Data Processing Agreement (DPA)
Obligations of both parties regarding the processing of Personal Data in accordance with the DPDP Act, 2023 and other applicable data protection laws.
This Data Processing Agreement ("DPA") forms part of the agreement between Digital Anumati ("Processor", "we", "our", or "us") and the customer ("Controller", "Customer", or "you") for the provision of Digital Anumati's Consent Management Platform, Privacy Operations Platform, APIs, and related services ("Services").
This DPA sets out the obligations of both parties regarding the processing of Personal Data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and, where applicable, other relevant data protection laws and regulations.
1. Purpose
The purpose of this Data Processing Agreement is to ensure that Personal Data processed through Digital Anumati is handled securely, lawfully, and only in accordance with the Customer's documented instructions.
Digital Anumati processes Personal Data solely to provide the Services agreed upon with the Customer and does not determine the purposes or means of processing unless acting as an independent Data Fiduciary for its own business operations.
2. Definitions
For the purposes of this Agreement:
- Customer means the organization using Digital Anumati's Services.
- Digital Anumati means the provider of the Consent Management Platform and related privacy solutions.
- Personal Data means any data about an individual who is identifiable by or in relation to such data.
- Processing includes collection, recording, storage, organization, use, disclosure, sharing, retrieval, deletion, or any other operation performed on Personal Data.
- Data Principal means the individual to whom the Personal Data relates.
- Data Fiduciary means the entity that determines the purpose and means of processing Personal Data.
- Data Processor means an entity processing Personal Data on behalf of a Data Fiduciary.
3. Scope of Processing
Digital Anumati processes Personal Data only for the purpose of delivering the Services requested by the Customer. Typical processing activities may include:
- Consent collection
- Consent verification
- Consent lifecycle management
- Preference management
- Consent withdrawal processing
- Data Rights Request management
- Audit logging
- Compliance reporting
- API-based consent verification
- Secure storage of consent records
Processing activities are performed strictly in accordance with the Customer's documented instructions.
4. Nature of Personal Data
Depending on the Customer's implementation, Personal Data processed may include:
- Name
- Email address
- Mobile number
- Customer identifiers
- Device information
- IP address
- Browser information
- Consent records
- Preference selections
- Communication preferences
- Audit logs
- Metadata related to consent events
Digital Anumati does not require Customers to upload unnecessary Personal Data and encourages data minimization.
5. Categories of Data Subjects
Personal Data may relate to:
- Customers
- Website visitors
- Mobile application users
- Employees
- Prospective customers
- Vendors
- Partners
- Contractors
- Subscribers
- Other individuals interacting with the Customer's digital services
6. Customer Responsibilities
The Customer agrees to:
- Obtain all required notices and valid consent where necessary.
- Ensure a lawful basis exists for processing Personal Data.
- Provide accurate processing instructions.
- Respond to Data Principal requests where required.
- Ensure uploaded data complies with applicable laws.
The Customer remains responsible for determining the purposes and means of processing.
7. Digital Anumati Responsibilities
Digital Anumati agrees to:
- Process Personal Data only on documented instructions from the Customer.
- Implement appropriate technical and organizational security measures.
- Maintain confidentiality of processed Personal Data.
- Restrict access to authorized personnel.
- Assist Customers in responding to Data Principal requests where technically feasible.
- Maintain records of processing activities where applicable.
- Notify Customers of confirmed Personal Data Breaches without undue delay, subject to contractual obligations.
- Support Customers in meeting applicable compliance obligations.
8. Security Measures
Digital Anumati maintains appropriate security controls designed to protect Personal Data against unauthorized access, disclosure, alteration, loss, or destruction. Our security measures include, where applicable:
- Encryption of data in transit and at rest
- Secure API communications
- Role-Based Access Control (RBAC)
- Multi-Factor Authentication (MFA)
- Audit logging
- Continuous monitoring
- Infrastructure security controls
- Vulnerability assessments
- Backup and disaster recovery processes
Security controls are regularly reviewed and updated to address evolving risks.
9. Confidentiality
Digital Anumati ensures that personnel authorized to process Personal Data:
- Are bound by confidentiality obligations.
- Receive appropriate privacy and security training.
- Access Personal Data only where necessary to perform their duties.
