Initializing workspace...

Legal

Data Processing Agreement

Template — provided for review. Contact us for an executed copy.

Template — provided for review

This is the template of the Data Processing Agreement DeelSignal offers its customers under GDPR Article 28. It is published so your team can review it before signing; it is not in force until both parties execute it. Bracketed terms are completed in the executed copy.

1. Parties

This Data Processing Agreement ("DPA") is entered into between:

The Customer named in the order form or account ("Controller"); and

Algobain Technologies Opc Pvt Ltd, trading as DeelSignal, Indore, India ("Processor").

It forms part of the Terms of Service or other agreement under which the Processor provides the DeelSignal platform (the "Agreement"). Where this DPA conflicts with the Agreement on the processing of personal data, this DPA prevails. Where the Standard Contractual Clauses apply and conflict with this DPA, the Standard Contractual Clauses prevail.

2. Subject matter and duration

The Processor processes personal data on behalf of the Controller to provide the platform under the Agreement. This DPA applies for as long as the Processor processes personal data on the Controller's behalf, and ends when that processing ends under Section 12.

3. Nature and purpose of processing

Hosting, storage, retrieval, organisation, analysis (including AI-assisted analysis the Controller's users request), transmission (including email the Controller's users send through the platform), and deletion of personal data, solely to provide, secure and support the platform for the Controller, and only on the Controller's documented instructions. The Agreement, this DPA and the Controller's use of the platform's features are the Controller's instructions.

4. Categories of data subjects and personal data

Data subjects: the Controller's users (partners, analysts, controllers and other staff); limited partners and their representatives; founders, employees and officers of portfolio and prospective companies; other contacts the Controller records.

Personal data: names, business contact details, job titles and affiliations; account and authentication data; investment, commitment and capital-account data relating to individuals; content of notes, documents and communications the Controller uploads or sends; technical data such as IP addresses and device information.

Special categories: none are intended. The Controller will not upload special-category data unless both parties have agreed in writing to additional safeguards.

5. Processor obligations

The Processor will:

  • →process personal data only on the Controller’s documented instructions, including for international transfers, unless required otherwise by law (in which case it will inform the Controller first, unless the law prohibits it);
  • →tell the Controller promptly if, in its opinion, an instruction infringes applicable data protection law;
  • →ensure that everyone authorised to process the personal data is bound by confidentiality;
  • →implement the technical and organisational measures in Annex II;
  • →engage subprocessors only as set out in Section 6;
  • →assist the Controller, taking into account the nature of the processing, in responding to data subject requests;
  • →assist the Controller with its obligations on security, breach notification, data protection impact assessments and prior consultation, taking into account the information available to the Processor;
  • →make available the information needed to demonstrate compliance with Article 28 GDPR, and allow for audits as set out in Section 10.

6. Subprocessors

The Controller gives general written authorisation for the Processor to engage the subprocessors listed at deelsignal.com/legal/subprocessors.

The Processor will update that list, and notify the Controller by email to its account owner, before a new subprocessor begins processing personal data. The Controller may object on reasonable data protection grounds within 30 days of notice; if the parties cannot resolve the objection, the Controller may terminate the affected service.

The Processor will impose on each subprocessor, by contract, data protection obligations no less protective than those in this DPA, and remains liable to the Controller for each subprocessor's performance of those obligations.

Integrations the Controller itself enables with its own accounts (listed separately on the subprocessors page) are not subprocessors of the Processor.

7. Security

The Processor will implement and maintain appropriate technical and organisational measures to protect personal data, including those in Annex II. The Processor may update those measures, provided the overall level of protection is not reduced.

8. International transfers

The Processor is located in India, and some subprocessors are located outside the EEA, the UK and Switzerland (see the subprocessors page for locations).

EEA: to the extent the Controller's transfer of personal data to the Processor is a restricted transfer, the Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into this DPA by reference, with: Clause 7 (docking) included; Clause 9 Option 2 (general written authorisation, with notice as in Section 6); the optional language in Clause 11 omitted; Clause 17 governed by the law of [Ireland]; Clause 18 disputes resolved by the courts of [Ireland]. Annex I is completed by Sections 1 to 4 of this DPA; Annex II by Annex II below; Annex III by the subprocessors page.

UK: the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner applies to restricted transfers from the UK.

Switzerland: the Standard Contractual Clauses apply with the Swiss Federal Data Protection and Information Commissioner as competent authority and references to the GDPR read as references to the Swiss FADP.

Onward transfers to subprocessors are made under Module Three of the Standard Contractual Clauses or another transfer mechanism recognised under applicable law.

9. Personal data breach notification

The Processor will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's personal data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. The Processor will provide further information as it becomes available and will take reasonable steps to contain and remediate the breach.

10. Audit rights

On request, the Processor will provide the information reasonably necessary to demonstrate compliance with this DPA, including written answers to security questionnaires.

Where that information is not sufficient, the Controller (or an independent auditor bound by confidentiality) may audit the Processor's compliance on at least 30 days' written notice, no more than once in any 12 months unless required by a supervisory authority or following a personal data breach, during business hours and without unreasonably disrupting operations. Each party bears its own costs.

The Processor does not hold a SOC 2 report today; a SOC 2 Type II audit is in progress. Once a report is issued, the Processor may provide it in satisfaction of information requests it covers.

11. CCPA

To the extent the California Consumer Privacy Act applies, the Processor acts as a service provider: it will not sell or share the personal data, will not retain, use or disclose it for any purpose other than providing the platform under the Agreement, and will not combine it with personal data it receives from other sources except as permitted by the CCPA.

12. Deletion and return

On termination of the Agreement, the Controller may export its data from the platform for [30] days. After that period, the Processor will delete the Controller's personal data, unless applicable law requires it to be stored, and will confirm deletion in writing on request. Copies in backups are deleted in the ordinary course of the backup cycle and are not restored to active use in the meantime.

Annex II — Technical and organisational measures

The measures the platform implements today:

  • →Encryption in transit: the platform is served only over HTTPS (TLS).
  • →Encryption at rest: the primary database encrypts its storage at rest.
  • →Field-level encryption: stored connection credentials (OAuth tokens, API keys, SMTP passwords, SSO secrets) are encrypted with AES-256-GCM before they are written, under a key held outside the database.
  • →Tenant isolation: every workspace’s records are scoped to that workspace in the data-access rules, not only in the interface.
  • →Role-based access control within each workspace, with separate surfaces for fund staff, LPs and founders.
  • →Audit log: record changes, exports and LP document views are recorded with the acting user, time and, where available, IP address. Entries cannot be edited or deleted through the API.
  • →Authentication: accounts are locked for ten minutes after five consecutive failed sign-ins; session tokens expire; SAML single sign-on is available on every plan.
  • →Rate limiting on sign-in, sign-up and public endpoints.
  • →Uploaded files are stored under randomised, non-enumerable URLs.
  • →Subprocessor control: every outside system the platform connects to is declared in one register, and the build fails if a platform-operated vendor is missing from the published subprocessor list.
  • →A published channel for security reports: security@deelsignal.com.

Annex III — Subprocessors

The current list, with each subprocessor’s purpose and location, is maintained at deelsignal.com/legal/subprocessors.