Privacy Policy
1. Who is responsible for your data
Associate Works is operated by a single independent consultant (the "provider"). For the personal data described in this policy the provider is the data fiduciary under the DPDP Act (the person who decides why and how personal data is processed). "We", "us" and "our" refer to the provider acting through the platform.
Your organisation (the client whose workspace you belong to) decides what content it places in its workspace and who it invites. For that content your organisation may itself be a data fiduciary, and we process it on its behalf as part of the engagement between the provider and your organisation.
2. What this policy covers
This policy covers personal data processed through associate.works, admin.associate.works, the API, the email and WhatsApp notifications we send, and the public contact form. It does not cover the provider's professional services outside the platform, which are governed by the engagement with your organisation.
3. The personal data we process
| Category | Examples | Source |
|---|---|---|
| Account and identity | Name, email address, optional phone number in international format, role in the workspace, account status, password (stored as a one-way hash), two-factor secrets (encrypted) and passkey public keys, locale and timezone | You, or the person who invited you |
| Organisation profile | Client organisation name, legal name, primary contact details, address, website, logo | Your organisation's Workspace Admin or the provider |
| Workspace content | Projects, tasks, notes, files and their metadata, comments and mentions, resource links, vault items (encrypted), assignments | You and your colleagues |
| Notifications and preferences | Which events notify you, whether you receive immediate emails, digests or WhatsApp messages, read state of notifications | You (defaults set by the platform) |
| Security and usage logs | Sign-in events, IP address, approximate location derived from IP, device and browser characteristics used to detect new devices, audit trail of actions in a workspace, request identifiers | Generated automatically when you use the service |
| Delivery logs | Whether an email or WhatsApp message was sent, failed or skipped, with the recipient address or number stored in masked form | Generated automatically |
| Contact form | Full name, email address, your message, a keyed hash of your IP address and your browser's user-agent string | You, when you use the contact page |
| Privacy records | Consents you give or withdraw, requests you make about your data and how they were handled | You, through the privacy page in the application |
We do not process payment card data, government identifiers, or biometric data. We do not buy personal data from third parties.
4. Why we process it and on what basis
| Purpose | Data used | Basis under the DPDP Act |
|---|---|---|
| Creating and operating your account and workspace, letting you and your organisation collaborate with the provider | Account, organisation profile, workspace content, preferences | Your consent given when you accept an invitation and use the service; the legitimate use of performing the engagement your organisation asked for |
| Sending notifications you have chosen or that are essential (assignments, mentions, reminders, digests, security notices, invitation codes, one-time codes) | Name, email, phone number, preferences | Consent (WhatsApp and non-essential email can be switched off in your notification settings); legitimate use for security notices and one-time codes |
| Keeping the service secure: authentication, two-factor checks, detecting new devices and suspicious sign-ins, rate limiting, preventing abuse of the contact form | Security and usage logs, device characteristics, IP address | Legitimate use of protecting the service and its users |
| Recording who did what in a workspace so that your organisation and the provider can review activity | Audit trail | Legitimate use of performing the engagement and meeting record-keeping duties |
| Answering messages sent through the contact page | Contact form data | Consent, given when you submit the form |
| Complying with law, resolving disputes and enforcing our terms | Any of the above, as needed | Legitimate use of complying with legal obligations |
We do not use personal data for advertising, profiling for marketing, or selling to third parties, and we do not make decisions about you by automated means that have legal or similarly significant effects.
5. Browser storage, cookies and analytics
The application stores in your browser only what it needs to work: your sign-in tokens, your theme choice, the workspace you were last in, and, if you enable it, a "trusted device" marker so that two-factor prompts are not repeated on the same browser. These values are set by us, are not shared with third parties, and are removed when you sign out or clear your browser data.
The public home page checks for a sign-in token so that signed-in clients are taken to their workspace. It stores nothing new.
We do not run third-party analytics, advertising trackers or social-media pixels on any page.
7. Where data is stored and transferred
The application servers and database are hosted in a Microsoft Azure data centre. Files and encrypted backups are stored in an Amazon Web Services S3 bucket in the Asia Pacific (Mumbai) region. Email and WhatsApp messages are delivered through the providers named in section 6, which may process them outside India for delivery. Transfers are made in line with the DPDP Act and any restrictions notified by the Government of India.
