Privacy Policy

How Wyzmindz Solutions Private Limited handles information in the Workspace CRM platform, its web application, and the W CRM mobile application.

Effective Date: 12 August 2026  ·  Applies to: Workspace CRM (web) and W CRM mobile app (com.advaita.workspace)

Contents

  1. Introduction
  2. Scope
  3. Our Role and Your Organization’s Role
  4. Information We Collect
  5. Information You Provide
  6. Account and Authentication Information
  7. Workspace / Tenant Information
  8. CRM and Business Information
  9. Location Information
  10. Camera and Photos
  11. Files and Documents
  12. Customer Communication and Interaction History
  13. Notifications
  14. Device and Technical Information
  15. How We Use Information
  16. How We Share Information
  17. Third-Party Services
  18. Organization / Tenant Data
  19. Data Storage
  20. Local Storage on Your Device and Browser
  21. Logging and Diagnostics
  22. Data Retention
  23. Data Security
  24. User Rights
  25. Account and Data Deletion
  26. Children’s Privacy
  27. International Data Transfers
  28. Changes to This Privacy Policy
  29. Contact Us

1. Introduction

Wyzmindz Solutions Private Limited (“Wyzmindz”, “we”, “us”, “our”) develops and provides Workspace CRM — a multi-tenant, workflow-driven customer relationship management platform. The platform consists of a browser-based web application, the online services that support it, and a companion mobile application published under the display name W CRM (bundle identifier com.advaita.workspace).

Workspace CRM is business software. It is licensed to organizations (“Customers”), and it is used by people those organizations authorize — employees, agents, supervisors and administrators (“Users”, “you”). Access requires an account provisioned inside an organization’s workspace; the applications have no public, self-service or consumer sign-up.

This Privacy Policy explains what information the platform handles, why it is handled, where it is stored, and what choices are available to Users and to the organizations that operate a workspace.

Wyzmindz Solutions Private Limited is the publisher of the W CRM application on the Apple App Store and Google Play, and is the entity responsible for this policy. The website on which this policy is published, and the contact address support.crm@wyzmindz.com, are operated by Wyzmindz Solutions Private Limited.

2. Scope

This policy covers:

  • The W CRM mobile application for iOS and Android.
  • The Workspace CRM web application.
  • The online services the applications connect to over secure connections in order to deliver workflows and records, notifications, document storage and reporting.

This policy does not cover the internal privacy practices of the organizations that license the platform, the content those organizations choose to store in their workspace, or third-party applications you may open from the app (for example your device dialer, messaging app, WhatsApp, or email client).

3. Our Role and Your Organization’s Role

Workspace CRM is a business-to-business product, and the relationship works in three layers:

Who controls what in a workspace
PartyRole
Wyzmindz Builds and operates the platform software. We process workspace data on the instructions of the organization that licenses the platform, in order to run, support and maintain the service.
Your organization (the tenant) Decides which workflows, stages and dynamic form fields exist, what customer, lead or dealer information is collected, who is invited as a User, what roles and permission codes each User holds, and how long records are kept. The organization determines the purposes of the data held in its workspace.
You (the User) Sign in with an account issued by your organization and work on the records assigned or made visible to you by your organization’s configuration.

Scroll the table sideways to see all columns.

If you are an employee, agent or contractor using W CRM, questions about why particular information is collected — including the fields on a form, the use of a location field, or how long records are kept — should go to your organization’s CRM administrator first. Those choices are made by your organization, not by Wyzmindz.

4. Information We Collect

The platform handles the categories of information described in sections 5 to 14. Some of it is entered by you, some is created by the platform as you work (for example assignment and allocation history), and some is technical information needed to operate the applications.

The applications do not include any advertising, marketing-tracking, usage-analytics or crash-reporting service. We do not build advertising profiles and we do not sell information.

5. Information You Provide

Information you enter directly into the applications includes:

  • Values you type or select in dynamic forms — text, numbers, dates, dropdown and multi-select choices, toggles, computed/calculated fields, repeating sections and multi-page (wizard) form pages, exactly as configured by your organization’s form builder.
  • Dispositions, remarks, comments and notes recorded against a workflow record.
  • Search terms and filter selections used to find records.
  • Files, documents and images you attach to a record.
  • Recipients and message variable values you supply when sending a templated communication.

6. Account and Authentication Information

Sign-in is handled by a dedicated identity and access management service operated for the platform. You sign in on that service’s own secure sign-in page rather than inside the application, and the applications never see or store your password.

