Data Processing Addendum
The terms under which we process personal data on a client's behalf. Incorporated into every engagement that involves it.
Roles
Where we operate a system on your behalf, you are the Data Controller (DPDP Act: Data Fiduciary) and Relicsoft is the Data Processor (Data Processor). You decide what personal data goes in and why. We process it only on your documented instructions, which for these purposes means the agreed scope of work plus anything you tell us in writing afterwards.
If we ever believe an instruction breaches data protection law, we will tell you rather than carry it out quietly.
Scope of processing
- Subject matter
- Provision, hosting, maintenance and support of the systems described in the engagement.
- Duration
- For as long as the engagement runs, plus the retention window in the Privacy Policy.
- Categories of data subject
- Determined by you — typically your employees, your customers, your suppliers and your contractors.
- Categories of data
- Determined by you. Commonly names, contact details, employment identifiers, location and transaction records. Tell us before you put special-category data into a system we run: it changes how we build it.
Our obligations
- Process only on your instructions, and only for the purposes of the engagement.
- Keep the technical and organisational measures described in the Security page, including database-level access control and encryption in transit and at rest.
- Bind everyone with access to confidentiality.
- Help you respond to data-subject requests, and to any regulator, at no additional charge for a reasonable volume.
- Notify you without undue delay, and in any event within 48 hours, of any personal data breach affecting your data.
- Delete or return your data at the end of the engagement, at your choice, and confirm when it is done.
- Make available the information you need to demonstrate compliance, and permit an audit on reasonable notice, no more than once a year unless a regulator requires otherwise.
Sub-processors
You give general authorisation for the sub-processors listed on this site, each engaged under written terms no less protective than these. We will give you 30 days' notice before adding a new one, and you may object on reasonable data-protection grounds — in which case we will find an alternative or you may terminate the affected service without penalty.
International transfers
Primary storage and compute for systems we build is in India, in the Mumbai region. Where a sub-processor is outside India or the EEA, transfers rely on Standard Contractual Clauses or an adequacy decision. If your engagement requires data residency in a specific country, that is a design constraint and it needs to be agreed before we build.
Signing it
Most clients are content to incorporate this by reference in the engagement contract. If your procurement process needs it as a separate signed document, or you need your own DPA reviewed and signed instead, email admin@relicsoft.in and we will turn it round quickly. We have not yet refused a reasonable one.
Sub-processors
Every third party that can touch personal data, what it does, and where it runs. Entries marked planned are not yet live — they are listed in advance so this page does not have to be rewritten under time pressure the week they are switched on.
| Provider | What it does | Where |
|---|---|---|
| Vercel Inc. | Website and application hosting, content delivery | Global edge network; serverless compute in Mumbai (bom1) |
| Supabase | Database, authentication and file storage | Mumbai, India (ap-south-1) |
| Google (Workspace) | Business email, calendar and documents | Global; Google Ireland Ltd for EEA data |
| Cashfree PaymentsPlanned | Payment processing for invoices and online orders | India |
| ShiprocketPlanned | Last-mile and hyperlocal delivery dispatch | India |
| Meta Platforms (WhatsApp Business Platform)Planned | Order, dispatch and verification messages | Global |
| ResendPlanned | Transactional email — credentials, password resets, notifications | Global |