Skip to Content

Data Processing Addendum (DPA)

Last Updated: September 1, 2026

1. What This Data Processing Addendum Means

This Data Processing Addendum, also called a “DPA,” explains how Andabhurji Global Solutions handles personal data when providing services to a client.

A DPA is a legal document used when one organization handles personal data on behalf of another organization. It helps clarify:

  • What personal data may be processed

  • Why the data may be processed

  • Which party is responsible for making decisions about the data

  • Which party is responsible for carrying out processing activities

  • What security and confidentiality obligations apply

  • How service providers and subprocessors may be used

  • What happens if a security incident occurs

  • What happens to the data when services end

This DPA forms part of the agreement between Andabhurji Global Solutions, referred to as the “Processor,” and the customer or client, referred to as the “Controller.”

Depending on the applicable privacy law, the parties may also be referred to as:

  • Business and Service Provider

  • Data Fiduciary and Data Processor

  • Customer and Vendor

  • Organization and Contractor

The applicable legal terminology may vary by jurisdiction, but the responsibilities described in this DPA remain substantially similar.

2. Parties and Their Roles

2.1 Controller

The Controller is the organization that decides:

  • Why personal data is collected

  • What personal data is collected

  • How the data should be used

  • How long the data should be retained

  • Who may access the data

  • Whether the data may be shared with other parties

For example, a client may decide to collect customer names, email addresses, phone numbers, order information, employee records, or support requests.

The Controller is generally responsible for ensuring that it has a lawful basis, appropriate notices, permissions, consents, and authorizations to collect and provide personal data to the Processor.

2.2 Processor

The Processor is the organization that processes personal data on behalf of the Controller and according to the Controller’s instructions.

Andabhurji Global Solutions may act as a Processor when providing services such as:

  • Software implementation

  • Website development

  • Application development

  • Cloud configuration

  • Data migration

  • Customer support

  • Digital marketing technology services

  • Automation services

  • Hosting or infrastructure support

  • E-commerce implementation

  • Marketplace integration

  • Analytics configuration

  • Business process consulting

  • Technical maintenance

Andabhurji Global Solutions does not generally decide the business purpose for which the client’s personal data is collected. Instead, it processes the data as necessary to provide the contracted services.

2.3 Independent Controller Activities

In some situations, Andabhurji Global Solutions may process personal data as an independent Controller rather than as a Processor. This may include data used for:

  • Managing business relationships

  • Processing invoices and payments

  • Maintaining accounting records

  • Responding to inquiries

  • Managing contracts

  • Preventing fraud or misuse

  • Complying with legal obligations

  • Protecting legal rights

  • Managing security and access records

  • Communicating with customers and business contacts

This DPA applies only to personal data processed by Andabhurji Global Solutions on behalf of the Client.

3. Definitions

For purposes of this DPA:

3.1 Personal Data

Personal Data means information that identifies, relates to, describes, or can reasonably be linked to an individual.

Examples may include:

  • Name

  • Email address

  • Telephone number

  • Postal address

  • Account credentials

  • Identification numbers

  • IP address

  • Device information

  • Location information

  • Purchase history

  • Customer support records

  • Employment information

  • Online identifiers

  • Payment-related information

  • Any other information protected as personal data under applicable law

3.2 Processing

Processing means any operation performed on personal data, whether automated or manual.

Processing may include:

  • Collecting

  • Recording

  • Organizing

  • Storing

  • Accessing

  • Reviewing

  • Retrieving

  • Using

  • Transmitting

  • Sharing

  • Modifying

  • Combining

  • Exporting

  • Archiving

  • Deleting

  • Destroying

3.3 Data Subject

A Data Subject is the individual to whom personal data relates.

Examples include:

  • Customers

  • Employees

  • Contractors

  • Website visitors

  • Users

  • Patients

  • Students

  • Suppliers

  • Business contacts

  • Marketplace users

3.4 Subprocessor

A Subprocessor is a third-party service provider engaged by the Processor to process personal data on behalf of the Controller.

