🎉 Every plan includes a 14-day free trial - no credit card required. See plans →

Data Processing Agreement

1. Roles of the parties

For personal data the Customer submits to the Service ("Customer Personal Data") - such as the Customer's leads, contacts, and their messages - the Customer is the Data Fiduciary (controller) and DataSmart is the Data Processor. We process Customer Personal Data only on the Customer's documented instructions, which include the Terms of Service, this DPA, and the Customer's use of the Service, unless required otherwise by law.

2. Nature and purpose of processing

Subject matterProvision of the Zublox WhatsApp CRM
DurationFor the term of the subscription, plus the deletion/return period in Section 8
PurposeHosting, storing, and processing Customer Personal Data so the Customer can manage leads, conversations, follow-ups, and pipeline
Types of dataNames, phone numbers, email addresses, company names, deal values, notes, WhatsApp message content, uploaded files, and interaction history
Categories of data principalsThe Customer's leads, prospects, customers, and the Customer's own staff users

3. Our obligations as processor

We will:

  • Process Customer Personal Data only on the Customer's documented instructions and for the purpose of providing the Service;
  • Ensure that persons authorised to process the data are bound by confidentiality;
  • Implement appropriate technical and organisational security measures (see Section 6);
  • Assist the Customer, taking into account the nature of processing, in responding to requests from data principals and in meeting the Customer's own security and breach-notification obligations;
  • Not sell Customer Personal Data or use it for our own advertising.

4. Sub-processors

The Customer authorises DataSmart to engage sub-processors to help provide the Service. We currently use vetted third-party providers in the following categories: cloud hosting/infrastructure, messaging delivery, and secure file storage. Each sub-processor is bound by written terms imposing data-protection obligations no less protective than those in this DPA, and we remain responsible for their performance.

A current list of sub-processor categories (and, where requested by a prospective enterprise customer under confidentiality, named providers) is available at jaimin@dataproconsult.com. We will give the Customer reasonable notice of any intended addition or replacement of a sub-processor, and the Customer may object on reasonable data-protection grounds.

5. Data principal rights

To the extent the Customer cannot address a data principal's request (for access, correction, erasure, or grievance redressal) through the Service itself, we will provide reasonable assistance to enable the Customer to respond, taking into account the nature of the processing.

6. Security measures

  • Encryption of data in transit;
  • Role-based access controls and the principle of least privilege;
  • Logical isolation of each Customer organisation's data (multi-tenant separation);
  • Secure, access-controlled storage of uploaded files;
  • Regular backups and reasonable measures to restore availability after an incident;
  • Internal access limited to personnel who need it to operate and support the Service.

7. Personal-data breach

We will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Personal Data, and provide information reasonably available to help the Customer meet its own notification obligations under the DPDP Act.

8. Return and deletion

On termination or expiry of the subscription, we will, at the Customer's choice, delete or return Customer Personal Data within 60 days, and delete existing copies, except where retention is required by law. On request, we will confirm deletion.

9. Audit and information

We will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and allow for reasonable audits, on reasonable prior notice, no more than once per year (unless required by a regulator), subject to confidentiality and without compromising other customers' security.

10. International processing

Customer Personal Data is currently processed and stored in India. Any future processing in, or transfer to, another jurisdiction will be carried out in accordance with applicable law.

11. Liability and precedence

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. In the event of a conflict between this DPA and the Terms of Service in respect of data protection, this DPA prevails.

12. Governing law

This DPA is governed by the laws of India, with exclusive jurisdiction of the courts at Rajkot, Gujarat, India.

13. Contact

DataSmart Global Consultants LLP
Registered office: Hari Om, Navjyot Park-1, B/H Jade Blue, 150-ft Ring Road, Rajkot, Gujarat 360005, India
Email: jaimin@dataproconsult.com