v1.0Effective 1 August 2026

Data Processing Agreement (DPA)

Between:
The subscribing customer ("Data Controller / Data Fiduciary")

And:
NexAvinya AI Private Limited ("Data Processor")

Effective Date: 1 August 2026 | Version 1.0


1. Purpose

This Data Processing Agreement ("DPA") governs the processing of personal data by NexAvinya AI Private Limited (the "Processor") on behalf of each subscribing customer (the "Controller") in connection with the operation, maintenance, and support of the NexAvinya platform.


2. Scope of Processing

Categories of Data: Personal data the Controller manages in the Platform — lead and customer contact details, employee records, project participants, financial contacts
Purpose: Platform operation, maintenance, support, debugging, and feature delivery
Duration: Duration of the subscription agreement
Data Subjects: The Controller's leads, customers, employees, partners, and portal users


3. Processor Obligations

NexAvinya AI Private Limited shall:

  • Process personal data only on documented instructions from the Controller
  • Ensure persons authorised to process data are bound by confidentiality
  • Implement appropriate technical and organisational security measures
  • Not engage sub-processors beyond the approved list without notice and opportunity to object
  • Assist the Controller in fulfilling data subject rights requests
  • Delete or return all personal data upon termination of the agreement
  • Provide all information necessary to demonstrate compliance with this DPA

4. Sub-Processors

The following categories of sub-processors are pre-approved:

Sub-ProcessorLocationPurposeSafeguard
Cloud infrastructure & database hostingIndia / USA (AWS)Platform & data hostingSCC / provider DPA
Transactional email deliveryUSA / EUSystem & notification emailSCC / provider DPA
AI model providersUSA / EUAI features (processing only, no training on your data)Provider DPA

An up-to-date list is available on request at privacy@nexavinya.ai.


5. Security Measures

Both parties commit to:

  • Encryption at rest (AES-256) and in transit (TLS 1.3)
  • Access limited to authorised personnel only
  • Role-based access control within the Platform
  • Incident response and breach notification procedures
  • Regular security reviews

6. Breach Notification

In the event of a personal data breach, the Processor will notify the Controller within 24 hours of becoming aware, providing: nature of the breach, data categories affected, likely consequences, and measures taken.


7. Audit Rights

The Controller may audit the Processor's data processing activities upon 14 days written notice, no more than once per calendar year.


8. Governing Law

This DPA is governed by the laws of India. The DPDP Act 2023 and DPDP Rules 2025 apply.


Effective: 1 August 2026