) | Customer support, quality assurance |
| Marketing Data | Preferences, survey responses, event attendance, content downloads | Personalized marketing, lead nurturing |
2.2 Business Data (Processed on Your Behalf)
When you use our CRM, ERP, or HRMS platforms, we may process data that belongs to your organization:
- Customer/Employee Data: Names, contact details, performance records, payroll information (as configured by you)
- Transaction Data: Sales records, inventory data, financial transactions
- Communication Logs: WhatsApp messages, SMS delivery reports, email templates
- Document Data: Invoices, contracts, reports uploaded to our systems
Important: You remain the data controller for your business data. We act as a data processor and process this data only per your instructions and our Agreement.
2.3 Automatically Collected Data
- Cookies & Similar Technologies: Session cookies, preference cookies, analytics cookies, marketing cookies
- Log Files: Server logs capturing IP address, browser type, referring/exit pages, timestamps
- Analytics Data: Google Analytics, Hotjar, or similar tools tracking user behavior
- Error Reports: Automatic crash reports and diagnostic data from our applications
3. How We Use Your Information
We use your personal data for the following lawful purposes:
3.1 Service Delivery & Operations
- Provision and maintenance of software products (CRM, ERP, HRMS)
- Processing and delivery of communication services (WhatsApp API, SMS, RCS)
- Custom software development, deployment, and support
- Mobile application development and app store management
- Account setup, authentication, and access management
- Technical support, troubleshooting, and bug resolution
3.2 Communication
- Responding to inquiries submitted via contact forms, email, phone, or WhatsApp
- Sending service-related notifications (maintenance alerts, security updates, billing reminders)
- Project status updates and milestone communications
- Appointment scheduling and meeting confirmations
3.3 Billing & Payments
- Invoice generation and payment processing
- GST compliance and tax reporting
- Subscription management and renewal reminders
- Fraud detection and payment security
3.4 Marketing & Business Development
- Sending newsletters, product updates, and promotional offers (with your consent)
- Conducting surveys and collecting feedback
- Personalizing content and recommendations based on your preferences
- Lead scoring and sales pipeline management
3.5 Legal Compliance & Security
- Complying with legal obligations (tax, regulatory, law enforcement requests)
- Preventing fraud, abuse, and unauthorized access
- Investigating violations of our Terms & Conditions
- Protecting our rights, property, and safety
3.6 Analytics & Improvement
- Analyzing usage patterns to improve product features
- Measuring campaign effectiveness and ROI
- Training AI/ML models for chatbot and automation features (anonymized data only)
4. Legal Basis for Processing
Under applicable data protection laws, we process your personal data based on the following legal grounds:
| Legal Basis | Applicable Scenarios |
| Contractual Necessity | Service delivery, account management, billing, support — required to fulfill our contract with you |
| Consent | Marketing communications, cookies (non-essential), call recordings, data sharing with partners |
| Legal Obligation | Tax compliance, regulatory filings, responding to lawful government requests |
| Legitimate Interests | Security monitoring, fraud prevention, analytics, product improvement, debt collection |
| Vital Interests | Emergency situations involving health or safety |
Withdrawing Consent
You may withdraw your consent at any time by:
• Clicking the "Unsubscribe" link in marketing emails
• Emailing us at privacy@dcwwebtech.com with subject "Withdraw Consent"
• Updating preferences in your account dashboard
Withdrawal of consent does not affect the lawfulness of processing before withdrawal.
5. Data Sharing & Third Parties
We do not sell your personal data. We share data only in the following circumstances:
5.1 Service Providers & Sub-processors
We engage trusted third-party vendors to perform functions on our behalf:
| Category | Providers | Purpose |
| Cloud Infrastructure | AWS, Google Cloud, Microsoft Azure | Hosting, storage, computing |
| Payment Processing | Razorpay, Stripe, PayPal | Payment collection, invoicing |
| Communication APIs | Meta (WhatsApp), Twilio, MSG91, Kaleyra | WhatsApp API, SMS, RCS delivery |
| Analytics | Google Analytics, Mixpanel | Usage analytics, product improvement |
| Email Marketing | Mailchimp, SendGrid | Newsletter delivery, automation |
| Customer Support | Freshdesk, Zendesk | Ticket management, live chat |
| CRM & Sales | HubSpot, Zoho | Lead management, pipeline tracking |
All sub-processors are bound by data processing agreements (DPAs) that require them to maintain confidentiality and security standards at least equivalent to ours.
