Data Processing Agreement
Table of Contents
The Data Terms, Already Agreed
This Data Processing Agreement forms part of our Terms and Conditions and applies automatically wherever we process personal data on your behalf. You do not have to sign anything to rely on it. If your procurement process needs a countersigned copy, ask and we will send one.
It is written to satisfy the Digital Personal Data Protection Act, 2023 in India and Article 28 of the GDPR and UK GDPR where those apply to you, in language you can actually read.
WHO IS WHO
Two different sets of data are involved, and we hold a different role for each. This is the part most agreements leave vague.
Data you put into ViveLead, being your leads, contacts, deals, conversations, calls, employees and documents:
- You are the Data Fiduciary under the DPDP Act, and the Controller under the GDPR. You decide whose data goes in, why, and for how long.
- We are the Data Processor. We process it to run the service for you, on your instructions, and for nothing else.
Data about your account, being the names and contact details of your users, your billing details, and the logs of how the product was used:
- We are the Data Fiduciary and Controller for that, because we decide what is needed to run, bill and secure the service. Our Privacy Policy governs it.
Nothing in this agreement makes us a joint controller with you, and we never process your data for our own purposes.
WHAT WE PROCESS, AND WHY
Subject matter: provision of the ViveLead CRM, communication and HRMS services described in our Terms.
Duration: for as long as your subscription is active, plus the retention windows in section 11.
Nature and purpose: storing, organising, retrieving, transmitting, backing up and deleting personal data so that the features you use work, including sending messages you compose, recording calls you place, and generating summaries where you turn AI features on.
Categories of personal data, depending on which features you use:
- Identity and contact details of your leads, customers and contacts
- Conversation content: WhatsApp, SMS, email, web chat, notes
- Call metadata and, where enabled, call recordings and transcripts
- Your users’ names, emails, phone numbers and roles
- Employee data where you use HRMS or payroll, including attendance records, salary details and the location stamped at check in or check out
- Documents and files you upload
Categories of data subjects and Data Principals: your leads and prospects, your customers, your employees and contractors, and your own users of the product.
Special categories: The product is not designed for and should not be used to store special category or sensitive personal data, such as health, biometric or financial account data, beyond what payroll requires. If you put it in anyway, you do so on your own assessment and you remain responsible for it.
OUR OBLIGATIONS
We will:
- Process only on your instructions. Using the product is your instruction. We do not process your data for any other purpose, and we will tell you if we believe an instruction breaks the law.
- Keep it confidential. Anyone with access is bound by confidentiality obligations and is given access only to what their work requires.
- Secure it using the measures in section 5, and keep those measures under review rather than frozen at today’s list.
- Engage subprocessors only as set out in section 6, under written terms no weaker than these, and remain responsible to you for what they do.
- Help you answer requests from the people whose data it is, as set out in section 7.
- Tell you about a breach as set out in section 8.
- Help you meet your own obligations, including a data protection impact assessment or a consultation with a regulator, so far as the information is ours to give.
- Delete or return the data when the relationship ends, as set out in section 11.
- Give you the information you need to show that we are doing the above, as set out in section 10.
YOUR OBLIGATIONS
You will:
- Have the right to the data you upload. You confirm you have a lawful basis, and consent where the law requires it, for every person whose data you put into ViveLead or contact through it.
- Give notice to your own people. Where you use attendance, location or payroll features, you confirm you have told your employees what is collected and why, and hold a lawful basis for it.
- Keep it accurate and lawful, and not upload data you were never allowed to hold.
- Configure the product properly. Roles, permissions, visibility rules and who you invite are yours to set. We cannot know who in your organisation should see what.
- Handle consent for messaging and recording. Those obligations are in section 3 of our Terms, and they sit with you as the sender.
- Keep your credentials safe, and tell us promptly if you think an account has been compromised.
SECURITY MEASURES
What is in place today. This list is accurate as at the date on this page, and we may change a measure for one that is at least as protective.
In transit: All traffic between your browser or app and our servers runs over TLS. Data moving to a provider on our subprocessor list travels over TLS as well.
At rest: Files, uploaded documents, call recordings and generated invoice PDFs are stored in Amazon S3 in the Mumbai region with server-side encryption applied by the storage service using AES-256. Our backups are written to the same encrypted storage, so a backup copy is never less protected than the live record.
Access control:
- Role-based permissions inside the product, which you configure, down to individual actions.
- Row-level visibility scoping, so a user sees the records their role and location allow rather than everything in the tenant.
- Tenant isolation enforced in the application layer on every query, with an automated check in our build pipeline that fails a release containing a query which is not scoped to a company.
- Administrative access to production is limited to the smallest number of people needed, over key-based authentication.
- The application’s own cloud credentials are scoped to the specific actions it performs and cannot read or change account configuration, so a compromise of the running service does not become a compromise of the account around it.
