Data Processing Agreement
Effective Date: September 2026 | Last Updated: September 2026
1. Introduction & Parties
This Data Processing Agreement ("DPA") forms an integral part of your Subscription Agreement with Grapeit. It details how we process Personal Data on your behalf, in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act).
1.1 Party Definitions
- Data Controller = You (the organization using Grapeit) — You decide what personal data to collect, how it's processed, and why
- Data Processor = Grapeit (the service provider) — We process data only on your instructions and provide security measures
1.2 Relationship
You are responsible for lawful data collection and obtaining consent. We are responsible for secure processing according to your instructions.
2. Subject Matter & Duration
2.1 Personal Data Processed
This DPA covers processing of:
- Employee Data: Names, contact details, salary, bank accounts, tax information, Aadhaar/PAN, attendance, leave records, performance data
- Organizational Data: Business contacts, managers, company information
- Any data you input into Grapeit that identifies or relates to individuals
2.2 Scope of Processing
We process Personal Data to deliver:
- Payroll calculation and management
- Salary slip generation
- Statutory register creation and compliance reporting
- Employee records management
- Attendance and leave tracking
- HR analytics and reporting
- Customer support and service improvement
2.3 Duration
This DPA continues for the entire duration of our Subscription Agreement and survives termination for 90 days (during which we retain data for your access and deletion).
3. Your Obligations as Data Controller
3.1 Lawfulness of Processing
You must ensure:
- Personal data is collected lawfully and with proper consent from employees
- Employees are informed before or at the time of collection about data use, Grapeit processing, and their rights
- Data collection is necessary and proportionate for payroll and HR purposes
3.2 Consent
- For general employee data: Implicit consent through employment contract
- For sensitive data (Aadhaar, bank account, health): Explicit written consent required
- You are responsible for obtaining and maintaining records of consent
3.3 Data Accuracy
You must ensure Personal Data is accurate, complete, and up-to-date. We are not responsible for inaccurate payroll resulting from incorrect input data.
3.4 Purpose Limitation
You must use Grapeit only for payroll, HR, and compliance purposes. You must not use it for marketing, automated decision-making that significantly affects employees, or selling employee data.
4. Our Obligations as Data Processor
4.1 Data Security
We implement:
- Encryption at Rest: AES-256 encryption for all stored data
- Encryption in Transit: TLS 1.2+ for all data transmission
- Access Control: Role-based access control (RBAC)
- Audit Logging: All data access and modifications logged
- Regular Security Assessments: Annual penetration testing and vulnerability scans
4.2 Sub-Processors
We use the following sub-processors to deliver the Service:
- AWS: Cloud hosting, backup, disaster recovery (all data encrypted)
- Razorpay / AWS Payments: Payment processing (billing data only)
- SendGrid / AWS SES: Email notifications
- Twilio: Optional SMS notifications
All sub-processors are bound by data protection agreements. We notify you of any material changes to sub-processors and provide 30 days for objection.
4.3 Data Deletion & Retention
Upon your request:
- Non-legally-required data deleted within 30 days
- Backup copies retained for 30 additional days (disaster recovery)
- Legally-required data (tax records) retained per statutory obligations (up to 7 years)
4.4 Data Subject Rights Support
We assist you in fulfilling data subject rights requests:
- Right to Access: Export data in structured, machine-readable format within 30 days
- Right to Correction: Update inaccurate data
- Right to Erasure: Delete data (subject to legal retention)
- Right to Portability: Provide data in CSV/JSON format
5. Data Breach & Incident Response
5.1 Our Obligations
If we discover a breach affecting Personal Data, we will:
- Notify you within 72 hours of discovery
- Provide details of: nature of breach, affected individuals, measures taken
- Cooperate with your breach investigation and notifications
5.2 Your Obligations
As Data Controller, you must:
- Notify affected individuals if required by law
- Report to the Data Protection Board if individuals' rights are violated
- Document the breach and our response
6. Data Residency & Transfers
All Personal Data is stored and processed within India (AWS ap-south-1 region). We do not transfer employee data outside India without your explicit consent, as required by DPDP Act and RBI guidelines.
If you are an EU customer, we comply with GDPR and do not transfer EU personal data outside the EU without appropriate safeguards.
7. Audit & Compliance
You have the right to audit our compliance with this DPA. We provide:
- Annual security audits and penetration test reports
- Documentation of data handling procedures
- Proof of sub-processor agreements
- Incident response logs (upon request)
8. Contact & Questions
For DPA-related questions or to exercise data subject rights:
- Data Protection Officer: dpo@grapeit.in
- Privacy Inquiries: privacy@grapeit.in
- Support: support@grapeit.in
This Data Processing Agreement forms an integral part of your Subscription Agreement with Grapeit. By using the Service, you agree to the terms herein.
Last updated: September 2026 | Version: 1.0