People91

Compliance

How People91 helps your team stay on the right side of India's telecom and data protection rules — and where responsibility stays with you.

Last updated: September 27, 2026

This page explains the compliance-related practices built into People91, and how responsibility is shared between 91Technologies (as the platform provider) and your organization (as the customer using the platform to contact your own leads and customers). It is provided for informational purposes and does not constitute legal advice — your organization remains responsible for its own regulatory compliance.

DND / NDNC (TRAI) Compliance

Under TRAI's Telecom Commercial Communications Customer Preference Regulations, numbers registered on the National Do Not Call (NDNC) registry may not be contacted for commercial communications without valid consent or an applicable exemption. People91's bulk lead import flow checks every number against a DND reference list before it is committed, flags matches so you can exclude or explicitly tag them, and blocks the “log a call” action on DND-tagged leads unless a role authorized by you overrides it.

This scrubbing step reduces the risk of dialing a DND-registered number by mistake, but it does not replace your organization's own obligations — including telemarketer/principal entity registration with the relevant telecom operators, maintaining valid customer consent records, and honoring any consent withdrawal — all of which remain your responsibility as the entity initiating the communication.

Data Protection (DPDP Act, 2023)

We process Customer Data in line with the principles of India's Digital Personal Data Protection Act, 2023: data is collected and processed only for the purpose of providing the Service, access is restricted to what each role genuinely needs, and data is not used for any purpose beyond operating and supporting the Service you have subscribed to. Where your organization is the “Data Fiduciary” for personal data you upload (such as your leads' contact details), People91 acts as your data processor for that data, and you remain responsible for having a lawful basis to collect and process it.

Data Security

We apply the following safeguards across the platform:

  • Dedicated instance per customer — your data is not commingled in shared multi-tenant tables with other customers.
  • Encryption in transit — all traffic to the platform is served over HTTPS/TLS.
  • Password security — account passwords are stored using industry-standard salted hashing, never in plain text.
  • Two-factor login — admin and CRM accounts support one-time-passcode verification at login, with an optional trusted-device period for returning devices.
  • Role-based access control — each team member is assigned one of several defined roles, scoping what they can see and do within the platform.
  • Audit trail — key account and data actions are logged to support internal review.

Third-Party Services

We use a limited set of third-party infrastructure and communication providers (such as cloud hosting and transactional email delivery) strictly to operate the Service — for example, to deliver login one-time passcodes and account notifications. We do not sell Customer Data to third parties, and do not use it for advertising purposes.

Data Retention & Deletion

Customer Data is retained for as long as your subscription is active, so the Service can function as intended. On termination of your subscription, we make Customer Data available for export for a reasonable period, after which it is deleted from active systems in the ordinary course of our data lifecycle practices. Requests for earlier deletion can be sent to hello@people91.com.

Shared Responsibility

In short: 91Technologies is responsible for the security and integrity of the platform, and for providing tooling (DND scrubbing, role-based access, audit trails) that supports your compliance efforts. Your organization remains responsible for the legality of the data you upload, the consent you hold for the people you contact, your telemarketer registrations and obligations under TRAI and other applicable regulations, and how your team members use the access you grant them.

Reporting a Concern

If you believe you have identified a security vulnerability, a data handling issue, or a compliance concern related to People91, please contact us at hello@people91.com and we will respond promptly.

Changes to This Page

We may update this page as our practices, the Service, or applicable regulations evolve. Material changes will be reflected in the “Last updated” date above.