In connection with authentication we handle:

  • Your username or email address, and the sign-in details you present to the identity service.
  • The secure session credentials issued to you after sign-in, together with the details they carry — such as your user identifier, name, email address, workspace identifier, roles and permissions.
  • Session state: when you signed in, when your session was last renewed, and whether it has expired.
  • If you enable it, a biometric unlock preference on mobile. Biometric matching is performed by the operating system (Face ID / Touch ID / Android biometrics); the app receives only a success or failure result and never receives or stores your biometric data.

On mobile, session credentials are held in the protected storage area provided by your device’s operating system.

7. Workspace / Tenant Information

The platform is multi-tenant. Every request is checked against the workspace it belongs to before any data is read or written, and each organization’s data is held separately from every other organization’s data. As a User you can only see and act on data belonging to the workspace your account is provisioned in, and only within the roles and permission codes assigned to you by your administrator.

Workspace-level information includes the tenant identifier and name, workflow and stage definitions, form definitions and field configurations, list view and filter settings, communication templates, and the user/role/permission assignments that govern access.

8. CRM and Business Information

The core purpose of the platform is to hold and progress your organization’s business records. Depending entirely on how your organization has configured its workflows and forms, this may include:

  • Customer, lead and dealer information — such as names, phone numbers, email addresses, postal or site addresses, identifiers and any other field your organization chooses to define on its forms.
  • Workflow and stage records — the record’s current stage, its stage history, submitted form data per stage, dispositions, attempt and call counters, stage age and total age.
  • Assignment and reassignment — which User a record is assigned to, and reallocation actions performed by users who hold the relevant permission.
  • Allocation history — the audit trail of how a record was allocated and re-allocated over time, including the acting user and timestamp.
  • Dataset history — historical dataset rows related to a record, surfaced in the record’s side panel.
  • Stage documents / transaction files — files attached at each stage of the workflow.
  • Interaction history — the log of communication actions taken against a record.

Much of this information relates to third parties (your organization’s customers, leads or dealers) rather than to you. Your organization decides what is collected about those people and is responsible for having a lawful basis and appropriate notices for doing so.

9. Location Information

The W CRM mobile app requests location permission only when a form you are filling contains a location field and you tap the control to capture your position. There is no background location collection, no continuous tracking, and no location history is gathered while the app is in the background or closed.

When you tap to capture a location, the app requests a single high-accuracy position from the operating system and stores the following in that form field as part of your submission: latitude, longitude, accuracy and a timestamp. That value is then submitted to your organization’s workspace along with the rest of the form, and is visible to users in your organization who can see the record.

You can decline the location permission. If you decline, the location field simply cannot be captured; the rest of the application continues to work.

10. Camera and Photos

The app asks for access to your photo library — and, where you choose to take a new picture, your camera — only at the moment you tap an image or file field, or attach an image to a record. The app accesses the specific item you select. It does not scan, index or upload your photo library.

Selected images are uploaded to your organization’s workspace storage and attached to the relevant record or form submission.

11. Files and Documents

You can attach documents to records through file fields and stage document areas, and you can view, download and open documents that others in your workspace have attached. Uploaded files are transmitted over an encrypted connection to our secure file storage and stored against the workspace, along with metadata such as the file name, content type, size, uploading user and upload time. The platform enforces a maximum file size and a configured list of permitted file types.

Files you download or open from the app may be written to your device’s application storage so the operating system can display them.

12. Customer Communication and Interaction History

Where your organization has enabled it, you can act on a record through communication channels. Two different mechanisms are used, and it is worth understanding the difference:

  • Device hand-off. Actions such as placing a phone call open your device’s own dialer, messaging app, WhatsApp or email client with the recipient and, where applicable, a pre-filled message. The call or message itself is placed by that other application, under its own terms and privacy policy. The platform does not place calls and does not record call audio.
  • Server-sent templated messages. Where your organization has configured communication templates, the app can ask our online services to send a message on a channel such as email, SMS or WhatsApp. In that case the recipient address or number, the selected template, and the values merged into the template are sent to our online services, which dispatch the message through the provider your organization has configured.

In both cases the platform records an interaction history entry against the record — the channel used, the recipient, the acting user, timestamps and delivery status where the provider returns one — so that the record shows what contact has been attempted.

Where your organization integrates an external dialer system, call-related events from that system may also be associated with records.

13. Notifications

The mobile app delivers push notifications — such as record assignments, reminders and stage events — through the push notification services operated by Google (on Android) and Apple (on iOS).

To make this work, the app obtains a device registration identifier from that service and registers it with our online services, together with the device platform (iOS or Android) and the application version, so that notifications can be addressed to your device. The identifier is held in protected storage on your device and refreshed when the operating system replaces it. When you sign out, the app removes the registration so the device stops receiving notifications.

Notifications are also surfaced inside the app in a notification centre, where they are listed, marked read and acted upon. Push notifications are optional at the operating-system level: if you deny or disable notification permission, the rest of the application continues to work and in-app notifications remain available.

