Sahyak CRM
Sahyakcrm
PRIVACY & DATA GOVERNANCE POLICY // PRIV-2026-V4.2

Global Data Protection & Privacy Governance Policy

Last Revised & Effective: August 29, 2026Entity: MayaLok Ventures Pvt. Ltd. / Sahyak CRM (Noida, India)

1. Overview & Data Controller Identification

This Privacy Policy ("Policy") details the rigorous principles, data processing taxonomy, cryptographic storage standards, and cross-border routing protocols implemented by MAYALOK VENTURES PRIVATE LIMITED / SAHYAK TECHNOLOGIES PRIVATE LIMITED ("Sahyak CRM", "we", "us", or "our") in relation to the collection, ingestion, segregation, and processing of Personally Identifiable Information (PII) across sahyak.com, crm.sahyak.com, our API endpoints, and our mobile applications.

Under the provisions of the Digital Personal Data Protection Act, 2023 (India), the General Data Protection Regulation (EU GDPR), and international data privacy statutes, Sahyak CRM functions primarily as a Data Processor (processing lead records and customer communications on behalf of our enterprise subscribers) and as a Data Fiduciary / Controller with respect to direct account holder telemetry and billing data.

2. Comprehensive Data Collection Taxonomy

We classify and process data across three discrete architectural categories:

A. Account Holder & Administrator Credentials

  • Full legal name, corporate email address, verified phone number, and physical office address.
  • Hashed passwords (utilizing salted Argon2/bcrypt algorithms) and Multi-Factor Authentication (MFA) seeds.
  • Enterprise billing records, GSTIN identification, credit/debit card tokens (stored via PCI-DSS Level 1 payment gateways).

B. Prospect & Inbound Lead Data (Customer Processed Data)

  • Prospect Name, personal/work email, WhatsApp and telephone contact numbers.
  • Meta Lead Ad Webhook JSON payloads (campaign IDs, form IDs, Ad Set parameters, leadgen timestamps).
  • Google Ads Click Identifiers (GCLID) and UTM tracking attributes.
  • Real estate property preferences, investment budget brackets, floor plan requests, and consultation notes.
  • Field sales agent GPS check-in coordinates (logged exclusively during active field visit dispatches).

C. Automated Device, Network & Telemetry Logs

  • Internet Protocol (IP) addresses, Autonomous System Numbers (ASN), and coarse geo-location (City/Country).
  • Browser User-Agent strings, operating system versions, and unique mobile hardware identifiers (UUID).
  • API query response latencies, server error logs, rate-limiting counters, and honeypot bot trap triggers.

3. Cloudflare Edge Architecture & D1 Serverless Storage

3.1. Edge Computing & TLS 1.3 Routing: All incoming HTTP requests and API calls are routed through Cloudflare's global Anycast edge network. Traffic is terminated over TLS 1.3 encryption with strict HTTP Strict Transport Security (HSTS) and Web Application Firewall (WAF) rule enforcement.

3.2. Serverless SQL Nodes (Cloudflare D1): Lead records, deal stages, and customer form submissions are processed and stored upon Cloudflare D1 distributed serverless SQL databases. Primary database replication occurs within regional data nodes situated in Mumbai (BOM) and New Delhi (DEL), India.

3.3. Encryption at Rest & In Transit: All customer data stored in database partitions is encrypted at rest using AES-256 bit encryption algorithms. Database connection strings, API tokens, and session secrets are managed via cryptographically isolated hardware security modules.

4. Third-Party Integrations & External Sub-Processors

Sahyak CRM integrates with selected third-party service providers solely to execute contracted features. We require all sub-processors to maintain SOC 2 Type II or ISO/IEC 27001 certifications:

  • Meta Platforms, Inc. (Meta Graph API & WhatsApp Cloud API): Used to ingest Facebook/Instagram lead ads and execute automated WhatsApp message/brochure dispatches. Data passed includes recipient phone numbers, template payloads, and message status callbacks.
  • Google Cloud Platform & Analytics: Used for aggregate conversion tracking, server telemetry, and Google Ads integration.
  • Cloudflare, Inc.: Used for DNS management, edge caching, DDoS mitigation, and serverless SQL database execution.
  • Authorized Payment Gateways (Razorpay / Stripe): Used for secure subscription billing processing without Sahyak storing raw credit card details.

5. Strict Multi-Tenant Isolation Guarantee

5.1. Cryptographic & Logical Schema Isolation: Sahyak CRM operates on a zero-trust multi-tenant architecture. Every database query, webhook ingestion, and read operation is strictly scoped by an immutable tenant_id and authenticated via ephemeral JWT/session tokens.

5.2. Zero Cross-Tenant Leakage: No sales representative, administrator, or sub-account of Tenant A can access, query, index, or decrypt the customer leads, deals, or metrics of Tenant B under any circumstance. Automated anti-scraping and data isolation monitors constantly evaluate query execution plans to prevent multi-tenant data bleed.

6. User Rights, Data Portability & Complete Deletion Protocol

6.1. Statutory User Rights: In accordance with the Indian DPDP Act 2023 and global privacy frameworks, customers and data principals possess the right to: (a) request access to all stored PII; (b) demand correction of inaccurate records; (c) export data in standard structured formats (CSV/JSON); and (d) revoke processing consent.

6.2. Immutable Workspace Deletion: Upon formal termination of an enterprise account or receipt of a verified deletion request submitted via privacy@sahyak.com or our dedicated /data-deletion portal, Sahyak CRM executes an immutable purge routine within thirty (30) calendar days. This routine cascades through all primary tables, indexes, backups, and edge caches to permanently eradicate Customer Data.

7. Cookies, LocalStorage & Tracking Technologies

We utilize essential session cookies, HTTP-only tokens, and client-side localStorage objects exclusively to: (a) authenticate logged-in administrators and field reps; (b) remember active interface workspace preferences; and (c) detect and prevent automated credential stuffing attacks. We do not sell customer PII or lead lists to third-party data brokers or behavioral advertising networks.

8. Data Protection Officer (DPO) & Grievance Redressal

In compliance with Rule 5(9) of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the DPDP Act 2023, the designated Grievance Officer and Data Protection Officer for Sahyak CRM is:

Grievance & Data Protection Officer
MayaLok Ventures Private Limited / Sahyak CRM
Sector 62, Noida, Gautam Buddha Nagar, Uttar Pradesh 201309, India
Privacy Redressal Desk: privacy@sahyak.com
Security Audits: security@sahyak.com
Response SLA: Under 48 Business Hours