Data Processing Agreement

dpa-v1.0  •  Aptus Software Labs
Back to Privacy Notice

This Data Processing Agreement ("Agreement") forms part of the Subscription Agreement between the Data Fiduciary and Aptus Software Labs Pvt Ltd and governs the processing of personal data by Aptus on behalf of the Data Fiduciary in connection with the DPDP Readiness Platform ("Platform"). It is effective from the date the Data Fiduciary accepted the Subscription Agreement.

1. Parties
  • Data Fiduciary: The organisation whose authorised representative accepted this Agreement at registration. The Data Fiduciary determines the purposes and means of processing the personal data entered into the Platform.
  • Data Processor (Aptus): Aptus Software Labs Pvt Ltd, a company incorporated under the Companies Act, 2013, having its registered office at Bangalore, Karnataka, India. Contact: [email protected]
2. Subject Matter and Nature of Processing

Aptus provides a DPDP Act, 2023 compliance self-assessment platform. In delivering the Platform, Aptus may process the following categories of personal data entered by the Data Fiduciary:

  • Names, work email addresses, job titles of the Data Fiduciary's staff who use the Platform.
  • Assessment responses, free-text notes, and evidence references that may refer to identified or identifiable natural persons (employees, customers, or vendors of the Data Fiduciary).
  • Technical log data (IP addresses, session identifiers) generated during Platform use.

Processing activities include: storage, retrieval, display, export to PDF, and deletion. Aptus acts solely as a Data Processor and does not determine the purposes or means of processing the personal data contained in assessment notes.

3. Processing Instructions

3.1 Aptus shall process personal data only on documented instructions from the Data Fiduciary. This Agreement, together with the Data Fiduciary's in-Platform configuration, constitutes those instructions.

3.2 Aptus shall immediately inform the Data Fiduciary if, in its reasonable opinion, any instruction violates the DPDP Act, 2023 or any other applicable Indian law, without being obliged to carry out that instruction until the Data Fiduciary confirms or amends it.

3.3 Aptus shall not:

  • Use personal data for its own commercial purposes, including training machine-learning models, building datasets, or cross-customer analytics.
  • Disclose personal data to any third party except approved Sub-Processors (Clause 6) or as required by a court order or statutory authority, in which case Aptus will notify the Data Fiduciary to the extent permitted by law.
4. Confidentiality

4.1 Aptus shall ensure that all personnel authorised to process personal data are bound by enforceable confidentiality obligations and receive appropriate data-protection training.

4.2 Access to personal data is granted on a need-to-know basis only. Aptus maintains a register of personnel with access rights, reviewed at least annually.

4.3 Confidentiality obligations survive termination of this Agreement for a period of three (3) years, except where Aptus is required by law to retain or disclose the information.

5. Security Measures

Aptus implements the following technical and organisational security measures in compliance with Section 8(5) of the DPDP Act, 2023:

MeasureImplementation
Encryption in transitTLS 1.2 or higher on all external connections
Encryption at restAES-256 for database volumes and backups
AuthenticationPasswords stored as PBKDF2-SHA256 with unique per-user salt; MFA available for admin accounts
Access controlRole-based access; principle of least privilege; access reviews quarterly
Patch managementCritical CVEs remediated within 30 days of disclosure
Logging & monitoringApplication and access logs retained for 90 days; anomaly alerts configured
Backup & recoveryDaily encrypted backups; recovery tested at least annually
Security reviewAnnual vulnerability assessment or penetration test by an independent party

Aptus will review and update these measures in response to material changes in threat landscape or platform architecture.

6. Sub-Processors

6.1 The Data Fiduciary grants general written authorisation to engage the sub-processors listed below. Aptus shall impose equivalent data-protection obligations on each Sub-Processor.

