DAPVIORA Enterprise CRM Workspace Back to sign in
Legal information

Privacy Policy

Please review this document carefully before using the DAPVIORA platform and services.

Privacy Policy

Effective date: 26 July 2026 Last updated: 26 July 2026

This Privacy Policy explains how DAPVIORA Technologies ("DAPVIORA", "we", "us" or "our") collects, uses, stores, discloses and protects personal data when individuals use the DAPVIORA platform, website and related services (collectively, the "Platform").

This Policy should be read together with our Terms of Service.

1. Scope and privacy roles

DAPVIORA provides a multi-tenant business and customer relationship management Platform.

Depending on the circumstances:

  • DAPVIORA determines the purposes and means of processing account, subscription, security and service-administration data; and
  • a customer organisation generally determines why information about its leads, customers, employees, suppliers and other contacts is entered into its workspace.

For Customer Data controlled by an organisation, DAPVIORA processes that information to provide the Platform and follow the organisation's lawful instructions.

The organisation remains responsible for giving required privacy notices, obtaining required consent and responding to individuals whose information it places in the Platform.

2. Personal data we may collect

Account and identity information

We may collect:

  • name;
  • email address;
  • password in hashed form;
  • email-verification status;
  • profile photo;
  • passkey information;
  • two-factor authentication settings and protected recovery information;
  • account status;
  • platform-administrator status; and
  • authentication tokens and session information.

Organisation and workspace information

We may collect:

  • organisation and legal name;
  • business email and telephone number;
  • workspace identifier;
  • timezone, language and currency;
  • subscription, trial and suspension status;
  • team membership;
  • invitations;
  • roles and permissions; and
  • organisation settings.

CRM and business-contact information

Information entered by authorised users may include:

  • names and company names;
  • job titles;
  • email addresses and telephone numbers;
  • physical, billing and shipping addresses;
  • websites;
  • tax and registration identifiers;
  • lead sources, status and priority;
  • customer history;
  • notes and custom fields;
  • assigned team members;
  • tasks and follow-ups;
  • sales opportunities;
  • quotations and invoices;
  • payment and expense records; and
  • other business information selected by the organisation.

Financial and subscription information

We may process:

  • subscription plan and entitlement details;
  • invoice and receipt information;
  • payment date, amount and currency;
  • payment method;
  • reference or transaction numbers;
  • payment status;
  • refund information; and
  • related notes and metadata.

DAPVIORA does not claim to store complete payment-card credentials unless a specific payment service expressly requires and discloses such processing.

Documents and files

Authorised users may upload documents. We may store:

  • original and system file names;
  • file type, extension and size;
  • storage path;
  • file checksum;
  • category and status;
  • confidentiality setting;
  • version information;
  • descriptions, notes and metadata;
  • upload and expiry dates; and
  • links to related business records.

Activity, security and technical information

We may collect:

  • login and account events;
  • actions performed in Platform modules;
  • timestamps;
  • affected records;
  • request method and route;
  • webpage or Platform address;
  • internet protocol address;
  • browser or device information;
  • request and batch identifiers;
  • before-and-after values;
  • notification activity;
  • error, security and diagnostic information; and
  • session and anti-forgery security data.

Activity records may be immutable to preserve audit integrity.

3. How we collect information

We collect information:

  • directly from account holders;
  • from organisations and their authorised users;
  • when users upload, create, update or import records;
  • automatically through essential Platform operations;
  • through authentication and security systems;
  • from subscription and support communications; and
  • from service providers acting on our behalf.

An organisation may enter information about individuals who do not personally have a DAPVIORA account.

4. Why we process personal data

We may process personal data to:

  • create and administer accounts;
  • verify email addresses and identities;
  • authenticate users and maintain sessions;
  • provide tenant-isolated workspaces;
  • enforce roles, permissions and plan entitlements;
  • operate CRM, billing, document and reporting features;
  • send invitations, notifications and service communications;
  • process subscriptions and record payments;
  • prevent fraud, abuse and unauthorised access;
  • investigate incidents and maintain audit records;
  • provide support and resolve disputes;
  • maintain, test and improve reliability;
  • comply with legal, tax and regulatory duties;
  • establish, exercise or defend legal claims; and
  • carry out other purposes disclosed at the time of collection.

We process personal data with consent or another lawful ground permitted under applicable law.

5. Consent and organisation responsibility

Where consent is legally required, the party collecting the information must ensure that consent is informed, specific and capable of being withdrawn as required by law.

Customer organisations must not use DAPVIORA to process information they are not legally permitted to collect or use.

Withdrawal of consent does not affect processing already lawfully completed and may not require deletion where retention is permitted or required by law.