Examples may include:

  • Cloud hosting providers

  • Data storage providers

  • Email delivery providers

  • Customer support platforms

  • Payment service providers

  • Analytics providers

  • Security providers

  • Backup providers

  • Communication platforms

  • Technical integration providers

4. Scope of Processing

The Processor may process personal data only as necessary to provide the services described in the applicable:

  • Master services agreement

  • Statement of work

  • Order form

  • Quotation

  • Project proposal

  • Subscription plan

  • Support agreement

  • Implementation agreement

  • Written instructions from the Controller

The Processor shall not use the personal data for unrelated purposes unless:

  • The Controller provides written authorization

  • The processing is required by applicable law

  • The processing is necessary to protect the security of the services

  • The processing is necessary to prevent fraud, abuse, or misuse

  • The Processor is acting as an independent Controller for a separate lawful purpose

5. Processing Instructions

The Processor shall process personal data only on documented instructions from the Controller.

Instructions may be provided through:

  • A signed agreement

  • A statement of work

  • A project specification

  • A support ticket

  • An authorized email

  • A system configuration

  • An approved integration

  • A written change request

  • Other documented business instructions

The Controller is responsible for ensuring that its instructions are lawful and do not require the Processor to violate applicable privacy, security, or other laws.

If the Processor reasonably believes that an instruction violates applicable law, the Processor may:

  • Request clarification

  • Suspend the affected processing activity

  • Decline to perform the unlawful activity

  • Notify the Controller of the concern

  • Take other steps reasonably necessary to comply with legal obligations

6. Categories of Personal Data

Depending on the services provided, the Processor may process the following categories of personal data:

  • Names and contact details

  • Business contact information

  • Account and login information

  • Customer or user identification information

  • Transaction and order information

  • Billing and payment-related information

  • Support and communication records

  • Employment or contractor information

  • Technical and device information

  • IP addresses and online identifiers

  • Usage and activity information

  • Location information

  • Preferences and account settings

  • Information contained in uploaded files or documents

The actual categories of personal data processed will depend on the services, systems, applications, integrations, and instructions provided by the Controller.

7. Special Categories and Sensitive Personal Data

The Controller should not provide sensitive personal data or special categories of personal data unless:

  • The processing is necessary for the contracted services

  • The Controller has a lawful basis for processing

  • The Controller has provided appropriate instructions

  • Appropriate safeguards are in place

  • The processing is permitted under applicable law

Sensitive information may include:

  • Government identification numbers

  • Financial account information

  • Health information

  • Biometric information

  • Genetic information

  • Precise location information

  • Information about racial or ethnic origin

  • Religious or philosophical beliefs

  • Political opinions

  • Trade union membership

  • Information about criminal allegations or convictions

  • Information concerning children

Unless expressly agreed in writing, the Processor does not require the Controller to provide sensitive personal data for ordinary software, consulting, development, design, or implementation services.

The Controller remains responsible for determining whether sensitive personal data may lawfully be collected, disclosed, transferred, or processed.

8. Processing Activities

The Processor may process personal data for the following purposes, where applicable:

  • Providing contracted services

  • Configuring software and systems

  • Implementing websites and applications

  • Migrating or importing data

  • Maintaining databases

  • Providing technical support

  • Troubleshooting errors

  • Managing user accounts

  • Operating integrations

  • Providing hosting or infrastructure services

  • Performing backups and recovery

  • Monitoring service performance

  • Maintaining security

  • Preventing fraud and abuse

  • Communicating with authorized client representatives

  • Generating service-related reports

  • Complying with legal obligations

  • Performing other activities expressly authorized by the Controller

9. Duration of Processing

The Processor may process personal data for the duration of the applicable service relationship.

Processing may continue after termination where necessary to:

  • Complete an authorized transition

  • Return or export data

  • Comply with legal obligations

  • Maintain required business records

  • Resolve disputes

  • Establish, exercise, or defend legal claims

  • Maintain security logs

  • Complete backup deletion cycles

  • Protect the rights and safety of the parties

10. Confidentiality Obligations

The Processor shall ensure that individuals authorized to process personal data:

  • Are informed of their confidentiality obligations

  • Access personal data only when necessary

  • Use personal data only for authorized purposes

  • Do not disclose personal data without authorization

  • Protect personal data after their employment or engagement ends

Confidentiality obligations may arise through:

  • Employment agreements

  • Contractor agreements

  • Non-disclosure agreements

  • Internal policies

  • Professional obligations

  • Contractual commitments

11. Security Measures

The Processor shall implement reasonable technical and organizational measures designed to protect personal data against:

  • Accidental loss

  • Unauthorized access

  • Unauthorized disclosure

  • Unauthorized alteration

  • Destruction

  • Misuse

  • Unlawful processing

  • Security threats

  • Service disruption

Depending on the nature of the services and risks involved, safeguards may include:

