DashLoc Contact Details:
Main address: 3rd Floor, 27th Main, 12th Cross Rd, 1st Sector, HSR Layout,560102Bengaluru, Karnataka, India ,
Tel:08041485914, E-mail: care@dashloc.com

Dashloc GDPR Information

We are committed to honoring our users rights to data privacy and protection. Even if our users might not be based in the EU, their customers may be, so it is important that dashloc is GDPR compliant to ensure all our clients are covered.

We are committed to honoring our users rights to data privacy and protection. Even if our users might not be based in the EU, their customers may be, so it is important that dashloc is GDPR compliant to ensure all our clients are covered. Being GDPR-ready has been one of the highest priority this year (2025), and we have implemented technical and organizational measures to be fully compliant with GDPR.

If you are looking for specific questions under GDPR, read our GDPR FAQs document here.

Data Processing and Ownership

During the course of process, our clients need to collect PII (Personally Identifiable Information) from customers using our platform. Because we process customers on behalf of our customers, according to GDPR, we are considered a “Data Processor” and our customers are regarded as “Data Controllers”.

When a customers makes a enquiry or is contacted by a dashloc client in course of data managements Process, we store the following information of the customers on behalf of our client:

Email address

Name

Phone number

This data comes under the purview of GDPR. According to Article 5 and 6 of the regulation, personal data can be “collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes ('lawfulness, fairness and transparency')”. Given that the processing should be fair, dashloc ensures that we either obtain consent from customers or customers has provided consent in past, when they are processed as customers for an enquiry with dashloc client. Our updated privacy policy clearly states how we process information in a fair and transparent manner. In the capacity of a Data Processor, all the customers information we receive or collect is handled securely with adequate data protection. To the extent that we act as a data processor on your behalf in connection with the performance of our Services, we will enter into a separate ” Data Processing Addendum” with you. Our standard Data Processing Addendum (DPA) is available for your review. You can find out more information on this Data Processing Addendum by emailing us at care@dashloc.com. Dashloc does not store any financial or biometric information on customers.

Data Subject Rights

Under GDPR, individuals have the right to ask the organizations they apply to for the right to portability, rectify and to be forgotten. dashloc collects customers' data on behalf of our clients, any requests regarding accessing/ editing/ deleting of customers' data will be forwarded to our clients. We give our clients the mechanisms to access their customers' data and also comply with requests from their customers. This way, our customers are always in control of their customers data.

While GDPR requires that a data subject can revoke their consent at any time, pursuant to the above stipulations in Article 6, it also allows this request to be declined if the processing of this information is required for legitimate interests pursued by the data controller. In other words, our client (the data controller) can determine if the customers's (data subject's) request is valid and can be fulfilled. We will take action based on the direction provided by our client on how to proceed with any such request.

As a processor, dashloc gives flexibility to our clients to determine their data policies, which offer rights to their customers. This includes the ability to access / edit/ delete information regarding a customers. We also give the ability to set a routine data deletion process at a cadence determined by the client.

Data Management

Data within dashloc is secured using industry-standard encryption. Under Article 46 of the regulation, data can be transferred outside EU borders if the processor has appropriate security measures in place and if our client (the data controller) and dashloc (data processor) have entered into a contract that includes contractual clauses specified by EU. Dashloc has a standard EU-specific data transfer and processing agreement to ensure compliance with GDPR. Article 49 provides an additional basis for such a transfer. Transfer of data is allowed where “necessary for the performance of a contract between the data subject and the data controller”.

GDPR also stipulates that personally identifiable data should not be stored indefinitely. Dashloc's data retention policy provides flexibility to our client (the data controller) to define how long their customers' PII should be stored and when it should be deleted. Data is stored for the duration of the contracted period with our client, and a grace period thereafter.

