DPDPA Compliance
India — Digital Personal Data Protection Act, 2023
Last updated 25 July 2026
Template. This document describes how WhizzLink is built and configured, but it has not been reviewed by a lawyer. Have counsel review and adapt it for your jurisdiction before relying on it.
WhizzLink is a product of WhizzAct Private Limited, incorporated in India. This page explains how we meet our obligations under the Digital Personal Data Protection Act, 2023 (the “DPDPA”) and its rules. It sits alongside our Privacy Policy, which describes in detail what we collect and why; here we map that behaviour onto the Act's specific requirements.
Our role and key terms
Under the DPDPA, WhizzAct Private Limited is the Data Fiduciary — the entity that determines the purpose and means of processing your personal data. You, the individual whose data we process, are the Data Principal. The hosting, email, and geolocation vendors that process data on our instructions act as our Data Processors under written contract.
Notice and lawful basis
We process personal data only for a lawful purpose for which you have given consent, or for a “legitimate use” permitted by the Act. Concretely:
- Account holders — we process your name, email, and account records to provide the Service you signed up for (a purpose for which you have voluntarily provided your data).
- Link visitors — we record click analytics for the account holder who owns the link. This data is minimised by design: raw IP addresses are not stored — only a salted hash is kept, and location is resolved only to an approximate country, region, and city.
Where we rely on consent, the request is presented in clear terms, is specific to the stated purpose, and can be withdrawn as easily as it was given. Withdrawing consent does not affect processing already carried out lawfully.
Your rights as a Data Principal
The DPDPA gives you the right to:
- Access a summary of the personal data we process about you and the processing activities involved;
- Correct, complete, update, or erase your personal data — account holders can do most of this directly in their profile;
- Grievance redressal through the Grievance Officer named below, as a first point of contact before approaching the Data Protection Board of India;
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity;
- Withdraw consent at any time.
We respond to verified requests within the timelines prescribed under the Act. To make a request, email support@whizzact.com.
Your duties as a Data Principal
The Act also places duties on you: to not impersonate another person when providing data, to not suppress material information, to not file false or frivolous grievances, and to furnish only authentic information when exercising your right to correction.
Children's data
WhizzLink is not directed at children. We do not knowingly create accounts for anyone under 18 without verifiable consent of a parent or lawful guardian, and we do not carry out tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child's data has been collected, contact us and we will erase it.
Retention and erasure
We keep personal data only as long as needed for the stated purpose. Individual click events are deleted after 180 days and aggregated statistics after up to 365 days; our operational logs (sign-in history, API request logs, audit logs, resolved abuse reports) are pruned on their own windows. Account data is kept while your account is open; a deleted account is recoverable for 30 days and then permanently erased, along with its links and analytics, save where the law requires us to retain specific records. Scheduled jobs enforce every one of these windows automatically.
Security and breach notification
We apply reasonable security safeguards to protect personal data — hashed passwords, CSRF-protected forms, rate-limited sensitive endpoints, and audit logging of administrative actions. In the event of a personal data breach, we will notify the Data Protection Board of India and each affected Data Principal in the manner and within the time required by the Act.
Grievance Officer
As required by Section 13 of the DPDPA, you may contact our Grievance Officer for any question or complaint about how we handle your personal data:
If your grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India in accordance with the Act.