Skip to content
Relicsoft
← All policies

Data Processing Addendum

The terms under which we process personal data on a client's behalf. Incorporated into every engagement that involves it.

Roles

Where we operate a system on your behalf, you are the Data Controller (DPDP Act: Data Fiduciary) and Relicsoft is the Data Processor (Data Processor). You decide what personal data goes in and why. We process it only on your documented instructions, which for these purposes means the agreed scope of work plus anything you tell us in writing afterwards.

If we ever believe an instruction breaches data protection law, we will tell you rather than carry it out quietly.

Scope of processing

Subject matter
Provision, hosting, maintenance and support of the systems described in the engagement.
Duration
For as long as the engagement runs, plus the retention window in the Privacy Policy.
Categories of data subject
Determined by you — typically your employees, your customers, your suppliers and your contractors.
Categories of data
Determined by you. Commonly names, contact details, employment identifiers, location and transaction records. Tell us before you put special-category data into a system we run: it changes how we build it.

Our obligations

  • Process only on your instructions, and only for the purposes of the engagement.
  • Keep the technical and organisational measures described in the Security page, including database-level access control and encryption in transit and at rest.
  • Bind everyone with access to confidentiality.
  • Help you respond to data-subject requests, and to any regulator, at no additional charge for a reasonable volume.
  • Notify you without undue delay, and in any event within 48 hours, of any personal data breach affecting your data.
  • Delete or return your data at the end of the engagement, at your choice, and confirm when it is done.
  • Make available the information you need to demonstrate compliance, and permit an audit on reasonable notice, no more than once a year unless a regulator requires otherwise.

Sub-processors

You give general authorisation for the sub-processors listed on this site, each engaged under written terms no less protective than these. We will give you 30 days' notice before adding a new one, and you may object on reasonable data-protection grounds — in which case we will find an alternative or you may terminate the affected service without penalty.

International transfers

Primary storage and compute for systems we build is in India, in the Mumbai region. Where a sub-processor is outside India or the EEA, transfers rely on Standard Contractual Clauses or an adequacy decision. If your engagement requires data residency in a specific country, that is a design constraint and it needs to be agreed before we build.

Signing it

Most clients are content to incorporate this by reference in the engagement contract. If your procurement process needs it as a separate signed document, or you need your own DPA reviewed and signed instead, email admin@relicsoft.in and we will turn it round quickly. We have not yet refused a reasonable one.

Sub-processors

Every third party that can touch personal data, what it does, and where it runs. Entries marked planned are not yet live — they are listed in advance so this page does not have to be rewritten under time pressure the week they are switched on.

ProviderWhat it doesWhere
Vercel Inc.Website and application hosting, content deliveryGlobal edge network; serverless compute in Mumbai (bom1)
SupabaseDatabase, authentication and file storageMumbai, India (ap-south-1)
Google (Workspace)Business email, calendar and documentsGlobal; Google Ireland Ltd for EEA data
Cashfree PaymentsPlannedPayment processing for invoices and online ordersIndia
ShiprocketPlannedLast-mile and hyperlocal delivery dispatchIndia
Meta Platforms (WhatsApp Business Platform)PlannedOrder, dispatch and verification messagesGlobal
ResendPlannedTransactional email — credentials, password resets, notificationsGlobal