  • Access controls

  • Role-based permissions

  • Authentication controls

  • Password protection

  • Multi-factor authentication where available

  • Encryption in transit

  • Encryption at rest where appropriate

  • Network security controls

  • Malware protection

  • Vulnerability management

  • Security monitoring

  • Logging and audit trails

  • Backup procedures

  • Disaster recovery procedures

  • Business continuity planning

  • Secure development practices

  • Change management

  • Incident response procedures

  • Vendor security reviews

  • Employee confidentiality obligations

  • Security awareness training

Security measures may vary depending on:

  • The type of service

  • The sensitivity of the data

  • The volume of data

  • The nature of the processing

  • The likelihood and severity of potential harm

  • Available technology

  • Implementation costs

  • Applicable legal requirements

No security measure can guarantee absolute protection against every possible threat.

12. Access Controls

The Processor shall seek to limit access to personal data to authorized personnel who require access to perform their assigned responsibilities.

Access may be granted based on:

  • Job responsibilities

  • Project requirements

  • Support needs

  • Administrative duties

  • Security requirements

  • Contractual obligations

Access rights may be reviewed, modified, or removed when:

  • A person changes roles

  • A project ends

  • A contract ends

  • Access is no longer necessary

  • A security concern arises

  • The Controller requests removal where reasonably possible

13. Assistance with Data Subject Requests

The Controller is generally responsible for responding to requests from Data Subjects.

Data Subject requests may include requests to:

  • Access personal data

  • Correct inaccurate information

  • Delete personal data

  • Restrict processing

  • Object to processing

  • Receive a portable copy of data

  • Withdraw consent

  • Obtain information about processing

  • Exercise other rights under applicable law

Where the Processor receives a Data Subject request relating to the Controller’s personal data, the Processor may:

  • Forward the request to the Controller

  • Notify the requester that the Controller is responsible

  • Provide reasonable assistance to the Controller

  • Search for relevant data where technically feasible

  • Correct, export, restrict, or delete data based on the Controller’s documented instructions

The Processor shall not independently respond to or fulfill a request in a manner that conflicts with the Controller’s instructions or applicable law.

The Controller is responsible for:

  • Verifying the identity of the requester

  • Determining whether the request is legally valid

  • Determining whether an exemption applies

  • Providing the required response

  • Communicating with the Data Subject

  • Paying reasonable costs associated with extraordinary assistance, where permitted

14. Assistance with Privacy Compliance

Taking into account the nature of the processing and information available to the Processor, the Processor may provide reasonable assistance with:

  • Security assessments

  • Data protection impact assessments

  • Privacy risk assessments

  • Regulatory inquiries

  • Data breach investigations

  • Data subject requests

  • Records of processing

  • Data retention procedures

  • Data deletion requests

  • International transfer assessments

The Processor may charge reasonable fees for assistance that is unusually extensive, repetitive, technically complex, or outside the agreed scope of services, unless prohibited by applicable law or contract.

15. Security Incident Notification

A Security Incident means a confirmed or reasonably suspected event that compromises the security, confidentiality, integrity, or availability of personal data.

Examples may include:

  • Unauthorized access

  • Unauthorized disclosure

  • Accidental transmission

  • Loss of a device containing personal data

  • Destruction of personal data

  • Ransomware

  • Malware

  • Credential compromise

  • Unauthorized alteration

  • Improper deletion

  • System intrusion

The Processor shall notify the Controller of a confirmed Security Incident involving the Controller’s personal data where required by applicable law or contract.

The notification may include, where available:

  • A description of the incident

  • The approximate date and time

  • The categories of affected data

  • The approximate number of affected individuals

  • The likely consequences

  • Measures taken or proposed to address the incident

  • Contact information for follow-up

The Processor may provide information in stages as it becomes available.

The Processor shall take reasonable steps to:

  • Investigate the incident

  • Contain the incident

  • Reduce potential harm

  • Restore affected services

  • Preserve relevant evidence

  • Cooperate with the Controller

  • Implement corrective measures

The Controller remains responsible for determining whether notification must be made to regulators, Data Subjects, customers, employees, or other parties, unless the parties agree otherwise in writing.

16. Subprocessors

The Controller authorizes the Processor to engage subprocessors where reasonably necessary to provide the contracted services.

