Data Processing Agreement

This Data Processing Agreement (“DPA”) establishes the legally binding terms between Vogueware Solutions, acting as the Data Processor, and the organization accepting these terms, referred to as the Data Controller. It outlines how the Processor accesses, manages, and processes Personal Data while delivering its services.

Roles and Responsibilities

Responsibilities of the Data Controller

The Data Controller is responsible for:

  • Determining the lawful purpose, scope, and legal basis for processing Personal Data
  • Ensuring that all data processing activities comply with applicable data protection laws and regulatory requirements
Responsibilities of the Data Processor

The Data Processor agrees to:

  • Process Personal Data strictly according to the documented instructions provided by the Controller
  • Use Personal Data solely for services that are explicitly authorized and approved by the Controller

Scope of Personal Data Processing

The Processor is permitted to process Personal Data only for the following purposes:

  • Initiating, verifying, and completing payment transactions
  • Conducting KYC verification and implementing fraud prevention measures
  • Authenticating users through two-factor authentication or other secure verification mechanisms
  • Generating reconciliation reports and transaction-related statements
  • Complying with directives issued by the RBI and other authorized payment networks

Data Security and Protection Measures

The Processor will apply appropriate technical and organizational safeguards, including:

  • Encryption of Personal Data during both storage and transmission
  • Mandatory multi-factor authentication (MFA) for platform access
  • Secure creation, storage, and management of cryptographic keys
  • Routine vulnerability assessments and penetration testing
Additional Security Requirements
  • Personnel with access to Personal Data must maintain strict confidentiality at all times
  • Employees are required to undergo periodic training on data protection and security practices

Assistance with Data Subject Rights

The Processor will support the Controller in addressing requests made by Data Subjects, including:

  • Requests to access Personal Data
  • Requests to correct inaccurate or incomplete data
  • Requests to delete Personal Data, including those submitted under the Right to be Forgotten
  • Requests related to data portability
  • Requests to restrict or object to certain processing activities

Use of Subprocessors

The Processor shall not appoint any Subprocessor without obtaining prior written consent from the Controller.

Any approved Subprocessor must be contractually obligated to uphold data protection responsibilities equivalent to those defined in this DPA.

Personal Data Breach Notification

If a Personal Data breach occurs, the Processor must notify the Controller within 24 hours and provide the following information:

  • A detailed explanation of the breach and the circumstances surrounding it
  • The categories and estimated number of affected Data Subjects
  • Immediate mitigation steps and corrective actions taken
  • Recommendations intended to prevent similar incidents in the future

Audit and Compliance Rights

The Controller has the right to conduct audits or inspections, provided reasonable prior notice is given, in order to verify compliance with the terms of this DPA.

Data Retention and Secure Deletion

Personal Data will be retained only for the period necessary to support payment processing and meet regulatory obligations, including RBI requirements.

Once services are terminated, Personal Data must be securely returned to the Controller or permanently deleted unless legal obligations require continued retention.

Regulatory Updates

The Processor must promptly notify the Controller of any legal, regulatory, or compliance developments that may impact the lawful processing of Personal Data.

Liability and Indemnification

  • Each Party is responsible for any losses or damages resulting from its own violation of this Agreement.
  • The Processor agrees to indemnify and hold the Controller harmless from penalties, claims, or damages arising from non-compliance with applicable data protection obligations.

Governing Law and Jurisdiction

This Data Processing Agreement is governed by the laws of India. Any disputes arising under or related to this Agreement shall fall under the exclusive jurisdiction of Indian courts.

Amendments

Any amendments or revisions to this DPA must be documented in writing and formally executed by both the Data Controller and the Data Processor.

Acknowledgment and Acceptance

By accepting this Data Processing Agreement, both Parties confirm that they have read, understood, and agreed to all the terms, responsibilities, and obligations set out in this Agreement.