ISO 27001:2022 certified
Our information security management system is certified against the international standard, covering how we build, operate and monitor the platform.
You are trusting us with the pipeline your business runs on. This page sets out how that data is protected, who is accountable for what, and what we will never do with it.

Our information security management system is certified against the international standard, covering how we build, operate and monitor the platform.
Platform data is hosted in India on Amazon Web Services infrastructure. AWS operates that infrastructure as our processor under contract and does not use your data for its own purposes.
Lead and buyer data you bring remains yours. You can export it, and if you leave we delete or de-identify it in line with our Privacy Policy.
We do not sell personal data, and one developer’s data is never shared with another or used for their benefit. There is no shared pool.
Under India’s Digital Personal Data Protection Act, 2023, the roles matter more than the labels. Here is the honest division, the same one written into our agreements.
You are. Under the DPDP Act, the developer is the Data Fiduciary for its buyers and Propfocus acts as a Data Processor, handling that data only on your documented instructions.
No. Buyers reach you through their own enquiry, and consent to contact them is obtained by your team when the lead is generated. We process that data in reliance on your confirmation, as set out in our Terms.
From you. Propfocus never supplies buyer details to developers or to anyone else. Leads arrive from your own enquiries and your connected CRM.
It speaks only within the boundaries you approve during onboarding, identifies itself as your assistant, and hands over to your team when a buyer asks for a human.
The full detail lives in our Privacy Policy and Terms and Conditions. Live platform health is published on the status page.
Practices that sit under our certified management system.
Access to customer data is limited to the people who need it to run the service, and is granted on a least-privilege basis.
Traffic between your team, your systems and Propfocus is encrypted using current transport security standards.
Each customer’s data is isolated. Attempting to reach another customer’s data is prohibited under our Terms and prevented by design.
How the platform is built and operated is reviewed as part of our certified management system, not as an afterthought.
Sub-processors such as our hosting and message delivery providers are contracted so they may only use data to provide services to us.
If something affects your account, your point of contact reaches out directly, and platform status is published publicly.
Running a security review? We are happy to walk your IT team through this directly.
Security questions are welcome before a demo, not just after. Ask us anything about how your data is handled, or read the answers already written up in our FAQ.