5.2 Legal & Regulatory Disclosures
- We may disclose personal data if required by law, court order, or governmental authority.
- We may disclose data to enforce our Terms & Conditions or protect our rights, property, or safety.
- In case of merger, acquisition, or asset sale, personal data may be transferred to the acquiring entity with notice to you.
5.3 Business Partners (With Consent)
- We may share your information with technology partners or resellers only with your explicit consent.
- Referral partners receive only the minimum information necessary to facilitate introductions.
6. WhatsApp API, SMS & RCS Data Handling
Our communication services involve special data handling considerations:
6.1 WhatsApp Business API (Meta Platforms)
- WhatsApp message content is processed through Meta's infrastructure and is subject to Meta's Data Policy and WhatsApp Business Terms.
- We act as a Business Solution Provider (BSP) / Tech Provider and process message data solely to deliver messages on your behalf.
- Message templates must be pre-approved by Meta. We do not control Meta's approval decisions or platform availability.
- End-to-end encryption applies to WhatsApp messages as per Meta's architecture. We cannot access message content in transit.
- Conversation history is retained as per your configured retention settings (default: 90 days, configurable up to 2 years).
6.2 SMS & RCS Services
- SMS/RCS message content is transmitted through telecom operators and aggregators (Twilio, MSG91, Kaleyra, etc.).
- Delivery reports (success/failure timestamps) are retained for 30 days for billing and troubleshooting.
- Message content is not stored permanently unless you explicitly enable archiving features.
- We comply with TRAI regulations including DND scrubbing, sender ID registration, and timing restrictions.
Prohibited Content: You must NOT use our communication services to send: hate speech, threats, spam, phishing, fraudulent content, sexually explicit material, or any content violating applicable laws. Violations may result in immediate service suspension and reporting to authorities.
7. Data Security Measures
We implement comprehensive technical and organizational security measures:
7.1 Technical Safeguards
- Encryption: AES-256 encryption for data at rest; TLS 1.3 for data in transit
- Access Control: Role-based access control (RBAC), multi-factor authentication (MFA), single sign-on (SSO) support
- Network Security: Web Application Firewall (WAF), DDoS protection, intrusion detection systems
- API Security: OAuth 2.0, API key rotation, rate limiting, request validation
- Code Security: Regular security audits, static/dynamic application security testing (SAST/DAST), dependency scanning
7.2 Organizational Measures
- All employees undergo background verification and sign confidentiality agreements
- Regular security awareness training and phishing simulations
- Incident response plan with defined escalation procedures
- Annual third-party security audits and penetration testing
- ISO 27001-aligned information security management practices
7.3 Data Breach Notification
- In the unlikely event of a personal data breach, we will notify affected users and relevant authorities within 72 hours of discovery, as required by law.
- Notification will include: nature of breach, categories of data affected, likely consequences, and measures taken.
- We maintain cyber insurance coverage to address potential liabilities from security incidents.
8. Data Retention & Deletion
| Data Category | Retention Period | Deletion Method |
| Account & Profile Data | Duration of account + 2 years | Secure deletion within 30 days of request |
| Transaction & Billing Data | 7 years (legal requirement) | Anonymized after 7 years |
| Communication Logs (WhatsApp/SMS) | 90 days - 2 years (configurable) | Automated purging per policy |
| Support Tickets | 3 years | Secure deletion after retention |
| Marketing Preferences | Until consent withdrawn | Immediate upon opt-out |
| Server Logs | 90 days | Automated rotation |
| Backup Data | 30 days | Encrypted deletion after expiry |
Upon account closure or service termination, you may request a data export. After the export window (30 days), data will be permanently deleted from production systems. Backup copies may persist for up to 30 days before automatic deletion.
