Tutorials/Data Privacy and DPDP Policy

Data Privacy and DPDP Policy

Document control

Field Value
Document status Active policy document
Owner Security / Operations
Approver Management
Review frequency Annual or on material change
Classification Customer-shareable

Purpose

This policy defines Hybrowlabs' approach to protecting personal data and supporting obligations under applicable privacy and data protection requirements, including the Digital Personal Data Protection Act, 2023 where applicable.

The objective is to ensure personal data is collected, used, accessed, stored, shared, retained, and deleted in a controlled, lawful, secure, and transparent manner.

Scope

This policy applies to:

  • Personal data processed during customer projects, implementation, support, operations, and managed services.
  • Personal data of employees, contractors, applicants, customers, users, and business contacts.
  • Personal data present in applications, databases, backups, logs, documents, tickets, screenshots, exports, emails, and integrations.
  • Employees, contractors, vendors, and subprocessors who access or process personal data on behalf of Hybrowlabs.

This policy applies regardless of whether the data is stored in a production system, support environment, business application, spreadsheet, document, backup, or communication channel.

Key definitions

Term Meaning
Personal Data Any data about an individual who is identifiable by or in relation to such data.
Data Principal The individual to whom the personal data relates.
Data Fiduciary The entity that determines the purpose and means of processing personal data.
Data Processor The entity that processes personal data on behalf of a Data Fiduciary.
Processing Any operation performed on personal data, including collection, storage, use, sharing, retrieval, modification, deletion, or disclosure.
Subprocessor A third party engaged to process personal data as part of service delivery.

Privacy governance model

Privacy responsibilities are shared across teams:

Role / Team Responsibilities
Management Approves privacy/security direction, customer commitments, and material exceptions.
Security / Operations Maintains privacy/security controls, evidence, reviews, and incident coordination.
Project / Delivery Owners Ensure customer data is used only for agreed service purposes and access remains appropriate.
Engineering / DevOps Implement technical safeguards such as access control, encryption, logging, secure configuration, and deletion support.
HR / Admin Protect employee, applicant, and contractor personal data.
Legal / Commercial Owner Maintains contractual privacy obligations, DPDP addendums, confidentiality clauses, and subprocessor obligations.
All Personnel Follow confidentiality, acceptable-use, access-control, and incident-reporting requirements.

Privacy principles

Hybrowlabs follows these privacy principles:

1. Purpose limitation

Personal data must be processed only for documented and authorized business purposes, such as project delivery, implementation, support, payroll/HR operations, compliance, security, or customer-authorized activities.

Personnel must not access or use personal data out of curiosity, for personal reasons, or for any purpose outside the approved scope.

2. Data minimization

Only the minimum personal data required for the specific purpose should be collected, accessed, exported, or shared.

Examples:

  • Use masked or sample data where full personal data is not required.
  • Avoid downloading full datasets when a filtered extract is sufficient.
  • Avoid screenshots containing unnecessary personal information.
  • Do not copy production personal data into unmanaged locations.

3. Accuracy and relevance

Where Hybrowlabs is responsible for maintaining personal data, reasonable steps should be taken to ensure it is accurate and relevant to the processing purpose. Where the customer is the system/data owner, correction requests should be routed through the agreed customer process.

4. Storage limitation

Personal data should be retained only for as long as required for the approved business, legal, contractual, security, or operational purpose. Temporary working copies must be removed when no longer needed.

5. Security safeguards

Personal data must be protected through appropriate administrative, technical, and organizational controls, including access control, encryption where applicable, secure sharing, logging, endpoint security, confidentiality obligations, and incident response.

6. Accountability

Processing activities, access decisions, exceptions, customer requests, and incidents should be documented with sufficient evidence to demonstrate compliance with this policy.

Lawful and authorized processing

Personal data may be processed only when there is an approved basis, such as:

  • Customer contract or statement of work.
  • Customer instruction for implementation, support, migration, integration, or troubleshooting.
  • Employee/contractor administration and HR obligations.
  • Legal, tax, accounting, or compliance requirement.
  • Security monitoring, fraud prevention, incident response, or audit support.
  • Consent or notice-based processing where applicable.

Where Hybrowlabs acts as a processor for a customer, Hybrowlabs processes personal data according to the customer's documented instructions and applicable contractual terms.

Categories of personal data

Depending on the engagement or business process, personal data may include:

  • Identity data: name, employee ID, user ID, contact details.
  • Employment data: role, department, reporting manager, attendance, leave, payroll-related fields where applicable.
  • Authentication/access data: usernames, access roles, audit trails, login metadata.
  • Communication data: emails, tickets, meeting notes, support comments.
  • Document data: forms, attachments, contracts, approvals, identity or HR records where applicable.
  • Technical data: IP address, device/browser metadata, logs, request IDs, error traces.

Sensitive or high-risk data must receive stronger access, sharing, retention, and deletion controls.

Data inventory and processing records

For customer or internal systems that process meaningful volumes of personal data, the relevant owner should maintain or be able to produce:

  • System / process name.
  • Data owner.
  • Purpose of processing.
  • Categories of personal data.
  • Categories of data principals.
  • Storage location / system of record.
  • Access groups / privileged users.
  • Retention expectation.
  • Third-party/subprocessor involvement.
  • Security controls in place.
  • Deletion/export process where applicable.

Access control for personal data

Access to personal data must follow least privilege and business need.

Requirements

  • Access must be approved by the relevant owner or authorized manager.
  • Privileged/admin access must be restricted and reviewed periodically.
  • Access must be removed when the user no longer requires it.
  • Shared accounts should be avoided wherever possible.
  • Service accounts and API keys must have documented ownership and purpose.
  • Personnel must not share credentials or reuse customer credentials.

