vedhasAI

Data Processing Addendum

How {{entity}} processes End Customer data on your instructions, as your Data Processor under the DPDP Act and equivalent laws.

Last updated: 17 September 2026 · Effective: 17 September 2026

This Addendum forms part of the Terms of Service between TODO_LEGAL_ENTITY_NAME ("Processor", "we") and the business using vedhasAI ("Controller", "you"). Where they conflict on personal data processing, this Addendum prevails.

1. Roles

For personal data belonging to End Customers — the people who message your business — you are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 (the controller under GDPR-style laws) and we are the Data Processor.

For your own account data, we are the Data Fiduciary. That is covered by the Privacy Policy, not this Addendum.

2. Processing on documented instructions

We process End Customer data only:

  • to provide the Service as configured in your workspace;
  • on your further documented instructions, including instructions given through the app's settings; and
  • where the law requires, in which case we will tell you first unless the law forbids it.

Your configuration — connected channels, prompts, lead fields, follow-up rules, assignment rules, retention choices — is your documented instruction.

3. Nature, purpose and duration

Nature: receiving, storing, generating replies for, analysing and transmitting conversations and lead records across the channels you connect.

Purpose: answering enquiries, creating and updating leads, running follow-ups, recording lead sources, reporting, and supporting you.

Duration: for as long as your subscription lasts, plus the deletion periods in section 10.

4. Categories of data and data principals

Data principals: your End Customers, and your own staff who use the workspace.

Categories of End Customer data: name and WhatsApp profile name, phone number, email address where provided, message content and media, ad referral details, lead form answers, website UTM and page data, and any custom lead fields you define (for example budget, city, product interest, stage).

You control which custom fields exist. Do not configure fields that collect special-category data without a lawful basis (see the Acceptable Use Policy).

5. Confidentiality of personnel

Everyone we allow to access End Customer data is bound by confidentiality obligations, is trained on handling it, and gets access only to what their role requires.

6. Security measures

We maintain, at minimum:

  • HTTPS/TLS for all data in transit;
  • encryption at rest for third-party access tokens;
  • a separate database per business, or your own MongoDB if you bring one;
  • role-based access control and granular permissions inside the workspace;
  • one-time-code verification for sensitive account actions, and login history;
  • internal access limited to staff who need it, with logging;
  • an incident response process.

We review these measures as the Service changes, and will not reduce them materially during your subscription.

7. Sub-processors

You give general authorisation for the sub-processors listed in the Privacy Policy. Each is bound by written terms no less protective than this Addendum.

If we add or replace a sub-processor that handles End Customer data, we will update that list and notify account holders by email at least 30 days in advance. If you reasonably object on data protection grounds within that period, tell us and we will work with you on an alternative; if none is workable, you may terminate the affected part of the Service without penalty for the unused period.

8. Assisting with data principal requests

The Service lets you find, correct, export and delete End Customer records yourself. If an End Customer contacts us directly, we will forward the request to you and help you respond, taking into account the nature of the processing and the information available to us. We do not respond to such requests on our own authority unless you instruct us to, or the law requires it.

9. Personal data breach

If we become aware of a personal data breach affecting End Customer data, we will notify you without undue delay and in any case within 72 hours of becoming aware. The notice will describe what happened, the categories and approximate volume of data involved, the likely consequences, and the steps we have taken or propose.

We will cooperate with your own regulatory reporting duties, including notification to the Data Protection Board of India, and to CERT-In where its directions apply.

10. Deletion and return

You can export Customer Data at any time during the subscription. On termination, we delete Workspace data within 30 days and account data within 90 days, except:

  • records the law requires us to keep; and
  • copies in backups, until those backups rotate — within 90 days.

Details are in How to delete your data.

11. Audits and information

On reasonable written request, and no more than once a year unless a regulator or a breach requires otherwise, we will provide the information reasonably necessary to show we meet this Addendum. Where an on-site audit is legally required, the parties will agree scope, timing and confidentiality in advance, and you will bear the reasonable cost.

12. International transfers

Some sub-processors process data outside India. We rely on the safeguards permitted under applicable law and on contractual commitments requiring an equivalent standard of protection.

13. Liability

Liability under this Addendum is subject to the limitations in the Terms of Service.

14. Contact