6. Cookies and session technologies

The Platform may use cookies or similar technologies that are necessary to:

  • keep users signed in;
  • maintain secure sessions;
  • prevent cross-site request forgery;
  • remember essential preferences;
  • support authentication and passkeys; and
  • protect the Platform.

DAPVIORA does not currently represent that it uses third-party advertising cookies or behavioural advertising trackers. This Policy will be updated before materially different tracking is introduced.

Disabling essential cookies may prevent the Platform from functioning correctly.

7. How personal data may be shared

We may disclose personal data:

Within an organisation

Information may be available to authorised users according to their tenant membership, roles and permissions.

To service providers

We may use infrastructure, hosting, storage, email, security, support and other technical providers that process information for us under appropriate obligations.

For legal and safety purposes

We may disclose information where reasonably necessary to:

  • comply with applicable law or binding legal process;
  • respond to lawful government requests;
  • protect users, DAPVIORA or the public;
  • investigate fraud, abuse or security incidents; or
  • establish, exercise or defend legal claims.

Business changes

Information may be transferred as part of a merger, acquisition, financing, restructuring or sale of all or part of the business, subject to applicable law and appropriate safeguards.

We do not sell personal data to advertisers.

8. International processing

Personal data may be processed in India or in other locations where approved infrastructure or service providers operate.

Where cross-border processing occurs, we will take reasonable steps to use appropriate safeguards and comply with restrictions issued under applicable Indian law.

9. Retention

We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, including:

  • while an account or customer relationship remains active;
  • according to an organisation's lawful instructions;
  • to provide requested Platform functionality;
  • for security, audit and fraud-prevention needs;
  • to comply with taxation, accounting and legal requirements;
  • to resolve disputes and enforce agreements; and
  • for backup and disaster-recovery cycles.

Different record types may have different retention periods.

Deleted information may remain temporarily in soft-deleted records, backups, security records or legally required archives before being securely removed or overwritten.

Immutable activity records may be retained where necessary to protect audit integrity, prevent fraud, investigate incidents or comply with law.

10. Account deletion and organisation records

An account holder may use available account-deletion functionality or contact us.

Deleting an individual account may remove the user's profile photo, access tokens and user account, but it does not automatically erase business records belonging to an organisation.

Records created by the user may remain within the organisation's workspace where the organisation has a lawful need to retain them.

Requests concerning lead, customer, employee or other business-contact data should normally be directed first to the organisation that entered or controls that information.

11. Security

We use reasonable technical and organisational safeguards designed to protect personal data, which may include:

  • tenant-aware access restrictions;
  • role-based permissions;
  • password hashing;
  • email verification;
  • two-factor authentication;
  • passkeys;
  • session protections;
  • access and activity records;
  • confidential-document controls;
  • subscription and feature-access controls; and
  • operational monitoring.

No storage or transmission method is completely secure. Users must protect their credentials, devices, exports and downloaded documents.

12. Personal-data breaches

We investigate suspected personal-data breaches and take proportionate containment and remediation measures.

Where required by applicable law, we will notify affected parties and competent authorities within the legally required manner and timeframe.

Customer organisations must promptly notify DAPVIORA of suspected unauthorised access affecting their workspace.

13. Your rights

Subject to applicable law, individuals may have rights to:

  • obtain information about personal-data processing;
  • request access to personal data;
  • request correction, completion or updating;
  • request erasure where legally available;
  • withdraw consent;
  • submit a grievance;
  • nominate another individual to exercise rights in specified circumstances; and
  • seek remedies from the competent authority.

We may need to verify identity and authority before acting on a request.

Rights may be limited where an organisation controls the information, retention is legally required or another lawful exception applies.

14. Requests involving organisation-controlled data

When DAPVIORA receives a request concerning Customer Data controlled by an organisation, we may refer the request to that organisation or assist it in responding.

The organisation is responsible for determining whether a request is valid and what action is required under applicable law.

15. Children's data

The Platform is designed for business use and is not directed to children.

Customer organisations must not process children's personal data through DAPVIORA unless they have satisfied all applicable legal requirements, including verifiable parental consent where required.

16. Third-party links and services

The Platform may contain links to third-party websites or services.

Their privacy practices are governed by their own policies. DAPVIORA is not responsible for third-party processing outside our control.

17. Changes to this Policy

We may update this Policy to reflect legal, security, operational or Platform changes.

The revised version will display an updated date. Material changes may also be communicated through the Platform or registered email address.

18. Privacy and grievance contact

Questions, privacy requests or grievances may be sent to:

Privacy & Grievance Contact DAPVIORA Technologies Website: https://dapviora.com Email: notifications@dapviora.com

Please include enough information for us to identify the relevant account or organisation and understand the request. Do not send passwords, recovery codes or unnecessary confidential information by email.