Legal · Data Processing Addendum

Data Processing Addendum

Last updated: 5 June 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between VyaptIX Technologies LLP(“Processor”) and the customer organisation identified in the order or account (“Controller”) and governs the Processor’s processing of personal data on behalf of the Controller in connection with the BharatTrade Copilot service. Capitalised terms not defined here have the meaning given in the Terms.

1. Roles & scope

For Customer Content uploaded to the Service, the Controller is the data controller and VyaptIX is the data processor. For account, billing, and security telemetry, VyaptIX acts as an independent controller. This DPA applies to processing carried out in the context of the DPDP Act 2023 (India), the EU GDPR, and the UK GDPR, to the extent applicable.

2. Processing details

3. Instructions

VyaptIX will process personal data only on documented instructions from the Controller, including with regard to transfers, except where required by law. The Terms, this DPA, and the in-product configuration constitute the Controller’s complete and final instructions.

4. Confidentiality

Personnel authorised to process personal data are bound by written confidentiality obligations.

5. Security

VyaptIX implements technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.3) and at rest (AES-256), row-level security at the database, magic-link authentication, audit logging, regular dependency scanning, and least-privilege access controls.

6. Sub-processors

Controller authorises VyaptIX to engage the sub-processors listed in the Privacy Policy at /legal/privacy §6. VyaptIX will notify Controller by email at least 30 days before any new sub-processor begins processing Customer Content. Controller may object on reasonable grounds; if the parties cannot resolve the objection, Controller may terminate the affected portion of the Service. VyaptIX remains liable for sub-processor acts and omissions.

7. International transfers

Where the Service involves transfer of EU/UK personal data outside the EEA/UK, the parties rely on the EU Standard Contractual Clauses (Module Two: controller-to-processor) and the UK International Data Transfer Addendum, which are incorporated into this DPA by reference.

8. Data subject requests

VyaptIX provides Controller with the tools to respond to data subject requests (access, correction, deletion, portability) directly via the in-product settings and export flows. Where a request is made to VyaptIX directly, VyaptIX will, without undue delay, redirect it to the Controller and assist as reasonably required.

9. Breach notification

VyaptIX will notify the Controller without undue delay (and in any case within 72 hours) after becoming aware of a personal data breach affecting Customer Content, providing the information needed for Controller to meet its own regulatory notification obligations.

10. Audits

VyaptIX will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA. Audits are satisfied by VyaptIX’s then-current third-party security attestations and questionnaires; on-site audits are available to Enterprise customers under reasonable scope and notice.

11. Return & deletion

On termination, Controller may export Customer Content for 30 days. After that period, VyaptIX will delete or anonymise Customer Content in the ordinary course, subject to backups that expire on the standard retention schedule and to legal-hold exceptions.

12. Liability

Liability arising under this DPA is subject to the limitations in the Terms of Service.

13. Order of precedence

In the event of conflict between this DPA, the Terms, and any negotiated order form, this DPA prevails on data-protection matters.

14. Contact

Questions? Email privacy@vyaptix.ai.