01
Accountability
Role map
Roles depend on who decides purpose and means, who acts on instructions, and what each party actually does. Record the conclusion and its evidence; do not infer it from the vendor label.
- Name owners for CRM, support and shared identity settings.
- Separate account admins, product admins, agents, integration users and temporary vendor access.
- Assess Freshworks and connected services from current agreements and actual flows.
02
Collection surfaces
Collection and notice touchpoints
Walk each entry path as a real user. Save the notice, fields, choices, time and destination rather than relying on a policy page alone.
- Sales forms, imports, agent entry, support email, chat and portal submissions.
- Call notes, ticket replies, attachments and internal comments.
- Marketplace apps, bots, telephony and CRM synchronisation.
03
Purpose discipline
Purpose and data minimisation checks
Every field and copy should have a named operating reason, accountable owner and review event.
- Compare CRM and ticket fields for unnecessary duplication.
- Review attachments, internal notes and conversation transcripts.
- Limit bulk export, broad agent access and inactive contact retention.
04
Choice evidence
Consent and preference evidence
When consent is relied on, preserve the affirmative action and withdrawal path. Where another legal route is assessed, record that analysis instead of manufacturing a consent record.
- Trace collection notices from sales and support entry points.
- Test marketing or messaging preference propagation.
- Do not infer consent from a support interaction.
05
Least privilege
Access control and privileged roles
Test ordinary view, sensitive fields, bulk action, export, configuration and integration access separately.
- Review admins, agents, groups, roles, exports and connected apps.
- Test separation between sales, support and sensitive ticket categories.
- Exercise offboarding and temporary support-access expiry.
06
Lifecycle
Retention, deletion, backup and export behaviour
A delete button is not a lifecycle rule. Record the start event, end event, exception, system action, residual copy and accountable approver.
- Define different events for leads, customers, closed tickets and attachments.
- Test export, deletion, archived tickets and connected copies.
- Record product and plan limitations.
07
Service chain
Processor, sub-processor and contract checks
Use the current contract and actual architecture. A product page cannot establish the complete role allocation for your organisation.
- Retrieve terms, processing terms, location and sub-processor information.
- Inventory marketplace, telephony, bot and sync providers.
- Record assistance, exit, deletion and incident commitments.
08
Detection + response
Logs, monitoring and breach evidence
Coverage, event types, retention and exportability vary. Preserve an evidence timeline without claiming that one log proves the complete event.
- Confirm which configuration changes and user actions appear in available logs.
- Record stated log window and plan dependency.
- Sample export, permission and integration changes.
09
Request workflow
Rights-request search, export, correction and erasure workflow
- 01
Search all Freshworks products by verified identifiers.
- 02
Include tickets, contacts, attachments, notes and synchronised CRM records.
- 03
Review exceptions before action.
- 04
Document downstream and residual results.
10
Bounded configuration
Configuration checklist
Required configuration events are retrievable for the available period.
- Admin path
- Verify in the current admin console
- Evidence to save
- Audit sample, plan and retention note.
Export permission, delivery and disposal are controlled.
- Admin path
- Verify in the current admin console
- Evidence to save
- Test export and custody record.
Vendor or support access is authorised, bounded and reviewed.
- Admin path
- Verify in the current admin console
- Evidence to save
- Approval, expiry and activity review.
No menu-path fiction: open the current vendor documentation and your live console together. Feature names, paths and entitlements can change.
11
Retrievable proof
Evidence to save
Product and workspace map
Role and agent review
Ticket/CRM duplication sample
Connected-app register
Audit and export samples
Rights-request exercise
Save redacted configuration evidence in an approved internal location. This private preview does not accept uploads or store these records.
12
Do not overclaim
Known limitations and questions for the vendor
Known limitations
- Products and plans expose different settings and event coverage.
- Conversation channels and integrations can create copies outside Freshworks.
- Audit documentation may describe configuration events rather than every record action.
Questions to resolve
- Which Freshworks products and plans are active?
- Where are attachments copied?
- Who can bulk export?
- How is vendor support access approved and closed?
13
Traceable record
Official vendor sources, DPDP sources and corrections
Vendor documentation supports configuration questions only. DPDP statements are mapped separately to official Indian sources and phased commencement records.
Official vendor documentation
Official DPDP record
- Act No. 22 of 2023Ministry of Law and Justice, Government of India · checked 2026-09-27 ↗
- G.S.R. 843(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 846(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
- G.S.R. 892(E)Ministry of Electronics and Information Technology, Government of India · checked 2026-09-27 ↗
Reviewed · not counsel-reviewed · educational implementation guidance, not legal advice, certification or a legal conclusion.
Report or inspect a correctionFreshworks and Freshsales are trademarks of Freshworks Inc. They are referenced nominatively; no affiliation or endorsement is implied.