According to Article 30 of GDPR, our clients need to maintain a record of all activities pertaining to the personal information of a data subject. Dashloc maintains a detailed audit log of all the activities. As part of compliance, dashloc will add any additional activities that our clients need to be recorded. These logs are viewable in our dashboard or can be requested for export/ deletion by contacting us at care@dashloc.com

Data Breach And Mitigration Process

Article 33 states that for any potential data breach, the supervisory authority (our client) must be notified within 72 hours of occurrence. We have sufficient data monitoring mechanisms in place to become aware of any such breach. In case a personal data breach occurs, we will send breach notifications in accordance with our internal incident response policy (within 72 hours of us discovering the breach). The communication will be sent as per the guideline mentioned in Article 33. This will give sufficient time for our clients to convey the breach to the respective authorities. Additionally, we will notify users through our blogs and social media for general incidents. We will notify the concerned party through email (using the primary email address) for incidents specific to an individual user or an organization.

Quick Summary

- Dashloc tech deployment AWS (India). This is permitted under GDPR thanks to the AWS Data Processing Agreement

Any data requests from customers will be routed through our clients who need to process the data requests. Dashloc provides functionality to comply with any such requests.

the duration of data storage would be customized on a client-to-client basis as per the contract. We will store the data for the stipulated time in the contract and a grace period thereafter.

Data backups are kept safe, and strongly encrypted. We have provisions to anonymize data, when requested.

We provide product features to anonymize/ delete data. We also delete data by request to care@dashloc.com

For any queries, please contact us at care@dashloc.com

Data Breach And Mitigration Process

What data do we collect?

When a customers makes a registration or is contacted by a dashloc client in course of data management s Process, we store the following information of the customers on behalf of our client:

- Email address

- Name

- Phone number

We also collect usage data, and geographic position through third-party tools like Google Analytics and Google MAPS. This data is may also be mapped to a specific individual but is analyzed only as a whole.
Dashloc does not store any financial or biometric information on customers.

What is our privacy policy?

You can read more about our privacy policy here.

Who is responsible for customers data?

Any dashloc client that undertakes the data management process using dashloc, owns the data of all customers who did enquiry. The responsibility of updating and deleting all customers data when requested by a customers lies with the client. Dashloc provides our clients with necessary support (customer support/ product features) to carry out any such requests however and whenever the client wants to.

For how long is the customers data stored?

It depends on the contract with our client. By default, we store data until it's explicitly removed. But we provide provisions to set up a periodic data removal process for our clients on a contract-to-contract basis. However, we always support data deletion through requests sent to care@dashloc.com for all of our clients. We delete data at the specified/ requested time by our clients with an additional grace period.

Who has access to customers data?

Clients that perform data management process on dashloc.

- customers through requests to Client.

- dashloc internal team only when a support request is raised by the Client and data access is necessary to support such request.

Which roles/ permissions are required for employees of the client to have access to customers data?

All users of a client account with access based roles have access to customers reports as per role definition and permissions defined by Client Administrator.

How do clients request customers data to be deleted?

For enterprise users with specific contracts, they can delete the customers entry using 'delete' action in customers' view.

Furthermore, you can email us at care@dashloc.com with the list of customers' data to be deleted. You can also contact your dashloc Customer Success Manager for such requests.

How to access audit logs?

Dashloc maintains logs of several actions that are state changing as well as un-permissioned actions for troubleshooting and security. Super Admins of a client account can view the audit logs from their dashboard. Any further processing requests of audit logs should be routed through care@dashloc.com or your dashloc Customer Success Manager.

Can the deleted data be reinstated?

No.

Can we edit a customers's data?

Client users and admins with specific contracts, they can delete the customers entry using 'delete' action in customers' view.

For any specific request, please contact us at care@dashloc.com with details about the request.
customers who took part in data management process for a client

Can I delete/ edit/ view/ access my candidature or personal information?

Dashloc is an data Management Software as Service provider and your data provided to the client, is owned by our client who managed your customers and representative. Please contact the client user who managed your customers, directly to request the deletion of your data.

If you require any help in making such requests, please feel free to contact us at care@dashloc.com with specifics of Client and customers to.