Data Processing Agreement
Last updated 24 July 2026
1. Parties & how this DPA applies
This Data Processing Agreement (“DPA”) is between Vyapnova Technologies Private Limited, Gurugram, Haryana, India (“Vyapnova”, the “Processor”) and the business that uses the Vyapnova service (the “Merchant”, the “Controller” / “Data Fiduciary”). It forms part of, and is incorporated into, our Terms of Service, and applies automatically — no signature is needed — whenever the Service processes personal data of the Merchant's customers on the Merchant's behalf. A countersigned copy is available on request at hello@vyapnova.com.
This DPA is written to satisfy the contract requirements of Article 28 of the GDPR (and the UK GDPR) and of India's Digital Personal Data Protection Act, 2023 for engagements between a Data Fiduciary and a Data Processor.
2. Definitions
“Applicable Data Protection Law” means the privacy and data-protection laws that apply to the processing under this DPA, including India's DPDP Act, 2023 and, where applicable, the EU/UK GDPR. “Customer Data” means personal data of the Merchant's customers and prospects that the Service processes on the Merchant's behalf. “Controller” includes “Data Fiduciary”, “processor” includes “Data Processor”, and “data subject” includes “Data Principal”, each as defined in Applicable Data Protection Law. Terms not defined here have the meaning given in the Terms of Service or Applicable Data Protection Law.
3. Scope of processing
Subject matter and purpose: operating the Vyapnova AI sales and support agent for the Merchant — receiving and responding to customer messages, capturing structured requests, enabling human takeover, and producing the Merchant's own analytics. Duration: the term of the Merchant's use of the Service, plus the deletion period in Section 10. Nature: collection, storage, organisation, analysis (including AI-generated replies), disclosure to the sub-processors in Section 5, and deletion.
Data subjects: the Merchant's customers and prospects who message its connected channels. Categories of data: platform identifiers and profile names, contact details, message content and media, request details (orders, bookings, appointments, quotes, callbacks), and order-tracking information. Special categories: the Service is not designed for, and the Merchant agrees not to direct into it, special or sensitive categories of data (such as health, biometric, or financial-account data) unless the Merchant has a lawful basis and tells us in writing first.
4. Our obligations as your processor
As Processor, Vyapnova will:
- process Customer Data only on the Merchant's documented instructions— which are: the Terms of Service, this DPA, the Merchant's configuration of the Service (knowledge base, agent settings, takeover actions), and written instructions to hello@vyapnova.com — unless law requires otherwise, in which case we inform the Merchant unless the law prohibits it;
- inform the Merchant if, in our opinion, an instruction infringes Applicable Data Protection Law;
- ensure persons authorised to process Customer Data are bound by confidentiality obligations;
- implement the technical and organisational measures described on our Security page and in Section 14 of our Privacy Policy — including encryption in transit and at rest, role-based access control, per-merchant data isolation, and audit logging — and not materially decrease the overall security of the Service;
- not sell Customer Data, not use it for advertising, and not use it to train foundation models or permit our AI sub-processors to do so.
5. Sub-processors
The Merchant gives general authorisation for the sub-processors listed in Section 8 of our Privacy Policy (cloud infrastructure, AI providers, and supporting services). We impose data-protection obligations on each sub-processor by contract that are no less protective than this DPA, and we remain responsible for their performance.
We will give at least 15 days' notice (by email or in-product message) before adding or replacing a sub-processor that processes Customer Data. If the Merchant reasonably objects on data-protection grounds and we cannot offer an alternative, the Merchant may terminate the affected subscription and receive a pro-rata refund of the unused prepaid period under our Refund & Cancellation Policy.
6. Assistance with rights & obligations
Taking into account the nature of the processing, we assist the Merchant in fulfilling its obligations to data subjects and regulators:
- the Service provides per-customer export and erasure tools, so most access and deletion requests can be completed by the Merchant directly from the dashboard;
- we forward to the Merchant, without undue delay, any request we receive directly from its customers, and do not respond on the Merchant's behalf except to direct the person to the Merchant or as law requires;
- we provide reasonable assistance with data-protection impact assessments, prior consultations, and security-related enquiries, where the Merchant cannot obtain the information itself.
7. Personal data breaches
We notify the Merchant without undue delay after becoming aware of a personal data breach affecting Customer Data, and provide — as information becomes available — the nature of the breach, the categories and approximate number of data subjects and records concerned, likely consequences, and the measures taken or proposed. We do not notify the Merchant's customers or regulators on the Merchant's behalf unless required by law or agreed in writing.
8. International transfers
Customer Data is processed on infrastructure in India and in the other regions where our sub-processors operate, as described in Section 13 of the Privacy Policy. Where the GDPR applies to a transfer, the European Commission's Standard Contractual Clauses (controller-to-processor module, and processor-to-processor for our sub-processors) are incorporated by reference, with the details in Section 3 serving as the annexes. We do not transfer Customer Data to any jurisdiction restricted by the Government of India under the DPDP Act.
9. Information & audit
We make available the information reasonably necessary to demonstrate compliance with this DPA — including our Privacy Policy, Security page, and written answers to reasonable security questionnaires. Where Applicable Data Protection Law grants an audit right, the Merchant may audit once per 12-month period, on at least 30 days' written notice, during business hours, without disrupting the Service, at the Merchant's cost, and subject to confidentiality — starting with written materials, with on-site or technical inspection only where written materials are demonstrably insufficient.
10. Return & deletion of data
During the term, the Merchant can export Customer Data through the Service. After termination or account deletion, the Merchant has 30 days to request a final export; we then delete Customer Data from live systems within 30 days and from encrypted backups within 90 days, per the retention schedule in the Privacy Policy — except where law requires longer retention, in which case we protect the data and stop all other processing.
11. Liability
Each party's liability under this DPA is subject to the exclusions and the limitation of liability in Section 13 of the Terms of Service, to the extent permitted by Applicable Data Protection Law. Nothing in this DPA limits a data subject's rights against either party.
12. Term, precedence & governing law
This DPA applies for as long as we process Customer Data for the Merchant. If this DPA conflicts with the Terms of Service on a data-protection matter, this DPA prevails; if it conflicts with the Standard Contractual Clauses where they apply, the Clauses prevail. Updates to this DPA follow the change process in the Terms (Section 16). Governing law and jurisdiction are as set out in the Terms (Section 15).
13. Contact
Vyapnova Technologies Private Limited
Registered office: Gurugram, Haryana, India
Email (including data-protection matters): hello@vyapnova.com