Data processing agreement

For a customer who needs the processing terms in writing, separately from the privacy policy.

This document is not written yet, and nothing on it is in force.

The headings below are the shape it will take. Each one says what it needs before it can be published. It is not indexed by search engines while it says this.

1. What this covers, and what it sits under

Copy owed. Nothing here is written yet.

  • Whether this is incorporated into the terms of service or signed separately, and how a customer executes it.
  • The registered legal name of the company.
  • Which laws it is written against: the DPDP Act 2023, and the GDPR if there will be customers in the EU.

2. Roles

Copy owed. Nothing here is written yet.

  • Who is controller and who is processor for each kind of data. A customer own team, and that customer own customers, may not have the same answer.
  • The words used: the DPDP Act says data fiduciary and data processor rather than controller and processor.

3. What we process, and why

The categories the product actually holds: people at the customer and their contact details, the customer own customers and suppliers as the accounting system returns them, WhatsApp messages and the phone numbers they came from, files sent in for reading, and the audit trail of who did what.

Copy owed. Nothing here is written yet.

  • The list as the agreement states it, including anything above that should not be there.
  • The instruction: that we process only to provide the service and as the customer directs.
  • How long processing lasts, tied to the subscription.

4. Sub-processors

What the code talks to today: Meta for WhatsApp, Razorpay for payments, OpenAI for the AI tasks, Resend for email, and the hosting for the servers, the database and the queue. Zoho and QuickBooks are connected by the customer own authorisation rather than by us.

Copy owed. Nothing here is written yet.

  • The list to publish, each with what it receives and which country it is in. This has to be confirmed by somebody who knows the accounts, not taken from imports.
  • How a customer is told before one changes, and whether they may object.
  • Whether the hosting provider and region are named in the document.

5. Security measures

The security page is the factual starting point, and every claim on it points at a file or a decision record. What a contract warrants is a separate decision from what is true.

Copy owed. Nothing here is written yet.

  • The annex of measures, and which of them are warranted rather than described.
  • Backups: how often, kept how long, and whether a restore has been tested.
  • Who at our end can reach production data, and under what procedure.

6. Telling a customer when something goes wrong

Copy owed. Nothing here is written yet.

  • The notification window, in hours, and what the notice contains.
  • Who we tell besides the customer, and whether a regulator is named.
  • What help we give the customer with their own notification duties.

7. Helping with the rights of the people in the data

Copy owed. Nothing here is written yet.

  • What we do when a customer forwards a request: access, correction, erasure.
  • How long we take, and whether it is charged for.

8. Audits and evidence

Copy owed. Nothing here is written yet.

  • What a customer may ask for: a questionnaire, a report, an audit, and how often.
  • Whether any certification is claimed. None is claimed today.

9. Transfers outside the country

Copy owed. Nothing here is written yet.

  • The position, given that at least the AI provider and WhatsApp process outside India.
  • The mechanism relied on, and whether standard contractual clauses are attached.

10. When a customer leaves

Copy owed. Nothing here is written yet.

  • Return or deletion, which one is the default, and how soon.
  • What we keep anyway, and why. The audit trail is kept for eight years because books of account must be, and that has to be stated rather than discovered.

11. Contact

Copy owed. Nothing here is written yet.

  • Who a customer compliance team writes to.
  • The Grievance Officer named under the DPDP Act, if that is who it is.