Privacy Policy

PRIVACY POLICY

PRIVACY POLICY FOR THE WYU APP

Effective Date: 1st August, 2026

Last Updated: 1st August, 2026

Labecon Innovations Private Limited (hereinafter referred to as "the Company", "We", "Us", or "Our") operates the Wyu mobile application (the "Platform"). We operate as a Data Fiduciary under India's Digital Personal Data Protection (DPDP) Act, 2023. This Privacy Policy explains how we collect, process, store, archive, protect, and delete the personal data of security professionals, guards, and contractors (the "Data Principals", "Users", or "You") who register and utilize our platform.

Effective Date: 1st August, 2026
Last Updated: 24th August, 2026

1. Information We Collect and Process

To provide vertical SaaS workforce management tools, verified identity protocols, and operational utility features, we collect several categories of personal data. The specific data processed depends on your interaction with the Platform:

Identity Verification & Demographic Data (Onboarding):

  • Government Identity Records: Full legal name, gender, date of birth, contact number, parent/guardian name, postal code, and demographic address records obtained via authorized third-party verification partners, including Perfios Software Solutions Private Limited, which acts as our identity-verification processor under a data-processing agreement.
  • Identifier Safeguards: We do not permanently store or display raw, unmasked government identity numbers in our production environments. Only masked representations, secure verification request tokens, and cryptographic validation logs are retained for legal audit trails.
  • Permanent Profile Lock: Your verified legal name is extracted directly from official identity records and permanently locked to your user profile to prevent identity fraud, impersonation, or unauthorized profile transfers.
  • Tax & Clearance Records: Permanent Account Number (PAN) details—including holder name, verification match status, and linked address data—are processed to confirm deployment readiness and legal compliance.

Device Permissions & Automated Operational Data (Telemetry):

  • Precise Location Tracking (Duty Telemetry): We collect your precise geographical coordinates, accuracy parameters, movement indicators, and operational status flags. This tracking occurs exclusively during the active duration of an assigned shift or active-duty status.
  • Device Integrity & Security Logs: We capture automated technical parameters including session identifiers, login timestamps, activity logs, and fraud prevention flags (such as automated checks for mocked or manipulated location data).

Private Encrypted Communications (WYU Chat):

  • Zero-Knowledge Messaging Architecture: The Platform provides an in-app messaging utility enabling direct and group communications between security personnel and contractors.
  • End-to-End Encryption (E2E): All text content, media attachments, and image payloads transmitted via private chat are cryptographically encrypted client-side prior to server transmission. We store solely encrypted ciphertext and structural message delivery statuses. The Company does not hold or possess the decryption keys required to view your private communications.

Public User-Generated Content & Social Interaction Data:

  • Micro-Posts & Media Uploads: Short-form text broadcasts (up to 400 characters), along with photos or media assets published voluntarily to the public feed.
  • Social Graph & Interactions: Records of posts you interact with, comment threads, timestamps, follower relationships, and outbound content sharing activity.

Workforce Sourcing & Marketplace Visibility Data

Where you indicate on the Platform that you are open to work, we display certain elements of your profile — such as your name, verified status, role/experience information, and relevant demographic details (e.g., age, height, weight, where relevant to physical security role requirements) — to businesses and security agencies using Wyu Ops, so that they may search for and invite you to a site or engagement. This visibility is controlled by your open-to-work status, which you may enable or disable at any time in your account settings.

Worker Details Book — Extended KYC, Financial & Statutory Compliance Data

Optionality: Completing your Worker Details Book is entirely optional and is never required to register on the platform, browse listings, or submit Applications. Businesses may, independently and as part of their own hiring practices, request or require some or all of this information before proceeding with your candidacy; this is a decision made by that business, not a condition imposed by us. You may decline to provide any field, though doing so may affect which businesses are willing to engage you.

What We Collect: If you choose to complete your Worker Details Book, you may voluntarily provide: (i) identity and banking information (ID proof type and number, PAN, bank account number, bank name, account type, IFSC code, UAN, ESIC number, and, where applicable, arms/gun licence number); (ii) personal information (religion, marital status, and education); (iii) address information (temporary address and PIN code); (iv) experience information (past employer and experience); and (v) emergency contact and reference information (name and phone number of an emergency contact and up to two personal references). This information supports statutory obligations connected to your deployment — including verification requirements under the Private Security Agencies (Regulation) Act, 2005, wage disbursement under the Payment of Wages Act, and social security contributions under the EPF Act, 1952 and ESI Act, 1948 — and is shared with a business only once that business has accepted or hired you. Aadhaar verification is handled separately, as described elsewhere in this Policy, and is not part of the Worker Details Book.