Sub-ProcessorPurposeLocation
Razorpay Software Pvt LtdPayment processing (paid plans). Card/bank data is tokenised by Razorpay; Aptus receives only a payment reference ID.India
Cloud infrastructure providerCompute, storage, and database hosting for the PlatformIndia
Sendy (self-hosted by Aptus)Transactional and marketing email delivery (only to users who opt in)India

6.2 Aptus shall give the Data Fiduciary at least 30 days' prior written notice before adding or replacing a Sub-Processor. The Data Fiduciary may object within 14 days on reasonable data-protection grounds. If no resolution is reached, the Data Fiduciary may terminate the Subscription Agreement without penalty.

7. Data Principal Rights Assistance

7.1 Aptus shall, upon the Data Fiduciary's written request, provide reasonable technical assistance to enable the Data Fiduciary to fulfil its obligations under Sections 11–14 of the DPDP Act (access, correction, erasure, grievance redressal, and nomination).

7.2 Aptus shall forward to the Data Fiduciary, without undue delay and within 48 hours, any rights request received directly from a Data Principal that relates to the Data Fiduciary's data. Aptus shall not independently grant or refuse such requests.

7.3 The Platform provides a self-service data export feature (Account Settings) enabling the Data Fiduciary to satisfy access and portability requests without Aptus intervention.

8. Personal Data Breach Notification

8.1 Aptus shall notify the Data Fiduciary of a confirmed personal data breach affecting the Data Fiduciary's data without undue delay and, where feasible, not later than 72 hours after becoming aware of it, in alignment with Section 8(6) of the DPDP Act.

8.2 The breach notification shall include, to the extent then known:

  • Nature and likely cause of the breach.
  • Categories and approximate number of Data Principals and records affected.
  • Name and contact details of the Aptus Data Protection contact.
  • Likely consequences of the breach.
  • Measures taken or proposed to address the breach and mitigate its effects.

8.3 Aptus shall cooperate with the Data Fiduciary in notifying the Data Protection Board of India where the Data Fiduciary is required to do so under applicable law.

9. Deletion and Return of Data

9.1 On expiry or termination of the Subscription Agreement, the Data Fiduciary may, within 30 days of termination, request an export of all assessment data in machine-readable format (CSV and/or PDF). Aptus shall fulfil such a request within 10 working days at no additional charge.

9.2 Following the 30-day export window, Aptus shall securely delete all personal data belonging to the Data Fiduciary from active systems and backups within 60 days, and shall provide a written deletion certificate upon request.

9.3 Aptus may retain the following data beyond termination solely to the extent required by law:

  • Invoice and payment records — 7 years (Income Tax Act and GST law).
  • Consent and acceptance logs — as required to demonstrate regulatory compliance.
  • Pseudonymised or aggregated analytics that cannot be re-identified.
10. Audit Rights

10.1 Aptus shall make available to the Data Fiduciary, on written request with at least 30 days' notice, all information reasonably necessary to demonstrate compliance with this Agreement, including relevant audit logs and security policy summaries.

10.2 The Data Fiduciary (or an appointed independent auditor bound by confidentiality) may conduct one (1) audit per calendar year during normal business hours, provided it does not unreasonably disrupt Aptus's operations.

10.3 Aptus may satisfy an audit request by providing a current third-party audit report (e.g., ISO 27001 certification, SOC 2 Type II). If the Data Fiduciary reasonably requires an additional audit after reviewing such a report, Aptus shall facilitate it at the Data Fiduciary's cost, except where the audit reveals material non-compliance by Aptus.

11. Term and Termination

This Agreement commences on the date of acceptance of the Subscription Agreement and continues until all personal data processed under it has been deleted or returned in accordance with Clause 9. Obligations under Clauses 4, 8, 9, and 10 survive termination.

12. Governing Law and Dispute Resolution

12.1 This Agreement is governed by the laws of India, including the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025.

12.2 The courts of Bangalore, Karnataka shall have exclusive jurisdiction over any dispute arising out of or in connection with this Agreement.

12.3 Before initiating legal proceedings, the parties shall attempt to resolve any dispute through good-faith negotiations for a period of 30 days.

This Agreement is accepted electronically at the time of registration. By completing registration on the Platform, the authorised representative confirms they have authority to bind the Data Fiduciary to these terms. For queries, contact [email protected].