How iSyph approaches the Digital Personal Data Protection Act, 2023 (DPDP) — the principles we follow, the roles we take, and the rights we uphold.
iSyph is built and operated in India, for Indian businesses. This statement describes how we align our platform and practices with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and its rules as they come into force.
In most engagements, your company is the Data Fiduciary — you determine the purpose and means of processing the personal data of your employees and contacts. iSyph acts as a Data Processor, processing that data only on your documented instructions, under a Data Processing Agreement.
Where iSyph collects limited personal data directly (for example, a prospect's details submitted through our website), iSyph acts as a Data Fiduciary for that limited purpose, as described in our Privacy Policy.
Individuals whose personal data is processed ("Data Principals") have rights under the DPDP Act. Where your company is the Data Fiduciary, requests to exercise these rights are directed to your company; iSyph assists you in fulfilling them technically. The rights, and how iSyph supports each:
A Data Principal may ask what personal data concerning them is processed, and for what purpose. Within a company space, this corresponds to a person's messages, files, and space membership. iSyph provides your company's administrators tools to review this data so you can respond to the request.
A Data Principal may ask that inaccurate or outdated personal data be corrected, or that data no longer necessary for its purpose be erased. Where erasure applies to conversation content or files, iSyph performs an actual, irreversible deletion — not a soft delete or a hidden flag. Files removed from the platform's storage are removed from disk; a request that is acted on is not later recoverable by iSyph.
A Data Principal may raise a grievance about how their data is handled. See our Grievance Redressal & DPO page for the mechanism and timelines.
A Data Principal may nominate another individual to exercise these rights on their behalf, including in the event of death or incapacity, in the manner the DPDP Rules prescribe.
Separately from conversation content, iSyph keeps a record of the commercial engagement itself — the plan, features, and retention terms agreed with your company, and any later amendments to them. This record is a business document, not personal conversation data: it does not contain the content of messages or the identities of individual employees. It is retained as proof of what was configured and when, and is not erased on a per-individual basis, since it does not describe individuals.
iSyph's default posture is to keep your data within India. We do not transfer your conversation data outside India in the ordinary course of providing the service.
In the event of a personal-data breach affecting iSyph's systems, we will notify the affected Data Fiduciary without undue delay, and support notification to the Data Protection Board of India and affected Data Principals where the law requires it. Our incident process covers identification, containment, assessment of what data was affected and how, and notification — in the manner and timelines the DPDP Act and its rules prescribe.
Because your company sets retention and we do not extend it beyond your configuration, the scope of any breach is bounded by what your company has chosen to retain — a further reason data minimisation matters in practice, not only in principle.
For questions about this statement or our DPDP practices, contact our Data Protection Officer / Grievance Officer at Mr. Arpit Patel, iSyph, grievance@isyph.com or legal@isyph.com, Pune, Maharashtra, India. See Grievance Redressal & DPO.
This statement is provided for transparency and does not constitute legal advice. It will evolve as the DPDP Rules are notified and as our practices mature.