Genbays Software Private Limited
Data processing agreement
This is the data processing agreement we sign with every client whose personal data we touch. It says we act only on your instructions, keep the data in the region you choose, tell you within 48 hours if something goes wrong, and delete everything within 30 days of the end. The signed copy has the annexes filled in for your project.
- 01
Scope and roles
This agreement applies whenever Genbays processes personal data for you under a proposal, statement of work or retainer. You are the controller (the Data Fiduciary under India's DPDP Act). We are the processor (the Data Processor). It forms part of the engagement agreement and overrides it where the two conflict on personal data.
Annex 1 of the signed copy describes the processing: the subject matter, duration, nature and purpose, the types of personal data and the categories of people it's about. Annex 2 lists the security measures. Annex 3 lists the sub-processors for the project.
- 02
Our obligations
- We process personal data only on your documented instructions, including the engagement agreement, written requests and settings you configure. If we think an instruction breaks the law, we'll tell you before we act on it.
- Everyone who works on your data is bound by written confidentiality and has been trained on it. Access is limited to the people doing the work and revoked when they leave the project.
- We keep the security measures in Annex 2, which match what's published on the trust page. We may improve them; we won't reduce them without your written agreement.
- We help you answer requests from data subjects, respond to regulators, carry out data protection impact assessments and meet breach-notification duties, at no extra charge for reasonable help and at our standard rate where it becomes a project of its own.
- We don't send your data to third-party AI services unless the engagement agreement names the service, the data and the region, and you've agreed in writing.
- 03
Sub-processors
You authorise the sub-processors listed in Annex 3 and on the sub-processor page. Each one is under a written contract with data protection terms at least as strict as these.
Before adding or replacing a sub-processor for your project we'll email your named contact at least 30 days ahead. You can object in writing within 10 business days with your reasons. If we can't resolve the objection, either of us can end the affected part of the work and we refund any prepaid fees for work not yet done. We stay responsible for what our sub-processors do.
- 04
Where data lives, and transfers
Your data is stored in the region named in the engagement agreement. Our default is Mumbai, India. Other regions are available on request, and we can build into a cloud account you own so the data never leaves your control.
We won't move your data to another country without your written instruction, except to a sub-processor listed in Annex 3 in the region shown there.
- 05
Personal data breaches
If we become aware of a breach affecting your data, we tell your named contact without undue delay and in any case within 48 hours of confirming it. The notice says what happened, which data and roughly how many people are affected, what we've done and what we recommend you do. We update it as we learn more and we keep a written record. We don't notify data subjects or regulators on your behalf unless you ask us to in writing.
- 06
End of the engagement
When the engagement ends, you choose: we return your data in a standard format and then delete it, or we delete it straight away. Either way, deletion from live systems happens within 30 days and from backups within 90 days, unless a law requires us to keep a specific record, in which case we keep only that and tell you. We confirm deletion in writing on request.
If we built into a cloud account you own, there's nothing to return: you revoke our access and the data was never anywhere else.
- 07
Audit
We'll give you the information you need to show that we're meeting these terms, including our written security measures and any third-party audit reports we hold. You can audit us once in any 12 months, on 30 days' written notice, during business hours, at your cost, by yourself or an independent auditor bound by confidentiality. If a regulator requires an audit, or a breach has occurred, the once-a-year limit doesn't apply.
- 08
Liability and law
Liability under this agreement is subject to the limits in the engagement agreement. This agreement is governed by the same law as the engagement agreement.
- Legal name
- Genbays Software Private Limited
- Contact
- [email protected]
- Version
- 0.1
Questions people ask us
Do we have to sign this before the workflow review?
Only if the review involves personal data. Most do, since we look at real records. So yes, in practice we sign it, along with an NDA, before we see anything.
Can we use our own DPA instead?
Yes, if it covers the same ground. Send it and we'll compare. Where a term is stricter in yours, yours wins.
What if a sub-processor changes mid-project?
You get 30 days' notice and 10 business days to object. If we can't agree, that part of the work stops and you get back what you prepaid for it.