Data processing addendum
This addendum is part of our terms of service. It applies when Vatsin Technology Solutions Pvt. Ltd. (“we”) processes personal data for a customer (“you”) through Vatsin. Under the Digital Personal Data Protection Act, 2023, you are the Data Fiduciary and we are your Data Processor.
1. What it covers
- Whose data: your employees, former employees, candidates, contractors and anyone else whose data you put into Vatsin.
- What data: the kinds of data listed in section 3 of our privacy policy.
- Why: only to provide, secure and support the service for you.
- For how long: while your account is active, and then as section 8 says.
2. Your instructions
We process your personal data only on your instructions. These terms, the settings you choose in Vatsin and your requests to our support team are your instructions. If we think an instruction breaks the law, we will tell you.
3. Our people
Only staff who need access to run or support the service can reach your data, and they must keep it confidential. Our support team opens a company’s data only to help it. Every such visit is logged, and you can require your approval first.
4. Security
We keep reasonable security safeguards, as the DPDP Rules require. These include encryption of sensitive identity numbers, encryption in transit, access controls, two-step sign-in, separate data for every company, audit logs and backups. We report cyber security incidents to CERT-In within 6 hours of noticing them, and keep the logs of our systems in India for a rolling 180 days, as the CERT-In directions of 28 April 2022 require. Our security page has details.
5. Our service providers
You allow us to use the service providers listed in section 7 of our privacy policy. If we add or replace a provider that handles your personal data, we will update that list and tell your admins at least 15 days before. If you object on reasonable data protection grounds and we cannot resolve it, you can end the affected service, and we will refund the unused part of any period you paid for in advance. We remain responsible for our providers’ work.
6. Breaches
If we become aware of a personal data breach affecting your data, we will tell you without undue delay, and in any case within 24 hours of becoming aware of it. We will share what we know and help you inform the Data Protection Board and the people affected, as the DPDP Rules require.
7. Helping you
Through the features of Vatsin, or on request, we will help you answer requests from people about their data, and meet your own duties under the DPDP Act.
8. When the service ends
When your account ends, you can download your data for 30 days. After that we delete it from the live service. Copies in backups are removed as the backups are replaced. Security and audit logs are kept for at least one year (180 days for CERT-In) even after deletion, as the law requires, and are used only for that purpose. On request, we will confirm the deletion in writing.
9. Checks
Once a year, or after a breach, you may send us a reasonable written security questionnaire, and we will answer it. Any other audit needs both sides to agree in writing on its scope, timing and cost.
10. Where data is kept
We store your data in India. Some providers listed in our privacy policy may handle limited data outside India, as described there. We will not send it to a country the Government of India has restricted.
11. Liability
The limits on liability in our terms of service also apply to this addendum.