1. Who we are
CTX.works ("we", "our", "CTX.works") operates the CTX.works Event Suite — a SaaS platform for event transport management (EVlo), guest RSVP collection (CTX-RSVP), and hotel accommodation coordination (CTX-Stay). Our platform is available at ctx.works and the app portal at app.ctx.works.
[PLACEHOLDER: Legal entity name, registered address, CIN, and GSTIN of the operating company — required for DPDP Act compliance.]
We are the Data Fiduciary as defined under the Digital Personal Data Protection Act, 2023 ("DPDP Act") for all personal data we collect in connection with our services.
2. Data we collect
2.1 Account data
- Name, email address, mobile number (used for WhatsApp OTP)
- Organisation name, organisation type, and optional GSTIN
- Role within the organisation (coordinator, vendor, hotel staff, etc.)
- Account creation date and trial / subscription status
2.2 Event and operational data
- Guest names, mobile numbers, dietary preferences, travel details — uploaded or collected through CTX-RSVP
- Vehicle and driver details — uploaded to EVlo by event coordinators
- GPS location data and odometer photographs captured by driver devices during active trips
- Hotel block details, room assignment records, and check-in confirmations
- Trip records including start/end times, estimated and actual distance, and billing amounts
2.3 Payment and billing data
- Subscription tier, billing cycle, and payment status (stored in our database)
- Payment method tokens (stored by Razorpay, not by us; we retain only the last 4 digits and payment method type for display)
- GST invoice records including GSTIN, billing address, and invoice amounts — retained for 7 years per Indian tax law
- Razorpay payment IDs and subscription IDs for dispute resolution
2.4 Usage data
- Pages visited, features used, actions taken within the platform (event log, session duration)
- Device type, browser type, and approximate IP-derived location (city level) for security and fraud detection
- Error logs and crash reports to identify and fix bugs
- Analytics events via Plausible Analytics (cookieless, no personal identifiers transmitted)
2.5 Communication data
- WhatsApp messages sent and received through the AiSensy integration on behalf of your events (message content, delivery status, timestamp)
- AI voice call transcripts from CTX-RSVP guest calls (processed by Sarvam AI / ElevenLabs; transcript stored against the guest RSVP record)
- Support emails and contact form submissions
3. How we use your data
We use the data we collect for the following purposes:
| Purpose | Data used |
|---|---|
| Providing the service | Account, event, operational data |
| Billing and payment processing | Payment data, GSTIN, billing address |
| WhatsApp and voice communications to guests | Guest mobile numbers, RSVP responses |
| Fraud detection and security | IP address, device fingerprint, payment metadata |
| Product improvement and analytics | Anonymised usage data via Plausible |
| Legal compliance (tax, court orders) | Billing data, invoice records |
| Customer support | Account data, event records, support messages |
We do not sell your personal data. We do not use your data for advertising to third parties. We do not use guest data (collected through CTX-RSVP) for any purpose other than serving your event.
4. Lawful basis under the DPDP Act, 2023
Under the Digital Personal Data Protection Act, 2023, we process personal data on the following grounds:
- Consent (§7): For guest personal data collected via CTX-RSVP (WhatsApp opt-in captured at RSVP flow initiation; voice call consent captured verbally at call start).
- Contract (§7): For processing account and billing data necessary to deliver the SaaS service you have subscribed to.
- Legitimate uses (§8): For fraud detection, security, and legal compliance.
- Legal obligation: For retaining GST invoice records as required by the Income Tax Act and GST law.
For guest data collected through CTX-RSVP on behalf of an event organizer, the organizer (not CTX.works) is the Data Fiduciary. CTX.works acts as a Data Processor in this capacity. The organizer is responsible for obtaining lawful consent from their guests.
5. Storage in India & security
All personal data processed by CTX.works is stored within India:
- Primary database: PostgreSQL on a VPS located in Bangalore, India.
- Object storage (photos, exports): Cloudflare R2 with an India-region PoP. Data at rest is encrypted with AES-256.
- No data is transferred to servers outside India except as described in §6 (third-party processors) for specific processing tasks.
Security measures we apply:
- TLS 1.3 in transit for all API calls, web portal traffic, and webhook delivery.
- Database encrypted at rest. Application secrets managed via environment-specific secret store.
- Access controls: row-level tenant isolation; coordinators cannot access other tenants' data.
- Payment data: we store no raw card numbers. Payment tokens are held by Razorpay under PCI DSS compliance.
- Odometer photographs are stored in R2 with access-controlled presigned URLs (15-minute expiry).
- Regular security review schedule [PLACEHOLDER: specific frequency and scope].
