Data Processing Addendum (DPA)
Last Updated: September 1, 2026
1. What This Data Processing Addendum Means
This Data Processing Addendum, also called a “DPA,” explains how Andabhurji Global Solutions handles personal data when providing services to a client.
A DPA is a legal document used when one organization handles personal data on behalf of another organization. It helps clarify:
What personal data may be processed
Why the data may be processed
Which party is responsible for making decisions about the data
Which party is responsible for carrying out processing activities
What security and confidentiality obligations apply
How service providers and subprocessors may be used
What happens if a security incident occurs
What happens to the data when services end
This DPA forms part of the agreement between Andabhurji Global Solutions, referred to as the “Processor,” and the customer or client, referred to as the “Controller.”
Depending on the applicable privacy law, the parties may also be referred to as:
Business and Service Provider
Data Fiduciary and Data Processor
Customer and Vendor
Organization and Contractor
The applicable legal terminology may vary by jurisdiction, but the responsibilities described in this DPA remain substantially similar.
2. Parties and Their Roles
2.1 Controller
The Controller is the organization that decides:
Why personal data is collected
What personal data is collected
How the data should be used
How long the data should be retained
Who may access the data
Whether the data may be shared with other parties
For example, a client may decide to collect customer names, email addresses, phone numbers, order information, employee records, or support requests.
The Controller is generally responsible for ensuring that it has a lawful basis, appropriate notices, permissions, consents, and authorizations to collect and provide personal data to the Processor.
2.2 Processor
The Processor is the organization that processes personal data on behalf of the Controller and according to the Controller’s instructions.
Andabhurji Global Solutions may act as a Processor when providing services such as:
Software implementation
Website development
Application development
Cloud configuration
Data migration
Customer support
Digital marketing technology services
Automation services
Hosting or infrastructure support
E-commerce implementation
Marketplace integration
Analytics configuration
Business process consulting
Technical maintenance
Andabhurji Global Solutions does not generally decide the business purpose for which the client’s personal data is collected. Instead, it processes the data as necessary to provide the contracted services.
2.3 Independent Controller Activities
In some situations, Andabhurji Global Solutions may process personal data as an independent Controller rather than as a Processor. This may include data used for:
Managing business relationships
Processing invoices and payments
Maintaining accounting records
Responding to inquiries
Managing contracts
Preventing fraud or misuse
Complying with legal obligations
Protecting legal rights
Managing security and access records
Communicating with customers and business contacts
This DPA applies only to personal data processed by Andabhurji Global Solutions on behalf of the Client.
3. Definitions
For purposes of this DPA:
3.1 Personal Data
Personal Data means information that identifies, relates to, describes, or can reasonably be linked to an individual.
Examples may include:
Name
Email address
Telephone number
Postal address
Account credentials
Identification numbers
IP address
Device information
Location information
Purchase history
Customer support records
Employment information
Online identifiers
Payment-related information
Any other information protected as personal data under applicable law
3.2 Processing
Processing means any operation performed on personal data, whether automated or manual.
Processing may include:
Collecting
Recording
Organizing
Storing
Accessing
Reviewing
Retrieving
Using
Transmitting
Sharing
Modifying
Combining
Exporting
Archiving
Deleting
Destroying
3.3 Data Subject
A Data Subject is the individual to whom personal data relates.
Examples include:
Customers
Employees
Contractors
Website visitors
Users
Patients
Students
Suppliers
Business contacts
Marketplace users
3.4 Subprocessor
A Subprocessor is a third-party service provider engaged by the Processor to process personal data on behalf of the Controller.