Subprocessors may include:

  • Cloud infrastructure providers

  • Hosting providers

  • Data storage providers

  • Backup providers

  • Email and communication providers

  • Payment processors

  • Fulfillment providers

  • Customer support platforms

  • Analytics providers

  • Security providers

  • Software vendors

  • API providers

  • Professional advisers

  • Technical contractors

The Processor shall seek to require subprocessors to maintain privacy and security obligations appropriate to the services they provide.

The Processor remains responsible for the performance of its subprocessors to the extent required by applicable law and the applicable agreement.

The Controller may request information about relevant subprocessors, subject to confidentiality, security, and commercial restrictions.

17. Changes to Subprocessors

The Processor may add, replace, or remove subprocessors when reasonably necessary to operate, improve, secure, or support the services.

Where required by applicable law or contract, the Processor may provide notice of material changes.

The Controller may raise a reasonable objection where it has legitimate data protection concerns. The parties shall attempt to resolve the concern in good faith.

If the concern cannot reasonably be resolved, the parties may discuss alternative arrangements, service changes, or termination rights available under the applicable agreement.

18. International Data Transfers

Personal data may be processed or transferred across national borders when necessary to provide the services.

International transfers may involve:

  • Cloud hosting locations

  • Technical support locations

  • Communication providers

  • Payment providers

  • Backup locations

  • Subprocessor locations

  • Data centers

  • Business operations

The parties shall seek to use appropriate safeguards where required by applicable law.

Safeguards may include:

  • Adequacy decisions

  • Standard contractual clauses

  • Data transfer agreements

  • Binding corporate rules

  • Contractual protections

  • Technical safeguards

  • Encryption

  • Access restrictions

  • Data minimization

  • Other legally recognized transfer mechanisms

The Controller is responsible for determining whether its transfer of personal data to the Processor is lawful and whether any required notices, consents, assessments, or authorizations are in place.

19. Data Location

Unless otherwise agreed in writing, the Processor does not guarantee that personal data will be stored in a particular country or region.

Data location may depend on:

  • The selected service

  • Cloud provider architecture

  • Backup systems

  • Subprocessor operations

  • Technical requirements

  • Security requirements

  • Availability requirements

  • Legal requirements

The Controller may request information about data locations where reasonably necessary for compliance purposes.

20. Data Retention

The Processor shall retain personal data only for as long as reasonably necessary to:

  • Provide the services

  • Follow the Controller’s instructions

  • Maintain backups

  • Comply with legal obligations

  • Resolve disputes

  • Protect legal rights

  • Maintain security records

  • Complete deletion procedures

The Controller is responsible for establishing appropriate retention periods for personal data under its control.

The Processor may rely on the Controller’s instructions regarding retention, deletion, archiving, and export.

21. Return, Export, and Deletion of Data

When services end, the Controller may request that personal data be:

  • Returned

  • Exported

  • Transferred to another provider

  • Archived

  • Deleted

  • Destroyed

The Processor shall follow the applicable agreement and reasonable written instructions.

Deletion may not be immediate where data exists in:

  • Backups

  • Disaster recovery systems

  • Security logs

  • Legal records

  • Accounting records

  • Archived systems

  • Technical caches

  • Fraud prevention systems

Where immediate deletion is not technically feasible, the Processor shall seek to ensure that the data is protected and not actively processed except as required for the applicable purpose.

The Processor may retain information where required by law or reasonably necessary to establish, exercise, or defend legal claims.

22. Controller Responsibilities

The Controller shall:

  • Provide lawful and documented instructions

  • Maintain a lawful basis for processing

  • Provide required privacy notices

  • Obtain required consents

  • Ensure data accuracy where appropriate

  • Avoid providing unnecessary personal data

  • Avoid providing sensitive data unless necessary and authorized

  • Manage user permissions

  • Protect its own credentials and systems

  • Respond to Data Subject requests

  • Determine applicable retention periods

  • Assess international transfer requirements

  • Notify the Processor of relevant legal or regulatory requirements

  • Ensure that its use of the services complies with applicable law

The Controller shall not instruct the Processor to process personal data in a manner that violates applicable law.

