Legal document
Privacy Policy
How COSQ Network handles WorqNET personal data.
1. Who we are and what this policy covers
COSQ Network Private Limited (“COSQ Network”, “we”, “us”, or “our”) operates WorqNET, a work and project management platform. WorqNET supports organization administration, project and work-item tracking, documents and attachments, CRM, collaboration, people and leave management, payroll-related workflows, reporting, calendar connections, email notifications, SaaS billing, and separately licensed on-premise deployments.
This Privacy Policy explains how we collect, use, disclose, retain, secure, and otherwise process personal data when you visit our public pages, create or use a WorqNET account, use a customer organization, contact support or sales, use our SaaS services, or interact with our billing and communication systems. It applies to personal data processed by COSQ Network directly. It does not replace a customer’s own employee, applicant, customer, or user privacy notice.
“Personal data” includes information that identifies or can reasonably be linked to an individual. “Process” and “processing” include collecting, storing, using, sharing, analyzing, securing, and deleting information.
2. Our role: business account data and customer content
For account, support, sales, billing, security, and website operations, COSQ Network generally determines why and how personal data is processed and acts as a controller or “Data Fiduciary”, subject to the terminology and obligations of the applicable law.
For personal data that a business customer places into its WorqNET organization—such as employee, contractor, customer, prospect, project-member, contact, payroll, leave, document, or collaboration information—the customer generally determines the purposes and means of processing. COSQ Network processes that customer content on the customer’s documented instructions as a service provider, processor, or “Data Processor”, as applicable. The customer remains responsible for providing appropriate notices, obtaining permissions or consents where required, responding to its people’s requests, and configuring the service lawfully.
Where a customer requires processor terms, the Data Processing Agreement applies where signed or otherwise incorporated into the applicable order or contract. If this policy conflicts with a negotiated agreement, the negotiated agreement controls for that customer’s contracted processing.
3. Personal data we may collect
3.1 Account and identity data
We may collect your name, email address, phone number, password-derived authentication data, email-confirmation status, profile photo, job title, organization membership, roles, permissions, and sign-in or account-recovery information. Passwords are not stored as readable text.
3.2 Organization and business data
Organizations may provide legal name, address, country, business type, registration or tax identifiers, branches, billing contacts, users, roles, subscription details, and configuration data. Customers should not place special-category, highly sensitive, or regulated information into fields that do not require it.
3.3 Product content
Depending on the features used, WorqNET may process project names and descriptions, work items, comments, dependencies, attachments, documents, versions, time logs, CRM contacts and campaigns, leave and people records, payroll-related information, reports, calendar events, social-account connection metadata, and other content submitted by an organization or its users. A customer controls the content it chooses to upload and must ensure it has a lawful basis and appropriate notices for that content.
3.4 Billing and transaction data
We process subscription, plan, country, currency, invoice, tax, payment-status, order, refund, and billing-contact information. Online SaaS payments are processed through Cashfree where enabled. We do not intend to store payment-card credentials in WorqNET; payment credentials are handled by the payment provider under its terms and privacy notice. We may receive provider references, masked details, payment status, transaction events, and webhook data needed to reconcile billing, prevent fraud, provide support, and issue invoices or credit notes.
3.5 Device, log, and security data
We may collect IP address, user-agent, device and browser information, approximate request time, route or page accessed, authentication events, failed-login information, session identifiers, error information, and security or audit records. This information is used for authentication, abuse prevention, troubleshooting, tenant security, auditability, and service reliability. We do not use IP-based geolocation to select pricing.
3.6 Cookies and local storage
WorqNET uses necessary cookies and similar storage for authentication, security, session continuity, preferences, and application operation. The public pricing page may store the explicitly selected billing country in the worqnet-pricing-country cookie; the URL query parameter takes precedence over that cookie. Optional browser local storage may be used for client-side convenience. We do not silently infer a pricing country from IP address.
Before introducing non-essential analytics, advertising, personalization, or tracking technologies, we will assess whether consent, notice, opt-out, or other controls are required and will update this policy and the relevant consent experience. Browser settings may block cookies, but doing so can affect sign-in and service functionality.
