Data Security & Privacy Compliance Policy
Official Policy & Legal Statement
Back to Home
Effective Date: 1st September 2026 | Last Updated: 1st September 2026
This Data Security & Privacy Compliance Policy describes the technical and organizational security measures implemented by welleservices to protect personal data processed through the Expo Lead CRM platform, in compliance with:
- Section 43A of the Information Technology Act, 2000 — Reasonable Security Practices
- IT (Reasonable Security Practices and Procedures and SPDI) Rules, 2011 — IS/ISO 27001 standard adherence
- Digital Personal Data Protection Act, 2023 (DPDP Act) — Data Fiduciary obligations
- RBI Guidelines on Cyber Security Framework for Payment Systems
- CERT-In Directions (April 2022) — Incident reporting requirements
1. Infrastructure Security
- Hosting Environment: The platform is hosted on enterprise-grade cloud infrastructure with physical access controls, redundant power supply, and environmental monitoring.
- Network Perimeter: All production servers are protected by Web Application Firewalls (WAF), rate-limiting middleware, and automated DDoS mitigation.
- Transport Encryption: All data transmitted between user devices and Platform servers is encrypted using TLS 1.3 with HSTS enforcement. HTTP connections are automatically redirected to HTTPS.
- Database Encryption: Sensitive database fields (passwords, API keys, payment tokens) are stored using industry-standard one-way hashing (bcrypt) and AES-256 encryption where applicable.
2. Role-Based Access Control (RBAC)
Access to all Platform resources is governed by a four-tier Role-Based Access Control system:
| Role | Access Scope |
| SuperAdmin | Platform-wide configuration, tenant management, plan administration, AI settings, payment oversight. Cannot access tenant lead data. |
| Owner | Full access to own Tenant workspace: leads, sales, marketing, team management, billing, API keys, reports. |
| Admin | Workspace access excluding billing, plan management, and API key administration. |
| Sales Representative | Lead capture, Kanban board view, task management only. No access to billing, reports, team, or settings. |
All role-permission matrices are enforced server-side via Laravel Spatie Permissions. UI-level restrictions are supplemented by server-side authorization middleware on every sensitive route.
3. Multi-Tenant Data Isolation
Expo Lead CRM employs database-level multi-tenant isolation using Laravel Global Scopes bound to Tenant IDs on all database queries. This technical control ensures:
- No cross-tenant data leakage is possible through API endpoints, web routes, or report exports.
- All webhook payloads, email broadcasts, and PDF invoice generation are scoped to the initiating Tenant.
- SuperAdmin accounts are architecturally prevented from accessing individual Tenant's lead, sales, or marketing data.
4. Authentication & Session Security
- All passwords are hashed using bcrypt with a minimum cost factor of 12. Plaintext passwords are never stored or transmitted.
- Session tokens are rotated upon login to prevent session fixation attacks.
- All web forms are protected by CSRF tokens (Cross-Site Request Forgery protection) validated on every state-changing request.
- Idle sessions expire automatically after a configurable period of inactivity.
- API endpoints are authenticated via SHA-256 hashed Bearer tokens with configurable expiry.
5. AI Vision & Business Card OCR Security
When the AI Vision Business Card Scanner feature is enabled:
- Business card images are transmitted over TLS-encrypted HTTPS connections to the selected AI Vision provider (Google Gemini or Groq).
- Images are processed transiently for text extraction only. The Company does not retain or store business card image data on our servers beyond the immediate extraction request.
- The AI provider API keys are stored as encrypted environment variables and are never exposed to frontend clients.
- The SuperAdmin may globally lock/disable AI Vision scanning for all Tenants via the AI Settings control panel.
6. Payment Security (RBI Compliance)
- Payment processing is handled exclusively by Razorpay Financial Solutions Pvt. Ltd., a PCI-DSS Level 1 certified and RBI-licensed Payment Aggregator.
- No card numbers, CVV, or sensitive payment credentials are transmitted to or stored on Expo Lead CRM servers at any point.
- Razorpay payment webhook events are verified using HMAC-SHA256 digital signature validation before any wallet credit is applied.
- All payment API keys (Key ID and Key Secret) are stored as server-side encrypted environment variables, inaccessible to frontend JavaScript.
7. Security Vulnerability Management
- Regular automated dependency audits are conducted using Composer security advisories to detect and patch known vulnerabilities in third-party libraries.
- The platform applies security patches and framework updates on a rolling basis.
- Developer API keys support revocation and rotation from the Tenant's workspace settings at any time.
8. Data Backup & Disaster Recovery
- Database backups are performed on a daily basis, with backups encrypted and stored in geographically redundant storage.
- Backup retention period: 30 days for operational backups; 90 days for monthly snapshots.
- Recovery Time Objective (RTO): 4 hours for critical service restoration.
9. Incident Response & CERT-In Compliance
In compliance with the CERT-In Directions of April 2022:
- Detected security incidents are triaged and contained within 6 hours of discovery.
- Reportable cybersecurity incidents (as classified by CERT-In) will be reported to CERT-In within 6 hours of being brought to notice.
- Affected Tenants will be notified within 72 hours of a confirmed personal data breach involving their Tenant workspace, as required under the DPDP Act, 2023.
- A post-incident report will be prepared within 14 days of containment, detailing root cause, impact, and corrective actions.
10. Responsible Disclosure
We welcome responsible security vulnerability disclosures from security researchers. If you discover a security vulnerability in the Expo Lead CRM Platform, please report it to:
Email: security@welleservices.com
Subject: "Responsible Disclosure – [Brief Description]"
We commit to acknowledging all valid reports within 48 hours and will not initiate legal action against good-faith security researchers who comply with responsible disclosure guidelines.
11. Contact
Data Protection / Security Officer: welleservices Management
Email: security@welleservices.com
Address: #30, First Floor, Near Villapuram Arch, Aruppukottai Main Road, Villapuram, Madurai, Tamil Nadu – 625012, India