Legal

Data Processing Agreement

Effective: July 20, 2026Company: Nunmathi Technologies Pvt Ltd
On This Page

1. Introduction & Parties

This Data Processing Agreement ("DPA") forms part of the Master Services Agreement or other written agreement ("Agreement") between the enterprise customer identified in the applicable Order Form ("Controller" or "Customer") and Nunmathi Technologies Private Limited, a company incorporated under the Companies Act, 2013, with its registered office at NO.1A, Street-5, R K Nagar, Irugur, Coimbatore – 641103, Tamil Nadu, India ("Processor" or "Nunmathi").

This DPA is effective as of July 20, 2026, or the date on which the Customer first accesses or uses the Services, whichever is earlier. In the event of any conflict between this DPA and the Agreement, the terms of this DPA shall prevail with respect to the processing of Personal Data.

Regulatory Scope: This DPA is designed to satisfy the requirements of the European Union General Data Protection Regulation (EU GDPR), the United Kingdom GDPR (UK GDPR), and the Digital Personal Data Protection Act, 2023 (India DPDP Act). Where the laws differ, Nunmathi adopts the stricter standard to the extent technically and commercially feasible.

2. Definitions

For the purposes of this DPA, the following terms shall have the meanings set out below:

  • "Personal Data" means any information relating to an identified or identifiable natural person (a "data subject"), including but not limited to names, email addresses, identification numbers, location data, online identifiers, and any data that, in combination, could identify a person, as defined under the GDPR and the DPDP Act.
  • "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
  • "Controller" means the natural or legal person who determines the purposes and means of the processing of Personal Data.
  • "Processor" means the natural or legal person who processes Personal Data on behalf of the Controller.
  • "Sub-Processor" means any third party engaged by Nunmathi to process Personal Data on behalf of the Controller.
  • "Data Subject" means the identified or identifiable natural person to whom the Personal Data relates.
  • "Supervisory Authority" means an independent public authority established under applicable data protection law, including the Data Protection Board of India under the DPDP Act.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed.
  • "Standard Contractual Clauses" or "SCCs" means the contractual clauses adopted by the European Commission pursuant to Article 46(2)(c) of the GDPR for the transfer of personal data to third countries.
  • "Services" means the AI-powered software products, platforms, and professional services provided by Nunmathi to the Customer under the Agreement.

3. Scope of Processing

3.1 Nature and Purpose

Nunmathi processes Personal Data solely to deliver the Services described in the Agreement and any applicable Order Forms. Processing activities may include data ingestion, model inference, analytics, report generation, storage, and support-related operations.

3.2 Categories of Personal Data

The Customer may submit Personal Data to the Services covering, but not limited to, the following categories:

  • Identification data (name, employee ID, national identification numbers)
  • Contact data (email address, telephone number, postal address)
  • Professional data (job title, department, employer)
  • Usage data (log files, IP addresses, session identifiers, browser type)
  • Operational data uploaded or generated through use of the Services
  • Any special categories of data only if explicitly agreed in writing

3.3 Categories of Data Subjects

Data subjects may include the Customer's employees, contractors, end-users, customers, and other individuals whose data is submitted to the Services.

3.4 Duration

Processing will continue for the term of the Agreement unless terminated earlier in accordance with Section 14 of this DPA.

4. Controller & Processor Obligations

4.1 Controller Obligations

The Customer, as Controller, represents and warrants that:

  • It has a lawful basis for processing Personal Data under applicable law and has provided all required notices and obtained all necessary consents from Data Subjects.
  • It has the authority to enter into this DPA and to disclose Personal Data to Nunmathi for processing as described herein.
  • The instructions it gives to Nunmathi comply with applicable data protection laws.
  • It will promptly inform Nunmathi of any changes to applicable data protection laws that may affect Nunmathi's processing activities.

4.2 Processor Obligations

Nunmathi, as Processor, undertakes to:

  • Process Personal Data only on documented instructions from the Controller, including with regard to international transfers, unless required to do so by applicable law.
  • Ensure that persons authorised to process Personal Data are subject to appropriate confidentiality obligations.
  • Implement appropriate technical and organisational security measures as described in Section 6.
  • Assist the Controller in responding to Data Subject requests and in meeting its obligations under applicable data protection law.
  • Delete or return all Personal Data upon termination of the Agreement, as specified in Section 12.
  • Maintain records of all processing activities carried out on behalf of the Controller.
  • Cooperate with the Supervisory Authority and make available all information necessary to demonstrate compliance.

5. Processing Instructions

Nunmathi shall process Personal Data only in accordance with the Customer's documented instructions. The Agreement, this DPA, and any Order Forms or written instructions issued pursuant thereto constitute the Customer's complete and authorised instructions to Nunmathi.

