Saathi Bot v1.0 Live — BYOK Multi-Provider RAGTry free
Legal & ComplianceLast updated: September 30, 2026

Data Processing Agreement (DPA)

Formal contractual commitments for business customers requiring DPDP Act 2023 or GDPR data processing terms.

1. Overview & Roles of Parties

For organizations subject to data protection regulations like India's Digital Personal Data Protection Act, 2023 (DPDP Act) or the European Union's General Data Protection Regulation (GDPR), clear legal division of responsibilities is essential:

Customer (You)

Data Fiduciary / Data Controller

You determine the purpose and means of collecting your website visitors' queries and publishing your organization's documentation.

Saathi Bot (Us)

Data Processor

We process data strictly on your documented instructions to index knowledge, generate vector embeddings, and serve chat responses.

2. Key Commitments in our Standard DPA

Our formal enterprise Data Processing Agreement incorporates standard contractual protections, including:

  • Processing on Instructions Only: We process customer personal data strictly in accordance with your dashboard settings and documented API interactions.
  • Confidentiality Obligations: All personnel with administrative database access are bound by strict non-disclosure obligations.
  • Subprocessor Governance: A commitment to maintain an updated list of authorized subprocessors (Supabase, Google, Groq, Vercel) and provide advance notice of new providers.
  • Security Measures: Technical and organizational measures including PostgreSQL Row-Level Security (RLS), AES-256 encryption at rest, TLS 1.3 in transit, and continuous SSRF network defenses.
  • Assistance with Data Subject Rights: Assisting you in fulfilling your statutory obligations to respond to visitor requests for data access, correction, or erasure.
  • Audit & Compliance Assistance: Providing reasonable information and documentation necessary to demonstrate compliance with applicable data protection legislation.
  • Data Return or Deletion: Permanent deletion of all customer personal data upon termination of service via relational database cascade.

3. How to Request a Countersigned DPA

If your compliance, legal, or procurement department requires a signed DPA prior to deploying Saathi Bot in production:

Request an Executable Agreement

Turnaround time for standard pre-signed DPAs is typically within 24–48 hours.

4. Applicable Jurisdictions

Our DPA is harmonized to support cross-border transfers and compliance with the DPDP Act 2023 (India), EU GDPR, and UK GDPR through Standard Contractual Clauses (SCCs).

Notice & Contact

If you have questions regarding this policy or our data handling practices, please write to our Grievance & Compliance team at privacy@saathibot.com.