Legal

Data Processing Agreement

Last updated August 2026

This is the agreement that governs how WTS CRM processes the personal data you put into your workspace — your clients’ names, contact details, invoices and payments. It applies automatically to every account, alongside the Terms of Service, because you cannot use WTS CRM without us processing that data on your behalf. Nothing below overrides the Terms; where the two conflict, the Terms govern liability and this document governs data handling.

The five questions, answered directly

Before the formal clauses, the things a customer actually asks us before signing up:

  • Where is our data stored? In InsForge’s Asia-Pacific (Singapore) data centre. Nowhere else, and we do not move it without updating this page first.
  • Who can access it? Your own team, through your own logins. On our side, nobody has a standing way to browse your workspace — row-level security in the database enforces that, not just the app’s screens. The handful of people who can reach the database directly (to run the service, ship a fix, or handle a support request you raised) are named in Web Total Solution, and doing so outside a support request you raised is a breach of this agreement.
  • What happens when we terminate? Export your data first, then delete the account. Deletion is immediate, permanent and irreversible — see “Return and deletion of data” below for exactly what runs and when.
  • Will you use our customer data to train AI? No. We do not use your workspace content — or anything in it about your clients — to train, fine-tune or evaluate any AI or machine-learning model, ours or anyone else’s, and we do not sell it or use it to advertise to you.
  • What happens if you have a security incident? We tell you without undue delay, plainly, with what happened and what to do — see “Breach notification” below and the full commitment on the security page.

1. Roles

For the personal data in your workspace, you are the Data Fiduciary (the DPDP Act’s term for what other frameworks call a Controller): you decide why that data is collected and what it is used for. We are your Data Processor — we hold and process it only on your documented instructions, as given through your use of WTS CRM, and for no purpose of our own. We do not decide the purpose or means of processing your clients’ data, and their rights over it run against you, not us.

2. Subject matter, nature and duration

We process the personal data you enter into WTS CRM — your clients’ names, phone numbers, email addresses, company details, notes, invoices and payment records — by storing it, making it available to you through the app, and backing it up, for as long as your account exists. Processing ends when the account is deleted, subject to the deletion process below.

3. Categories of data and data subjects

  • Data subjects: the individuals you deal with through WTS CRM — your clients, leads and contacts. Not your own staff’s account details, which we process as Data Fiduciary ourselves under the privacy policy.
  • Data categories: name, phone number, email address, company name, deal or project notes, invoice line items, GSTIN and place of supply, and payment records against an invoice. We do not ask you to collect, and do not knowingly process, any special category of data (health, biometric, financial account credentials) beyond what a normal invoice contains.

4. Our obligations as processor

  • Process the data only as needed to run WTS CRM, and on no instruction but yours.
  • Keep it confidential: our staff and contractors who can reach it are bound to the same confidentiality this agreement requires of us.
  • Apply the technical and organisational measures on the security page — encryption in transit and at rest, database-enforced tenant isolation, write-only payment secrets, and restricted production access.
  • Use no sub-processor beyond the list in section 5 without telling you first, on the privacy policy’s “Where your data lives” section, which is the one place that list is kept so it cannot drift out of date.
  • Give you what you need to answer a data subject’s request from one of your clients — access, correction, erasure — since you, not us, must respond to them.
  • Notify you of a personal data breach without undue delay. See section 7.
  • Delete or return your data on termination, as set out in section 8.

5. Sub-processors

Kept deliberately short, and identical to the list in privacy policy’s “Where your data lives” section — read that for what each one does and where. Today: InsForge (database and file storage, Singapore), Vercel (application hosting), and Google (only for accounts using Sign in with Google). If you save your own payment gateway credentials to collect from your clients, that gateway is your sub-processor, not ours — we are not a party to that relationship.

6. International transfer

Your data is stored in Singapore, outside India. The DPDP Act permits this except to a country the government restricts; we will move the data, or tell you before it becomes a problem, if that changes.

7. Breach notification

If personal data in your workspace is lost, exposed or accessed without authorisation, we tell you without undue delay: what happened, what data was involved, what we have done about it, and what you should do. Because you, not us, know who your clients are outside your own workspace, notifying them is yours to do — we give you what you need to do it. The full commitment, including our own notice to the Data Protection Board of India, is on the security page.

8. Return and deletion of data

While your account is active, you can export everything in your workspace as a JSON file from settings, at any time, for no charge. On deletion — whether you delete the account yourself or your access lapses and is never renewed and you ask us to delete it — every row you own is permanently removed in one transaction: clients, projects, tasks, notes, invoices, payments, billing details and login. This is a hard delete, not a flag; there is no recovery afterwards, which is why export comes first. Backups and platform logs held by our sub-processors age out on their own retention cycles rather than being purged on request; the live, working copy of your data is what this section governs.

Your invoices and payment records may be documents you are separately required by tax law to keep for several years. Deleting your WTS CRM account does not satisfy that obligation on your behalf — export first.

9. No AI training

We do not use your workspace content, or anything in it about your clients, to train, fine-tune or evaluate any AI or machine-learning model — not ours, and not a third-party model we call. If that ever changes for a specific, clearly-labelled feature, it will be opt-in and disclosed here before it processes a single record of yours.

10. Audit

On reasonable written notice, we will answer written questions about how we meet this agreement and provide the documentation we already hold to support it (such as the security page and our sub-processor list). We do not host on-site audits given the size of the operation, but will not unreasonably withhold information a genuine compliance review needs.

11. Liability

Liability for a breach of this agreement is governed by the limitations and exclusions in the Terms of Service, section 12. This document does not create any additional liability beyond what the Terms already set out.

For larger customers

If your organisation needs a countersigned version of this agreement, or standard contractual clauses for a specific jurisdiction, write to support@webtotalsolution.com and we will put one together.

WTS CRM

Stop losing leads.
Start closing them.

Start a free 3-day trial with every feature unlocked. No card required.