1Roles of the parties
Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”), you are the Data Fiduciary for the personal data you place in the Easarc services — your staff records, your buyers’ contact details, the people appearing in inspection footage. You determine the purpose and means of that processing.
Easarc Technologies Private Limited, CIN U62011GJ2026PTC180081, registered at 20 Pramukh Park, Soc Mota Varachha, Mota Varachha, Chorasi, Surat – 394101, Gujarat, India, acts as your Data Processor for that data. We process it only on your documented instructions, which for ordinary operation are the instructions you give through the product itself.
Where we process personal data for our own purposes — your billing contact, our own marketing, our website analytics — we act as a Data Fiduciary in our own right, and our privacy policy governs that.
2Scope of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the Easarc products you subscribe to |
| Duration | The subscription term, plus the 90-day export window |
| Nature and purpose | Storage, retrieval, computation, transmission and deletion, to operate order management, quality inspection, hosting and customer support |
| Categories of data | Names, work contact details, employment and shift identifiers, buyer contact details, message content, and images or video of a work area that may incidentally contain identifiable individuals |
| Data Principals | Your employees and contractors, your buyers and their staff, and your suppliers |
3Our obligations as Processor
- Process personal data only on your documented instructions, and tell you if we believe an instruction breaches the DPDP Act.
- Not sell, share, transfer or otherwise use the personal data for any purpose of our own.
- Not use your content to train models that serve any other customer without your written consent.
- Ensure our personnel with access are bound by confidentiality and are granted access on a least-privilege, need-to-know basis.
- Implement and maintain the reasonable security safeguards set out in clause 5.
- Assist you in responding to requests from Data Principals, and in meeting your own obligations for security, breach notification and impact assessment.
- Delete or return the personal data at the end of the agreement, as set out in clause 8.
- Make available the information you reasonably need to demonstrate our compliance.
4Your obligations as Data Fiduciary
- Ensure you have a lawful basis — consent, or a legitimate use under the DPDP Act — for the personal data you place in the services.
- Give the notice required under section 5 of the DPDP Act to your own Data Principals, including that a processor is involved.
- Where Vision cameras cover areas in which staff work, inform those staff and comply with any applicable workplace and surveillance requirements.
- Configure access, roles and retention settings in the product appropriately for your organisation.
- Not place personal data in free-text fields that we have not been told to expect, particularly any data relating to health or finance.
5Security measures
- Encryption in transit using TLS 1.2 or better, and at rest using AES-256 with keys managed in AWS KMS.
- Network isolation in private subnets, with no direct public access to databases.
- Role-based access control within the product, and SSO on Enterprise plans.
- Least-privilege, individually attributed and time-bound access for Easarc personnel, with production access logged.
- An append-only audit log of security-relevant events, retained for the life of the account plus one year.
- Automated daily backups, encrypted, retained 35 days, with restore tested quarterly.
- Vulnerability scanning of dependencies and images, and patching of critical issues within seven days.
- Annual review of these measures, and of the access rights of all personnel.
6Sub-processors
You give us general authorisation to engage the sub-processors below. We remain responsible for their performance, and we impose data protection obligations on them that are no less protective than these.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services India Private Limited | Cloud hosting, storage, managed databases and model inference | India — ap-south-1 (Mumbai) |
| Payment gateway (Razorpay / PayU) | Collection of subscription fees and issue of payment receipts | India |
| WhatsApp Business API provider | Delivery of order status and support messages you choose to send | India and EU |
| Transactional email provider | System notifications, invoices and password resets | India and USA |
| Error and performance monitoring | Diagnostic telemetry, with personal data scrubbed before transmission | EU |
We will give you 30 days’ notice by email before adding or replacing a sub-processor. If you reasonably object on data protection grounds within that period and we cannot offer an alternative, you may terminate the affected subscription and receive a pro-rata refund.
7Data residency and transfers
Customer content — everything inside your Flow, Vision, Deploy and Desk workspaces — is stored and processed exclusively in AWS ap-south-1 (Mumbai), within India, including backups.
Limited personal data may reach sub-processors outside India as marked in the table above, in each case restricted to account and support metadata rather than customer content. We do not transfer personal data to any country that the Central Government has restricted under section 16 of the DPDP Act.
8Return and deletion
You can export your data in full, as CSV and JSON, at any time from the dashboard and without asking us. On termination that capability remains available for 90 days.
After the 90-day window we delete customer content from live systems within 7 days and from backups within a further 35 days, except where we are required by Indian tax or company law to retain a record — in which case we retain only that record, and only for as long as required.
9Personal data breach
We will notify you without undue delay, and in any case within 48 hours of becoming aware of a personal data breach affecting your data. The notification will describe the nature of the breach, the categories and approximate number of Data Principals affected, the likely consequences, and the measures taken or proposed.
We will assist you in meeting your own notification obligations to the Data Protection Board of India and to affected Data Principals. Notification is not an acknowledgement of fault.
10Audit
On written request, no more than once in twelve months, we will provide a completed security questionnaire and our current architecture and controls documentation.
Enterprise customers may additionally conduct an on-site or remote audit, at their own cost, on 30 days’ notice, during business hours, conducted so as not to disrupt our operations or the confidentiality of other customers’ data. Where a regulator requires an audit, we will co-operate on the timeline the regulator sets.
11Precedence and contact
Where this addendum conflicts with the terms of service on the processing of personal data, this addendum prevails. Everything else in the terms of service — including the limitation of liability and the jurisdiction of the courts at Surat, Gujarat — continues to apply.
Questions, requests and notices under this addendum go to support@easarctech.com.