3.7 Information from third parties
We may receive information from an organization administrator, an identity provider such as Google, Microsoft, or another configured OpenID Connect provider, Cashfree, email providers, calendar or social integrations, fraud/security services, and other vendors used by the customer or by us. We use that information consistently with the integration’s authorization flow and this policy.
4. Why we process personal data
- To create and secure accounts, authenticate users, confirm email addresses, reset passwords, manage sessions, and enforce organization and project permissions.
- To provide, maintain, troubleshoot, personalize, and improve the WorqNET features requested by the customer.
- To store, retrieve, synchronize, and transmit customer content at the customer’s direction.
- To send transactional messages such as invitations, confirmations, security alerts, password-reset messages, service notices, invoices, and billing notifications.
- To process subscriptions, payments, renewals, cancellations, refunds, tax calculations, invoices, credit notes, fraud checks, and accounting records.
- To monitor availability, diagnose errors, prevent abuse, investigate security incidents, enforce our agreements, and protect users, customers, COSQ Network, and the public.
- To respond to sales, support, privacy, legal, and data-subject requests.
- To comply with applicable law, court orders, tax and accounting duties, lawful government requests, and regulatory obligations.
- To send product or commercial communications where permitted. You can use the unsubscribe mechanism in marketing messages; service and security communications may still be sent where necessary.
We do not sell personal data. We do not use customer content to build advertising profiles. We will not use customer content for unrelated purposes merely because it is available to us.
5. Legal bases and India’s DPDP framework
For processing subject to the Digital Personal Data Protection Act, 2023 (“DPDP Act”), COSQ Network will process personal data according to the applicable notice, consent, legitimate permitted purpose, contract, legal requirement, and other grounds recognized by the DPDP Act and rules in force. Where consent is the basis, it should be specific, informed, and capable of withdrawal through a reasonably accessible method, subject to lawful consequences of withdrawal.
We intend to apply the DPDP principles of purpose limitation, data minimization, accuracy, security safeguards, retention limitation, accountability, and grievance handling. Data Principals may have rights to access information about personal data and processing, correction and erasure where applicable, grievance redressal, withdrawal of consent, and nomination, subject to the Act, rules, exemptions, identity verification, contractual arrangements, and other applicable limits. Requests may be sent to privacy@worqnet.com.
We will publish or update operational details such as the designated grievance contact, response process, and any Data Protection Officer or equivalent contact when confirmed for the relevant processing and notified under applicable law. The DPDP Act and the Digital Personal Data Protection Rules, 2025 are available from the Ministry of Electronics and Information Technology.
6. GDPR and other international privacy laws
Where the General Data Protection Regulation (EU) 2016/679 (“GDPR”) applies—for example, because processing falls within its territorial scope—we will address the relevant controller or processor obligations. Depending on the facts and the processing purpose, our lawful bases may include performance of a contract, compliance with a legal obligation, consent, protection of vital interests, or legitimate interests that are not overridden by an individual’s rights and freedoms.
Subject to applicable conditions and exemptions, individuals in relevant jurisdictions may request access, correction, deletion, restriction, portability, or object to processing, and may withdraw consent where consent is the basis. Individuals may also object to direct marketing. Requests should be sent to privacy@worqnet.com; we may request information needed to verify identity and authority.
Individuals may complain to the supervisory authority in the country or EU/EEA Member State where they live, work, or believe an infringement occurred. The GDPR does not apply identically to every user or processing activity, and this policy does not promise a particular territorial status. The official text is available on EUR-Lex.
7. Disclosure and service providers
We disclose personal data only as needed for the purposes described here, the customer’s instructions, a contract, or applicable law. Categories of recipients may include:
- Infrastructure and hosting providers supporting application, PostgreSQL database, backups, monitoring, logging, caching, storage, and disaster recovery.
- Cashfree and related financial, payment, fraud, tax, and accounting providers for SaaS transactions and billing events.
- SMTP and communications providers for transactional email, invitations, password resets, notifications, and approved campaigns.
- Google, Microsoft, or another configured identity, calendar, or collaboration provider when an authorized user connects an integration.
- Professional advisers, auditors, insurers, legal counsel, regulators, courts, law enforcement, or prospective transaction parties when reasonably necessary and lawful.
- Other subprocessors approved under a customer contract or DPA.