If Nunmathi is required by applicable Union, Member State, or Indian law to process Personal Data other than as instructed, Nunmathi shall inform the Customer of that legal requirement before processing, unless that law prohibits such notification on important grounds of public interest.

Important: Where Nunmathi determines, in its reasonable opinion, that an instruction from the Customer infringes the GDPR, DPDP Act, or other applicable data protection law, it shall immediately notify the Customer. Nunmathi shall not be obliged to follow any instruction that would cause it to violate applicable law.

6. Security Measures

Nunmathi shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons.

6.1 Technical & Organisational Security Measures (TOMs)

CategoryMeasureImplementation Detail
Access ControlRole-based access control (RBAC)Least-privilege principles enforced; access reviewed quarterly
Access ControlMulti-factor authentication (MFA)MFA mandatory for all internal systems and cloud consoles
EncryptionEncryption at restAES-256 encryption for all stored Personal Data
EncryptionEncryption in transitTLS 1.2+ enforced for all data transmissions; TLS 1.3 preferred
Network SecurityFirewalls & intrusion detectionWeb Application Firewall (WAF), network segmentation, IDS/IPS monitoring
Vulnerability ManagementPatch management & scanningCritical patches applied within 72 hours; monthly vulnerability scans
Vulnerability ManagementPenetration testingAnnual third-party penetration testing; results remediated on risk-priority basis
AvailabilityBusiness continuity & disaster recoveryRTO < 4 hours; RPO < 1 hour; geo-redundant backups encrypted and tested quarterly
Logging & MonitoringAudit loggingAll access and processing events logged with tamper-evident audit trails; retained for 12 months
Logging & MonitoringSecurity incident monitoring24/7 SIEM monitoring; security operations reviewed continuously
Physical SecurityData centre securityISO 27001-certified data centres; badge access, CCTV, biometric controls
PersonnelSecurity trainingMandatory annual security awareness training for all staff; background checks on hire
Data MinimisationPseudonymisation & anonymisationApplied where technically feasible; data minimisation enforced at system design level
Vendor ManagementThird-party risk assessmentsAll sub-processors assessed against Nunmathi security standards before onboarding

Nunmathi shall review and, where necessary, update these measures on a regular basis to ensure they remain appropriate in light of evolving threats and technological developments.

7. Sub-Processors

7.1 Authorisation

The Customer grants Nunmathi general written authorisation to engage Sub-Processors for the provision of the Services. Nunmathi shall maintain an up-to-date list of Sub-Processors and shall notify the Customer at least 30 days in advance of any intended changes, giving the Customer an opportunity to object on reasonable grounds relating to data protection.

7.2 Current Approved Sub-Processors

Sub-ProcessorParent EntityLocationProcessing ActivityTransfer Mechanism
Amazon Web Services (AWS)Amazon.com, Inc.USA / India (ap-south-1)Cloud infrastructure, storage, compute, managed database servicesSCCs / AWS Data Processing Addendum
Google Cloud Platform (GCP)Google LLCUSA / India (asia-south1)AI/ML model hosting, analytics, BigQuery data warehousingSCCs / Google Cloud DPA
Microsoft AzureMicrosoft CorporationUSA / India (Central India)Cognitive services, OpenAI API access, identity management (Azure AD)SCCs / Microsoft DPA
StripeStripe, Inc.USAPayment processing (limited to billing contact and payment method data)SCCs / Stripe DPA

7.3 Sub-Processor Obligations

Nunmathi shall impose data protection obligations on each Sub-Processor equivalent to those set out in this DPA by way of a written contract. Nunmathi remains fully liable to the Controller for the performance of Sub-Processors' obligations.

8. International Data Transfers

Where Personal Data originating from the European Economic Area (EEA), United Kingdom, or Switzerland is transferred outside those jurisdictions, or where data subject to the DPDP Act is transferred outside India, Nunmathi shall ensure that such transfers are subject to appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs) as approved by the European Commission (Module 2: Controller to Processor) for EEA data;
  • The International Data Transfer Agreement (IDTA) or addendum for UK data;
  • Adequacy decisions, where applicable;
  • Binding Corporate Rules, where applicable; and
  • Compliance with the cross-border transfer restrictions and approved transfer mechanisms under the DPDP Act and associated rules.

By signing the Agreement or by accepting this DPA, the Customer agrees to the SCCs (including any applicable annexes) as if they were set out in full herein, with Nunmathi as the data importer and the Customer as the data exporter where applicable.

