Data Processing Addendum

Last updated: August 3, 2026

1. Parties and scope

This Data Processing Addendum (“DPA”) forms part of the UdyamSync Terms of Service or another agreement between UdyamSync and the customer.

For Customer Personal Data, the customer is the Data Fiduciary/controller and UdyamSync is the Data Processor/service provider, except where UdyamSync independently determines purposes for account, billing, security, support or legal-compliance data.

This DPA applies to personal data contained in contacts, WhatsApp messages, media, templates, metadata and other Customer Data processed by UdyamSync to provide the Service.

2. Documented instructions

UdyamSync will process Customer Personal Data only on the customer’s documented instructions expressed through the agreement, product configuration, support requests and lawful use of the Service, unless processing is required by law.

If UdyamSync believes an instruction violates applicable data-protection law or Meta/WhatsApp requirements, it may suspend the instruction and notify the customer where legally permitted.

3. Customer obligations

The customer will ensure it has a lawful purpose and legal basis for processing; provide required notices; obtain and record valid consent or WhatsApp opt-in; honour opt-outs; minimise data; maintain accurate contact information; and avoid prohibited or excessive sensitive data.

The customer is responsible for responding to its contacts and data principals and for the legality of its communications, products, services and content.

4. Confidentiality and access

UdyamSync will limit access to Customer Personal Data to authorised persons who need access for the Service, support, security or legal compliance and who are subject to confidentiality obligations.

There is no routine human review of message content. Access, where necessary, will be limited and controlled.

5. Security measures

UdyamSync will maintain reasonable technical and organisational safeguards, including HTTPS/TLS, secure password hashing, role-based permissions, encrypted sensitive integration credentials, token masking, rate limits, access controls, security/audit logging, protected backups and incident-response procedures.

The customer will configure appropriate user permissions, protect credentials, maintain lawful opt-in records and promptly notify UdyamSync of suspected compromise.

6. Subprocessors

The customer authorises the subprocessors listed in the public Subprocessor List, including BigRock, Meta/WhatsApp, Razorpay and Google Firebase Authentication.

UdyamSync may add or replace a material subprocessor by updating the Subprocessor List and providing reasonable advance notice where practical.

The customer may raise a reasonable, documented data-protection objection. The parties will work in good faith on a commercially reasonable solution. If no solution is available, the customer may terminate the affected Service before the new subprocessor begins material processing, without a refund for already used service except where required by law.

7. Cross-border processing

The customer authorises processing in India and other countries where UdyamSync’s authorised subprocessors operate, subject to applicable law and appropriate contractual, technical and organisational safeguards.

8. Data-principal requests

Taking into account the nature of processing, UdyamSync will provide reasonable assistance through available product controls, exports, correction and deletion functions so the customer can respond to access, correction, erasure, grievance and other lawful requests.

If UdyamSync receives a request clearly concerning Customer Personal Data, it may refer the requester to the customer unless law requires a direct response.

9. Security incidents

UdyamSync will notify the affected customer without undue delay after confirming a personal-data breach affecting Customer Personal Data where notification is legally required.

The notice will provide available information reasonably needed for the customer’s response, such as the nature of the incident, affected data, likely consequences and remediation, subject to security, legal and investigative restrictions.

The customer and UdyamSync will reasonably cooperate with legally required notifications and mitigation.

10. Return and deletion

During the agreement, the customer may request an available export in a common format where technically feasible.

On termination or verified request, UdyamSync will delete or anonymise eligible Customer Personal Data within 30 days, except for data retained under law, legal hold, fraud/security requirements or the customer’s contrary documented instruction.

Deleted data may remain in protected rotating backups for up to 60 days and will not be restored to active use except for disaster recovery, after which deletion controls will be reapplied.

Billing/invoice records, security logs and support records follow the retention periods in the Privacy Policy.

11. Audit information

On reasonable written request, UdyamSync will provide available security and compliance information or respond to a reasonable questionnaire.

An onsite audit is available only where required by applicable law, a regulator, or a substantiated serious incident and after agreeing scope, confidentiality, timing, cost and measures to protect other customers and systems.

12. Government requests

UdyamSync will disclose Customer Personal Data only in response to a valid legal requirement or order, or where necessary to protect rights and safety. Where legally permitted, UdyamSync may notify the customer.

13. Liability, precedence and termination

Liability under this DPA is subject to the Terms of Service, including applicable limits and non-excludable statutory rights.

If this DPA conflicts with the Terms regarding processing of Customer Personal Data, this DPA controls to the extent of the conflict.

This DPA ends when UdyamSync no longer processes Customer Personal Data, subject to surviving confidentiality, retention, liability and legal obligations.

Schedule A - Processing details

Subject matter: provision of UdyamSync business communication and WhatsApp management services.

Duration: for the agreement and applicable retention/deletion periods.

Nature and purpose: hosting, storage, organisation, retrieval, transmission, display, backup, support, security, billing-related association and deletion of Customer Personal Data.

Data subjects: customer personnel, workspace users, the customer’s contacts, WhatsApp recipients and senders, and individuals whose data the customer lawfully places in the Service.

Data categories: names, mobile numbers, contact details, consent/opt-out records, WhatsApp messages, media, metadata, templates, delivery status, business identifiers and other Customer Data chosen by the customer.

Special/sensitive data: not required by the Service and should not be submitted unless lawful, strictly necessary, adequately protected and permitted by WhatsApp policy.

Schedule B - Minimum security controls

HTTPS/TLS; secure password hashing; mandatory mobile verification; role-based access; encrypted sensitive credentials; masked tokens; rate limiting; session and CSRF protection; protected backups; security and audit events; incident response; deletion workflow; and confidentiality restrictions for authorised access.


Privacy Policy Terms Refund Policy Cookie Notice Subprocessors DPA Grievance Data Deletion Login