Data Processing Addendum
Last updated 2026-06-04
Template for demonstration — review and adapt with qualified counsel before relying on it.
This Data Processing Addendum ("DPA") forms part of the Terms between Harvbery Technologies Pvt. Ltd. ("Processor") and the customer ("Data Fiduciary").
1. Roles. The Data Fiduciary determines the purposes and means of processing; the Processor processes personal data only on documented instructions.
2. Scope. Processing is limited to providing the Service: storage, retrieval, AI-assisted research/drafting, and support.
3. Confidentiality. Personnel with access are bound by confidentiality obligations.
4. Security. The Processor maintains reasonable security safeguards as required by the DPDP Act (encryption in transit, RBAC, MFA, audit logging, retention controls).
5. Sub-processors. The Data Fiduciary authorises the sub-processors listed in the Privacy Policy; the Processor remains responsible and will give notice of changes.
6. Data-principal requests. The Processor assists the Data Fiduciary in responding to access/correction/erasure requests, including via the in-app Compliance tools.
7. Breach notification. The Processor notifies the Data Fiduciary without undue delay after becoming aware of a personal-data breach, to enable Board/affected-principal notification.
8. Erasure. On termination, the Processor deletes or returns personal data per the configured retention policy, subject to legal-hold obligations.
Contact: privacy@harvbery.example