Security & privacy
Security and data protection at SaudaFlow.
This is the written posture, for a vendor assessment or a security questionnaire: where tenant data is stored, how it is encrypted, how workspaces are separated, what happens when a SaudaFlow operator needs access, and which obligations we are bound by. Everything below describes what runs today. A Data Processing Agreement is available on request, and the standard text is published.
Where your data physically sits.
Four places, all of them in the Mumbai region — and one box that is deliberately drawn outside them.
Your device
The Android app or a browser in your office. TLS 1.2+ from here on, every hop.
SaudaFlow, Mumbai
The application servers that answer the request. India region, no overseas failover.
Postgres, Mumbai
Encrypted at rest with AES-256. Every row scoped to your workspace by row-level security.
Backblaze B2, Mumbai
Documents, cost sheets and recordings. Encrypted before upload, separate key envelope.
SaudaFlow staff
Outside the boundary by default. No standing access to any tenant workspace.
The only way in is a scoped, time-bound grant for support or a legal obligation — and it writes an append-only audit row you can read in your own workspace.
Mumbai data residency
Your workspace data — leads, deals, calls and documents — is stored and processed on infrastructure in the Mumbai region and does not leave India. Our public marketing site uses Google Analytics only with your consent; that covers website page visits, never workspace data.
Encrypted at rest & in transit
Data is encrypted at rest with AES-256 and transmitted over TLS 1.2+. Backups are encrypted with a separate key envelope.
Per-workspace isolation
Every row is scoped to your workspace with Postgres row-level security. One tenant can never see another tenant’s data.
DPDP Act 2023 compliant
We act as your Data Processor. Consent capture, breach notification and data-principal rights workflows are built into the product.
Audit trails — visible to you
Sensitive actions write append-only audit rows. Staff have no standing access to tenant data; any access for support or legal compliance is logged and visible to you.
India-first compliance
TRAI-compliant SMS/recording disclosures, DLT registration support, and GST-correct invoicing on every tenant receipt.
What we never do
- We never sell or share your tenant data with advertisers, or with anyone in the business of reselling personal data.
- We never move your data out of the Mumbai region without your consent.
- We never lock you in — export your full data to CSV any time.
Send us your questionnaire and we will answer it directly, including the rows where the answer is no: support@saudaflow.in. For a suspected vulnerability, use the same address with “Security disclosure” in the subject line. Read the DPA →