Examples may include:
Cloud hosting providers
Data storage providers
Email delivery providers
Customer support platforms
Payment service providers
Analytics providers
Security providers
Backup providers
Communication platforms
Technical integration providers
4. Scope of Processing
The Processor may process personal data only as necessary to provide the services described in the applicable:
Master services agreement
Statement of work
Order form
Quotation
Project proposal
Subscription plan
Support agreement
Implementation agreement
Written instructions from the Controller
The Processor shall not use the personal data for unrelated purposes unless:
The Controller provides written authorization
The processing is required by applicable law
The processing is necessary to protect the security of the services
The processing is necessary to prevent fraud, abuse, or misuse
The Processor is acting as an independent Controller for a separate lawful purpose
5. Processing Instructions
The Processor shall process personal data only on documented instructions from the Controller.
Instructions may be provided through:
A signed agreement
A statement of work
A project specification
A support ticket
An authorized email
A system configuration
An approved integration
A written change request
Other documented business instructions
The Controller is responsible for ensuring that its instructions are lawful and do not require the Processor to violate applicable privacy, security, or other laws.
If the Processor reasonably believes that an instruction violates applicable law, the Processor may:
Request clarification
Suspend the affected processing activity
Decline to perform the unlawful activity
Notify the Controller of the concern
Take other steps reasonably necessary to comply with legal obligations
6. Categories of Personal Data
Depending on the services provided, the Processor may process the following categories of personal data:
Names and contact details
Business contact information
Account and login information
Customer or user identification information
Transaction and order information
Billing and payment-related information
Support and communication records
Employment or contractor information
Technical and device information
IP addresses and online identifiers
Usage and activity information
Location information
Preferences and account settings
Information contained in uploaded files or documents
The actual categories of personal data processed will depend on the services, systems, applications, integrations, and instructions provided by the Controller.
7. Special Categories and Sensitive Personal Data
The Controller should not provide sensitive personal data or special categories of personal data unless:
The processing is necessary for the contracted services
The Controller has a lawful basis for processing
The Controller has provided appropriate instructions
Appropriate safeguards are in place
The processing is permitted under applicable law
Sensitive information may include:
Government identification numbers
Financial account information
Health information
Biometric information
Genetic information
Precise location information
Information about racial or ethnic origin
Religious or philosophical beliefs
Political opinions
Trade union membership
Information about criminal allegations or convictions
Information concerning children
Unless expressly agreed in writing, the Processor does not require the Controller to provide sensitive personal data for ordinary software, consulting, development, design, or implementation services.
The Controller remains responsible for determining whether sensitive personal data may lawfully be collected, disclosed, transferred, or processed.
8. Processing Activities
The Processor may process personal data for the following purposes, where applicable:
Providing contracted services
Configuring software and systems
Implementing websites and applications
Migrating or importing data
Maintaining databases
Providing technical support
Troubleshooting errors
Managing user accounts
Operating integrations
Providing hosting or infrastructure services
Performing backups and recovery
Monitoring service performance
Maintaining security
Preventing fraud and abuse
Communicating with authorized client representatives
Generating service-related reports
Complying with legal obligations
Performing other activities expressly authorized by the Controller
9. Duration of Processing
The Processor may process personal data for the duration of the applicable service relationship.
Processing may continue after termination where necessary to:
Complete an authorized transition
Return or export data
Comply with legal obligations
Maintain required business records
Resolve disputes
Establish, exercise, or defend legal claims
Maintain security logs
Complete backup deletion cycles
Protect the rights and safety of the parties
10. Confidentiality Obligations
The Processor shall ensure that individuals authorized to process personal data:
Are informed of their confidentiality obligations
Access personal data only when necessary
Use personal data only for authorized purposes
Do not disclose personal data without authorization
Protect personal data after their employment or engagement ends
Confidentiality obligations may arise through:
Employment agreements
Contractor agreements
Non-disclosure agreements
Internal policies
Professional obligations
Contractual commitments
11. Security Measures
The Processor shall implement reasonable technical and organizational measures designed to protect personal data against:
Accidental loss
Unauthorized access
Unauthorized disclosure
Unauthorized alteration
Destruction
Misuse
Unlawful processing
Security threats
Service disruption
Depending on the nature of the services and risks involved, safeguards may include:
Access controls
Role-based permissions
Authentication controls
Password protection
Multi-factor authentication where available
Encryption in transit
Encryption at rest where appropriate
Network security controls
Malware protection
Vulnerability management
Security monitoring
Logging and audit trails
Backup procedures
Disaster recovery procedures
Business continuity planning
Secure development practices
Change management
Incident response procedures
Vendor security reviews
Employee confidentiality obligations
Security awareness training
Security measures may vary depending on:
The type of service
The sensitivity of the data
The volume of data
The nature of the processing
The likelihood and severity of potential harm
Available technology
Implementation costs
Applicable legal requirements
No security measure can guarantee absolute protection against every possible threat.
