Data Processing Agreement
This describes the terms on which we process personal data on your behalf. Where you are the controller of data in your workspace, we are the processor.
Last updated August 12, 2026
1. Parties
Worksynk is a product of Fulgid Software Solutions Pvt Ltd. Worksynk is a product name, not a separate legal entity — Fulgid Software Solutions Pvt Ltd is the contracting party and the processor referred to below.
2. Roles
For the content you and your team put into a workspace — work items, notes, files, time entries, client records — you are the controller and we are the processor. We process that content to provide the service and on your documented instructions, which include your use of the product’s features.
For your own account and billing relationship with us, and for the operation and security of the platform, we act as a controller in our own right. That processing is described in the Privacy Policy.
3. Subject matter and duration
- Subject matter — provision of a delivery management platform.
- Duration — for as long as your subscription is active, plus the retention window described below.
- Nature and purpose — storage, organisation, retrieval, analysis, and transmission of workspace content in order to run the service you have subscribed to.
- Categories of data subject— your personnel, your clients’ personnel, and anyone your team records in a work item, note, or client record.
- Types of personal data — names, work contact details, authentication data, activity and timing metadata, and whatever free-text content your team chooses to enter.
Please do not put special category data, payment card numbers, or health records into a workspace unless we have agreed that separately in writing. See the Acceptable Use Policy.
4. Our obligations
- Process personal data only on your documented instructions, unless required otherwise by law — in which case we will tell you first, where we are permitted to.
- Ensure people authorised to process the data are bound by confidentiality.
- Implement appropriate technical and organisational measures — see section 5.
- Assist you, so far as reasonable, with data subject requests, impact assessments, and consultations with a supervisory authority.
- Notify you without undue delay after becoming aware of a personal data breach affecting your workspace, with the information we have at the time.
5. Security measures
The measures in place are described in detail on the Security page. In summary:
- Passkey (WebAuthn) and two-factor authentication, with credentials encrypted at rest.
- Access decided by workspace role and project role together, narrowed further by module state and client access level.
- Stored credentials encrypted with AES-256-GCM, decrypted only on access by a permitted user, with every view logged. Vault contents are unreachable by AI assistants and integrations.
- A workspace-wide activity log, login history, and a record of every AI tool call.
- Server-side sanitisation of rich text on write, allow-listed file uploads, and baseline security response headers.
- Optional IP allowlisting for workspaces that require it.
6. Subprocessors
You give general authorisation for us to engage subprocessors. Current categories are listed on the Subprocessors page. Each is bound by terms no less protective than these, and we remain responsible for their performance.
We will give notice before adding or replacing a subprocessor that processes customer content, so you have a reasonable opportunity to object.
7. International transfers
Where personal data is transferred outside the jurisdiction it was collected in, we rely on an appropriate transfer mechanism — such as standard contractual clauses — together with the technical measures in section 5. Tell us if your organisation has data residency requirements and we will confirm what we can support before you commit.
8. Data subject requests
The product gives you direct access to the content in your workspace, which is usually the fastest route to satisfying a request. Where a request cannot be resolved through the product, contact us and we will assist within a reasonable period.
9. Return and deletion
Deleting an item in the product moves it to Trash rather than removing it immediately, so an accidental deletion is recoverable. On termination you may export your workspace content; after the export window closes we delete or anonymise it, except where we are required to retain it by law.
Disabling a module hides its interface and blocks its endpoints. It does not delete the underlying data.
10. Audits
On reasonable written notice, and no more than once a year unless a regulator requires otherwise, we will make available the information reasonably necessary to demonstrate compliance with this agreement. We may satisfy this with documentation and written responses where that is sufficient.
11. Getting this countersigned
If your procurement process needs a signed copy, or an amended version for a particular jurisdiction, get in touch and we will work through it with you.
This document describes how the product behaves and is provided for transparency. It is not legal advice, and it has not been reviewed by counsel. If you need a countersigned agreement or a jurisdiction-specific version, please contact us.