Emergency Contact & Reference Data: When you provide another person’s name and phone number as an emergency contact or reference, you confirm you have that person’s permission to share their details with us and, upon your deployment, with the relevant business. We do not independently verify that permission was obtained.

Retention: Where the Worker Details Book contains data relevant to statutory recordkeeping (tax, provident fund, or ESI records), we may retain that data for the minimum period required by law, even after a deletion request.

Security: Worker Details Book data, including financial and statutory information, is encrypted at rest using industry-standard encryption, with keys managed through a secure key-management system separate from the underlying data.

2. Legitimate Purposes & Legal Grounds for Processing

We process your personal data under the strict boundaries of contractual necessity, explicit consent, and Legitimate Uses as prescribed by regional regulations (including the DPDP Act, 2023). Where you are engaged as our direct employee or are otherwise directly deployed by the Company, identity verification and deployment-clearance processing is carried out in reliance on the "employment purposes" legitimate-use ground set out under Section 7(i) of the DPDP Act, 2023, and does not require your separate consent under Section 6 of the Act. Where you are engaged as an independent contractor, or as a guard or workforce personnel deployed through a third-party security agency or business client that is not your direct employer, processing of your personal data is instead carried out on the basis of contractual necessity (to perform and administer your duty assignments on the Platform) and your clear affirmative consent, captured at the point of onboarding. Where we process any personal data on the basis of your consent, that consent will be captured through a clear affirmative action at the point of collection, and you may withdraw it at any time as described in Section 6 of this Policy.

  • Identity Enforcement: Processing verification data is required to establish accountability, prevent impersonation, and confirm legal clearance for private security deployments.
  • Operational Validation: Tracking precise location logs is fundamentally required to verify duty attendance, confirm guard presence at high-security deployment sites, and validate shift fulfillment to enterprise clients.
  • Fraud Mitigation: Monitoring device integrity flags (such as mocked location attempts) safeguards platform integrity against malicious manipulation.
  • Workforce Sourcing: Displaying your open-to-work profile to businesses seeking workforce personnel fulfils the core purpose of the Platform as a job marketplace. This is carried out on the basis of your affirmative action in setting your status to open-to-work, which constitutes your consent for this specific, expected purpose, and which you may withdraw at any time by changing your status as described in Section 6.
  • Religious Deployment Matching: Certain deployment sites and events — such as religious institutions or religious processions — have a bona fide requirement that assigned personnel share the religion associated with that site. Where you choose to provide your religion, we use it solely to match you to such opportunities, on the basis of your explicit consent, which you may withdraw at any time.

3. Location Tracking & Background Access Disclosures

PROMINENT LOCATION DISCLOSURE

The Platform requires continuous access to your device’s precise location services, including background location permissions, to accurately document shift fulfillment, enforce site safety protocols, and log guard presence at assigned zones.

  • Active Duty Windows Only: Automated location tracking is active only during designated shift windows or when you are actively checked in for duty.
  • No Passive Off-Duty Tracking: We do not engage in background location tracking or capture passive location logs outside your official duty timelines.

4. Data Storage, Sovereignty, and Security

  • Local Infrastructure: In compliance with India's data residency frameworks and data sovereignty standards, all user profiles, databases, and binary media assets are hosted exclusively within Microsoft Azure Cloud Data Centers located physically inside India.
  • Data Security Standards: All data streams are isolated using commercial encryption protocols both at rest in storage volumes and in transit across public networks.
  • Personal Data Breach Notification: In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in the form and manner required under the DPDP Act, 2023, and its implementing rules, without undue delay, describing the nature of the breach, its likely consequences, and the measures taken or proposed to mitigate its effects.
  • Third-Party Service Providers: We share limited categories of data with third-party service providers strictly on a need-to-know basis for operational purposes, including: identity-verification vendors (such as Perfios Software Solutions) for KYC checks; cloud hosting providers (Microsoft Azure) for data storage; and SMS, email, or other communication gateways for OTP and notification delivery. These providers are contractually bound to process data solely on our instructions and for the stated purpose, and are prohibited from using it for their own independent purposes.

