Legal
Data Processing Agreement
The processor terms that apply whenever Vahmine handles personal data on behalf of an enterprise customer - GDPR aligned and ready for procurement review.
1. Scope and roles
This Data Processing Agreement ("DPA") forms part of the master services agreement, order form or subscription terms between the customer ("Controller") and Vahmine Technologies Pvt. Ltd. or the contracting Vahmine entity ("Processor").
Vahmine processes personal data only on the Controller's documented instructions, including for transfers, unless required otherwise by law - in which case we notify the Controller before processing, where legally permitted.
2. Subject matter and duration
Processing lasts for the term of the underlying agreement plus any agreed retention or migration window. The subject matter is the provision of the contracted software, platform, support and professional services.
3. Nature, purpose and data categories
- Nature and purpose: hosting, storage, configuration, support, analytics and processing necessary to deliver the contracted services.
- Categories of data subjects: the Controller's employees, contractors, partners, customers, applicants and end users.
- Categories of personal data: identity and contact data, employment and role data, usage and device data, transaction and workflow records, and any other data the Controller chooses to submit.
- Special categories: not processed unless expressly agreed in writing with additional safeguards.
4. Confidentiality
Vahmine personnel with access to personal data are subject to binding confidentiality obligations, background screening appropriate to the role, and role-based access granted on a least-privilege, need-to-know basis.
5. Security measures (Article 32)
Vahmine maintains an ISO 27001 certified ISMS with SOC 2 aligned controls, including:
- Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256), with managed key rotation.
- SSO/SAML, multi-factor authentication, least-privilege RBAC and full administrative audit logging.
- Secure SDLC with threat modelling, SAST/DAST in CI, dependency scanning and mandatory peer review.
- Independent penetration testing and continuous vulnerability assessment with tracked remediation SLAs.
- Multi-region deployment, tested backups and documented disaster recovery with agreed RTO/RPO targets.
- 24x7 monitoring, incident response playbooks and annual control and policy reviews.
6. Sub-processors
The Controller grants general authorisation for Vahmine to engage sub-processors, each bound by written terms no less protective than this DPA. Vahmine remains fully liable for their performance.
A current sub-processor list is available on request. We give at least 30 days' notice of any intended addition or replacement, and the Controller may object on reasonable data protection grounds.
7. International transfers
Where personal data is transferred outside the EEA, the UK or another restricted jurisdiction, transfers are made under the EU Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), supported by a transfer impact assessment and supplementary technical measures. Regional data residency - including within the EU, India or the GCC - can be agreed in the order form.
8. Assistance to the Controller
Taking into account the nature of processing, Vahmine assists the Controller with data subject requests, data protection impact assessments, prior consultations and security obligations. Where we receive a request directly from a data subject, we forward it to the Controller and do not respond unless instructed.
9. Personal data breach notification
Vahmine notifies the Controller without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting Controller data, providing the nature of the breach, categories and approximate volumes affected, likely consequences, and the containment and remediation measures taken.
10. Audit and records
Vahmine maintains records of processing and makes available the information needed to demonstrate compliance, including certifications, audit report summaries and completed security questionnaires. The Controller may conduct an audit no more than once per year, on 30 days' notice, during business hours and subject to confidentiality - or more frequently where a supervisory authority or a confirmed breach requires it.
11. Return and deletion
On termination or expiry, Vahmine will, at the Controller's choice, return personal data in an agreed machine-readable format or delete it, together with existing copies, within 30 days - unless storage is required by applicable law. Backup copies are deleted on their normal rotation cycle.
12. Requesting a signed DPA
This page reflects our standard processor terms. To execute a countersigned DPA, add Standard Contractual Clauses, or review our sub-processor list and certificates, email privacy@vahmine.com with your entity details and we will return a signature-ready copy.
Start a conversation
Procurement or risk team need more?
We can provide the signed DPA, Standard Contractual Clauses, sub-processor list and ISO 27001 certificate.
