This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Kayease Global Solutions (“Processor”) and the customer (“Customer”) for Kayease CRM. It applies to personal data the Customer puts into the Service (“Customer Personal Data”), for which the Customer is the data fiduciary under the Digital Personal Data Protection Act, 2023.
1. Instructions
The Processor processes Customer Personal Data only to provide the Service and on the Customer's documented instructions, which are the Terms, this DPA, and the Customer's use of the Service's features. The Processor will tell the Customer if it believes an instruction breaks the law.
2. The Customer's responsibilities
- The Customer has a lawful basis — normally the data principal's consent — for every contact it imports or messages, and gives any notice the law requires.
- The Customer records consent per channel in the Service before messaging, and handles requests from its data principals.
3. Confidentiality and access
Only personnel who need it to run or support the Service can access Customer Personal Data, under confidentiality obligations. Access to a Customer's workspace for support is recorded in that Customer's audit log.
4. Security
The Processor maintains reasonable security safeguards, including:
- logical isolation of each Customer's data, enforced in every query and covered by automated tests;
- role-based access control, hashed passwords and revocable sessions;
- encryption in transit, and encrypted backups;
- an audit log of security-relevant actions;
- dependency vulnerability monitoring and prompt patching.
5. Sub-processors
The Customer authorises the sub-processors listed in the Privacy Policy. The Processor will give at least 30 days' notice of a new sub-processor, during which the Customer may object and, if the objection cannot be resolved, terminate. The Processor remains responsible for its sub-processors.
6. Personal data breaches
The Processor will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a breach affecting Customer Personal Data, with the information the Customer needs to meet its own obligations to inform the Data Protection Board and affected data principals.
7. Assistance
The Processor will help the Customer respond to data principals' requests (access, correction, erasure, grievance) — the Service lets the Customer export, edit, suppress and delete contacts directly — and with any impact assessment the Customer must carry out.
8. Deletion and return
On termination the Customer may export its data for 30 days. The Processor then deletes Customer Personal Data from the live Service, and from backups as they expire, unless the law requires it to be kept. On request, the Processor erases an organisation's data immediately.
9. Audit
The Processor will make available the information reasonably needed to show compliance with this DPA, and will answer reasonable security questionnaires once a year.
10. Transfers
Customer Personal Data may be processed outside India by sub-processors only where the DPDP Act permits it.
Contact
Kayease Global Solutions, Vaishali Nagar, Jaipur - Rajatshan. Data protection queries: support@kayease.com.