Skip to content
AI Digital Hub

Legal

Data Processing Addendum

A summary of the processing terms that apply when we handle personal data on your behalf. This page is the plain-English version; the executable DPA is available on request and forms part of your engagement.

Last updated 1 July 2026 · Exinary Technologies Private Limited

Roles

When we process personal data to deliver an engagement, you are the Data Fiduciary (DPDP Act) or Controller (GDPR) and Exinary Technologies Private Limited is the Data Processor. We process only on your documented instructions and only for the purposes of the engagement.

For personal data collected through our own website — enquiries, applications, newsletter — we are the Fiduciary/Controller in our own right. That is covered by the privacy policy, not this addendum.

What we commit to

  • Process personal data only as instructed, and tell you if we believe an instruction breaches applicable law.
  • Implement appropriate technical and organisational measures — the specifics are on our security page and are contractually binding, not aspirational.
  • Bind everyone with access to confidentiality obligations that survive the engagement.
  • Assist you in responding to data principal requests — access, correction, erasure — within the timeframes the law gives you.
  • Assist with your data protection impact assessments and with regulator enquiries relating to our processing.
  • Delete or return personal data at the end of the engagement, on your instruction.

Sub-processors

We use sub-processors only where the engagement requires it, and we impose data protection terms on them no less protective than these. Our current list is published on the sub-processors page.

We give at least 30 days’ notice before adding or replacing a sub-processor that touches your data. You may object on reasonable data protection grounds, in which case we will either propose an alternative or allow you to terminate the affected part of the engagement without penalty.

AI providers and model training

Where an engagement uses a third-party model provider, that provider is a sub-processor and is named in your engagement documentation.

We contract for zero retention and no training on your data with every model provider we use. We do not use your data to train models, and we do not permit our sub-processors to.

Where residency requirements mean data cannot leave a jurisdiction, we design around in-region processing or self-hosted models. We will quantify the capability trade-off before you commit rather than discover it later.

International transfers

Where processing occurs outside India, we rely on the relevant provider’s contractual protections, including EU/UK Standard Contractual Clauses where GDPR applies, together with supplementary technical measures — encryption in transit and at rest, and minimisation or pseudonymisation of identifiers before transfer where the task allows.

Breach notification

We notify you without undue delay and within 24 hours of becoming aware of a personal data breach affecting your data. The notification includes what we know, what we are doing, and what we need from you — we do not wait until the picture is complete to tell you something happened.

We assist with your own notification obligations to the Data Protection Board of India, other supervisory authorities and affected individuals.

Audit and evidence

You may audit our compliance with these terms once per year on reasonable notice, or more often if required by a regulator. In most cases our security documentation, control evidence and — once available — third-party audit reports satisfy the requirement without an on-site visit. See compliance for current certification status, stated honestly.

Getting the executable version

Email [email protected] and we will send the signable DPA, usually within one business day. If your legal team prefers to work from your own paper, send it over — we are reasonable about it and will mark up rather than insist on ours.

Questions?

Email [email protected] for anything about data or these policies, or [email protected] for security matters. See also our security page.