14. Device and Technical Information

To operate and secure the applications, the platform handles limited technical information, including:

  • Application version and platform (iOS / Android) sent with device registration.
  • Device and operating-system information available to the app, used for compatibility and for troubleshooting.
  • Network connectivity status, used to decide whether to serve cached data or queue work.
  • Standard information present in any request to our services — including IP address, request timing and browser or app identification — as seen by our servers.

15. How We Use Information

Information in the platform is used to:

  • Authenticate you, establish your session, and enforce your workspace, role and permission scope.
  • Deliver the core CRM functionality — workflows, stages, records, dynamic forms, filters, search, assignment and reassignment, allocation history, dataset history, documents and reporting.
  • Send the notifications and reminders your organization has configured.
  • Carry out communication actions you initiate and record the resulting interaction history.
  • Maintain audit trails of who created, changed, allocated or submitted what, and when.
  • Cache data locally so the application remains responsive, and to hold form drafts and queued work.
  • Operate, secure, troubleshoot and improve the platform, including diagnosing errors reported to us.
  • Provide support to your organization, and to comply with legal obligations that apply to us.

We do not use workspace data for advertising, and we do not sell it.

16. How We Share Information

Information is shared only as follows:

  • Within your workspace. Records, submissions, attachments, assignment and allocation history and interaction history are visible to other users of the same workspace according to the roles, permission codes and visibility rules your administrator configures.
  • With your organization. Administrators of the workspace can access workspace data, including data you enter and actions you take.
  • With infrastructure and service providers used to run the platform, as described in section 17.
  • With applications you hand off to when you tap a call, SMS, WhatsApp or email action on your device.
  • Where required by law, or to establish, exercise or defend legal claims, or to protect the rights and safety of users and the public.
  • In a corporate transaction, such as a merger, acquisition or transfer of assets, subject to the terms of the agreement with the affected organization.

17. Third-Party Services

The platform relies on the following third-party services. Which of these are in use for a given deployment depends on how the platform has been configured for your organization.

Third-party services used by the platform
ServicePurposeInformation involved
Identity and access management service operated for the platform Sign-in, session management, roles and permissions Sign-in details, user profile information, session records
Push notification services operated by Google and Apple Delivering notifications to Android and iOS devices Device registration identifier and notification content
Cloud hosting, database and storage providers Hosting the platform, storing workspace records, and storing uploaded files and documents Workspace data, uploaded files and their details
Email service provider, where configured Sending notification and templated emails Recipient address, subject and message content
SMS and WhatsApp messaging providers, where configured by your organization Sending templated messages on those channels Recipient number and message content
Telephony or dialer provider, where integrated by your organization Placing calls and recording call outcomes against records Contact number, call events and outcomes

Scroll the table sideways to see all columns.

The applications do not include any advertising network, marketing tracker, usage-analytics service or third-party crash-reporting service.

18. Organization / Tenant Data

All CRM content in a workspace — records, submissions, documents, allocation and interaction history — belongs to the organization that licenses the platform. Wyzmindz handles that content on the organization’s behalf in order to provide the service.

Because of this, requests about workspace content — access, correction, export, restriction or deletion of a particular record or of a customer’s information — are directed to the organization that controls the workspace. Where we receive such a request directly and the data belongs to a customer workspace, we will refer the request to that organization, unless the law requires otherwise. Any specific written agreement between Wyzmindz and your organization governs where its terms differ from this policy.

19. Data Storage

Workspace data is stored in our online services on managed cloud infrastructure. Records and form submissions are held in workspace-segregated databases, uploaded files and documents are held in secure file storage, and frequently used information may be cached for short periods so the applications stay responsive.

All communication between the applications and our services takes place over encrypted connections.

20. Local Storage on Your Device and Browser

Mobile app

To stay responsive and to tolerate poor connectivity, W CRM stores data on your device:

  • A local store holding cached workflows, records and form settings, unsent form drafts, and a queue of work waiting to be sent.
  • A local cache of lists, lookups and other frequently used information.
  • Protected storage provided by your device’s operating system, holding your session credentials, session details and the notification registration identifier.
  • Cached images and downloaded files in the app’s own storage area.

This local data is removed when you sign out, when the app’s data is cleared, or when the app is uninstalled.

Web application

The web application uses your browser’s own storage to hold your sign-in session and interface preferences. These are strictly functional; the web application does not use advertising or tracking cookies.

21. Logging and Diagnostics

Our services keep operational logs — such as records of requests, errors and scheduled processing — which are used to run, secure and troubleshoot the platform. These logs may contain identifiers such as user, workspace and record identifiers, along with basic technical details of the request. The applications also produce diagnostic messages locally on your device or in your browser. No third-party crash-reporting or usage-analytics service is used.