12. Access Controls
The Processor shall seek to limit access to personal data to authorized personnel who require access to perform their assigned responsibilities.
Access may be granted based on:
Job responsibilities
Project requirements
Support needs
Administrative duties
Security requirements
Contractual obligations
Access rights may be reviewed, modified, or removed when:
A person changes roles
A project ends
A contract ends
Access is no longer necessary
A security concern arises
The Controller requests removal where reasonably possible
13. Assistance with Data Subject Requests
The Controller is generally responsible for responding to requests from Data Subjects.
Data Subject requests may include requests to:
Access personal data
Correct inaccurate information
Delete personal data
Restrict processing
Object to processing
Receive a portable copy of data
Withdraw consent
Obtain information about processing
Exercise other rights under applicable law
Where the Processor receives a Data Subject request relating to the Controller’s personal data, the Processor may:
Forward the request to the Controller
Notify the requester that the Controller is responsible
Provide reasonable assistance to the Controller
Search for relevant data where technically feasible
Correct, export, restrict, or delete data based on the Controller’s documented instructions
The Processor shall not independently respond to or fulfill a request in a manner that conflicts with the Controller’s instructions or applicable law.
The Controller is responsible for:
Verifying the identity of the requester
Determining whether the request is legally valid
Determining whether an exemption applies
Providing the required response
Communicating with the Data Subject
Paying reasonable costs associated with extraordinary assistance, where permitted
14. Assistance with Privacy Compliance
Taking into account the nature of the processing and information available to the Processor, the Processor may provide reasonable assistance with:
Security assessments
Data protection impact assessments
Privacy risk assessments
Regulatory inquiries
Data breach investigations
Data subject requests
Records of processing
Data retention procedures
Data deletion requests
International transfer assessments
The Processor may charge reasonable fees for assistance that is unusually extensive, repetitive, technically complex, or outside the agreed scope of services, unless prohibited by applicable law or contract.
15. Security Incident Notification
A Security Incident means a confirmed or reasonably suspected event that compromises the security, confidentiality, integrity, or availability of personal data.
Examples may include:
Unauthorized access
Unauthorized disclosure
Accidental transmission
Loss of a device containing personal data
Destruction of personal data
Ransomware
Malware
Credential compromise
Unauthorized alteration
Improper deletion
System intrusion
The Processor shall notify the Controller of a confirmed Security Incident involving the Controller’s personal data where required by applicable law or contract.
The notification may include, where available:
A description of the incident
The approximate date and time
The categories of affected data
The approximate number of affected individuals
The likely consequences
Measures taken or proposed to address the incident
Contact information for follow-up
The Processor may provide information in stages as it becomes available.
The Processor shall take reasonable steps to:
Investigate the incident
Contain the incident
Reduce potential harm
Restore affected services
Preserve relevant evidence
Cooperate with the Controller
Implement corrective measures
The Controller remains responsible for determining whether notification must be made to regulators, Data Subjects, customers, employees, or other parties, unless the parties agree otherwise in writing.
16. Subprocessors
The Controller authorizes the Processor to engage subprocessors where reasonably necessary to provide the contracted services.
