Trust & Privacy
CrewForge holds employee records, client relationships, and company financials, so protecting personal data is fundamental to how we operate. This page explains how we handle personal data in line with India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025 — our role, your rights, how we secure data, and how to reach us.
CrewForge is a multi-tenant ERP and workforce-management platform for software companies. Operating it means processing personal data — about a customer's own team, their clients, and their business. We are committed to handling that data lawfully, transparently, and securely, and to helping our customers meet their own obligations under the DPDP Act.
This statement is written in plain language and is intended to be read alongside our Privacy Policy, Security page, and Subprocessors list. Where this page describes a step you must take to exercise a right, we tell you exactly how to do it.
The DPDP Act distinguishes between a Data Fiduciary (who decides why and how personal data is processed) and a Data Processor (who processes data on a Fiduciary's behalf). CrewForge plays both roles, depending on the data:
| Our role | Which data | What it means for you |
|---|---|---|
| Data Processor | Everything a customer loads into their workspace — employee records, client and contact details, CRM leads, support tickets, worklogs, payroll, and uploaded documents. | The customer (your employer or the business that engaged you) is the Data Fiduciary. We process this data on their instructions. If you are an individual whose data was added by a CrewForge customer, please direct rights requests to that organisation first; we will assist them in responding. |
| Data Fiduciary | Account & billing data of the business that signs up — the account holder's name and email, business legal name, GSTIN, and billing address. | For this data we are directly responsible: we provide notice, honour your rights, retain it only as needed, and handle any breach in line with the DPDP Act. |
The categories below reflect what CrewForge can store on behalf of a customer. The exact data present in any workspace depends on which modules that customer uses and what they choose to enter.
| Whose data | Categories | Purpose |
|---|---|---|
| Employees & team members | Identity & contact (name, work and personal email, phone, address); employment details (role, joining/exit dates, manager); payroll & financial (salary, bank details); government identifiers (PAN, and where entered, Aadhaar); attendance & worklog data, which can include device and approximate location when location capture is enabled. | HR operations, time tracking, payroll, and workforce management for the customer. |
| Clients & contacts | Company and contact-person details (name, email, phone, address), tax identifiers (GSTIN), and support-portal access data. | Managing client relationships, projects, billing, and the support portal. |
| Sales leads | Prospect company and contact details, deal information, and notes. | CRM and sales-pipeline management. |
| Account holders | Sign-up name and email, business legal name, GSTIN, and billing address. | Providing, billing, and supporting the CrewForge service. |
| All users | Usage and system data — login timestamps, IP address at sign-in, and operational logs. | Security, troubleshooting, and maintaining a reliable service. |
Under the DPDP Act you have rights over your personal data. Because most data in CrewForge is held on behalf of our customers, the route to exercise a right depends on who controls your data:
The rights available to you include:
We will acknowledge and respond to rights and grievance requests within 90 days, and usually much sooner. We may need to verify your identity before acting on a request.
We combine our own controls with the capabilities of trusted infrastructure providers to safeguard data throughout its lifecycle:
For a fuller picture of our security model, see our Security page. We continue to strengthen these safeguards over time as part of our DPDP readiness programme.
We rely on a small number of carefully vetted third-party providers to operate the service. Each is listed, with the data they handle, on our Subprocessors page. Some of these providers may process or store data on infrastructure outside India; we engage them under contractual data-protection commitments and in line with applicable law.
We retain personal data for as long as a customer's account is active and the data is needed to provide the service, and thereafter only as required to meet legal, tax, or accounting obligations. When data is no longer needed for these purposes, we take steps to delete or anonymise it. Customers control the data in their own workspaces and may delete records at any time.
If a personal-data breach occurs, we are committed to acting promptly: notifying affected customers and, where we are the Data Fiduciary, the Data Protection Board of India and affected individuals, consistent with the timelines under the DPDP Rules. Where we act as a Data Processor, we will inform the affected customer without undue delay so they can meet their own notification obligations.
We have designated a Grievance Officer to receive and address questions, requests, and complaints about how we handle personal data. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
For DPDP rights, grievances, and data-protection queries.
Ashish Singh
CEO & Co-founder, TheCodeWork
Director, Debsin Technologies Private Limited
The company responsible for CrewForge.
TheCodeWork (registered under Debsin Technologies Private Limited)
H12, Baghajatin Lane, Chengcoorie Road, Silchar, Assam, 788004, India
If you use CrewForge to process personal data about your own employees or clients, you are the Data Fiduciary for that data and CrewForge acts as your Data Processor. A Data Processing Agreement (DPA) is available on request, and our security controls and sub-processor transparency are designed to help you meet your obligations under the DPDP Act. Please reach out using the contact details above.
Last updated: June 25, 2026
This page is reviewed periodically and updated as our practices and the law evolve. It is provided for transparency and is not legal advice.