This Data Processing Agreement (“DPA”) sets out a legally binding arrangement between (Website Name), referred to as the “Data Processor,” and the entity accepting these terms, referred to as the “Data Controller.” It regulates the Processor’s Processing of Personal Data in connection with the digital payment services provided.
Roles of the Parties
The Controller determines the purpose and lawful basis for Processing Personal Data and remains accountable for complying with all Applicable Data Protection Laws.
The Processor shall process Personal Data strictly in accordance with the documented instructions of the Controller and solely for the purpose of delivering digital payment services.
Scope of Processing
The Processor shall process Personal Data exclusively for:
Security Measures
The Processor shall implement appropriate technical and organizational safeguards, including:
The Processor shall ensure that its personnel are bound by strict confidentiality obligations and receive training in recognized data security practices.
Data Subject Rights
The Processor shall support the Controller in responding to Data Subject requests under Applicable Laws, including:
Subprocessors
Data Breach Notification
The Processor shall inform the Controller within 24 hours of becoming aware of any Personal Data Breach.
Such notification shall include:
Audit & Compliance
Upon reasonable notice, the Controller may audit the Processor’s compliance with this DPA. The Processor shall provide access to relevant documentation, internal policies, and certifications (including reports demonstrating adherence to applicable security standards).
Data Retention & Deletion
Personal Data shall be retained only for the duration necessary to support payment processing activities and meet legal requirements (including RBI-mandated retention obligations).
Upon termination of services, the Processor shall securely delete or return all Personal Data unless continued retention is legally required.
Legal & Regulatory Changes
The Processor shall promptly notify the Controller of any legal or regulatory developments that may impact its ability to process Personal Data in accordance with this Agreement.
Liability & Indemnification
Each Party shall be responsible for damages resulting from its own breach of this Agreement. The Processor agrees to indemnify the Controller against fines, claims, or losses arising from failure to comply with applicable data protection obligations.
Governing Law & Dispute Resolution
This Agreement shall be governed by and interpreted in accordance with the laws of India. Any disputes arising from this Agreement shall fall under the exclusive jurisdiction of the courts in India.
Amendments
Any modifications to this Agreement must be documented in writing and executed by both Parties.
Acknowledgment and Acceptance
By entering into this Agreement, both Parties confirm that they understand and agree to the terms set forth in this Data Processing Agreement.