Logging and audit: Audit logs record significant actions with the user who performed them and the account they belong to. Application errors and access are logged for operational and security review.
Backups: Automated backups run daily to encrypted storage in the same region, are retained for 30 days, and older copies are pruned in the same run. Backup copies of deleted data roll off within that window.
Secrets: Third-party tokens and keys we hold on your behalf, such as channel access tokens, are encrypted with AES-256 before they are written to our database, never stored in plain text.
Change management: Changes reach production through a build pipeline with automated tests and a blue-green deploy. The replacement is started alongside the running version and only receives traffic once it reports healthy, which includes proving it can reach the database and cache, so a bad release is rolled back rather than patched live.
SUBPROCESSORS
You give us general authorisation to engage subprocessors. Every one currently engaged is named on our Subprocessors page, with what it does, what it can see and the region it processes in.
We will give at least 30 days notice by email before a new subprocessor starts processing your data, unless it replaces one already listed on materially equivalent terms. You may object on reasonable data protection grounds within that period, and what happens then is set out on that page, including an exit with a pro rata refund if we cannot offer the product without it.
Each subprocessor is engaged under terms that require it to protect the data and process it only for the service it provides to us. We remain responsible to you for their performance.
REQUESTS FROM THE PEOPLE IN YOUR DATA
A Data Principal or data subject who asks us directly about data you control will be pointed back to you, because it is your data and your decision. We will tell you when that happens.
Where you need to answer such a request, the product itself lets you find, export, correct and delete records without our involvement, which is usually faster than asking us. Where it does not, we will help you within a reasonable time and at no charge for a normal volume of requests.
If you ask us to delete specific records, we do it and it is permanent. We do not second-guess a deletion instruction, so check before you send it.
PERSONAL DATA BREACH
If we become aware of a personal data breach affecting data we process for you, we will:
- Notify you without undue delay, and no later than 48 hours after becoming aware of it, at the email address registered on your account;
- tell you what we know: what happened, when, what categories of data and roughly how many records are involved, what we are doing about it, and what we suggest you do;
- keep you updated as we learn more, rather than sending one message and going quiet; and
- help you make any notification you are required to make, to the Data Protection Board of India, a supervisory authority, or the affected people.
Notifying a regulator or the affected individuals about data you control is your obligation, not ours, because you are the Fiduciary or Controller. Our job is to get you what you need in time to do it.
We will not tell a regulator that you had a breach without telling you first, unless the law requires us to.
INTERNATIONAL TRANSFERS
Your data is stored in India. Some features send data to providers outside India, and those are marked by region on our Subprocessors page.
If you or your data subjects are in the European Union or the United Kingdom: sending data to us is a transfer to India, which has no adequacy decision. We enter into the Standard Contractual Clauses approved by the European Commission, Module Two where you are a controller and we are your processor, and Module Three where you are yourself a processor, with the UK International Data Transfer Addendum where UK data is involved. Ask and we will put them in place as part of a signed DPA.
If you are in India: transfers out of India are limited to what a feature needs, and we do not transfer to a territory the Central Government has restricted.
AUDITS AND INFORMATION
On reasonable written request, and not more than once a year unless a regulator or a breach makes another one necessary, we will give you the information you reasonably need to confirm we are meeting this agreement, including answers to a security questionnaire and a description of our measures.
We are a small team and a physical on-site audit is disruptive out of proportion to what it would show. Where your regulator or your own policy requires more than a documentary review, write to us and we will agree something workable, at your cost for anything beyond a documentary response.
Do not run a penetration test, vulnerability scan or load test against our systems without our written agreement first, including the scope and the window. Unannounced testing is indistinguishable from an attack and we will treat it as one.
DELETION AND RETURN
While you are a customer: you can export your data from the product at any time. Ask us if you want a bulk export and we will help.
When the relationship ends: the timings are in section 6 of our Terms and they are the same timings that apply here. In short, a paid-up cancellation keeps your data available for 30 days for export and then it is deleted, an unpaid suspension can lead to deletion 60 days later after written notice, and an unpaid trial can be deleted from 14 days after expiry.
On written instruction: we delete sooner if you tell us to.
What we keep: only records the law requires us to, principally invoices and tax records, and anything needed to resolve a live dispute. Those are kept for the period the law requires and for no other purpose.
Deletion is permanent. Copies in routine backups roll off within 30 days of deletion.
PUTTING THIS IN PLACE
This DPA already applies. Nothing needs signing for you to rely on it.
If you need a countersigned copy, Standard Contractual Clauses, the UK Addendum, or a completed security questionnaire, write to contact@vivelead.com with the subject line DPA request and tell us which. We will also work through your own DPA template where your policy requires it.
Where this DPA and our Terms and Conditions conflict on the handling of personal data, this DPA governs.
Need a Signed Copy?
Email us and we will countersign this DPA, or work through your own template.
Contact Us