Legal
Data Processing Agreement
This DPA is incorporated into the Terms of Service between AB Corp (“SaudaFlow”, the Data Processor) and the customer firm operating a SaudaFlow workspace (the “Tenant”, the Data Fiduciary under the DPDP Act 2023). It is accepted electronically when the workspace is created and governs all tenant CRM data.
Effective 5 August 2026 · AB Corp, Mumbai, India · support@saudaflow.in
1. Roles and scope
- The Tenant is the Data Fiduciary for personal data its team stores in SaudaFlow — leads, buyers, enquiries, site visits, calls, documents, and staff records (“Tenant Data”). The Tenant determines the purposes and means.
- AB Corp is the Data Processor, processing Tenant Data only on the Tenant’s documented instructions — the configuration, integrations and actions taken in the product — as Section 8(2) of the DPDP Act contemplates for processing under a valid contract.
- Duration: the life of the workspace plus the post-termination export and deletion window in Section 7.
- For its own account and billing data, AB Corp is a Fiduciary; that dataset is governed by the Privacy Policy, not this DPA.
2. Processor obligations
- Process Tenant Data only to provide, secure and support the service, or as Indian law requires. Never for advertising, profiling for third parties, or sale.
- Ensure persons authorised to process Tenant Data are bound by confidentiality obligations.
- Assist the Tenant in honouring Data Principal rights requests (access, correction, erasure, nomination, grievance) within the product’s Data Principal Rights workflow, targeting completion within 90 days of a verified request.
- Notify the Tenant without undue delay of any personal data breach affecting Tenant Data, with enough detail for the Tenant to meet its own DPDP notification duties to the Data Protection Board and affected Data Principals; we handle our own processor-side duties in parallel.
- Not engage a sub-processor except under Section 5.
3. Data residency
Tenant Data is stored and processed on infrastructure in the Mumbai region. AB Corp does not transfer Tenant Data outside India on its own initiative. Where the Tenant enables an integration whose provider operates outside India (for example WhatsApp Business via Meta), the specific data sent to that provider moves on the Tenant’s instruction, and the Tenant remains responsible for the lawfulness of that transfer.
4. Security measures
- Encryption of Tenant Data at rest with tenant-derived key material; TLS 1.2+ in transit; encrypted backups in the Mumbai region.
- Per-tenant isolation enforced with Postgres row-level security across every business-data table.
- No standing staff access. Access by AB Corp personnel to Tenant Data requires an operational reason (support the Tenant requested, incident response, or a legal obligation). Every such access is written to an append-only audit log that the Tenant can inspect in-product. This is the custody model we operate and can evidence; we do not represent that staff access is cryptographically impossible.
- Role-based access control, least privilege, and logging across production systems; reasonable security practices per Section 43A of the IT Act 2000 and the DPDP security-safeguard obligations.
5. Sub-processors
Current sub-processors for Tenant Data:
- Hostinger International Ltd. — virtual-server hosting, Mumbai region (compute and primary storage).
- Backblaze, Inc. — object storage, Mumbai region bucket (documents, media, backups; content encrypted before upload).
- Razorpay Software Pvt. Ltd. — subscription billing only. Razorpay processes the Tenant’s billing data, not Tenant CRM data.
We may add or replace sub-processors with at least 30 days’ notice to workspace owners, holding each to obligations no less protective than this DPA. A Tenant that objects on reasonable data-protection grounds may terminate and export under the Terms.
6. Audit and information
On written request, no more than once in any 12-month period, AB Corp will provide the Tenant a summary of its security measures and sub-processor arrangements sufficient to demonstrate compliance with this DPA, and will answer reasonable security questionnaires. The in-product access log gives the Tenant continuous, self-serve visibility of every staff access to its data — the audit that matters most, available without asking.
7. Return and deletion
- During the term, the Tenant can export all Tenant Data from the product at any time.
- After termination, the export window is 30 days. After it closes, AB Corp deletes Tenant Data from live systems and lets encrypted backups age out on their fixed cycle.
- Deletion is subject to the retention floors Indian law imposes — statutory billing records, the one-year floor of DPDP Rule 8(3) where it applies, and append-only audit logs — which are then retained solely for that legal purpose and nothing else.
8. Liability and precedence
Liability under this DPA is subject to the caps and exclusions in the Terms of Service. If this DPA and the Terms conflict about the processing of Tenant Data, this DPA prevails. Nothing here limits either party’s obligations under the DPDP Act 2023 itself.
Draft — under legal review. Questions or corrections: support@saudaflow.in. See also Privacy · Terms · Acceptable use · DPA · Your DPDP rights.