9. Your Rights & Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data:
9.1 Rights Under Indian DPDP Act, 2023
- Right to Access: Request a copy of your personal data we hold
- Right to Correction: Request correction of inaccurate or misleading data
- Right to Erasure: Request deletion of your personal data (with exceptions)
- Right to Grievance Redressal: File complaints with our Data Protection Officer or the Data Protection Board of India
- Right to Nominate: Nominate another individual to exercise rights on your behalf
9.2 Rights Under GDPR (EU Residents)
- Right to be Informed: Transparent information about data processing (this policy)
- Right of Access: Confirmation of processing and access to personal data
- Right to Rectification: Correction of inaccurate data without undue delay
- Right to Erasure ("Right to be Forgotten"): Deletion under specific circumstances
- Right to Restrict Processing: Limit processing while disputes are resolved
- Right to Data Portability: Receive data in structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests or direct marketing
- Right to Object to Automated Decision-Making: Including profiling
9.3 How to Exercise Your Rights
Data Protection Officer (DPO)
DCW Webtech Solutions
Email: privacy@dcwwebtech.com
Address: Main Najafgarh, New Delhi, India
Phone: +91 79425 32549
Please include "Data Subject Request" in the subject line. We will respond within 30 days of receiving a verifiable request. We may need to verify your identity before processing sensitive requests.
10. Cookies & Tracking Technologies
We use cookies and similar technologies to enhance your browsing experience:
| Cookie Type | Purpose | Duration | Control |
| Essential | Authentication, security, session management | Session - 1 year | Cannot be disabled |
| Functional | Language preferences, display settings, form auto-fill | 1 year | Browser settings |
| Analytics | Google Analytics, visitor behavior, page performance | 2 years | Cookie banner / Opt-out |
| Marketing | Ad targeting, retargeting, campaign measurement | 90 days - 1 year | Cookie banner / Opt-out |
| Third-Party | Embedded content (YouTube, LinkedIn, Twitter) | Varies | Third-party controls |
You can manage cookie preferences through:
11. Children's Privacy
Our services are not directed to individuals under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal data from children.
- If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately at privacy@dcwwebtech.com.
- Upon verification, we will promptly delete such data from our systems.
- Our CRM/ERP/HRMS clients are responsible for ensuring their own data collection practices comply with child protection laws (COPPA, etc.).
12. International Data Transfers
DCW Webtech Solutions is based in India. Your data may be transferred to and processed in countries other than your own:
- We primarily store data in AWS Mumbai (ap-south-1) and Google Cloud Mumbai regions.
- For global redundancy, encrypted backups may be stored in Singapore (AWS ap-southeast-1) and Frankfurt (AWS eu-central-1).
- When transferring data outside India, we implement appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by relevant authorities
- Adequacy decisions where applicable
- Data Processing Agreements (DPAs) with all sub-processors
- Encryption during transit and at rest
- EU residents: We comply with GDPR Chapter V requirements for international transfers.
13. Changes to This Policy & Contact
- We may update this Privacy Policy periodically to reflect changes in our practices, legal requirements, or technology.
- Material changes will be notified via email (for registered users) and a prominent banner on our website at least 15 days before taking effect.
- Continued use of our services after changes constitutes acceptance of the updated policy.
- The "Last Updated" date at the top of this page indicates when the policy was last revised.
Contact Us — Privacy Matters
Data Protection Officer
DCW Webtech Solutions
Main Najafgarh, New Delhi, India
Email: privacy@dcwwebtech.com
Phone: +91 79425 32549
Support: info@dcwwebtechsolutions@gmail.com
Working Hours: Monday - Saturday, 10:00 AM - 6:00 PM IST
Response Time: Within 2 business days for privacy-related inquiries
Grievance Officer (India):
In accordance with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023, our Grievance Officer can be reached at grievance@dcwwebtech.com. We will endeavor to address grievances within 30 days of receipt.