1. Who is responsible for your data

Associate Works is operated by a single independent consultant (the "provider"). For the personal data described in this policy the provider is the data fiduciary under the DPDP Act (the person who decides why and how personal data is processed). "We", "us" and "our" refer to the provider acting through the platform.

Your organisation (the client whose workspace you belong to) decides what content it places in its workspace and who it invites. For that content your organisation may itself be a data fiduciary, and we process it on its behalf as part of the engagement between the provider and your organisation.

2. What this policy covers

This policy covers personal data processed through associate.works, admin.associate.works, the API, the email and WhatsApp notifications we send, and the public contact form. It does not cover the provider's professional services outside the platform, which are governed by the engagement with your organisation.

3. The personal data we process

CategoryExamplesSource
Account and identityName, email address, optional phone number in international format, role in the workspace, account status, password (stored as a one-way hash), two-factor secrets (encrypted) and passkey public keys, locale and timezoneYou, or the person who invited you
Organisation profileClient organisation name, legal name, primary contact details, address, website, logoYour organisation's Workspace Admin or the provider
Workspace contentProjects, tasks, notes, files and their metadata, comments and mentions, resource links, vault items (encrypted), assignmentsYou and your colleagues
Notifications and preferencesWhich events notify you, whether you receive immediate emails, digests or WhatsApp messages, read state of notificationsYou (defaults set by the platform)
Security and usage logsSign-in events, IP address, approximate location derived from IP, device and browser characteristics used to detect new devices, audit trail of actions in a workspace, request identifiersGenerated automatically when you use the service
Delivery logsWhether an email or WhatsApp message was sent, failed or skipped, with the recipient address or number stored in masked formGenerated automatically
Contact formFull name, email address, your message, a keyed hash of your IP address and your browser's user-agent stringYou, when you use the contact page
Privacy recordsConsents you give or withdraw, requests you make about your data and how they were handledYou, through the privacy page in the application

We do not process payment card data, government identifiers, or biometric data. We do not buy personal data from third parties.

4. Why we process it and on what basis

PurposeData usedBasis under the DPDP Act
Creating and operating your account and workspace, letting you and your organisation collaborate with the providerAccount, organisation profile, workspace content, preferencesYour consent given when you accept an invitation and use the service; the legitimate use of performing the engagement your organisation asked for
Sending notifications you have chosen or that are essential (assignments, mentions, reminders, digests, security notices, invitation codes, one-time codes)Name, email, phone number, preferencesConsent (WhatsApp and non-essential email can be switched off in your notification settings); legitimate use for security notices and one-time codes
Keeping the service secure: authentication, two-factor checks, detecting new devices and suspicious sign-ins, rate limiting, preventing abuse of the contact formSecurity and usage logs, device characteristics, IP addressLegitimate use of protecting the service and its users
Recording who did what in a workspace so that your organisation and the provider can review activityAudit trailLegitimate use of performing the engagement and meeting record-keeping duties
Answering messages sent through the contact pageContact form dataConsent, given when you submit the form
Complying with law, resolving disputes and enforcing our termsAny of the above, as neededLegitimate use of complying with legal obligations

We do not use personal data for advertising, profiling for marketing, or selling to third parties, and we do not make decisions about you by automated means that have legal or similarly significant effects.

5. Browser storage, cookies and analytics

The application stores in your browser only what it needs to work: your sign-in tokens, your theme choice, the workspace you were last in, and, if you enable it, a "trusted device" marker so that two-factor prompts are not repeated on the same browser. These values are set by us, are not shared with third parties, and are removed when you sign out or clear your browser data.

The public home page checks for a sign-in token so that signed-in clients are taken to their workspace. It stores nothing new.

We do not run third-party analytics, advertising trackers or social-media pixels on any page.

6. Who we share data with

We share personal data only with the people and services needed to run the platform:

  • Your organisation. Workspace Admins of your organisation can see the members of their workspace and the content in it. Members can see the people involved in items they can access.
  • The provider. As operator of the platform the provider can see every workspace in order to deliver the engagement and support the service.
  • Data processors. Service providers that process data on our instructions and under contract: cloud hosting for the servers and database (Microsoft Azure), object storage for files and encrypted backups (Amazon Web Services S3), transactional email delivery (Zoho ZeptoMail) and, when WhatsApp notifications are enabled, the WhatsApp Business Platform (Meta Platforms). Each receives only what it needs to perform its function.
  • Authorities. Where the law requires it or to protect the rights, safety or property of the provider, its clients or the public.
  • A successor. If the provider's business is transferred, personal data may be transferred to the successor under the same protections, and you will be informed.

