Legal · Draft

Data Processing Agreement

This page summarises the terms on which Accurith processes personal data on a client's behalf during an engagement. It is a description of our position, not the executable agreement — the signed DPA attached to your engagement paperwork is the document that binds us.

Last updated · Accurith Technologies Private Limited, Bangalore 560092, Karnataka, India

01

Status

Draft — pending legal review. This page describes how the site works today and has not been reviewed by counsel. It is published for transparency, not as a binding legal document, and will be replaced by a reviewed version before launch.

02

Terms

01

When this applies

Our work often means handling systems and records that contain personal data — reviewing access logs during an IS audit, examining a device in a forensic engagement, testing an application that holds customer records. Where we do that on your instructions, you are the data fiduciary or controller and we are the data processor.

This does not describe personal data you give us through this website, such as an enquiry or a job application. There we act for ourselves, and our Privacy Policy governs.

02

Our undertakings as processor

  • We process personal data only on your documented instructions, and for the purposes of the engagement — never for our own purposes
  • We do not sell personal data, and we do not use it to train models
  • Everyone we allow to access it is bound by confidentiality obligations
  • We apply appropriate technical and organisational security measures, described below
  • We assist you in responding to data-principal and data-subject requests
  • We assist you with security, breach notification and impact assessment obligations, to the extent the information is ours to give
  • We return or delete the data at the end of the engagement, at your election
  • We make available the information reasonably needed to demonstrate our compliance
03

Scope of processing

The specifics are set per engagement, because they follow the work. The signed DPA records them for that engagement:

ItemHow it is fixed
Subject matter and durationThe services in the statement of work, for the term of that engagement
Nature and purposeAudit, assessment, forensic examination, advisory or automation work as scoped
Categories of personal dataIdentified per engagement — typically identifiers, contact details, employment and access records; special-category or financial data only where the scope requires it
Categories of data principalsTypically your employees, contractors and, where in scope, your customers
Your obligationsEnsuring you have a lawful basis for the data you give us, and that your instructions are lawful

We ask for the minimum personal data the work requires, and prefer masked, redacted or synthetic data whenever it will do the job. The cheapest way to protect a record is not to hold it.

04

Security measures

Measures are proportionate to the engagement and recorded in the signed DPA. Our baseline includes encryption in transit and at rest, access restricted to the engagement team on a need-to-know basis, multi-factor authentication on the systems that hold client data, logging of access, segregation of client data between engagements, and secure disposal at the end of the retention period.

For forensic engagements we additionally maintain evidence handling and chain-of-custody procedures appropriate to material that may be relied on in a proceeding.

05

Sub-processors

We engage a sub-processor only where the engagement needs it. Any sub-processor is bound by written terms no less protective than these, and we remain responsible to you for its performance.

We maintain a current list of sub-processors and give notice before adding one, so you have the opportunity to object. Where we host or transmit client data, the underlying cloud and communications providers are the sub-processors most likely to be relevant.

06

Location and transfers

Where personal data is stored depends on the engagement, and we agree it with you rather than assume it. Our own website infrastructure is hosted in the United States; client engagement data does not automatically follow that choice, and for a regulated client it usually should not.

If you require the data to remain in India, tell us before the engagement starts so we can scope the tooling accordingly. Where a transfer outside India or outside your region is necessary, we implement the safeguards the applicable law requires, and the DPA records them.

07

Personal data breaches

If we become aware of a personal data breach affecting data we process for you, we notify you without undue delay and in any case within the period stated in the signed DPA. Our notice sets out what we know: the nature of the breach, the categories and approximate volume of data involved, the likely consequences, and the measures taken or proposed.

We do not notify a regulator or your data principals on your behalf unless you instruct us to — that reporting decision is yours to make, and we support it with the facts.

08

Your rights to verify

You may audit our compliance with these obligations, on reasonable notice and without disrupting our other clients' confidentiality. Where an independent report or completed assessment questionnaire answers your question, we will offer it first — but a report is not a substitute for an audit you are entitled to, and we will not treat it as one.

We hold ourselves to the standard we advise. If our answers do not satisfy your security reviewer, that is a problem for us to fix rather than for you to accept.

09

Return and deletion

At the end of the engagement we return your data, delete it, or both, as you choose. Where we are required by law to retain a copy — or where working papers must be kept to evidence an audit opinion — we retain only what is necessary, keep it protected under these terms, and tell you what has been kept and for how long.

10

Getting a copy

The executable DPA is issued with your engagement paperwork. To review it before then, or to have us complete your own DPA template or security questionnaire, write to [email protected].

03

Open items

Still to be settled.

Listed here rather than answered with a guess — a policy that states a commitment nobody has agreed to is worse than one that admits the gap.

  • The executable DPA document itself is not yet drafted. This page describes the intended position; counsel to produce the agreement, including the schedules referenced above.
  • Breach notification window is not fixed. A defined period — commonly 24, 48 or 72 hours from awareness — must be agreed and stated, since 'without undue delay' alone is what a client's reviewer will push back on.
  • Sub-processor list is described but not published. Decide whether it lives on this page, in a client portal, or only in the signed DPA.
  • Working-paper retention for audit engagements needs a stated period, aligned to professional standards and to the retention decisions still open in the Privacy Policy.
  • Liability for processing, and how it interacts with the MSA cap, is for counsel.
  • Whether we offer Standard Contractual Clauses as a matter of course for clients with a GDPR nexus, or only on request.