Data Processing Agreement
Last updated: August 18, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Chakrasoft Private Limited ("ChakraHQ", "Chakra", "Processor") and the customer ("Controller") governing the processing of personal data in connection with the Service — the Master Subscription Agreement — and supplements our Privacy Policy. The purpose of this DPA is to ensure that ChakraHQ’s processing of Customer Personal Data is conducted in accordance with applicable data protection law and with due respect for the rights of the individuals whose personal data is processed.
1. Purpose and Scope
1.1. This DPA reflects the parties’ agreement with regard to the processing of personal data by ChakraHQ on behalf of the Controller in connection with the Service, in accordance with applicable data protection laws. The subject matter of the processing is the provision of the Service, and processing will be carried out for the duration of the underlying Master Subscription Agreement. This DPA applies only to the extent ChakraHQ processes, on behalf of Customer, personal data to which applicable data protection legislation (including the GDPR, where relevant) applies.
2. Definitions
2.1. Capitalized terms not defined in this DPA have the meaning given to them in the Master Subscription Agreement. In addition:
- 2.1.1. "Customer Personal Data" means personal data that ChakraHQ processes as a Processor on behalf of Customer in connection with the Service.
- 2.1.2. "Controller" and "Processor" have the meanings given to them under applicable data protection legislation (including the GDPR).
- 2.1.3. "Security Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data.
- 2.1.4. "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries annexed to European Commission Implementing Decision (EU) 2021/914, and, where relevant, the UK International Data Transfer Addendum issued by the UK Information Commissioner’s Office.
- 2.1.5. "Sub-processor" means any third-party processor engaged by ChakraHQ or its Affiliates to assist in fulfilling ChakraHQ’s obligations under the Master Subscription Agreement and which processes Customer Personal Data.
3. Processing of Personal Data
3.1. ChakraHQ shall process personal data only on documented instructions from the Controller, including with regard to transfers of personal data to a third country, unless required to do so by applicable law — in which case ChakraHQ will inform Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest. The subject matter, duration, nature and purpose of processing, and the types of personal data and categories of data subjects, are set out in the applicable Order Form or the Master Subscription Agreement.
4. Customer Compliance Obligations
4.1. Customer shall be responsible for ensuring that: (a) all notices have been given, and all authorizations obtained, as required under applicable data protection legislation for ChakraHQ (and its Affiliates and Sub-processors) to process Customer Personal Data as contemplated by the Master Subscription Agreement and this DPA; (b) it has complied, and will continue to comply, with all applicable privacy and data protection laws; and (c) it has, and will continue to have, the right to transfer, or provide access to, Customer Personal Data to ChakraHQ for processing in accordance with this DPA. Customer will ensure that its processing instructions comply with applicable data protection legislation, and ChakraHQ is neither responsible for determining which laws apply to Customer’s business nor whether the Service meets the requirements of such laws.
5. Confidentiality of Personnel
5.1. ChakraHQ will ensure that any person it authorizes to process Customer Personal Data (including its employees, agents, and contractors) is subject to a duty of confidentiality, whether by contract or statutory obligation, and processes Customer Personal Data only for the Permitted Purposes described in this DPA and the Master Subscription Agreement.
6. Obligations of the Processor
6.1. ChakraHQ shall ensure that persons authorized to process personal data have committed themselves to confidentiality, implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, and assist the Controller in ensuring compliance with its obligations under applicable data protection law, including in relation to data protection impact assessments and prior consultations with supervisory authorities, at Customer’s reasonable cost.
7. Sub-processors
7.1. Customer provides general authorization for ChakraHQ to engage the Sub-processors listed in our Subprocessors List, which may be updated from time to time. ChakraHQ shall impose data protection obligations on any Sub-processor that are no less protective than those set out in this DPA, restrict the Sub-processor’s access to Customer Personal Data to what is strictly necessary to provide the Service, and shall remain liable for the acts and omissions of its Sub-processors.