We never sell personal data and never share one client organisation's data with another.

7. Where data is stored and transferred

The application servers and database are hosted in a Microsoft Azure data centre. Files and encrypted backups are stored in an Amazon Web Services S3 bucket in the Asia Pacific (Mumbai) region. Email and WhatsApp messages are delivered through the providers named in section 6, which may process them outside India for delivery. Transfers are made in line with the DPDP Act and any restrictions notified by the Government of India.

8. How long we keep data

DataRetention
Account and organisation profileFor as long as the account or workspace exists, then deleted or anonymised within a reasonable period after the engagement ends, subject to legal duties
Workspace contentUntil deleted by an authorised person. Deleted items stay in the workspace trash until restored or purged
NotificationsIn-app notifications are kept while the account exists
Email and WhatsApp delivery logs90 days, then purged automatically
Sign-in, device and audit recordsFor the life of the account and as required to investigate incidents or meet legal duties
Contact form messagesUntil the provider archives or deletes them in the inbox; you may ask for earlier deletion
Invitations and one-time codesUntil used, expired or revoked, then purged automatically
BackupsDaily encrypted backups are kept for 14 days on the server and up to 35 days offsite, then deleted on a rolling basis. Data deleted from the live system disappears from backups on that schedule

9. How we protect data

  • Every workspace is isolated at the database and storage level; requests without a valid workspace context are refused.
  • All traffic uses HTTPS. Connections between the application and its database are encrypted.
  • Passwords are stored as salted one-way hashes. Vault items are encrypted with AES-256-GCM and revealed only after a fresh second-factor check. Two-factor secrets and sensitive contact fields are encrypted at rest.
  • Two-factor authentication (authenticator app or passkey) is available to everyone and can be made mandatory for a workspace.
  • Files are stored in a private bucket and served through short-lived, authenticated links; the platform never exposes storage credentials to browsers.
  • Security notices are sent when an administrator resets your password or disables your two-factor authentication, when your account is suspended or reactivated, and when you sign in from a new device.
  • Backups are encrypted before they leave the server. Logs mask email addresses and phone numbers.
  • Access to production systems is limited to the provider, over authenticated channels only.

No system is perfectly secure. You help by following the security responsibilities in our Terms of Service.

10. Your rights and how to use them

Under the DPDP Act you have the right to:

  • Access a summary of the personal data we process about you, the processing activities, and the identities of the data fiduciaries and processors with whom it has been shared;
  • Correction and completion of inaccurate or incomplete personal data, and updating of your details;
  • Erasure of personal data that is no longer necessary for the purpose it was collected for, unless retention is required by law;
  • Grievance redressal through the process in section 14;
  • Nominate another person to exercise your rights if you die or become incapacitated.

Signed-in users can exercise most of these rights directly in the application: the profile pages let you update your details and notification preferences, and the privacy page lets you review consents and open access or erasure requests, which we answer within the time the law allows. For anything else, or if you no longer have access, use the contact page. We may need to verify your identity before acting on a request.

You also have the duties the DPDP Act places on data principals, including not impersonating others, not suppressing material information, and not making false or frivolous grievances.

12. Children

The service is a business tool for adults. We do not knowingly process the personal data of anyone under 18. If you believe a child has been given an account, tell us through the contact page and we will remove it.

13. Security incidents

If a personal data breach affects you, we will notify you and the Data Protection Board of India in the form and time the DPDP Act and its rules require, and tell you what happened, what data was involved and what we are doing about it.

14. Grievance redressal

The provider is the grievance officer for the platform. Send any grievance about how your personal data is handled through the contact page, describing the issue and the account or workspace concerned. We acknowledge grievances promptly and aim to resolve them within the period the DPDP Act prescribes. If you are not satisfied with our response you may approach the Data Protection Board of India.

15. Changes to this policy

We may update this policy as the service or the law changes. The current version is always published at associate.works/privacy-policy with its effective date, and material changes are announced in the application or by email before they take effect.

16. Contact

Requests about your data, grievances and questions about this policy all reach the provider through the contact page.

Go to the contact page