Subprocessors may include:
Cloud infrastructure providers
Hosting providers
Data storage providers
Backup providers
Email and communication providers
Payment processors
Fulfillment providers
Customer support platforms
Analytics providers
Security providers
Software vendors
API providers
Professional advisers
Technical contractors
The Processor shall seek to require subprocessors to maintain privacy and security obligations appropriate to the services they provide.
The Processor remains responsible for the performance of its subprocessors to the extent required by applicable law and the applicable agreement.
The Controller may request information about relevant subprocessors, subject to confidentiality, security, and commercial restrictions.
17. Changes to Subprocessors
The Processor may add, replace, or remove subprocessors when reasonably necessary to operate, improve, secure, or support the services.
Where required by applicable law or contract, the Processor may provide notice of material changes.
The Controller may raise a reasonable objection where it has legitimate data protection concerns. The parties shall attempt to resolve the concern in good faith.
If the concern cannot reasonably be resolved, the parties may discuss alternative arrangements, service changes, or termination rights available under the applicable agreement.
18. International Data Transfers
Personal data may be processed or transferred across national borders when necessary to provide the services.
International transfers may involve:
Cloud hosting locations
Technical support locations
Communication providers
Payment providers
Backup locations
Subprocessor locations
Data centers
Business operations
The parties shall seek to use appropriate safeguards where required by applicable law.
Safeguards may include:
Adequacy decisions
Standard contractual clauses
Data transfer agreements
Binding corporate rules
Contractual protections
Technical safeguards
Encryption
Access restrictions
Data minimization
Other legally recognized transfer mechanisms
The Controller is responsible for determining whether its transfer of personal data to the Processor is lawful and whether any required notices, consents, assessments, or authorizations are in place.
19. Data Location
Unless otherwise agreed in writing, the Processor does not guarantee that personal data will be stored in a particular country or region.
Data location may depend on:
The selected service
Cloud provider architecture
Backup systems
Subprocessor operations
Technical requirements
Security requirements
Availability requirements
Legal requirements
The Controller may request information about data locations where reasonably necessary for compliance purposes.
20. Data Retention
The Processor shall retain personal data only for as long as reasonably necessary to:
Provide the services
Follow the Controller’s instructions
Maintain backups
Comply with legal obligations
Resolve disputes
Protect legal rights
Maintain security records
Complete deletion procedures
The Controller is responsible for establishing appropriate retention periods for personal data under its control.
The Processor may rely on the Controller’s instructions regarding retention, deletion, archiving, and export.
21. Return, Export, and Deletion of Data
When services end, the Controller may request that personal data be:
Returned
Exported
Transferred to another provider
Archived
Deleted
Destroyed
The Processor shall follow the applicable agreement and reasonable written instructions.
Deletion may not be immediate where data exists in:
Backups
Disaster recovery systems
Security logs
Legal records
Accounting records
Archived systems
Technical caches
Fraud prevention systems
Where immediate deletion is not technically feasible, the Processor shall seek to ensure that the data is protected and not actively processed except as required for the applicable purpose.
The Processor may retain information where required by law or reasonably necessary to establish, exercise, or defend legal claims.
22. Controller Responsibilities
The Controller shall:
Provide lawful and documented instructions
Maintain a lawful basis for processing
Provide required privacy notices
Obtain required consents
Ensure data accuracy where appropriate
Avoid providing unnecessary personal data
Avoid providing sensitive data unless necessary and authorized
Manage user permissions
Protect its own credentials and systems
Respond to Data Subject requests
Determine applicable retention periods
Assess international transfer requirements
Notify the Processor of relevant legal or regulatory requirements
Ensure that its use of the services complies with applicable law
The Controller shall not instruct the Processor to process personal data in a manner that violates applicable law.
23. Processor Responsibilities
The Processor shall:
Process personal data only for authorized purposes
Maintain confidentiality
Implement reasonable security measures
Restrict access to authorized personnel
Assist with reasonable privacy requests
Cooperate with incident investigations
Maintain appropriate records where required
Use subprocessors responsibly
Follow applicable deletion or return instructions
Notify the Controller of relevant incidents where required
Comply with applicable contractual obligations
24. Audits and Compliance Information
Where required by applicable law or contract, the Processor may provide reasonable information demonstrating compliance with this DPA.
