Last updated: 6 August 2026
1. Policy objective
This Data Protection Policy describes the organisational and technical practices AdyOps uses to protect personal data throughout collection, use, access, storage, transfer, backup, retention and deletion. It is designed to support the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025 as they become applicable, contractual commitments and recognised security practices.
2. Scope
The policy applies to the AdyOps public website, SaaS application, support operations, internal administrative records, production and backup systems, authorised employees and contractors, and service providers that process data for AdyOps.
3. Data protection principles
- Lawful and purpose-limited: process data for a defined and permitted purpose.
- Data minimisation: collect only fields reasonably needed for the workflow.
- Accuracy: provide methods to correct or update records.
- Storage limitation: do not retain data indefinitely without a business, contractual or legal reason.
- Security and accountability: apply safeguards, maintain records and assign responsibility.
- Transparency: provide understandable notices about collection and use.
4. Governance and responsibility
Product, engineering, support and account administrators are responsible for implementing controls within their functions. Access to production or customer data is limited to authorised personnel with a legitimate need. The final contracting entity should designate a privacy or grievance contact and maintain records of relevant decisions, requests and incidents.
5. Data inventory and classification
AdyOps should maintain an inventory of systems, data categories, owners, processors, integrations and retention periods. Information is classified according to risk, for example: public, internal, confidential customer data, authentication secrets and restricted security information. Higher-risk categories receive stricter access and handling rules.
6. Collection and minimisation controls
Forms and integrations should request only fields necessary for the customer workflow. Optional fields should be clearly identified. Customers should avoid free-text collection of unnecessary sensitive information. New modules and custom integrations should be reviewed for purpose, field necessity, user notice and retention before deployment.
7. Access management
- Unique accounts and role-based permissions.
- Least-privilege access to workspaces, reports and administrative functions.
- Strong passwords, login throttling, session expiry and optional single-device controls where supported.
- Prompt removal or adjustment of access when a user's role changes or employment ends.
- Periodic review of privileged and inactive accounts.
8. Encryption and secure transmission
Production access should use HTTPS/TLS. Secrets and integration credentials must not be placed in public source code, browser-visible responses or unsecured files. Encryption at rest, key handling and database protection depend on the selected hosting and deployment architecture and should be verified during implementation.
9. Secure product development
Changes should include input validation, output encoding, authorisation checks, CSRF protection for state-changing actions, secure session handling, file-type and size controls, dependency review, error handling that avoids exposing internal details, and compatibility testing before production release.
10. Logging and monitoring
Security-relevant events such as login attempts, access changes, administrative actions, integration errors and suspicious activity may be logged. Logs must be access-controlled, protected from unauthorised alteration and retained according to legal, contractual and operational requirements. Logs should avoid storing passwords, full secrets or unnecessary customer content.
11. Vendor and subprocessor management
Before using a provider, AdyOps should assess the provider's purpose, data access, location, security practices, incident process, deletion capability and contractual commitments. Providers receive only the information required for their role and should be removed or replaced when no longer needed.
12. Data retention, deletion and media handling
Retention schedules should cover active data, exports, temporary files, logs, support attachments and backups. Secure deletion must be applied when retention expires, subject to backup cycles and legal holds. Public hosting folders must not contain source archives, old backups, exported customer files or credentials.
13. Backup and recovery
Backups should be protected, tested and separated from normal application access where practical. Recovery procedures should define responsible personnel, restoration steps and validation. Customers remain responsible for exporting business-critical data when required by their continuity plan.
14. Personal-data breach and incident response
Suspected loss, unauthorised access, credential exposure or malicious activity must be reported immediately to the designated security contact. AdyOps should contain the event, preserve relevant evidence, assess affected information and users, document decisions, notify customers and authorities where legally required, and implement corrective action.
15. Data-principal and customer requests
Requests for access, correction, erasure or withdrawal must be authenticated and recorded. Where AdyOps acts for a customer, AdyOps will reasonably assist that customer. Requests should be completed within the applicable legal or contractual period, subject to permitted exceptions.
16. Training and confidentiality
Personnel with access to customer or security information should receive practical training on phishing, password safety, secure file sharing, incident escalation, data minimisation and confidentiality. Confidentiality obligations continue after access or engagement ends.
17. Audit and improvement
Controls should be periodically reviewed through access checks, backup tests, vulnerability review, incident lessons, policy review and—where appropriate—independent security assessment. Findings should be prioritised according to risk and tracked through remediation.
18. Contact
Questions or suspected data-protection issues can be sent to Support@adyops.com with “Data Protection” in the subject line.