Data Processing Agreement
Last updated: September 3, 2026
DPA governing the processing of personal data by Bizeneed as a data processor. This document covers definitions, processing details, security measures, sub-processors, data subject rights, audit rights, and termination provisions.
Definitions
For the purposes of this Data Processing Agreement (DPA): "Controller" means the entity that determines the purposes and means of processing personal data; "Processor" means Bizeneed India Private Limited, which processes personal data on behalf of the Controller; "Data Subject" means the identified or identifiable natural person to whom personal data relates; "Personal Data" means any information relating to a Data Subject; "Processing" means any operation performed on personal data; "Sub-processor" means any processor engaged by Bizeneed to process personal data on behalf of the Controller; and "Applicable Law" means the Digital Personal Data Protection Act, 2023, and any other applicable data protection legislation.
- Controller: entity determining purposes and means of processing personal data
- Processor: Bizeneed India Private Limited processing data on behalf of the Controller
- Data Subject: identified or identifiable natural person to whom personal data relates
- Personal Data: any information relating to a Data Subject
- Processing: any operation performed on personal data including collection, storage, and use
- Sub-processor: any processor engaged by Bizeneed for data processing on behalf of the Controller
Processing Details
Bizeneed processes personal data as a processor on behalf of the Controller for the following purposes: provision of professional services including company registration, GST compliance, trademark applications, and advisory services; storage and management of client data on the Bizeneed platform; communication with data subjects on behalf of the Controller; and compliance reporting and statutory filing support. The nature and purpose of processing, categories of data subjects, categories of personal data, and categories of recipients are as specified in the Data Processing Addendum signed with each Controller.
- Purpose: provision of professional services and platform management
- Nature: processing as instructed by the Controller for service delivery
- Data subjects: clients of the Controller and their authorized representatives
- Personal data categories: identity, contact, financial, and professional data as specified in the addendum
- Recipients: sub-processors, regulatory authorities, and professional advisors as instructed
- Processing duration: as per the Data Retention Policy and Controller instructions
Security Measures
Bizeneed implements and maintains appropriate technical and organizational security measures to ensure a level of security appropriate to the risk of processing. These measures include: encryption of personal data at rest using AES-256 and in transit using TLS 1.3; access controls including role-based access, multi-factor authentication, and least privilege principles; regular security assessments, vulnerability scanning, and penetration testing; data backup and disaster recovery procedures; employee training on data protection and security practices; incident response and breach notification procedures; and logging and monitoring of all access to personal data.
- Encryption at rest (AES-256) and in transit (TLS 1.3)
- Role-based access controls and multi-factor authentication
- Regular security assessments and penetration testing
- Data backup and disaster recovery procedures
- Employee training on data protection and security
- Incident response and breach notification within 72 hours
Sub-processors
The Controller grants Bizeneed a general authorization to engage sub-processors from the list maintained at /list-of-subprocessors. Bizeneed shall ensure that each sub-processor is bound by a written agreement imposing data protection obligations at least as restrictive as those in this DPA. Bizeneed shall notify the Controller of any intended changes to sub-processors at least 30 days in advance, providing the Controller with the opportunity to object. If the Controller objects to a sub-processor and the objection cannot be resolved, Bizeneed may terminate the agreement with appropriate notice.
- General authorization for sub-processors listed at /list-of-subprocessors
- Each sub-processor bound by data protection obligations at least as restrictive as this DPA
- 30 days' advance notice of changes to sub-processors
- Controller has right to object to new sub-processors
- Unresolved objections may result in termination with appropriate notice
- Bizeneend remains liable to Controller for sub-processor performance
Data Subject Rights
Bizeneed shall assist the Controller in responding to data subject requests and ensuring compliance with data subject rights under applicable law. This includes providing information about processing activities, facilitating access requests, supporting rectification and erasure requests, enabling data portability, and respecting objections to processing. Bizeneed shall promptly notify the Controller of any data subject request received directly and shall not respond to such requests without the Controller's prior authorization unless required by law.
- Assist Controller in responding to data subject rights requests
- Notify Controller promptly of any data subject requests received directly
- Not respond to direct data subject requests without Controller authorization
- Provide information about processing activities as requested by Controller
- Facilitate access, rectification, erasure, and portability requests as instructed
- Comply with applicable data subject rights timelines as directed by Controller
Audit Rights
The Controller has the right to audit Bizeneed's compliance with this DPA. Audits shall be conducted with at least 30 days' prior notice, during normal business hours, and shall not unreasonably interfere with Bizeneed's business operations. The Controller may conduct a maximum of one audit per calendar year at its own expense. If material non-compliance is found, Bizeneed shall be given 30 days to remediate. If remediation is not achieved, the Controller may terminate the agreement with 60 days' notice. Bizeneed shall provide all reasonable cooperation and access to documentation, personnel, and systems during audits.
- Controller has right to audit DPA compliance with 30 days' prior notice
- Maximum one audit per calendar year at Controller's expense
- Audits conducted during normal business hours without unreasonable interference
- Material non-compliance: 30 days to remediate, 60 days' notice to terminate if unresolved
- Bizeneed provides reasonable cooperation, documentation, and system access
- Third-party audit reports may be provided in lieu of on-site audit by mutual agreement
Term & Termination
This DPA shall remain in effect for the duration of the data processing relationship between Bizeneed and the Controller. Either party may terminate this DPA with 30 days' written notice. Upon termination or expiration, Bizeneed shall, at the Controller's choice, delete or return all personal data and provide certification of deletion. Bizeneed shall continue to protect the confidentiality of personal data after termination. Surviving obligations include confidentiality, data return/deletion, and audit rights for a period of 3 years following termination.
- DPA remains in effect for the duration of the data processing relationship
- 30 days' written notice for termination by either party
- Upon termination: delete or return all personal data as directed by Controller
- Provide certification of data deletion or return
- Continue protecting confidentiality of personal data after termination
- Surviving obligations: confidentiality, data handling, and audit rights for 3 years
For DPA inquiries, contact us at dpo@bizeneed.in