6. Third-party processors
We share personal data with the following processors solely to deliver the service. Each processor has been assessed for appropriate data handling:
| Processor | Purpose | Data shared |
|---|---|---|
| Razorpay (Razorpay Software Pvt. Ltd., India) | Payment processing, mandate capture, subscription billing | Name, email, phone, billing address — no raw card data |
| AiSensy (Aisensy Technologies Pvt. Ltd., India) | WhatsApp Business API — RSVP messages, trip dispatch, itinerary cards | Guest/driver mobile numbers, message content |
| Sarvam AI (Sarvam AI Pvt. Ltd., India) | AI voice RSVP calls in Indian languages | Guest phone numbers, call transcript (stored in India) |
| ElevenLabs (Scale-tier only) | High-fidelity voice synthesis for AI calls | Text scripts only — no personal caller data sent |
| Anthropic (Claude API) | AI extraction of structured data from RSVP responses, odometer OCR cross-check | Text snippets (anonymised where possible); no raw guest PII sent |
| AWS SES (Amazon Web Services, India region) | Transactional email (OTP, invoices, notifications) | Email address, email content |
| Cloudflare (R2 India PoP) | Object storage for photos, exports, and generated PDFs | File content only — no additional personal identifiers |
| Plausible Analytics | Cookieless, privacy-respecting web analytics | Aggregated page view data; no personal identifiers transmitted |
[PLACEHOLDER: Data Processing Agreements (DPAs) with each processor should be documented here or linked. DPDP Act requires contractual obligations on processors.]
7. Data retention
| Data type | Retention period | Basis |
|---|---|---|
| GST invoices, payment records | 7 years from invoice date | Income Tax Act 1961, GST law |
| Event operational data (Starter tier) | 1 year from event date | Tier feature: 1-year data retention |
| Event operational data (Growth tier) | 3 years from event date | Tier feature: 3-year data retention |
| Event operational data (Scale tier) | 7 years from event date | Tier feature: 7-year data retention |
| Account data | Until account deletion + 30-day soft-delete window | Service delivery; erasure on request |
| AI voice call transcripts | Same as event operational data for the tier | Evidence for RSVP record |
| Support correspondence | 3 years from last interaction | Dispute resolution |
| Security and access logs | 90 days | Security monitoring |
When a subscription is cancelled, the account enters a 30-day grace period during which the account holder can export their data. After this window, event and guest data is deleted. Billing records are retained for 7 years regardless of cancellation, as required by Indian tax law.
8. Your rights under the DPDP Act, 2023
As a Data Principal under the DPDP Act, you have the following rights:
8.1 Right to access (§11)
You may request a summary of the personal data we hold about you and the purposes for which it is processed. Submit a request via privacy@ctx.works. We will respond within 72 hours.
8.2 Right to correction (§12)
You may correct inaccurate personal data through your account settings. If the data is not accessible via settings, email us.
8.3 Right to erasure (§12)
You may request deletion of your account and associated personal data. Upon request, we will:
- Delete event and guest data within 30 days
- Anonymise account data (name, email, phone replaced with irreversible tokens)
- Retain billing records (GST invoices) for 7 years as required by law — these cannot be erased
- Confirm completion of the erasure process by email
8.4 Right to grievance redressal (§13)
If you believe your rights have been violated, you may file a complaint with our Grievance Officer (see §12 below). If not resolved to your satisfaction, you may escalate to the Data Protection Board of India.
8.5 Right to withdraw consent
Where processing is based on consent (e.g. guest RSVP data), you may withdraw consent at any time by contacting us. Withdrawal does not affect the lawfulness of processing before withdrawal.
9. Cookies & analytics
The marketing site (ctx.works) uses Plausible Analytics — a cookieless, privacy-respecting analytics tool. No cookies are set, no personal identifiers are collected, and no data is shared with advertising networks. No consent banner is required.
The app portal (app.ctx.works) uses session cookies (JWT tokens in httpOnly cookies) for authentication. These are strictly necessary and not used for tracking. An optional opt-in cookie for analytics may be offered in future versions.
10. Children
CTX.works services are not directed at persons under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, please contact us immediately and we will delete it.
11. Changes to this policy
We may update this privacy policy from time to time. Material changes will be communicated via email to account holders at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use of the service after the effective date constitutes acceptance of the revised policy.
12. Grievance officer
As required by the DPDP Act, 2023, CTX.works has appointed a Grievance Officer to address complaints related to personal data processing:
Grievance Officer — CTX.works
[PLACEHOLDER: Name of Grievance Officer]
[PLACEHOLDER: Designation]
Email: grievance@ctx.works
[PLACEHOLDER: Registered address]
Grievances will be acknowledged within 24 hours and resolved within 30 days, as required under DPDP Act §13.
13. Contact us
For privacy-related questions, data access requests, or erasure requests:
- Email: privacy@ctx.works
- Response time: within 72 hours for access/erasure requests
- Postal: [PLACEHOLDER: registered address of CTX.works operating entity]
For general inquiries, use our contact form.