Security & Trust

Your buyers’ data, handled properly

You are trusting us with the pipeline your business runs on. This page sets out how that data is protected, who is accountable for what, and what we will never do with it.

ISO 27001:2022 certified
The essentials

Four things worth knowing first

ISO 27001:2022 certified

Our information security management system is certified against the international standard, covering how we build, operate and monitor the platform.

Hosted on AWS

Platform data is hosted in India on Amazon Web Services infrastructure. AWS operates that infrastructure as our processor under contract and does not use your data for its own purposes.

Your data stays yours

Lead and buyer data you bring remains yours. You can export it, and if you leave we delete or de-identify it in line with our Privacy Policy.

Never sold, never pooled

We do not sell personal data, and one developer’s data is never shared with another or used for their benefit. There is no shared pool.

Accountability

Who is responsible for what

Under India’s Digital Personal Data Protection Act, 2023, the roles matter more than the labels. Here is the honest division, the same one written into our agreements.

Who is accountable for buyer data?

You are. Under the DPDP Act, the developer is the Data Fiduciary for its buyers and Propfocus acts as a Data Processor, handling that data only on your documented instructions.

Does Propfocus collect buyer consent?

No. Buyers reach you through their own enquiry, and consent to contact them is obtained by your team when the lead is generated. We process that data in reliance on your confirmation, as set out in our Terms.

Where do buyer details come from?

From you. Propfocus never supplies buyer details to developers or to anyone else. Leads arrive from your own enquiries and your connected CRM.

What about the RNR Agent messaging our buyers?

It speaks only within the boundaries you approve during onboarding, identifies itself as your assistant, and hands over to your team when a buyer asks for a human.

The full detail lives in our Privacy Policy and Terms and Conditions. Live platform health is published on the status page.

Controls

How the platform is operated

Practices that sit under our certified management system.

Access control

Access to customer data is limited to the people who need it to run the service, and is granted on a least-privilege basis.

Encryption in transit

Traffic between your team, your systems and Propfocus is encrypted using current transport security standards.

Separation between customers

Each customer’s data is isolated. Attempting to reach another customer’s data is prohibited under our Terms and prevented by design.

Security review of changes

How the platform is built and operated is reviewed as part of our certified management system, not as an afterthought.

Vendor management

Sub-processors such as our hosting and message delivery providers are contracted so they may only use data to provide services to us.

Incident communication

If something affects your account, your point of contact reaches out directly, and platform status is published publicly.

Commitments

What we will never do

  • Sell your data, or any personal data, to anyone.
  • Share one developer’s buyer data with another developer.
  • Use your buyer or lead data for our own advertising.
  • Contact your buyers outside the boundaries you approve.
  • Hold your data hostage. You can export it, and it is deleted or de-identified when you leave.

Running a security review? We are happy to walk your IT team through this directly.

Still have questions?

Security questions are welcome before a demo, not just after. Ask us anything about how your data is handled, or read the answers already written up in our FAQ.

Read the FAQ