Providers are expected to receive only the information necessary for their service and to provide confidentiality and security commitments appropriate to the processing. A current subprocessor list and notice process should be maintained for production SaaS operations; customers may contact privacy@worqnet.com for the applicable list or contractual process.
8. International transfers
WorqNET is intended for India and international SaaS customers. Personal data may be processed in India or another country where COSQ Network or an approved provider operates. Before a transfer subject to a law with cross-border requirements, COSQ Network will assess the applicable restriction and use the required mechanism, safeguards, contractual terms, adequacy decision, consent, or other lawful basis. Customers remain responsible for confirming that their instructions and notices cover the locations and integrations they enable.
9. Retention and deletion
We retain personal data only for as long as reasonably necessary for the purpose collected, the customer’s instructions, the account or subscription relationship, security and audit needs, dispute resolution, backups, and legal, tax, accounting, or regulatory obligations. Retention periods depend on the data type and context; there is no single period for all WorqNET data.
When an organization closes an account or requests deletion, we will delete, anonymize, or return customer content according to the applicable order, DPA, customer instructions, backup cycle, and law. Some records may be retained in restricted form to comply with legal obligations, prevent fraud, establish or defend claims, maintain security records, or document transactions. Deleted data may remain temporarily in encrypted backups until the normal backup expiry or overwrite cycle.
10. Security
We use administrative, technical, and physical safeguards appropriate to the risk and the nature of the information. Depending on the deployment and feature, safeguards include TLS in transit, protected credentials and secrets, hashed passwords and refresh tokens, role and tenant authorization, fail-closed tenant isolation, login lockout, upload validation, audit logging with sensitive-value redaction, restricted production containers, backups, monitoring, and incident-response procedures.
No internet service is risk-free. Customers must use strong unique credentials, limit administrator access, configure integrations carefully, avoid uploading unnecessary sensitive data, and promptly report suspected compromise to security@worqnet.com. We will assess and handle suspected personal-data incidents under the notification and cooperation duties applicable to the relevant role and law.
11. Children
WorqNET is a business service and is not directed to children. Customers must not invite or use the service to process children’s personal data unless they have a lawful basis, required notices, permissions, safeguards, and documented instructions. If you believe a child’s data was provided improperly, contact privacy@worqnet.com.
12. Your choices and how to make a request
To exercise a privacy right, ask a question, withdraw consent, request correction or deletion, or report an issue, email privacy@worqnet.com with “Privacy Request” in the subject. Account users should include the organization name, account email, request type, and enough detail to locate the relevant data. Do not send passwords, payment credentials, or unnecessary sensitive information.
We may verify identity, authority, residency, and the relationship to the organization before responding. If you are a member of a customer organization, the customer may be the appropriate first contact because it controls the relevant content. We will assist the customer where our contract requires it. We aim to respond within the period required by applicable law and will explain any lawful delay, refusal, limitation, or fee.
13. Complaints and grievance redressal
Privacy complaints should first be sent to privacy@worqnet.com. Billing complaints may be sent to billing@worqnet.com, and security reports to security@worqnet.com. We will acknowledge and investigate complaints using the process and timeframe required by the applicable law, contract, and operational policy. External regulator or supervisory-authority escalation remains available where provided by law.
14. On-premise deployments
On-premise WorqNET deployments are separately licensed and may be operated on infrastructure controlled by the customer. The customer is generally responsible for its deployment security, administrators, users, network, backups, integrations, retention, notices, and legal compliance. COSQ Network may still process data when providing support, updates, professional services, license administration, or an enabled external integration. The applicable license, support agreement, DPA, and customer configuration determine those responsibilities.
15. Changes to this policy
We may update this policy when the service, law, vendors, or processing practices change. We will update the version and date above and, where required, provide additional notice or obtain consent. Material changes for customers should be communicated through the applicable account, contract, or service channel. The effective version should be retained with relevant billing or contractual records where required.
16. Contact details
COSQ Network Private Limited
Operator of WorqNET
Privacy: privacy@worqnet.com
Billing: billing@worqnet.com
Security: security@worqnet.com
Sales and support: sales@worqnet.com
Registered business address, GSTIN, and any formally designated statutory privacy contact should be inserted after confirmation by the company and legal advisers. Do not publish placeholder details.
See also: Terms of Service, Data Processing Agreement, Pricing Policy, and Refund Policy.