Legal · Data Processing Addendum
Data Processing Addendum
Last updated: 5 June 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Service between VyaptIX Technologies LLP(“Processor”) and the customer organisation identified in the order or account (“Controller”) and governs the Processor’s processing of personal data on behalf of the Controller in connection with the BharatTrade Copilot service. Capitalised terms not defined here have the meaning given in the Terms.
1. Roles & scope
For Customer Content uploaded to the Service, the Controller is the data controller and VyaptIX is the data processor. For account, billing, and security telemetry, VyaptIX acts as an independent controller. This DPA applies to processing carried out in the context of the DPDP Act 2023 (India), the EU GDPR, and the UK GDPR, to the extent applicable.
2. Processing details
- Subject matter: provision of the BharatTrade Copilot compliance copilot.
- Duration: for the term of the subscription, plus 30 days for data export.
- Nature & purpose: hosting, processing, classification, FTA evaluation, RoDTEP estimation, CBAM computation, EUDR DDS generation, and operational support.
- Types of data:business contact data of Controller’s staff, buyers, suppliers; trade-document content (which may include personal data of individuals named on shipping documents); plot geolocation.
- Data subjects:Controller’s employees and authorised users, Controller’s buyers and suppliers and their staff, and individuals named on trade documents.
3. Instructions
VyaptIX will process personal data only on documented instructions from the Controller, including with regard to transfers, except where required by law. The Terms, this DPA, and the in-product configuration constitute the Controller’s complete and final instructions.
4. Confidentiality
Personnel authorised to process personal data are bound by written confidentiality obligations.
5. Security
VyaptIX implements technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.3) and at rest (AES-256), row-level security at the database, magic-link authentication, audit logging, regular dependency scanning, and least-privilege access controls.
6. Sub-processors
Controller authorises VyaptIX to engage the sub-processors listed in the Privacy Policy at /legal/privacy §6. VyaptIX will notify Controller by email at least 30 days before any new sub-processor begins processing Customer Content. Controller may object on reasonable grounds; if the parties cannot resolve the objection, Controller may terminate the affected portion of the Service. VyaptIX remains liable for sub-processor acts and omissions.
7. International transfers
Where the Service involves transfer of EU/UK personal data outside the EEA/UK, the parties rely on the EU Standard Contractual Clauses (Module Two: controller-to-processor) and the UK International Data Transfer Addendum, which are incorporated into this DPA by reference.
8. Data subject requests
VyaptIX provides Controller with the tools to respond to data subject requests (access, correction, deletion, portability) directly via the in-product settings and export flows. Where a request is made to VyaptIX directly, VyaptIX will, without undue delay, redirect it to the Controller and assist as reasonably required.
9. Breach notification
VyaptIX will notify the Controller without undue delay (and in any case within 72 hours) after becoming aware of a personal data breach affecting Customer Content, providing the information needed for Controller to meet its own regulatory notification obligations.
10. Audits
VyaptIX will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. Audits are satisfied by VyaptIX’s then-current third-party security attestations and questionnaires; on-site audits are available to Enterprise customers under reasonable scope and notice.
11. Return & deletion
On termination, Controller may export Customer Content for 30 days. After that period, VyaptIX will delete or anonymise Customer Content in the ordinary course, subject to backups that expire on the standard retention schedule and to legal-hold exceptions.
12. Liability
Liability arising under this DPA is subject to the limitations in the Terms of Service.
13. Order of precedence
In the event of conflict between this DPA, the Terms, and any negotiated order form, this DPA prevails on data-protection matters.
14. Contact
Questions? Email privacy@vyaptix.ai.