Data Processing Addendum
Last updated: [effective date]
This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer ("Controller"/"Customer") and Sunbots Innovations LLP ("Processor", "we"). It applies where we process Personal Data on the Customer's behalf in providing Marketing Autopilot for Agencies.
1. Definitions
“Personal Data”, “processing”, “controller”, “processor”, “data subject” and “personal data breach” have the meanings in the GDPR; “Data Fiduciary”, “Data Processor” and “Data Principal” have the meanings in the DPDP. “Data Protection Laws” means all privacy laws applicable to a party's processing. “Customer Personal Data” means Personal Data within Customer Content processed by us under the Agreement.
2. Roles & scope
The Customer is the controller / Data Fiduciary (or itself a processor acting for its own clients) and we are the processor / Data Processor. We process Customer Personal Data only to provide the Service and only on the Customer's documented instructions, unless required by law (in which case we inform the Customer unless legally prohibited). Annex A describes the processing.
3. Processor obligations
- Process only on documented instructions.
- Ensure personnel are bound by confidentiality.
- Implement the security measures in Annex B.
- Respect the conditions for engaging sub-processors (Section 5).
- Assist the Customer with data-subject requests and its security, breach-notification and DPIA obligations.
- At the Customer's choice, delete or return Customer Personal Data at the end of services.
- Make available information to demonstrate compliance and allow for audits.
4. Customer obligations
The Customer warrants it has a lawful basis and all necessary notices/consents to provide Customer Personal Data and to instruct the processing (including data of its leads, subscribers, social audience and website visitors), and that its instructions comply with Data Protection Laws.
5. Sub-processors
The Customer provides general authorisation for us to engage the sub-processors listed at https://sunbots.in/subprocessors. We impose data-protection obligations on each that are no less protective than this DPA and remain responsible for their performance. We give at least [30] days' notice of any intended addition or replacement, during which the Customer may object on reasonable grounds.
6. Data-subject requests
Taking into account the nature of processing, we assist the Customer by appropriate technical and organisational measures to respond to data-subject requests. If we receive a request directly, we will, where lawful, refer the individual to the Customer.
7. Security
We implement and maintain the measures in Annex B, appropriate to the risk, and will not materially decrease the overall security of the Service during the term.
8. Personal data breach
We notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, in time to allow the Customer to meet its own deadlines (e.g., 72 hours under GDPR/DPDP), with the information then known, and reasonably assist the Customer's breach obligations.
9. Deletion & return
On termination or on the Customer's request, we delete or return all Customer Personal Data and delete existing copies, except where retention is required by law. Backups are deleted on the normal rotation cycle.
10. Audits
We make available information necessary to demonstrate compliance and allow for audits no more than once per 12 months (or following a breach), on reasonable notice and subject to confidentiality. We may satisfy audit requests via third-party certifications/reports (e.g., SOC 2, ISO/IEC 27001).
11. International transfers
Where we transfer Customer Personal Data subject to the GDPR/UK GDPR outside the EEA/UK, the Standard Contractual Clauses (and the UK IDTA) are incorporated by reference and apply, with us (and our sub-processors) as data importer, with any required supplementary measures. Transfers under DPDP are made only to territories permitted by Indian law.
12. Liability & conflict
Each party's liability under this DPA is subject to the limitations in the Agreement. This DPA is effective for as long as we process Customer Personal Data, and prevails over the Agreement on data-protection matters in case of conflict.
Annex A — Details of processing
- Subject-matter & duration: provision of the Service for the term of the Agreement.
- Nature & purpose: hosting, generating, scheduling, publishing, analysing and improving marketing content and audiences on the Customer's instructions.
- Types of Personal Data: contact details (name, email, phone), social handles and messages, lead/subscriber records, website-visitor identifiers and behavioural/heatmap events, and any data the Customer connects.
- Categories of data subjects: the Customer's authorised users, leads, subscribers, social-media audience, reviewers, and website visitors.
- Special-category data: not requested; the Customer must not upload special-category data except as expressly agreed.
Annex B — Security measures
Encryption in transit (TLS 1.2+) and at rest (AES-256); encryption of connected-account tokens; role-based access control and least privilege; MFA for administrative access; network controls (firewalling, segmentation, rate limiting); centralised logging, monitoring and alerting with at least 1-year log retention; secure SDLC with code review and testing; vulnerability management and periodic penetration testing; encrypted, tested backups and documented disaster recovery; personnel confidentiality and security training; documented incident response; and data minimisation/masking where appropriate.
Annex C — Approved sub-processors
See the current list at https://sunbots.in/subprocessors: AWS (hosting/storage); Razorpay (payments); Anthropic and Google (AI generation); HeyGen (AI video); [email provider]; [SMS provider]; GitHub (website updates); DataForSEO (SEO data); social platforms (publishing).
Operated by Sunbots Innovations LLP. Questions about this page: privacy@sunbots.in.
← Back to home