7.2. ChakraHQ will give Customer at least 20 days’ notice before adding or replacing a Sub-processor on the Subprocessors List. If Customer reasonably objects to a new Sub-processor on grounds relating to the protection of Customer Personal Data within that notice period, the parties will work in good faith to find an alternative solution; if no resolution is reached within a reasonable time, Customer may terminate the affected Service.
8. Data Subject Rights Assistance
8.1. Taking into account the nature of the processing, ChakraHQ shall assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfilment of the Controller’s obligation to respond to requests for exercising data subject rights under applicable data protection law. If such a request is made directly to ChakraHQ, and ChakraHQ can identify Customer as the controller of the relevant data subject’s data, ChakraHQ will promptly inform Customer, and Customer shall have sole responsibility for responding to that request.
9. Security Measures
9.1. ChakraHQ implements and maintains appropriate technical and organizational security measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, including encryption of data in transit, access controls restricting Customer Personal Data to personnel with a need to know, and regular review of access permissions. ChakraHQ may update these measures over time, provided that any update does not result in a material degradation of the overall security of the Service. Further detail on ChakraHQ’s security practices is available on request by contacting us using the details in the "Contact Us" section below.
10. Data Breach Notification
10.1. Upon becoming aware of a Security Breach affecting Customer Personal Data, ChakraHQ shall notify Customer without undue delay and shall provide such information as Customer may reasonably require to enable Customer to fulfil its own breach notification obligations under applicable data protection law. ChakraHQ’s notification of, or response to, a Security Breach will not be construed as an acknowledgement of fault or liability with respect to the Security Breach.
11. International Data Transfers
11.1. Chakrasoft Private Limited is based in India. Where ChakraHQ or its Sub-processors transfer Customer Personal Data outside the jurisdiction in which it was originally collected, ChakraHQ shall ensure that such transfers are made in compliance with applicable data protection law.
11.2. Where the transfer of Customer Personal Data from Customer to ChakraHQ constitutes a "restricted transfer" under the GDPR, UK GDPR, or Swiss Federal Data Protection Act, the parties agree that the Standard Contractual Clauses (Module Two, or Module Three where Customer acts as a processor) are incorporated into and form part of this DPA and apply to that transfer, completed with the details of processing set out in the applicable Order Form and this DPA. To the extent the Standard Contractual Clauses conflict with any other term of this DPA or the Master Subscription Agreement, the Standard Contractual Clauses will prevail for the transfer they cover.
12. Audit Rights
12.1. Upon written request, and no more than once annually, ChakraHQ shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, and shall allow for and contribute to audits, including inspections, conducted by the Controller or a mutually agreed third-party auditor, subject to reasonable advance notice, ChakraHQ’s confidentiality requirements, and restriction to data relevant to Customer. Costs of an audit are borne by Customer.
13. Return or Deletion of Customer Personal Data
13.1. Upon termination or expiry of the Master Subscription Agreement, ChakraHQ will, at Customer’s election, delete or return all Customer Personal Data in its possession or control. The contents of closed accounts are deleted within 60 days of the date of closure, and server archival backups containing Customer Personal Data are retained for a further 90 days before deletion, except to the extent ChakraHQ is required by applicable law to retain some or all of the Customer Personal Data, in which case ChakraHQ will securely isolate that data from any further processing until deletion is possible.
14. Liability
14.1. Each party’s liability arising out of or related to this DPA is subject to the limitations of liability set forth in the Master Subscription Agreement, governed by the laws of India. Nothing in this DPA restricts or limits the rights of any data subject or competent supervisory authority.
15. Order of Precedence
15.1. If there is a conflict between the Master Subscription Agreement and this DPA, the terms of this DPA will prevail with respect to the parties’ data protection obligations. To the extent there is any conflict between the Standard Contractual Clauses and any other term of this DPA or the Master Subscription Agreement, the Standard Contractual Clauses will prevail.
16. Contact Us
16.1. For questions about this DPA, to object to a new Sub-processor, or to request an executed copy, please contact us at legal@chakrahq.com.