5. Data Retention, Archiving, and Deletion Lifecycle

We enforce strict data minimization practices. Personal data is systematically destroyed or anonymized once its core operational purpose finishes:

  • Location Telemetry Lifecycle: Coordinate data and associated duty telemetry generated during an active shift are stored within our production systems and operational archive tier for a period of 365 days (1 year) from the date of the shift.
  • Purpose of Archiving Window: This retention extension is maintained to protect platform integrity, satisfy client service-level obligations, and provide an official audit trail to cooperate with law enforcement or security investigations in the event of site incidents or unauthorized absences. The 365-day (1-year) duration is calibrated to the typical lifecycle of a security services engagement: enterprise security contracts are generally reviewed, audited, or renewed on an annual cycle, and client-side incident escalations, guard-conduct disputes, or billing reconciliations arising from a shift are ordinarily raised and investigated within that same annual window. Retaining duty telemetry for the full contract-review period ensures the data required to resolve such disputes or audits remains available for as long as it is reasonably likely to be needed, consistent with the data minimization principle under the DPDP Act, 2023.
  • Identity Verification Data Retention: Verification request tokens, cryptographic validation logs, and the masked verification responses received from our identity-verification partner (as described in Section 1(a)(ii)) are retained for a period of seven (7) years from the date of verification, to satisfy statutory audit, deployment-clearance, and legal-compliance obligations applicable to the private security industry, after which such records are automatically deleted or irreversibly anonymised, unless a longer period is required by applicable law or an active Legal Hold.
  • Automated Erasure & Legal Holds: Upon the conclusion of this 365-day (1-year) cycle, location telemetry is automatically purged or irreversibly anonymised. The sole exception occurs if a specific shift, guard profile, or enterprise workspace is flagged under an active corporate dispute, labor audit, or regulatory inquiry ("Legal Hold"), freezing that specific data slice until the investigation closes.
  • Account Deletion Mandate: Users may request account deletion within the app profile settings or via our web portal. Upon a valid request, your active identity profile and social footprint will be deactivated. However, transactional shift telemetry and duty audit records, including corresponding location data, will be securely retained in our archive tier until the expiration of the standard 365-day retention window, to satisfy operational compliance and client audit obligations, after which erasure is fully completed.

6. Rights of the Data Principal

In compliance with India's Digital Personal Data Protection (DPDP) Act, 2023, users may exercise the following rights by contacting our Privacy Desk. We will acknowledge your request within 24–48 hours and endeavor to resolve it within 15 days, or such other period as required under applicable law:

  • Right to Access & Summary: You have a right to request a summary of the personal data we hold and our processing activities.
  • Right to Correction: You may update editable contact details. However, core verified identity fields (such as your legally verified name) cannot be altered without completing a new identity re-verification process.
  • Right to Erasure: You may request the deletion of non-essential personal information, subject to our statutory and security archiving windows.
  • Right to Grievance Redressal: You have a right to register formal operational complaints regarding our data handling routines.
  • Right to Withdraw Consent: Where we process your personal data on the basis of your consent, you may withdraw that consent at any time by contacting our Privacy Desk, with the same ease with which it was given. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal, does not extend to data processed under a Legitimate Use ground (such as the identity-verification processing described in Section 2(a)), and may affect your ability to continue using certain features of the Platform.
  • Right to Escalate to the Data Protection Board: If you are dissatisfied with the resolution provided by our Privacy Desk, or do not receive a response within a reasonable time, you have the right to file a complaint with the Data Protection Board of India, constituted under the DPDP Act, 2023.
  • Right to Nominate: You may nominate another individual who may exercise your rights under this Section in the event of your death or incapacity, by submitting a nomination request to our Privacy Desk.

7. Age Restrictions & Age-Gating

The Platform is engineered strictly for adult professionals executing specialized security and workforce operations. We do not knowingly collect, analyze, or accept account registrations from individuals under eighteen (18) years of age. If we identify that a minor's profile has bypassed identity checks, the record will be erased immediately.

8. Contact Information & Privacy Desk

For data rights inquiries, privacy policy questions, or to engage with our privacy framework, please reach out to our representative:

  • Designated Privacy Officer: Parth Gupta, Founding Engineer
  • Official Corporate Address: 60, Anurag Nagar, Part-2, Ring Road, Indore, Madhya Pradesh 452010, India.
  • Dedicated Privacy Contact Email: grievance@wyu.work
  • Resolution Timeframe: We will acknowledge grievances within 24–48 hours of receipt and endeavor to resolve them within 45 days, or such other period as required under applicable law.
    Wyu | भारत का सर्वोच्च सुरक्षा कर्मी प्लेटफ़ॉर्म