Data Processing Agreement
This Data Processing Agreement (“DPA”) is entered into under the Digital Personal Data Protection Act, 2023 and applies where Ashutosh Yadav, sole proprietor trading as “terminalash”, having its place of business at Kolkata, West Bengal, India (“terminalash”, “Data Processor”) processes personal data on behalf of a client (“Data Fiduciary”) in providing the Services. It forms part of the Terms of Service between the parties.
01Roles of the parties
The Data Fiduciary (the client) determines the purpose and means of processing its contact data. The Data Processor (terminalash) processes such data only on the documented instructions of the Data Fiduciary, including as set out in the Terms and any campaign brief. The individuals whose data is processed are “Data Principals”.
02Subject matter and duration
The processing concerns the operation of cold email outreach on the Data Fiduciary's behalf and continues for the duration of the engagement, plus any short period reasonably required for return or deletion of the data.
03Nature and purpose of processing
Collecting, storing, organising, sending messages to, and recording responses from contacts, together with related automation and reporting, for the Data Fiduciary's outreach.
04Data Principals and categories of data
- Data Principals: the Data Fiduciary's prospects and business contacts.
- Personal data: typically names, business email addresses, job titles, company details, and message and response content.
The Data Fiduciary shall not provide sensitive or special-category data unless expressly agreed in writing.
05Obligations of the Data Processor
The Data Processor shall:
- process personal data only on the Data Fiduciary's documented instructions;
- ensure that persons authorised to process the data are bound by confidentiality;
- implement reasonable security safeguards to protect the data, consistent with the DPDP Act 2023 and Section 43A of the IT Act 2000;
- assist the Data Fiduciary, so far as reasonably possible, in responding to Data Principal requests and in meeting its security, breach, and compliance obligations;
- notify the Data Fiduciary without undue delay upon becoming aware of a personal data breach, to enable intimation to the Data Protection Board of India and affected Data Principals as required;
- at the choice of the Data Fiduciary, delete or return all personal data at the end of the engagement, subject to any legal retention requirement;
- make available information reasonably necessary to demonstrate compliance with this DPA.
06Sub-processors
The Data Fiduciary authorises the Data Processor to engage sub-processors to deliver the Services. Current categories of sub-processors include: hosting and infrastructure providers, email sending and deliverability providers, and workflow automation tools. The Data Processor will inform the Data Fiduciary of any intended change and remains responsible for its sub-processors' performance.
07Cross-border transfer
The Data Processor operates from India and may transfer personal data internationally in the course of providing the Services. Such transfers are carried out in accordance with the Digital Personal Data Protection Act, 2023 and subject to appropriate safeguards.
08Audit
The Data Processor shall, on reasonable prior notice and not more than once per year (unless required by a regulator), make available information and permit reasonable audits to verify compliance with this DPA, subject to confidentiality obligations.
09Liability
Liability under this DPA is subject to the limitations of liability set out in the Terms of Service.
10Governing law
This DPA is governed by the laws of India, and the courts at Kolkata, West Bengal shall have exclusive jurisdiction, consistent with the Terms of Service.
11Contact
Data protection contact: ashutosh@terminalash.in.
This document is provided for general informational purposes and does not constitute legal advice. terminalash is operated from India and this document is intended to be construed under Indian law.