DPDP Act 2023 Compliance

Last updated: 20 July 2026

Replova Labs Private Limited is committed to complying with the Digital Personal Data Protection Act, 2023 (DPDP Act) enacted by the Parliament of India. This page explains how OutreachAI processes personal data in accordance with the DPDP Act and the measures we have implemented to protect Data Principals' rights.

1. Our Role Under the DPDP Act

1.1 As a Data Fiduciary

For user account data (your name, email, authentication details), Replova Labs acts as a Data Fiduciary — we determine the purpose and means of processing your personal data.

1.2 As a Data Processor

For lead data that you upload or discover (business contact details of your prospects), Replova Labs acts as a Data Processor — we process this data on your behalf and according to your instructions (sending emails, making calls, etc.). You, as the OutreachAI user, are the Data Fiduciary for your leads' personal data.

2. Lawful Basis for Processing

We process personal data based on:

  • Consent: You consent to data processing when you create an account and configure campaigns
  • Contractual necessity: Processing required to deliver the services you have subscribed to
  • Legitimate interest: Lead data from public business directories (Google Places) is publicly available business information
  • Legal obligation: Retaining billing records as required by Indian tax law

3. Notice & Consent

In accordance with Section 5 and 6 of the DPDP Act:

  • We provide clear notice about what data we collect and why (see our Privacy Policy)
  • Consent is obtained at the time of account creation and before enabling new features that process additional data
  • You may withdraw consent at any time by closing your workspace or contacting our Data Protection Officer
  • Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal

4. Data Principal Rights

Under the DPDP Act, you (as a Data Principal) have the following rights:

RightDPDP SectionHow to Exercise
Right to AccessSection 11Email privacy@replov.com to request a summary of your personal data
Right to CorrectionSection 12Update your profile in Settings, or email us for corrections we cannot self-serve
Right to ErasureSection 12Delete your workspace from Settings, or email us. Subject to legal retention periods.
Right to Grievance RedressalSection 13Contact our Data Protection Officer (see Section 8 below)
Right to NominateSection 14Email privacy@replov.com to nominate a representative

We will respond to all rights requests within 30 days.

5. Data Protection Measures

5.1 Technical Safeguards

  • Encryption at rest: All database data encrypted using AES-256
  • Encryption in transit: All API communications over TLS 1.2+
  • Application-level encryption: Sensitive fields (API keys, SMTP passwords, IMAP credentials) are encrypted before database storage using a separate encryption key
  • Row-Level Security: PostgreSQL RLS policies ensure workspace-level data isolation — one workspace cannot access another's data at the database level
  • Audit logging: All billing transactions and data access events are logged

5.2 Organizational Safeguards

  • Access to production data is restricted to authorized personnel on a need-to-know basis
  • All team members with data access are bound by confidentiality agreements
  • Regular security reviews of third-party integrations
  • Incident response procedures for data breaches

6. Cross-Border Data Transfer

Some of our third-party service providers process data outside India (Anthropic for AI processing, Google for Places API). In accordance with the DPDP Act, we ensure that:

  • Data is transferred only to countries/entities not restricted by the Central Government
  • Appropriate contractual safeguards are in place with all processors
  • Data shared with foreign processors is limited to what is strictly necessary for the service

7. Data Breach Notification

In compliance with the DPDP Act, in the event of a personal data breach:

  • We will notify the Data Protection Board of India as required by the Act
  • We will notify affected Data Principals without undue delay
  • Notification will include the nature of the breach, data affected, and remedial measures taken

8. Your Responsibility as a Data Fiduciary

When you use OutreachAI to contact leads, you are the Data Fiduciary for your leads' personal data. This means:

  • You must have a lawful basis for contacting each lead
  • You must provide notice to leads about how their data is being used (in your outreach messages)
  • You must honor data access, correction, and erasure requests from your leads
  • You must not process lead data for purposes beyond what you have disclosed
  • You are responsible for the legality of contact data you upload (CSV/Excel files)

9. Data Protection Officer

In accordance with the DPDP Act, we have designated a Data Protection Officer who can be reached at:

  • Email: dpo@replov.com
  • Entity: Replova Labs Private Limited, India

If your grievance is not resolved satisfactorily, you may file a complaint with the Data Protection Board of India as established under the DPDP Act.

10. MCA Data Queries

OutreachAI's lead discovery features access publicly available data from business registries and directories. All MCA (Ministry of Corporate Affairs) data queries are:

  • Encrypted in transit and at rest
  • Audited and logged for compliance
  • Used solely for legitimate B2B lead discovery purposes
  • Subject to the same data protection measures as all other platform data