23. Processor Responsibilities

The Processor shall:

  • Process personal data only for authorized purposes

  • Maintain confidentiality

  • Implement reasonable security measures

  • Restrict access to authorized personnel

  • Assist with reasonable privacy requests

  • Cooperate with incident investigations

  • Maintain appropriate records where required

  • Use subprocessors responsibly

  • Follow applicable deletion or return instructions

  • Notify the Controller of relevant incidents where required

  • Comply with applicable contractual obligations

24. Audits and Compliance Information

Where required by applicable law or contract, the Processor may provide reasonable information demonstrating compliance with this DPA.

This may include:

  • Security summaries

  • Policy documents

  • Compliance statements

  • Questionnaire responses

  • Independent audit reports

  • Certifications

  • Subprocessor information

  • Descriptions of technical safeguards

Audits shall:

  • Be requested with reasonable advance notice

  • Occur during normal business hours

  • Avoid unnecessary disruption

  • Protect confidential information

  • Avoid access to unrelated customer data

  • Comply with security requirements

  • Be limited to information relevant to the services

The Controller may be responsible for reasonable costs associated with extraordinary audits, unless otherwise agreed or required by law.

25. Government and Legal Requests

If the Processor receives a legally binding request for personal data, the Processor may disclose the data where required by law.

Where legally permitted, the Processor may notify the Controller before disclosure and provide reasonable assistance.

The Processor may not be able to notify the Controller where:

  • Notification is legally prohibited

  • The request relates to an investigation

  • Notification could interfere with legal proceedings

  • A government authority requires confidentiality

26. Data Accuracy

The Controller is responsible for the accuracy, completeness, and legality of personal data it provides to the Processor.

The Processor may correct or update personal data based on the Controller’s instructions.

The Processor does not generally verify the accuracy of personal data unless verification is expressly included in the contracted services.

27. Children’s Data

The Controller shall not provide children’s personal data unless:

  • The processing is necessary for the contracted services

  • The Controller has obtained required parental or guardian consent

  • The Controller has complied with applicable child privacy laws

  • The Processor has agreed to process such data

The Processor may suspend processing if it reasonably believes that children’s data is being processed unlawfully or without required authorization.

28. Data Minimization

The Controller should provide only the personal data reasonably necessary for the contracted services.

The Processor may recommend reducing, masking, anonymizing, pseudonymizing, or removing unnecessary personal data where appropriate.

29. Anonymized and Aggregated Information

The Processor may create or use anonymized, de-identified, or aggregated information where permitted by law and where the information cannot reasonably be used to identify an individual.

Such information may be used for:

  • Service improvement

  • Security analysis

  • Performance analysis

  • Statistical reporting

  • Product development

  • Business planning

  • Operational research

The Processor shall not intentionally use anonymized or aggregated information to re-identify individuals.

30. Confidentiality of the DPA

The terms of this DPA may contain confidential business, technical, or security information.

Each party shall protect confidential information received from the other party and use it only for legitimate business or compliance purposes.

31. Relationship with Other Agreements

This DPA supplements the applicable services agreement.

If there is a conflict between this DPA and another agreement:

  1. Applicable privacy law shall control.

  2. The DPA shall control with respect to personal data processing obligations.

  3. The services agreement shall control for commercial, payment, and general service terms.

  4. A specific written data protection agreement may control where expressly stated.

32. Changes to This DPA

The Processor may update this DPA when necessary to reflect:

  • Changes in privacy law

  • Changes in security practices

  • Changes in services

  • Changes in subprocessors

  • Changes in technology

  • Regulatory guidance

  • Business or operational requirements

Material changes may be communicated through the applicable service, contract, website, email, or other reasonable method.

33. No Guarantee of Regulatory Compliance

This DPA is intended to establish reasonable data processing responsibilities. It does not guarantee that the Controller or Processor will satisfy every legal requirement in every jurisdiction.

Each party remains responsible for obtaining its own legal, regulatory, and professional advice.

34. Contact Information

Questions, requests, notices, or concerns relating to this DPA may be sent to:

andabhurji.corp@outlook.com

email@andabhurjiglobal.com

35. Acceptance

By entering into an agreement with Andabhurji Global Solutions that incorporates this DPA, the Controller acknowledges that:

  • It understands the roles of Controller and Processor

  • It understands how personal data may be processed

  • It is responsible for providing lawful instructions

  • It authorizes the use of appropriate subprocessors

  • It understands that international processing may occur

  • It agrees to the return, export, retention, and deletion provisions

  • It accepts the security and confidentiality obligations described in this DPA