Data Processing Agreement (DPA)
Formal contractual commitments for business customers requiring DPDP Act 2023 or GDPR data processing terms.
1. Overview & Roles of Parties
For organizations subject to data protection regulations like India's Digital Personal Data Protection Act, 2023 (DPDP Act) or the European Union's General Data Protection Regulation (GDPR), clear legal division of responsibilities is essential:
Data Fiduciary / Data Controller
You determine the purpose and means of collecting your website visitors' queries and publishing your organization's documentation.
Data Processor
We process data strictly on your documented instructions to index knowledge, generate vector embeddings, and serve chat responses.
2. Key Commitments in our Standard DPA
Our formal enterprise Data Processing Agreement incorporates standard contractual protections, including:
- Processing on Instructions Only: We process customer personal data strictly in accordance with your dashboard settings and documented API interactions.
- Confidentiality Obligations: All personnel with administrative database access are bound by strict non-disclosure obligations.
- Subprocessor Governance: A commitment to maintain an updated list of authorized subprocessors (Supabase, Google, Groq, Vercel) and provide advance notice of new providers.
- Security Measures: Technical and organizational measures including PostgreSQL Row-Level Security (RLS), AES-256 encryption at rest, TLS 1.3 in transit, and continuous SSRF network defenses.
- Assistance with Data Subject Rights: Assisting you in fulfilling your statutory obligations to respond to visitor requests for data access, correction, or erasure.
- Audit & Compliance Assistance: Providing reasonable information and documentation necessary to demonstrate compliance with applicable data protection legislation.
- Data Return or Deletion: Permanent deletion of all customer personal data upon termination of service via relational database cascade.
3. How to Request a Countersigned DPA
If your compliance, legal, or procurement department requires a signed DPA prior to deploying Saathi Bot in production:
Request an Executable Agreement
Turnaround time for standard pre-signed DPAs is typically within 24–48 hours.
4. Applicable Jurisdictions
Our DPA is harmonized to support cross-border transfers and compliance with the DPDP Act 2023 (India), EU GDPR, and UK GDPR through Standard Contractual Clauses (SCCs).