9. Data Subject Rights

Nunmathi shall, taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures in responding to requests by Data Subjects exercising their rights under applicable data protection law. These rights include:

  • Right of Access: The right to obtain confirmation of processing and a copy of Personal Data.
  • Right to Rectification: The right to have inaccurate Personal Data corrected.
  • Right to Erasure: The right to request deletion of Personal Data in certain circumstances.
  • Right to Restriction: The right to restrict processing in certain circumstances.
  • Right to Data Portability: The right to receive Personal Data in a structured, machine-readable format.
  • Right to Object: The right to object to processing based on legitimate interests or direct marketing.
  • Rights under the DPDP Act: The right to access information, right to correction, right to erasure, and right to grievance redressal as prescribed by the DPDP Act 2023.

Upon receipt of a Data Subject request directed to Nunmathi, Nunmathi shall promptly notify the Controller and shall not respond to the Data Subject directly unless authorised by the Controller or required by applicable law. Nunmathi shall assist the Controller in fulfilling requests within the statutory timeframes.

10. Audit Rights

Nunmathi shall make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations laid down in this DPA and shall allow for and contribute to audits, including inspections, conducted by the Customer or a mandated auditor.

In the first instance, Nunmathi shall provide the Customer with up-to-date third-party audit reports (including SOC 2 Type II reports, ISO 27001 certificates, or equivalent) to satisfy audit obligations. Physical on-site audits shall be conducted:

  • No more than once per calendar year, unless required by a Supervisory Authority;
  • With at least 30 days' prior written notice;
  • During normal business hours and without disrupting operations;
  • At the Customer's expense, unless the audit reveals a material breach by Nunmathi.

11. Breach Notification

In the event of a Personal Data Breach affecting Personal Data processed on behalf of the Customer, Nunmathi shall:

  • Notify the Customer without undue delay, and in any event within 48 hours of becoming aware of the breach;
  • Provide sufficient information to enable the Customer to meet its own notification obligations to Supervisory Authorities (within 72 hours under GDPR) and affected Data Subjects;
  • Cooperate fully with the Customer's incident response and mitigation efforts;
  • Provide ongoing updates as more information becomes available.

Breach notifications shall include, to the extent then known:

  • The nature of the breach, including the categories and approximate number of data subjects and personal data records affected;
  • The likely consequences of the breach;
  • The measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects;
  • Contact details of Nunmathi's designated point of contact.
Note: Notification under this section does not constitute an admission of fault or liability by Nunmathi. The Customer remains responsible for notifying the relevant Supervisory Authority and Data Subjects where required by applicable law.

12. Data Deletion & Return

Upon termination or expiry of the Agreement for any reason, or upon written request from the Customer, Nunmathi shall, at the Customer's election:

  • Securely return all Personal Data to the Customer in a standard machine-readable format; and/or
  • Securely delete or destroy all Personal Data, including all copies thereof held by Nunmathi and its Sub-Processors.

Nunmathi shall complete such deletion or return within 30 days of the termination date and, upon request, shall provide the Customer with written certification of deletion. Nunmathi may retain Personal Data for longer where required by applicable Union, Member State, or Indian law, in which case Nunmathi shall notify the Customer of any such requirement and shall continue to protect such retained data in accordance with this DPA.

13. Confidentiality

Nunmathi shall ensure that all personnel authorised to process Personal Data are bound by appropriate confidentiality obligations, whether under contract, professional rules, or statutory obligations. Nunmathi shall not disclose Personal Data to any third party except as permitted under this DPA, required by applicable law, or expressly authorised by the Customer in writing.

The confidentiality obligations in this section shall survive the termination or expiry of this DPA and the Agreement.

14. Term & Termination

This DPA shall commence on the effective date and shall continue in force for the duration of the Agreement. It shall terminate automatically upon the termination or expiry of the Agreement.

Either party may terminate this DPA immediately upon written notice if the other party materially breaches any provision of this DPA and fails to cure such breach within 30 days of receiving written notice of the breach.

Sections 12, 13, and 15 shall survive the termination or expiry of this DPA.

15. Governing Law

This DPA shall be governed by and construed in accordance with the laws of India. Any dispute arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts in Coimbatore, Tamil Nadu, India.

Notwithstanding the foregoing, where the Customer is established in the EEA or UK and SCCs apply, those clauses shall be governed by the law of the relevant Member State or the law of England and Wales respectively, as specified therein, and the courts specified in those clauses shall have jurisdiction over any dispute arising from them.

For questions about this DPA, please contact Nunmathi Technologies Pvt Ltd at info@nunmathi.com or call +91 93633 72992.

This document is effective as of July 20, 2026.
© 2026 Nunmathi Technologies Pvt Ltd · All rights reserved.