Security & Compliance

DPDP compliance is enforced by the software, not a policy document.

Every channel and every purpose carries its own consent record. Every client's data is walled off at the database itself. This is the page to forward to your legal and security teams.

9 consent purposes tracked per candidate 0 messaging credentials stored Row-level tenant isolation, enforced at the database

Consent & data protection — the DPDP Act

Consent is a build-time requirement here, not a launch-day checklist item.

Consent-first, per purpose

Separate, revocable consent for WhatsApp, SMS, RCS, email, voice calls, AI screening, audio, video and talent-pool retention — held in an append-only ledger. No record means no consent.

Consent basis on every import

The source's own consent records, a written attestation by a named user, or a pending opt-in — declared at the point of import, every time.

Visible skips

Every wave shows exactly how many people were skipped for missing consent — nothing silently dropped.

Opt-out that works everywhere

A STOP reply, or the signed unsubscribe link in any message, removes someone from one campaign or the whole company — synced straight to the messaging layer.

Account-wide do-not-call

Say it once, and every future campaign skips the number — automatically.

AI transparency

AI calls disclose themselves at the start of the call, and AI screening is disclosed on the application form.

Campaign terms before launch

The client confirms the data is theirs, that there's a lawful basis, that they're authorised, and that the content is theirs — before a campaign can go live.

Privacy notice first

Publishing a candidate privacy notice is a blocking setup step, not an afterthought.

Delete, honoured account-wide

Delete requests apply across the whole account, and exports carry only what screening actually needs.

Outreach is built to send SMS as promotional, exactly as DLT rules require.

Security & tenant isolation

Enterprise-grade isolation — your candidates can never be seen by another client.

Database-level isolation

Each client's data is walled off by the database itself using enforced row-level security. The platform refuses to start if that protection is switched off.

Your session decides your workspace

Editing a URL cannot reach another client's data — access is enforced by the session, not by the address bar.

No channel credentials held

WhatsApp tokens, sender IDs and sending domains stay inside the audited Eficaz Comms Hub — never on a client screen.

Strong accounts

Email verification before access, hashed passwords with a length-based policy, hashed session tokens, single-use expiring links, and protection against account enumeration.

Signed, deduplicated webhooks

Delivery webhooks are signed and deduplicated on the way in.

Rate-limited signup

Signup itself is rate-limited against abuse.

Uploads, size-limited & scanned

Every upload is size-limited and held pending a scan before it's used.

Commercial privacy

Costs and margins never reach a client screen — full stop.

Bring your legal or security team to the next call.

We'll walk through the consent ledger, the isolation model, and whatever your review needs to see.