This DPA forms part of the Terms of Use between Customer and Compliance Kart Pvt. Ltd to comply with EU GDPR requirements.
Controller (Customer) & Processor (Compliance Kart Pvt. Ltd)
The Parties seek to implement this DPA to comply with the requirements of EU GDPR in relation to Processor's processing of Personal Data as part of its obligations under the Agreement. This DPA shall apply to Processor's processing of Personal Data provided by the Controller.
"Data Transfer" — A transfer of Personal Data from Controller to Processor, between Processor establishments, or with a Sub-processor.
"EU GDPR" — Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data.
"Standard Contractual Clauses" — Contractual clauses pursuant to the European Commission's Implementing Decision (EU) 2021/914 for transfer of Personal Data to third-country processors.
"Controller" — The entity which determines the purposes and means of processing personal data.
"Processor" — The entity which processes personal data on behalf of the Controller.
"Sub-processor" — A processor/sub-contractor appointed by the Processor for provision of all or parts of the Services.
This DPA sets out various obligations of the Processor in relation to the Processing of Personal Data and shall be limited to the Processor's obligations under the Agreement. If there is a conflict between the Agreement and this DPA, the provisions of this DPA shall prevail.
The Controller authorizes the Processor to process Personal Data to the extent determined and regulated by the Controller, as specified in Annex I to Schedule 1.
Processing shall be limited to the Processor's provision of the Services to the Controller pursuant to the Agreement.
The Processor will Process Personal Data for the duration of the Agreement, unless otherwise agreed in writing.
Any Data Transfer outside the EEA shall comply with Schedule 1. The Processor shall not unduly withhold execution of Standard Contractual Clauses.
At least 90 days from agreement end, Processor shall return or delete all Personal Data including copies, in a commonly used format.
Warrant necessary rights to provide Personal Data for Processing
Ensure appropriate legal basis and obtain Data Subject consents
Provide natural persons with relevant privacy notices
Request purging of Personal Data when required
Immediately advise of complaints, access requests, or regulatory inquiries
Follow written and documented instructions from the Controller
Provide reasonable assistance responding to Data Subject rights requests
Obtain consent and/or provide notice as required by Data Protection Laws
Ensure cross-border transfers include equivalent contractual protections
Inform Controller if a processing instruction infringes applicable legislation
Assist with Data Protection Impact Assessments (DPIAs) as required under GDPR
Personnel are informed of confidentiality, regularly trained in data security/privacy, and Personal Data is kept strictly confidential with appropriate technical and organizational measures.
Controller may request information demonstrating compliance. On-site audits require 15 days' prior written notice. Controller bears audit expenses.
Processor may engage Sub-processors with technical and organizational confidentiality measures. 90 days advance notice required for changes. Processor remains liable for Sub-processor failures.
Processor shall notify Controller without undue delay of any Personal Data Breach. Processor shall assist with breach notifications and take commercially reasonable steps to mitigate and remedy.
The Processor will take appropriate technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction, or damage to Personal Data, ensuring a level of security appropriate to the harm that might result and the nature of the data to be protected.
| Field | Data Exporter (Controller) | Data Importer (Processor) |
|---|---|---|
| Name | Customer (as per Order Form) | Compliance Kart Pvt. Ltd |
| Address | As per Order Form | 10th Floor, Tower B, B1002, Sector 142, Noida, UP 201305 |
| Contact | As per Order Form | Alok Panday, ceo@compliancekart.io |
| Role | Controller | Processor |
Data Subjects
Customer's authorized users of the Services
Categories
Name, Address, DOB, Age, Email, Gender, Image, Job, Phone, User ID, Username
Sensitive Data
No sensitive data collected
Frequency
Continuous basis
Nature
Company and project details for KYC, verification, and agreement generation
Retention
As described in the Agreement and order forms
AWS
Amazon Web Services
IndiaMongoDB
MongoDB Database
IndiaFor any concerns regarding data processing, contact our Data Protection Officer.
Office
10th Floor, Tower-B, Advant Navis Business Park, B1002, Sector 142, Noida, UP 201305