This may include:
Security summaries
Policy documents
Compliance statements
Questionnaire responses
Independent audit reports
Certifications
Subprocessor information
Descriptions of technical safeguards
Audits shall:
Be requested with reasonable advance notice
Occur during normal business hours
Avoid unnecessary disruption
Protect confidential information
Avoid access to unrelated customer data
Comply with security requirements
Be limited to information relevant to the services
The Controller may be responsible for reasonable costs associated with extraordinary audits, unless otherwise agreed or required by law.
25. Government and Legal Requests
If the Processor receives a legally binding request for personal data, the Processor may disclose the data where required by law.
Where legally permitted, the Processor may notify the Controller before disclosure and provide reasonable assistance.
The Processor may not be able to notify the Controller where:
Notification is legally prohibited
The request relates to an investigation
Notification could interfere with legal proceedings
A government authority requires confidentiality
26. Data Accuracy
The Controller is responsible for the accuracy, completeness, and legality of personal data it provides to the Processor.
The Processor may correct or update personal data based on the Controller’s instructions.
The Processor does not generally verify the accuracy of personal data unless verification is expressly included in the contracted services.
27. Children’s Data
The Controller shall not provide children’s personal data unless:
The processing is necessary for the contracted services
The Controller has obtained required parental or guardian consent
The Controller has complied with applicable child privacy laws
The Processor has agreed to process such data
The Processor may suspend processing if it reasonably believes that children’s data is being processed unlawfully or without required authorization.
28. Data Minimization
The Controller should provide only the personal data reasonably necessary for the contracted services.
The Processor may recommend reducing, masking, anonymizing, pseudonymizing, or removing unnecessary personal data where appropriate.
29. Anonymized and Aggregated Information
The Processor may create or use anonymized, de-identified, or aggregated information where permitted by law and where the information cannot reasonably be used to identify an individual.
Such information may be used for:
Service improvement
Security analysis
Performance analysis
Statistical reporting
Product development
Business planning
Operational research
The Processor shall not intentionally use anonymized or aggregated information to re-identify individuals.
30. Confidentiality of the DPA
The terms of this DPA may contain confidential business, technical, or security information.
Each party shall protect confidential information received from the other party and use it only for legitimate business or compliance purposes.
31. Relationship with Other Agreements
This DPA supplements the applicable services agreement.
If there is a conflict between this DPA and another agreement:
Applicable privacy law shall control.
The DPA shall control with respect to personal data processing obligations.
The services agreement shall control for commercial, payment, and general service terms.
A specific written data protection agreement may control where expressly stated.
32. Changes to This DPA
The Processor may update this DPA when necessary to reflect:
Changes in privacy law
Changes in security practices
Changes in services
Changes in subprocessors
Changes in technology
Regulatory guidance
Business or operational requirements
Material changes may be communicated through the applicable service, contract, website, email, or other reasonable method.
33. No Guarantee of Regulatory Compliance
This DPA is intended to establish reasonable data processing responsibilities. It does not guarantee that the Controller or Processor will satisfy every legal requirement in every jurisdiction.
Each party remains responsible for obtaining its own legal, regulatory, and professional advice.
34. Contact Information
Questions, requests, notices, or concerns relating to this DPA may be sent to:
35. Acceptance
By entering into an agreement with Andabhurji Global Solutions that incorporates this DPA, the Controller acknowledges that:
It understands the roles of Controller and Processor
It understands how personal data may be processed
It is responsible for providing lawful instructions
It authorizes the use of appropriate subprocessors
It understands that international processing may occur
It agrees to the return, export, retention, and deletion provisions
It accepts the security and confidentiality obligations described in this DPA