top of page

Data Processing Agreement (DPA)

Last updated: 04/06/2026

This Data Processing Agreement (“DPA”) is entered into between [CLIENT LEGAL NAME] (“Controller”) and Geekynd Pvt Ltd (“Processor”). It forms part of, and is subject to, the services agreement or order between the parties (the “Agreement”). It applies where the processor processes personal data on behalf of the controller in the course of providing the services. If the Agreement and this DPA conflict on data-protection matters, this DPA controls.

1. Definitions

Capitalised terms not defined here have the meaning given in applicable data protection laws.

  • Data Protection Laws means all laws applicable to the processing of Personal Data under this DPA, including India’s Digital Personal Data Protection Act, 2023, and, where applicable, the EU/UK GDPR and the CCPA/CPRA.

  • Personal Data means any information relating to an identified or identifiable individual that the Processor processes on behalf of the Controller under the Agreement.

  • Processing means any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.

  • Sub-processor means any third party engaged by the processor to process personal data on the controller's behalf.

  • Data Subject means the individual to whom the Personal Data relates.

2. Roles and scope

The Controller determines the purposes and means of processing; the Processor processes Personal Data only on the Controller’s behalf. The subject matter, duration, nature, purpose, data types, and categories of Data Subjects are described in Annex A. The Processor will not sell Personal Data or process it for its own purposes.

3. Processor obligations

  • Process personal data only on the controller's documented instructions, including the agreement and this DPA, unless required by law (in which case it will inform the controller where permitted).

  • Ensure persons authorized to process Personal data are bound by confidentiality.

  • Implement appropriate technical and organisational security measures (Annex B).

  • Assist the Controller, taking into account the nature of processing, in responding to Data Subject requests and in meeting security, breach-notification, and (where applicable) impact-assessment obligations.

  • Make available information reasonably necessary to demonstrate compliance with this DPA.

4. Sub-processors

The Controller authorises the Processor to engage sub-processors listed in Annex C, which may include platform and tool providers used to deliver the Services. The processor will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA and remains responsible for their performance. The processor will give the controller reasonable notice of any intended change to sub-processors, and the controller may object on reasonable data-protection grounds.

5. Data subject rights

The processor will, where legally permitted, promptly notify the controller of any request it receives directly from a data subject and will not respond except on the Controller’s instructions. The Processor will provide reasonable assistance to enable the controller to respond to such requests.

6. Personal data breach

The processor will notify the controller without undue delay after becoming aware of a personal data breach affecting the controller's data and will provide information reasonably available to help the controller meet its own notification obligations and to mitigate the breach.

7. International transfers

The parties acknowledge that the processor operates in India and the United States, and personal data may be processed in those locations. Where Personal Data is transferred across borders, the parties will ensure an appropriate transfer mechanism and safeguards are in place as required by applicable Data Protection Laws.

8. Audits

On reasonable prior written notice and no more than once per year (or following a breach), the Controller may audit the Processor’s compliance with this DPA, subject to confidentiality and to not unreasonably disrupting operations. The processor may satisfy audit requests by providing relevant certifications or summaries where appropriate.

9. Return and deletion

On termination or expiry of the services, or on the controller's written request, the processor will, at the controller's choice, return or securely delete the personal data it processes on the controller's behalf, except where retention is required by law. Deletion will be confirmed on request.

10. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

11. Term

This DPA takes effect on the effective date of the Agreement and continues for as long as the Processor processes Personal Data on the Controller’s behalf.

Annex A — Description of processing

Item

Details

Subject matter

Provision of the Services described in the Agreement

Duration

Term of the Agreement plus any legally required retention

Nature & purpose

[e.g., customer support, back-office operations, CRM management, lead processing]

Types of Personal Data

[e.g., names, contact details, account data, transaction records]

Categories of Data Subjects

[e.g., the Controller’s customers, leads, employees, end users]

Annex B — Technical and organizational measures

  • Access controls and role-based, least-privilege access to systems and data

  • Confidentiality agreements and background vetting for personnel

  • Encryption in transit where supported by the relevant platforms

  • Secure credential management and use of approved tools only

  • Security awareness practices and onboarding for team members

  • Logging, monitoring, and incident-response procedures

Annex C — Approved sub-processors

Sub-processor

Purpose

Location

WiX

Website hosting and forms

Zoho

CRM / business operations tooling

Formspree

Form submission handling

WhatsApp Business

Client / candidate communications

Billing and payments

VS Code

All Places,

All Places,

All Places,

All Places,

All Places,

Controller: _________________________________________________________________________________________Date: ___________________________________________________

Processor (Geekynd Pvt Ltd): ________________________________________________________________________________ Date: ________________________________________

Signed for and on behalf of the parties:

Item

Details

Subject matter

Provision of the Services described in the Agreement

Duration

Term of the Agreement plus any legally required retention

Nature & purpose

[e.g., customer support, back-office operations, CRM management,lead processing]

Types of personal data

[e.g., names, contact details, account data, transaction records]

Categories of Data Subjects

[e.g., the Controller’s customers, leads, employees, end users]

Annex C — Approved sub-processors

  • Access controls and role-based, least-privilege access to systems and data

  • Confidentiality agreements and background vetting for personnel

  • Encryption in transit where supported by the relevant platforms

  • Secure credential management and use of approved tools only

  • Security awareness practices and onboarding for team members

  • Logging, monitoring, and incident-response procedures

Annex B — Technical and organizational measures

Wix

Purpose

Website hosting and forms

All Places,

Location

Zoho

Purpose

CRM / business operations tooling

All Places,

Location

WhatsApp Business

Purpose

Client / candidate communications

All Places,

Location

Formspree

Purpose

Form submission handling

All Places,

Location

VS Code

Purpose

App & Web Development

All Places,

Location

Wix

Purpose

Billing and payments

All Places,

Location

Controller:___________________________________________Date:________________________________________________

Processor (Geekynd Pvt Ltd): ____________________________________________________ Date: ________________________________________

Signed for and on behalf of the parties:

bottom of page