22. Data Retention

Workspace content is retained for as long as your organization’s workspace remains active, or for the period your organization configures or instructs. Because the platform maintains audit-style histories — stage submissions, allocation history and interaction history — earlier states of a record are retained alongside its current state so the workflow trail stays intact.

Session credentials are short-lived and are replaced or discarded on renewal, expiry or sign-out. Local caches and drafts on your device persist only until sign-out, cache clearing or uninstallation. Operational logs are retained for a limited operational period. On termination of a customer agreement, workspace data is handled in accordance with that agreement.

23. Data Security

Security measures implemented in the platform include:

  • Centralised sign-in through a dedicated identity service, so the application never handles your password directly.
  • Verification of your session on every request, with expired sessions rejected.
  • Workspace segregation, so a request cannot reach another organization’s data.
  • Role and permission checks that gate privileged actions such as reallocation.
  • Encryption of data in transit between the applications and our services.
  • Storage of session credentials in the protected storage area of your device, and an optional biometric app lock on mobile.
  • File type and file size restrictions on uploads.

No system can be guaranteed to be completely secure. We do not claim certification under any specific security or privacy standard in this policy; where an organization requires contractual security commitments, those are addressed in its agreement with us.

24. User Rights

Depending on the laws that apply to you, you may have rights to access, correct, export, restrict or object to the processing of your personal information, or to withdraw a consent you have given.

Within the applications you can already:

  • View and update record data you have permission to edit, and view your own profile information as issued by your organization.
  • Grant or deny location, camera/photo and notification permissions at any time from your device settings, and turn biometric unlock on or off.
  • Sign out, which clears local caches, drafts and stored session credentials on the device and deregisters the device from push notifications.

Because your account and your workspace data are controlled by your organization, please raise rights requests with your organization’s administrator first. You may also contact us at support.crm@wyzmindz.com and, where we act on an organization’s behalf, we will forward your request to it. We may need to verify your identity before acting on a request.

25. Account and Data Deletion

Accounts are created and removed by your organization’s administrator, not by self-service inside the app: there is no public sign-up and no in-app account-deletion control. To have your account disabled or deleted, or to have workspace records deleted, contact your organization’s CRM administrator.

You can remove all locally stored data from your own device at any time by signing out of the app or uninstalling it.

You may also send an account or data deletion request directly to us at support.crm@wyzmindz.com, stating the name of your organization and the account concerned. We will acknowledge the request and, where the data belongs to a customer workspace, act on it together with the organization that controls that workspace. We may need to verify your identity before acting on the request.

When an account is deleted, sign-in access ends and the personal information associated with that account is removed or anonymised, except where information must be retained to complete a transaction, resolve a dispute, or comply with a legal obligation. Records created in the course of the organization’s business remain the organization’s data and are deleted in accordance with its instructions and retention rules.

26. Children’s Privacy

Workspace CRM and W CRM are enterprise tools intended solely for use by adults acting in a professional capacity on behalf of a licensed organization. They are not directed to children, and we do not knowingly collect personal information from children. If you believe a child’s information has been provided to us, contact support.crm@wyzmindz.com so it can be addressed with the organization that controls the workspace.

27. International Data Transfers

The platform runs on cloud infrastructure and managed services, and the region in which a workspace’s data is hosted and processed depends on the deployment configuration agreed with your organization. Some supporting services — for example push notification delivery — necessarily operate across regions. Where information is transferred across borders, it remains subject to this policy and to the agreement between Wyzmindz and your organization. For the hosting region applicable to your workspace, contact your administrator or write to support.crm@wyzmindz.com.

28. Changes to This Privacy Policy

We may update this Privacy Policy as the platform develops or as legal requirements change. The revised policy will be published at this address with a new Effective Date. Where a change is significant, we will make reasonable efforts to notify organizations using the platform. Continued use of the applications after an update takes effect indicates acceptance of the revised policy.

29. Contact Us

For questions about this Privacy Policy or about how the platform handles information:

  • Company: Wyzmindz Solutions Private Limited
  • Product: Workspace CRM  ·  Mobile app: W CRM (com.advaita.workspace)
  • Email: support.crm@wyzmindz.com
  • Registered address: 3rd Floor, Survey # 19/3, Srinivasa Industrial Estate, Opp. METRO Pillar # 127, Kanakapura Main Road, Konanakunte, Bangalore, Karnataka 560062, India

If you use the platform as an employee, agent or contractor of a licensed organization, please contact that organization’s CRM administrator first — they control the workspace and the data held in it.

↑ Back to top