Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Customer and DataSmart Global Consultants LLP ("DataSmart", "we", "us"), operator of the Zublox WhatsApp CRM (the "Service"). It governs our processing of personal data that the Customer submits to the Service, and is designed to reflect the requirements of India's Digital Personal Data Protection Act, 2023 (the "DPDP Act").
1. Roles of the parties
For personal data the Customer submits to the Service ("Customer Personal Data") - such as the Customer's leads, contacts, and their messages - the Customer is the Data Fiduciary (controller) and DataSmart is the Data Processor. We process Customer Personal Data only on the Customer's documented instructions, which include the Terms of Service, this DPA, and the Customer's use of the Service, unless required otherwise by law.
2. Nature and purpose of processing
| Subject matter | Provision of the Zublox WhatsApp CRM |
|---|---|
| Duration | For the term of the subscription, plus the deletion/return period in Section 8 |
| Purpose | Hosting, storing, and processing Customer Personal Data so the Customer can manage leads, conversations, follow-ups, and pipeline |
| Types of data | Names, phone numbers, email addresses, company names, deal values, notes, WhatsApp message content, uploaded files, and interaction history |
| Categories of data principals | The Customer's leads, prospects, customers, and the Customer's own staff users |
3. Our obligations as processor
We will:
- Process Customer Personal Data only on the Customer's documented instructions and for the purpose of providing the Service;
- Ensure that persons authorised to process the data are bound by confidentiality;
- Implement appropriate technical and organisational security measures (see Section 6);
- Assist the Customer, taking into account the nature of processing, in responding to requests from data principals and in meeting the Customer's own security and breach-notification obligations;
- Not sell Customer Personal Data or use it for our own advertising.
4. Sub-processors
The Customer authorises DataSmart to engage sub-processors to help provide the Service. We currently use vetted third-party providers in the following categories: cloud hosting/infrastructure, messaging delivery, and secure file storage. Each sub-processor is bound by written terms imposing data-protection obligations no less protective than those in this DPA, and we remain responsible for their performance.
A current list of sub-processor categories (and, where requested by a prospective enterprise customer under confidentiality, named providers) is available at jaimin@dataproconsult.com. We will give the Customer reasonable notice of any intended addition or replacement of a sub-processor, and the Customer may object on reasonable data-protection grounds.
5. Data principal rights
To the extent the Customer cannot address a data principal's request (for access, correction, erasure, or grievance redressal) through the Service itself, we will provide reasonable assistance to enable the Customer to respond, taking into account the nature of the processing.
6. Security measures
- Encryption of data in transit;
- Role-based access controls and the principle of least privilege;
- Logical isolation of each Customer organisation's data (multi-tenant separation);
- Secure, access-controlled storage of uploaded files;
- Regular backups and reasonable measures to restore availability after an incident;
- Internal access limited to personnel who need it to operate and support the Service.
7. Personal-data breach
We will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and provide information reasonably available to help the Customer meet its own notification obligations under the DPDP Act.
8. Return and deletion
On termination or expiry of the subscription, we will, at the Customer's choice, delete or return Customer Personal Data within 60 days, and delete existing copies, except where retention is required by law. On request, we will confirm deletion.
9. Audit and information
We will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and allow for reasonable audits, on reasonable prior notice, no more than once per year (unless required by a regulator), subject to confidentiality and without compromising other customers' security.
10. International processing
Customer Personal Data is currently processed and stored in India. Any future processing in, or transfer to, another jurisdiction will be carried out in accordance with applicable law.
11. Liability and precedence
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. In the event of a conflict between this DPA and the Terms of Service in respect of data protection, this DPA prevails.
12. Governing law
This DPA is governed by the laws of India, with exclusive jurisdiction of the courts at Rajkot, Gujarat, India.
13. Contact
DataSmart Global Consultants LLP
Registered office: Hari Om, Navjyot Park-1, B/H Jade Blue, 150-ft Ring Road, Rajkot, Gujarat 360005, India
Email: jaimin@dataproconsult.com