This Data Processing Agreement (“DPA”) establishes the legally binding terms between
Vogueware Solutions, acting as the Data Processor, and the organization
accepting these terms, referred to as the Data Controller. It outlines how the
Processor accesses, manages, and processes Personal Data while delivering its services.
Roles and Responsibilities
Responsibilities of the Data Controller
The Data Controller is responsible for:
- Determining the lawful purpose, scope, and legal basis for processing Personal Data
- Ensuring that all data processing activities comply with applicable data protection laws and regulatory requirements
Responsibilities of the Data Processor
The Data Processor agrees to:
- Process Personal Data strictly according to the documented instructions provided by the Controller
- Use Personal Data solely for services that are explicitly authorized and approved by the Controller
Scope of Personal Data Processing
The Processor is permitted to process Personal Data only for the following purposes:
- Initiating, verifying, and completing payment transactions
- Conducting KYC verification and implementing fraud prevention measures
- Authenticating users through two-factor authentication or other secure verification mechanisms
- Generating reconciliation reports and transaction-related statements
- Complying with directives issued by the RBI and other authorized payment networks
Data Security and Protection Measures
The Processor will apply appropriate technical and organizational safeguards, including:
- Encryption of Personal Data during both storage and transmission
- Mandatory multi-factor authentication (MFA) for platform access
- Secure creation, storage, and management of cryptographic keys
- Routine vulnerability assessments and penetration testing
Additional Security Requirements
- Personnel with access to Personal Data must maintain strict confidentiality at all times
- Employees are required to undergo periodic training on data protection and security practices
Assistance with Data Subject Rights
The Processor will support the Controller in addressing requests made by Data Subjects, including:
- Requests to access Personal Data
- Requests to correct inaccurate or incomplete data
- Requests to delete Personal Data, including those submitted under the Right to be Forgotten
- Requests related to data portability
- Requests to restrict or object to certain processing activities
Use of Subprocessors
The Processor shall not appoint any Subprocessor without obtaining prior written consent from the Controller.
Any approved Subprocessor must be contractually obligated to uphold data protection responsibilities
equivalent to those defined in this DPA.
Personal Data Breach Notification
If a Personal Data breach occurs, the Processor must notify the Controller within
24 hours and provide the following information:
- A detailed explanation of the breach and the circumstances surrounding it
- The categories and estimated number of affected Data Subjects
- Immediate mitigation steps and corrective actions taken
- Recommendations intended to prevent similar incidents in the future
Audit and Compliance Rights
The Controller has the right to conduct audits or inspections, provided reasonable prior notice
is given, in order to verify compliance with the terms of this DPA.
Data Retention and Secure Deletion
Personal Data will be retained only for the period necessary to support payment processing
and meet regulatory obligations, including RBI requirements.
Once services are terminated, Personal Data must be securely returned to the Controller
or permanently deleted unless legal obligations require continued retention.
Regulatory Updates
The Processor must promptly notify the Controller of any legal, regulatory, or compliance
developments that may impact the lawful processing of Personal Data.
Liability and Indemnification
- Each Party is responsible for any losses or damages resulting from its own violation of this Agreement.
- The Processor agrees to indemnify and hold the Controller harmless from penalties, claims, or damages arising from non-compliance with applicable data protection obligations.
Governing Law and Jurisdiction
This Data Processing Agreement is governed by the laws of India. Any disputes arising under
or related to this Agreement shall fall under the exclusive jurisdiction of Indian courts.
Amendments
Any amendments or revisions to this DPA must be documented in writing and formally executed
by both the Data Controller and the Data Processor.
Acknowledgment and Acceptance
By accepting this Data Processing Agreement, both Parties confirm that they have read,
understood, and agreed to all the terms, responsibilities, and obligations set out in this Agreement.