This Data Processing Agreement ("DPA") describes how EasyDP processes personal data on your behalf as your processor, and the safeguards we apply, for compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and applicable law.
1. Scope & roles
This DPA forms part of the agreement between you ("Business", the Data Fiduciary) and EasyDP (the Data Processor) for your use of the Service. It governs EasyDP's processing of personal data that you submit to, or collect through, the Service ("Customer Data") — including your own customers' names, contact details, consent records, and Data Subject Request history — on your instructions.
2. Nature & purpose of processing
EasyDP processes Customer Data only to provide, secure and support the Service, and only on your documented instructions (including through use of the product).
- Subject matter — provision of EasyDP's consent management, notice generation, Data Subject Request (DSR) handling, breach-notification workflow, retention/erasure tracking, and audit-log products.
- Duration — for the term of your agreement with EasyDP and until deletion or return of Customer Data.
- Data subjects — your customers, leads, and end-users whose personal data you process using EasyDP.
- Data types — identifiers, contact details (name, phone, email, address), consent status and history, DSR records, and any other personal data you choose to process through the Service.
3. EasyDP's obligations
As your processor, EasyDP will:
- process Customer Data only on your instructions and for the purposes above;
- ensure personnel authorised to process Customer Data are bound by confidentiality;
- implement appropriate technical and organisational security measures (Section 4);
- assist you, taking into account the nature of processing, with data-principal requests, security, breach notification, and impact assessments; and
- make available information necessary to demonstrate compliance with this DPA.
4. Data residency & security measures
EasyDP hosts Customer Data exclusively in AWS's Mumbai (ap-south-1) region — your customers' personal data does not leave India as part of normal operation of the Service. Security measures include:
- Encryption of Customer Data at rest and in transit (TLS);
- Role-based access control and least-privilege authentication;
- Network isolation, secrets management, and encrypted credential storage;
- Immutable audit logs of consent events, DSR actions, and notice versions; and
- Regular backups and secure software-development practices.
5. Sub-processors
You authorise EasyDP to engage the following categories of sub-processor to provide the Service. EasyDP imposes data-protection obligations on each sub-processor no less protective than this DPA, and remains responsible for their performance:
- Payments — Razorpay, used solely to collect your subscription payment from you as the Business. Razorpay does not process your end customers' personal data.
- SMS & WhatsApp delivery — licensed messaging API providers used to deliver notices, consent requests, and DSR communications to your customers on your instructions. EasyDP only engages providers that offer their own DPA and data-protection commitments consistent with the DPDP Act.
- Infrastructure — Amazon Web Services (AWS), Mumbai (ap-south-1) region, for hosting and storage.
A current list of named sub-processors is available on request from privacy@easydp.in. EasyDP will give notice of new sub-processors so you may object on reasonable grounds.
6. Data-principal rights
Taking into account the nature of the processing, EasyDP provides product features — the DSR portal, consent ledger, and notice tools — and reasonable assistance to help you respond to requests from your customers to access, correct, erase, or withdraw consent for their personal data within the timelines the DPDP Act requires.
7. Personal-data breach notification
EasyDP will notify you without undue delay after becoming aware of a personal-data breach affecting Customer Data, and will provide information reasonably available to help you meet your notification obligations to the Data Protection Board of India and affected data principals under Rule 7.
8. Audits
EasyDP will make available information necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by you or an independent auditor, subject to reasonable notice, confidentiality, and frequency limits.
9. International transfers
EasyDP does not transfer Customer Data outside India as part of normal operation of the Service. Where a transfer is ever required, it will be made only with appropriate safeguards consistent with the DPDP Act.
10. Return & deletion of data
On termination of your agreement with EasyDP, and at your choice, EasyDP will delete or return Customer Data and delete existing copies within a reasonable period, unless retention is required by law. You can export Customer Data from the product before deletion.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
12. How to sign & contact
To execute a countersigned copy of this DPA, or for questions, email privacy@easydp.in. This DPA is incorporated into and forms part of your agreement with EasyDP.
This page is a plain-language summary for transparency. It is not a substitute for tailored legal advice; consult a qualified advocate for your specific situation.