Access reviews

Access to systems containing personal data should be reviewed periodically, especially for privileged users, leavers, role changes, vendors, and temporary support access.

Handling and sharing personal data

Personal data must be shared only through approved and controlled channels.

Approved handling practices

  • Share only with authorized recipients.
  • Use role-based access or named-user access where possible.
  • Apply expiry/revocation for temporary access where supported.
  • Use encryption or password protection for sensitive files where appropriate.
  • Mask or redact unnecessary personal data before sharing.
  • Avoid public links for files containing personal data.
  • Remove temporary files when work is complete.

Restricted practices

Personnel must not:

  • Share personal data through personal email or unmanaged storage.
  • Post personal data in public channels or broad groups.
  • Store customer personal data on local devices longer than necessary.
  • Use personal data for training, demos, testing, or analytics without approval and safeguards.
  • Upload personal data to unapproved third-party tools.
  • Commit personal data, credentials, or secrets into source control.

Data transfer and third-party sharing

Personal data may be shared with third parties or subprocessors only when:

  • There is a documented business purpose.
  • The third party is approved for the relevant processing activity.
  • Contractual confidentiality and security obligations are in place.
  • The data shared is limited to what is necessary.
  • Customer approval/notification is completed where contractually required.
  • Access is revoked when no longer needed.

Subprocessors must be tracked in a maintained register with service purpose, data categories, owner, approval status, and review date.

Security controls

Systems and processes handling personal data should apply controls proportionate to the sensitivity and risk of the data.

Baseline controls

  • Role-based or least-privilege access.
  • Strong authentication and MFA for sensitive/administrative systems where supported.
  • Encryption in transit for external access.
  • Encryption at rest where supported by the platform and data sensitivity.
  • Logging of security-relevant events and administrative activity where feasible.
  • Patch and vulnerability management for systems processing personal data.
  • Secure backup and recovery controls.
  • Endpoint security and hardening for devices accessing personal data.
  • Secure deletion or return at the end of processing.

Logs and monitoring

Logs must not intentionally expose passwords, tokens, secrets, or unnecessary personal data. If logs contain personal data, they must be access-controlled and retained only as required.

Data subject rights support

Where applicable and contractually required, Hybrowlabs supports customer or internal processes for data principal rights, such as:

  • Access to personal data.
  • Correction or update.
  • Deletion or erasure.
  • Grievance handling.
  • Withdrawal of consent where applicable.
  • Nomination or other rights recognized under applicable law.

Where Hybrowlabs acts as a processor, requests received directly from individuals should be routed to the relevant customer/data fiduciary unless Hybrowlabs is responsible for the data as a fiduciary in that context.

Retention and deletion

Personal data must be retained according to applicable contractual, legal, operational, security, and business requirements.

Requirements

  • Define retention expectations for systems and document repositories containing personal data.
  • Delete temporary extracts, screenshots, and working files when no longer required.
  • Revoke access at the end of engagement or role requirement.
  • Return, delete, anonymize, or retain customer data at exit according to the agreement.
  • Maintain deletion or return evidence where required.

Backups may retain data until the normal backup expiry cycle unless specific deletion obligations require additional handling.

Privacy incidents and breach response

A privacy incident includes suspected or confirmed unauthorized access, disclosure, alteration, loss, deletion, misuse, or exposure of personal data.

Examples

  • Personal data sent to the wrong recipient.
  • Public link created for a confidential personal-data file.
  • Credentials exposed in a repository or chat.
  • Unauthorized access to a system containing personal data.
  • Lost or stolen device containing personal data.
  • Logs or error messages exposing personal data beyond intended users.

Response requirements

  • Report suspected incidents immediately through the internal escalation channel.
  • Contain exposure by revoking links, disabling access, rotating credentials, or isolating affected systems.
  • Identify affected data, systems, users, and timeline.
  • Preserve evidence for investigation.
  • Notify customer, management, legal, or other stakeholders where required by contract or law.
  • Track remediation and post-incident corrective actions.

Privacy by design

New systems, integrations, reports, automations, or customer workflows should consider privacy during design.

Review should include:

  • What personal data is needed and why.
  • Whether data can be minimized, masked, or anonymized.
  • Who needs access.
  • How data will be stored and encrypted.
  • How logs and backups will treat the data.
  • How data will be exported, deleted, or returned.
  • Whether third-party tools are involved.
  • Whether the customer must approve or be notified.

Training and awareness

Personnel who handle personal data must understand confidentiality, acceptable use, secure sharing, incident reporting, phishing risks, access-control expectations, and customer-data handling requirements.

Training should be provided during onboarding and periodically thereafter, with additional training after incidents or recurring control gaps.

Exceptions

Exceptions to this policy require documented approval. The exception record must include:

  • Business reason.
  • Data involved.
  • Systems/users affected.
  • Risk and compensating controls.
  • Owner.
  • Expiry or review date.
  • Approver.

Exceptions must not be treated as permanent unless explicitly approved and reviewed periodically.

Review and maintenance

This policy must be reviewed at least annually or when there is a material change in legal requirements, customer obligations, systems, vendors, processing activities, or security risk.

Evidence to maintain

  • Approved Data Privacy and DPDP Policy.
  • Data Processing Agreement / DPDP Addendum where applicable.
  • Data inventory / processing record.
  • Access review records.
  • Subprocessor register.
  • Data retention and disposal evidence.
  • Secure data exchange approvals.
  • Training records.
  • Privacy incident records.
  • Customer request and deletion/return evidence.
  • Exception register.

Need help with your workflow setup?

If you're stuck or want help applying these guides to your setup, our team can assist with configuration, customization, and workflow implementation.