1. Overview
WorkVisaCRM is operated by Green Outdoors Global Private Limited ("we", "our", "us"), registered in Vadodara, Gujarat, India. We are committed to protecting the confidentiality, integrity, and availability of all candidate and agency data entrusted to our platform. This Security Policy describes the administrative, technical, and physical safeguards we maintain.
Our security programme is reviewed continuously and is aligned with internationally recognised frameworks including ISO 27001.
2. Infrastructure Security
WorkVisaCRM is hosted on ISO 27001-aligned cloud infrastructure. Key controls include:
- Geographic redundancy across multiple data centres for high availability
- DDoS (Distributed Denial of Service) protection at network and application layers
- Intrusion detection and prevention systems (IDS/IPS)
- Web Application Firewall (WAF) protecting against OWASP Top 10 vulnerabilities
- Network segmentation to isolate sensitive workloads
- Continuous uptime monitoring with automated incident alerting (99.9% uptime SLA)
3. Encryption
All data processed and stored by WorkVisaCRM is protected by strong encryption standards:
- At rest: AES-256 encryption for all stored data, including candidate profiles, documents, and backups
- In transit: TLS 1.3 for all data transmitted between clients and servers, and between internal services
- Backups: All backup data is encrypted with AES-256 before storage
- Encryption keys are managed using industry-standard key management practices and rotated on a defined schedule
4. Access Controls
Access to WorkVisaCRM systems and data is governed by a strict access control framework:
- Role-Based Access Control (RBAC): Users are granted only the access required for their role. Available roles include Administrator, Manager, Recruiter, Visa Officer, and Read-Only
- Principle of Least Privilege: All accounts, human and automated, are provisioned with the minimum access necessary
- Multi-Factor Authentication (MFA): MFA is available for all accounts and is strongly recommended for administrators
- Session Timeouts: Inactive sessions are automatically terminated after a defined idle period
- Password Policy: Minimum length and complexity requirements are enforced on all user accounts
5. Audit Logging
WorkVisaCRM maintains comprehensive audit logs of all user activity. Logged events include:
- User login and logout (including failed attempts)
- Data access — viewing, searching, and exporting candidate records
- Data modification — creating, editing, and deleting records
- Document uploads and downloads
- Administrative actions — user creation, role changes, and permission updates
- API access events
Audit logs are retained for a minimum of 12 months and are tamper-evident. Account administrators may request log extracts by contacting crm@gogpl.in.
6. Vulnerability Management
We maintain a proactive vulnerability management programme that includes:
- Regular automated and manual security assessments, including penetration testing
- Continuous monitoring of security advisories and vendor patch releases
- Critical patches applied within 24–48 hours of release
- A responsible disclosure programme (see Section 11)
- Annual third-party security audits
7. Incident Response
WorkVisaCRM maintains a documented Incident Response Plan:
- A dedicated security response team is available at all times
- In the event of a confirmed personal data breach, we will notify affected Controllers (agency customers) within 72 hours of becoming aware of the breach, in compliance with GDPR Article 33 and applicable Indian data protection law
- Notifications will include: the nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed
- All incidents are documented, reviewed, and used to strengthen security controls
- To report a security incident: crm@gogpl.in
8. Data Backup & Recovery
- Daily automated backups of all customer data
- Point-in-time recovery capability within the retention window
- Backup restoration procedures are tested quarterly for integrity and recovery time
- Backups are stored in geographically separate locations from primary data
- All backup data is encrypted (AES-256) and access-controlled
9. Employee Security
- Security Awareness Training: All employees receive security training at onboarding and annually thereafter
- Background Checks: Background verification is conducted for employees who handle customer data
- Need-to-Know Access: Employee access to customer data is strictly provisioned on need-to-know and revoked promptly on role change or departure
- Confidentiality Obligations: All employees are bound by written confidentiality agreements covering customer data
10. Third-Party Vendors
WorkVisaCRM uses a carefully vetted set of sub-processors. All are required to:
- Demonstrate adequate security controls commensurate with data sensitivity
- Enter into data processing agreements with appropriate security obligations
- Undergo security due diligence before onboarding and periodically thereafter
A current sub-processor list is available on request at crm@gogpl.in.
11. Reporting Security Issues
WorkVisaCRM welcomes responsible disclosure. If you have found a potential vulnerability:
- Email crm@gogpl.in with subject line "Security Report"
- Include a description of the vulnerability and steps to reproduce it
- Allow us reasonable time to investigate before any public disclosure
We do not take legal action against researchers acting in good faith and following responsible disclosure principles.
12. Contact
Green Outdoors Global Private Limited
Email: crm@gogpl.in
Vadodara, Gujarat, India
Legal Disclaimer: This document is provided for informational purposes only and does not constitute legal advice. WorkVisaCRM recommends that you consult a licensed legal professional for advice specific to your jurisdiction and circumstances before relying on this document.