10. Sub-processors
Digital Anumati may engage trusted third-party service providers ("Sub-processors") to support the delivery of the Services. Where Sub-processors are engaged:
- They are selected through appropriate due diligence.
- They are contractually required to implement appropriate security measures.
- They are bound by confidentiality obligations.
- They process Personal Data only for the agreed purposes.
A current list of Sub-processors is available upon request or through our Trust Center, where applicable.
11. Data Subject Rights Assistance
Where technically feasible and appropriate, Digital Anumati will assist Customers in responding to requests relating to:
- Access
- Correction
- Erasure
- Consent withdrawal
- Grievance handling
- Other rights available under applicable privacy laws
The Customer remains responsible for determining how such requests are handled.
12. Personal Data Breach
If Digital Anumati becomes aware of a confirmed Personal Data Breach affecting Customer data, we will:
- Notify the Customer without undue delay, in accordance with applicable law and contractual commitments.
- Provide available information regarding the nature and scope of the breach.
- Take reasonable steps to contain, investigate, and remediate the incident.
- Cooperate with the Customer in fulfilling applicable legal obligations.
13. Data Retention & Deletion
Digital Anumati retains Personal Data only for as long as necessary to:
- Provide the Services.
- Meet contractual obligations.
- Comply with applicable legal or regulatory requirements.
- Maintain audit records where required.
Upon termination of the Services or upon Customer instruction, Personal Data will be returned, deleted, or anonymized in accordance with the applicable agreement and legal requirements.
14. International Data Transfers
Where Personal Data is transferred across jurisdictions, Digital Anumati will implement appropriate safeguards and comply with applicable legal requirements governing such transfers.
Customers remain responsible for ensuring that any international transfer instructions comply with applicable laws.
15. Audit & Compliance
Digital Anumati maintains appropriate records and documentation relating to its security and privacy controls. Where contractually agreed and subject to reasonable notice, Customers may request information necessary to demonstrate compliance with this DPA. Any audit requests shall:
- Be reasonable in scope.
- Protect the confidentiality of other customers.
- Minimize operational disruption.
16. Limitation of Liability
Liability under this DPA shall be governed by the applicable Master Services Agreement (MSA), Subscription Agreement, or other governing commercial agreement executed between the parties.
17. Changes to this DPA
Digital Anumati may update this DPA from time to time to reflect changes in legal requirements, industry standards, or service offerings. Material updates will be communicated through appropriate channels where required.
18. Contact Information
For questions regarding this Data Processing Agreement or our data processing practices, please contact:
Privacy Office — Digital Anumati: dpo@digitalanumati.com
Website: https://digitalanumati.com
19. Annex A – Processing Summary
| Item | Description |
|---|---|
| Processor | Digital Anumati |
| Customer Role | Data Fiduciary / Controller |
| Processor Role | Data Processor |
| Purpose of Processing | Consent Management, Privacy Operations, DSR Management, Compliance |
| Categories of Data | Identity, Contact, Device, Consent, Preferences, Audit Logs |
| Data Subjects | Customers, Website Visitors, Employees, Partners, Vendors |
| Processing Activities | Collection, Storage, Consent Management, Retrieval, Reporting, Deletion |
| Security Measures | Encryption, RBAC, MFA, Logging, Monitoring |
| Retention | As instructed by Customer or required by law |
| Sub-processors | Trusted cloud and infrastructure providers under contractual safeguards |
20. Annex B – Technical & Organizational Measures (TOMs)
Digital Anumati implements a comprehensive security program that includes:
Identity & Access Management
- Role-Based Access Control (RBAC)
- Multi-Factor Authentication (MFA)
- Least Privilege Access
- Periodic Access Reviews
Data Protection
- Encryption in transit (TLS)
- Encryption at rest
- Secure key management
- Data minimization practices
Infrastructure Security
- Secure cloud infrastructure
- Network segmentation
- Firewall protection
- Intrusion detection and monitoring
Application Security
- Secure Software Development Lifecycle (SSDLC)
- Vulnerability assessments
- Patch management
- API authentication and authorization
Operational Security
- Continuous monitoring
- Incident response procedures
- Backup and disaster recovery
- Business continuity planning
Governance
- Employee confidentiality agreements
- Security awareness training
- Vendor risk assessments
- Privacy by Design and Default principles