8. How long we keep data
| Data | Retention |
|---|---|
| Account and organisation profile | For as long as the account or workspace exists, then deleted or anonymised within a reasonable period after the engagement ends, subject to legal duties |
| Workspace content | Until deleted by an authorised person. Deleted items stay in the workspace trash until restored or purged |
| Notifications | In-app notifications are kept while the account exists |
| Email and WhatsApp delivery logs | 90 days, then purged automatically |
| Sign-in, device and audit records | For the life of the account and as required to investigate incidents or meet legal duties |
| Contact form messages | Until the provider archives or deletes them in the inbox; you may ask for earlier deletion |
| Invitations and one-time codes | Until used, expired or revoked, then purged automatically |
| Backups | Daily encrypted backups are kept for 14 days on the server and up to 35 days offsite, then deleted on a rolling basis. Data deleted from the live system disappears from backups on that schedule |
9. How we protect data
- Every workspace is isolated at the database and storage level; requests without a valid workspace context are refused.
- All traffic uses HTTPS. Connections between the application and its database are encrypted.
- Passwords are stored as salted one-way hashes. Vault items are encrypted with AES-256-GCM and revealed only after a fresh second-factor check. Two-factor secrets and sensitive contact fields are encrypted at rest.
- Two-factor authentication (authenticator app or passkey) is available to everyone and can be made mandatory for a workspace.
- Files are stored in a private bucket and served through short-lived, authenticated links; the platform never exposes storage credentials to browsers.
- Security notices are sent when an administrator resets your password or disables your two-factor authentication, when your account is suspended or reactivated, and when you sign in from a new device.
- Backups are encrypted before they leave the server. Logs mask email addresses and phone numbers.
- Access to production systems is limited to the provider, over authenticated channels only.
No system is perfectly secure. You help by following the security responsibilities in our Terms of Service.
10. Your rights and how to use them
Under the DPDP Act you have the right to:
- Access a summary of the personal data we process about you, the processing activities, and the identities of the data fiduciaries and processors with whom it has been shared;
- Correction and completion of inaccurate or incomplete personal data, and updating of your details;
- Erasure of personal data that is no longer necessary for the purpose it was collected for, unless retention is required by law;
- Grievance redressal through the process in section 14;
- Nominate another person to exercise your rights if you die or become incapacitated.
Signed-in users can exercise most of these rights directly in the application: the profile pages let you update your details and notification preferences, and the privacy page lets you review consents and open access or erasure requests, which we answer within the time the law allows. For anything else, or if you no longer have access, use the contact page. We may need to verify your identity before acting on a request.
You also have the duties the DPDP Act places on data principals, including not impersonating others, not suppressing material information, and not making false or frivolous grievances.
11. Consent and withdrawing it
Where we rely on your consent you may withdraw it at any time: switch off optional notification channels in your notification settings, withdraw a consent on the privacy page, or ask us through the contact page. Withdrawing consent does not affect processing that already happened, and where processing is needed to run your account we may have to close the account if you withdraw it.
12. Children
The service is a business tool for adults. We do not knowingly process the personal data of anyone under 18. If you believe a child has been given an account, tell us through the contact page and we will remove it.
13. Security incidents
If a personal data breach affects you, we will notify you and the Data Protection Board of India in the form and time the DPDP Act and its rules require, and tell you what happened, what data was involved and what we are doing about it.
14. Grievance redressal
The provider is the grievance officer for the platform. Send any grievance about how your personal data is handled through the contact page, describing the issue and the account or workspace concerned. We acknowledge grievances promptly and aim to resolve them within the period the DPDP Act prescribes. If you are not satisfied with our response you may approach the Data Protection Board of India.
15. Changes to this policy
We may update this policy as the service or the law changes. The current version is always published at associate.works/privacy-policy with its effective date, and material changes are announced in the application or by email before they take effect.
16. Contact
Requests about your data, grievances and questions about this policy all reach the provider through the contact page.