Trust Center

Transparency, security, and compliance at the core of Digital Anumati — under India's DPDP Act, 2023.

Data Processing Agreement (DPA)

Obligations of both parties regarding the processing of Personal Data in accordance with the DPDP Act, 2023 and other applicable data protection laws.

Effective Date: 1 February 2026Last Updated: 24 July 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Digital Anumati ("Processor", "we", "our", or "us") and the customer ("Controller", "Customer", or "you") for the provision of Digital Anumati's Consent Management Platform, Privacy Operations Platform, APIs, and related services ("Services").

This DPA sets out the obligations of both parties regarding the processing of Personal Data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and, where applicable, other relevant data protection laws and regulations.

1. Purpose

The purpose of this Data Processing Agreement is to ensure that Personal Data processed through Digital Anumati is handled securely, lawfully, and only in accordance with the Customer's documented instructions.

Digital Anumati processes Personal Data solely to provide the Services agreed upon with the Customer and does not determine the purposes or means of processing unless acting as an independent Data Fiduciary for its own business operations.

2. Definitions

For the purposes of this Agreement:

  • Customer means the organization using Digital Anumati's Services.
  • Digital Anumati means the provider of the Consent Management Platform and related privacy solutions.
  • Personal Data means any data about an individual who is identifiable by or in relation to such data.
  • Processing includes collection, recording, storage, organization, use, disclosure, sharing, retrieval, deletion, or any other operation performed on Personal Data.
  • Data Principal means the individual to whom the Personal Data relates.
  • Data Fiduciary means the entity that determines the purpose and means of processing Personal Data.
  • Data Processor means an entity processing Personal Data on behalf of a Data Fiduciary.

3. Scope of Processing

Digital Anumati processes Personal Data only for the purpose of delivering the Services requested by the Customer. Typical processing activities may include:

  • Consent collection
  • Consent verification
  • Consent lifecycle management
  • Preference management
  • Consent withdrawal processing
  • Data Rights Request management
  • Audit logging
  • Compliance reporting
  • API-based consent verification
  • Secure storage of consent records

Processing activities are performed strictly in accordance with the Customer's documented instructions.

4. Nature of Personal Data

Depending on the Customer's implementation, Personal Data processed may include:

  • Name
  • Email address
  • Mobile number
  • Customer identifiers
  • Device information
  • IP address
  • Browser information
  • Consent records
  • Preference selections
  • Communication preferences
  • Audit logs
  • Metadata related to consent events

Digital Anumati does not require Customers to upload unnecessary Personal Data and encourages data minimization.

5. Categories of Data Subjects

Personal Data may relate to:

  • Customers
  • Website visitors
  • Mobile application users
  • Employees
  • Prospective customers
  • Vendors
  • Partners
  • Contractors
  • Subscribers
  • Other individuals interacting with the Customer's digital services

6. Customer Responsibilities

The Customer agrees to:

  • Obtain all required notices and valid consent where necessary.
  • Ensure a lawful basis exists for processing Personal Data.
  • Provide accurate processing instructions.
  • Respond to Data Principal requests where required.
  • Ensure uploaded data complies with applicable laws.

The Customer remains responsible for determining the purposes and means of processing.

7. Digital Anumati Responsibilities

Digital Anumati agrees to:

  • Process Personal Data only on documented instructions from the Customer.
  • Implement appropriate technical and organizational security measures.
  • Maintain confidentiality of processed Personal Data.
  • Restrict access to authorized personnel.
  • Assist Customers in responding to Data Principal requests where technically feasible.
  • Maintain records of processing activities where applicable.
  • Notify Customers of confirmed Personal Data Breaches without undue delay, subject to contractual obligations.
  • Support Customers in meeting applicable compliance obligations.

8. Security Measures

Digital Anumati maintains appropriate security controls designed to protect Personal Data against unauthorized access, disclosure, alteration, loss, or destruction. Our security measures include, where applicable:

  • Encryption of data in transit and at rest
  • Secure API communications
  • Role-Based Access Control (RBAC)
  • Multi-Factor Authentication (MFA)
  • Audit logging
  • Continuous monitoring
  • Infrastructure security controls
  • Vulnerability assessments
  • Backup and disaster recovery processes

Security controls are regularly reviewed and updated to address evolving risks.

9. Confidentiality

Digital Anumati ensures that personnel authorized to process Personal Data:

  • Are bound by confidentiality obligations.
  • Receive appropriate privacy and security training.
  • Access Personal Data only where necessary to perform their duties.

