GDPR Compliance

Data Processing Agreement

This DPA forms part of the Terms of Use between Customer and Compliance Kart Pvt. Ltd to comply with EU GDPR requirements.

Parties

Controller (Customer) & Processor (Compliance Kart Pvt. Ltd)

The Parties seek to implement this DPA to comply with the requirements of EU GDPR in relation to Processor's processing of Personal Data as part of its obligations under the Agreement. This DPA shall apply to Processor's processing of Personal Data provided by the Controller.

Section 1

Definitions

"Data Transfer"A transfer of Personal Data from Controller to Processor, between Processor establishments, or with a Sub-processor.

"EU GDPR"Regulation (EU) 2016/679 on the protection of natural persons with regard to the processing of personal data.

"Standard Contractual Clauses"Contractual clauses pursuant to the European Commission's Implementing Decision (EU) 2021/914 for transfer of Personal Data to third-country processors.

"Controller"The entity which determines the purposes and means of processing personal data.

"Processor"The entity which processes personal data on behalf of the Controller.

"Sub-processor"A processor/sub-contractor appointed by the Processor for provision of all or parts of the Services.

Section 2

Purpose of this Agreement

This DPA sets out various obligations of the Processor in relation to the Processing of Personal Data and shall be limited to the Processor's obligations under the Agreement. If there is a conflict between the Agreement and this DPA, the provisions of this DPA shall prevail.

Section 3

Categories of Personal Data

The Controller authorizes the Processor to process Personal Data to the extent determined and regulated by the Controller, as specified in Annex I to Schedule 1.

4

Purpose of Processing

Processing shall be limited to the Processor's provision of the Services to the Controller pursuant to the Agreement.

5

Duration of Processing

The Processor will Process Personal Data for the duration of the Agreement, unless otherwise agreed in writing.

10

Data Transfer Mechanism

Any Data Transfer outside the EEA shall comply with Schedule 1. The Processor shall not unduly withhold execution of Standard Contractual Clauses.

13

Return & Deletion

At least 90 days from agreement end, Processor shall return or delete all Personal Data including copies, in a commonly used format.

6

Controller's Obligations

Warrant necessary rights to provide Personal Data for Processing

Ensure appropriate legal basis and obtain Data Subject consents

Provide natural persons with relevant privacy notices

Request purging of Personal Data when required

Immediately advise of complaints, access requests, or regulatory inquiries

7

Processor's Obligations

Follow written and documented instructions from the Controller

Provide reasonable assistance responding to Data Subject rights requests

Obtain consent and/or provide notice as required by Data Protection Laws

Ensure cross-border transfers include equivalent contractual protections

Inform Controller if a processing instruction infringes applicable legislation

Assist with Data Protection Impact Assessments (DPIAs) as required under GDPR

8

Data Secrecy

Personnel are informed of confidentiality, regularly trained in data security/privacy, and Personal Data is kept strictly confidential with appropriate technical and organizational measures.

9

Audit Rights

Controller may request information demonstrating compliance. On-site audits require 15 days' prior written notice. Controller bears audit expenses.

11

Sub-processors

Processor may engage Sub-processors with technical and organizational confidentiality measures. 90 days advance notice required for changes. Processor remains liable for Sub-processor failures.

12

Breach Notification

Processor shall notify Controller without undue delay of any Personal Data Breach. Processor shall assist with breach notifications and take commercially reasonable steps to mitigate and remedy.

Section 14

Technical & Organizational Measures

The Processor will take appropriate technical and organizational measures against unauthorized or unlawful processing and against accidental loss, destruction, or damage to Personal Data, ensuring a level of security appropriate to the harm that might result and the nature of the data to be protected.

S1Schedule 1 — Annex I

FieldData Exporter (Controller)Data Importer (Processor)
NameCustomer (as per Order Form)Compliance Kart Pvt. Ltd
AddressAs per Order Form10th Floor, Tower B, B1002, Sector 142, Noida, UP 201305
ContactAs per Order FormAlok Panday, ceo@compliancekart.io
RoleControllerProcessor

Description of Transfer

Data Subjects

Customer's authorized users of the Services

Categories

Name, Address, DOB, Age, Email, Gender, Image, Job, Phone, User ID, Username

Sensitive Data

No sensitive data collected

Frequency

Continuous basis

Nature

Company and project details for KYC, verification, and agreement generation

Retention

As described in the Agreement and order forms

S3Annex III — Sub-Processors

AWS

Amazon Web Services

India

MongoDB

MongoDB Database

India

Questions about this DPA?

For any concerns regarding data processing, contact our Data Protection Officer.

Office

10th Floor, Tower-B, Advant Navis Business Park, B1002, Sector 142, Noida, UP 201305