Data Processing Agreement (DPA)
Between:
The subscribing customer ("Data Controller / Data Fiduciary")
And:
NexAvinya AI Private Limited ("Data Processor")
Effective Date: 1 August 2026 | Version 1.0
1. Purpose
This Data Processing Agreement ("DPA") governs the processing of personal data by NexAvinya AI Private Limited (the "Processor") on behalf of each subscribing customer (the "Controller") in connection with the operation, maintenance, and support of the NexAvinya platform.
2. Scope of Processing
Categories of Data: Personal data the Controller manages in the Platform — lead and customer contact details, employee records, project participants, financial contacts
Purpose: Platform operation, maintenance, support, debugging, and feature delivery
Duration: Duration of the subscription agreement
Data Subjects: The Controller's leads, customers, employees, partners, and portal users
3. Processor Obligations
NexAvinya AI Private Limited shall:
- Process personal data only on documented instructions from the Controller
- Ensure persons authorised to process data are bound by confidentiality
- Implement appropriate technical and organisational security measures
- Not engage sub-processors beyond the approved list without notice and opportunity to object
- Assist the Controller in fulfilling data subject rights requests
- Delete or return all personal data upon termination of the agreement
- Provide all information necessary to demonstrate compliance with this DPA
4. Sub-Processors
The following categories of sub-processors are pre-approved:
| Sub-Processor | Location | Purpose | Safeguard |
|---|---|---|---|
| Cloud infrastructure & database hosting | India / USA (AWS) | Platform & data hosting | SCC / provider DPA |
| Transactional email delivery | USA / EU | System & notification email | SCC / provider DPA |
| AI model providers | USA / EU | AI features (processing only, no training on your data) | Provider DPA |
An up-to-date list is available on request at privacy@nexavinya.ai.
5. Security Measures
Both parties commit to:
- Encryption at rest (AES-256) and in transit (TLS 1.3)
- Access limited to authorised personnel only
- Role-based access control within the Platform
- Incident response and breach notification procedures
- Regular security reviews
6. Breach Notification
In the event of a personal data breach, the Processor will notify the Controller within 24 hours of becoming aware, providing: nature of the breach, data categories affected, likely consequences, and measures taken.
7. Audit Rights
The Controller may audit the Processor's data processing activities upon 14 days written notice, no more than once per calendar year.
8. Governing Law
This DPA is governed by the laws of India. The DPDP Act 2023 and DPDP Rules 2025 apply.
Effective: 1 August 2026