Data Processing Addendum
Summary of the Regulens Data Processing Addendum governing processing of customer personal data within the platform, aligned to the DPDP Act, 2023.
Last updated
This page summarises our standard Data Processing Addendum (DPA), which forms part of every platform agreement. It is a summary for evaluation purposes — the executed DPA is the operative document, and we will send you the full text on request before you sign anything.
Roles
For personal data that a customer uploads to or generates within the platform, the customer is the Data Fiduciary and Regulens is the Data Processor, consistent with the terminology of the DPDP Act. Where a customer's own client is the Data Fiduciary, Regulens acts as a sub-processor and the DPA is drafted to accommodate that chain.
Subject matter and duration
Processing is for the provision of the Regulens platform and support services, for the term of the agreement plus any agreed retention or export period.
Categories of data principals
Typically the customer's employees, contractors and authorised users. In Compliance Audit deployments where transaction data is connected, this may extend to the customer's own clients or customers — which is why that scoping is agreed in writing before any connection is made.
Types of personal data
Identity and contact data, employment and role data, authentication and audit records, content authored by users, and — where connected — transactional records containing personal data such as payroll, KYC or claims information.
Our commitments
- Process only on documented instructions from the customer
- Ensure personnel are bound by confidentiality obligations
- Implement the technical and organisational measures set out in Annex II of the DPA
- Not engage a sub-processor without prior authorisation, with 30 days notice of any change and a right to object
- Assist with data principal rights requests reaching us through the platform
- Notify the customer without undue delay and in any event within 6 hours of confirming a personal data breach, so it does not consume the customer's own DPDP or CERT-In reporting clock
- Delete or return personal data at the end of the agreement, at the customer's election
- Make available all information necessary to demonstrate compliance and allow for audits
AI processing
The DPA specifically addresses AI processing:
- Customer content is not used to train shared or third-party models
- Inference is performed under zero-retention terms with model providers
- Model providers are listed in the sub-processor register like any other sub-processor
- Prompt, retrieval and response logs are the customer's data and subject to the same commitments
Data residency
Customer data is stored and processed within India (Mumbai and Hyderabad regions) by default. Where a specific sub-processor requires processing outside India, we ensure the destination is not a country restricted by the Central Government under the DPDP Act, and appropriate contractual protections apply.
For Enterprise customers, the platform can be deployed single-tenant within India or entirely within the customer's own infrastructure.
Audit rights
Customers may audit compliance annually, or more frequently following a security incident or where a regulator or inspector requires it. In the first instance we provide our SOC 2 Type II report, ISO 27001 certificate and completed questionnaires; where those are insufficient for a specific concern, on-site or remote audit is available.
Getting the full document
Email legal@regulens.in or ask your account contact. We send the full DPA before contract signature as standard, not on request.