10. Sub-processors

Digital Anumati may engage trusted third-party service providers ("Sub-processors") to support the delivery of the Services. Where Sub-processors are engaged:

  • They are selected through appropriate due diligence.
  • They are contractually required to implement appropriate security measures.
  • They are bound by confidentiality obligations.
  • They process Personal Data only for the agreed purposes.

A current list of Sub-processors is available upon request or through our Trust Center, where applicable.

11. Data Subject Rights Assistance

Where technically feasible and appropriate, Digital Anumati will assist Customers in responding to requests relating to:

  • Access
  • Correction
  • Erasure
  • Consent withdrawal
  • Grievance handling
  • Other rights available under applicable privacy laws

The Customer remains responsible for determining how such requests are handled.

12. Personal Data Breach

If Digital Anumati becomes aware of a confirmed Personal Data Breach affecting Customer data, we will:

  • Notify the Customer without undue delay, in accordance with applicable law and contractual commitments.
  • Provide available information regarding the nature and scope of the breach.
  • Take reasonable steps to contain, investigate, and remediate the incident.
  • Cooperate with the Customer in fulfilling applicable legal obligations.

13. Data Retention & Deletion

Digital Anumati retains Personal Data only for as long as necessary to:

  • Provide the Services.
  • Meet contractual obligations.
  • Comply with applicable legal or regulatory requirements.
  • Maintain audit records where required.

Upon termination of the Services or upon Customer instruction, Personal Data will be returned, deleted, or anonymized in accordance with the applicable agreement and legal requirements.

14. International Data Transfers

Where Personal Data is transferred across jurisdictions, Digital Anumati will implement appropriate safeguards and comply with applicable legal requirements governing such transfers.

Customers remain responsible for ensuring that any international transfer instructions comply with applicable laws.

15. Audit & Compliance

Digital Anumati maintains appropriate records and documentation relating to its security and privacy controls. Where contractually agreed and subject to reasonable notice, Customers may request information necessary to demonstrate compliance with this DPA. Any audit requests shall:

  • Be reasonable in scope.
  • Protect the confidentiality of other customers.
  • Minimize operational disruption.

16. Limitation of Liability

Liability under this DPA shall be governed by the applicable Master Services Agreement (MSA), Subscription Agreement, or other governing commercial agreement executed between the parties.

17. Changes to this DPA

Digital Anumati may update this DPA from time to time to reflect changes in legal requirements, industry standards, or service offerings. Material updates will be communicated through appropriate channels where required.

18. Contact Information

For questions regarding this Data Processing Agreement or our data processing practices, please contact:

Privacy Office — Digital Anumati: dpo@digitalanumati.com

Website: https://digitalanumati.com

19. Annex A – Processing Summary

ItemDescription
ProcessorDigital Anumati
Customer RoleData Fiduciary / Controller
Processor RoleData Processor
Purpose of ProcessingConsent Management, Privacy Operations, DSR Management, Compliance
Categories of DataIdentity, Contact, Device, Consent, Preferences, Audit Logs
Data SubjectsCustomers, Website Visitors, Employees, Partners, Vendors
Processing ActivitiesCollection, Storage, Consent Management, Retrieval, Reporting, Deletion
Security MeasuresEncryption, RBAC, MFA, Logging, Monitoring
RetentionAs instructed by Customer or required by law
Sub-processorsTrusted cloud and infrastructure providers under contractual safeguards

20. Annex B – Technical & Organizational Measures (TOMs)

Digital Anumati implements a comprehensive security program that includes:

Identity & Access Management

  • Role-Based Access Control (RBAC)
  • Multi-Factor Authentication (MFA)
  • Least Privilege Access
  • Periodic Access Reviews

Data Protection

  • Encryption in transit (TLS)
  • Encryption at rest
  • Secure key management
  • Data minimization practices

Infrastructure Security

  • Secure cloud infrastructure
  • Network segmentation
  • Firewall protection
  • Intrusion detection and monitoring

Application Security

  • Secure Software Development Lifecycle (SSDLC)
  • Vulnerability assessments
  • Patch management
  • API authentication and authorization

Operational Security

  • Continuous monitoring
  • Incident response procedures
  • Backup and disaster recovery
  • Business continuity planning

Governance

  • Employee confidentiality agreements
  • Security awareness training
  • Vendor risk assessments
  • Privacy by Design and Default principles