Data Processing Agreement (DPA)
Last updated: 04/06/2026
This Data Processing Agreement (“DPA”) is entered into between [CLIENT LEGAL NAME] (“Controller”) and Geekynd Pvt Ltd (“Processor”). It forms part of, and is subject to, the services agreement or order between the parties (the “Agreement”). It applies where the processor processes personal data on behalf of the controller in the course of providing the services. If the Agreement and this DPA conflict on data-protection matters, this DPA controls.
1. Definitions
Capitalised terms not defined here have the meaning given in applicable data protection laws.
-
Data Protection Laws means all laws applicable to the processing of Personal Data under this DPA, including India’s Digital Personal Data Protection Act, 2023, and, where applicable, the EU/UK GDPR and the CCPA/CPRA.
-
Personal Data means any information relating to an identified or identifiable individual that the Processor processes on behalf of the Controller under the Agreement.
-
Processing means any operation performed on personal data, such as collection, storage, use, disclosure, or deletion.
-
Sub-processor means any third party engaged by the processor to process personal data on the controller's behalf.
-
Data Subject means the individual to whom the Personal Data relates.
2. Roles and scope
The Controller determines the purposes and means of processing; the Processor processes Personal Data only on the Controller’s behalf. The subject matter, duration, nature, purpose, data types, and categories of Data Subjects are described in Annex A. The Processor will not sell Personal Data or process it for its own purposes.
3. Processor obligations
-
Process personal data only on the controller's documented instructions, including the agreement and this DPA, unless required by law (in which case it will inform the controller where permitted).
-
Ensure persons authorized to process Personal data are bound by confidentiality.
-
Implement appropriate technical and organisational security measures (Annex B).
-
Assist the Controller, taking into account the nature of processing, in responding to Data Subject requests and in meeting security, breach-notification, and (where applicable) impact-assessment obligations.
-
Make available information reasonably necessary to demonstrate compliance with this DPA.
4. Sub-processors
The Controller authorises the Processor to engage sub-processors listed in Annex C, which may include platform and tool providers used to deliver the Services. The processor will impose data-protection obligations on each sub-processor that are no less protective than those in this DPA and remains responsible for their performance. The processor will give the controller reasonable notice of any intended change to sub-processors, and the controller may object on reasonable data-protection grounds.
5. Data subject rights
The processor will, where legally permitted, promptly notify the controller of any request it receives directly from a data subject and will not respond except on the Controller’s instructions. The Processor will provide reasonable assistance to enable the controller to respond to such requests.
6. Personal data breach
The processor will notify the controller without undue delay after becoming aware of a personal data breach affecting the controller's data and will provide information reasonably available to help the controller meet its own notification obligations and to mitigate the breach.
7. International transfers
The parties acknowledge that the processor operates in India and the United States, and personal data may be processed in those locations. Where Personal Data is transferred across borders, the parties will ensure an appropriate transfer mechanism and safeguards are in place as required by applicable Data Protection Laws.
8. Audits
On reasonable prior written notice and no more than once per year (or following a breach), the Controller may audit the Processor’s compliance with this DPA, subject to confidentiality and to not unreasonably disrupting operations. The processor may satisfy audit requests by providing relevant certifications or summaries where appropriate.
9. Return and deletion
On termination or expiry of the services, or on the controller's written request, the processor will, at the controller's choice, return or securely delete the personal data it processes on the controller's behalf, except where retention is required by law. Deletion will be confirmed on request.
10. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
11. Term
This DPA takes effect on the effective date of the Agreement and continues for as long as the Processor processes Personal Data on the Controller’s behalf.
Annex A — Description of processing
Item
Details
Subject matter
Provision of the Services described in the Agreement
Duration
Term of the Agreement plus any legally required retention
Nature & purpose
[e.g., customer support, back-office operations, CRM management, lead processing]
Types of Personal Data
[e.g., names, contact details, account data, transaction records]
Categories of Data Subjects
[e.g., the Controller’s customers, leads, employees, end users]
Annex B — Technical and organizational measures
-
Access controls and role-based, least-privilege access to systems and data
-
Confidentiality agreements and background vetting for personnel
-
Encryption in transit where supported by the relevant platforms
-
Secure credential management and use of approved tools only
-
Security awareness practices and onboarding for team members
-
Logging, monitoring, and incident-response procedures
Annex C — Approved sub-processors
Sub-processor
Purpose
Location
WiX
Website hosting and forms
Zoho
CRM / business operations tooling
Formspree
Form submission handling
WhatsApp Business
Client / candidate communications
Billing and payments
VS Code
All Places,
All Places,
All Places,
All Places,
All Places,
Controller: _________________________________________________________________________________________Date: ___________________________________________________
Processor (Geekynd Pvt Ltd): ________________________________________________________________________________ Date: ________________________________________
Signed for and on behalf of the parties:
Item
Details
Subject matter
Provision of the Services described in the Agreement
Duration
Term of the Agreement plus any legally required retention
Nature & purpose
[e.g., customer support, back-office operations, CRM management,lead processing]
Types of personal data
[e.g., names, contact details, account data, transaction records]
Categories of Data Subjects
[e.g., the Controller’s customers, leads, employees, end users]
Annex C — Approved sub-processors
-
Access controls and role-based, least-privilege access to systems and data
-
Confidentiality agreements and background vetting for personnel
-
Encryption in transit where supported by the relevant platforms
-
Secure credential management and use of approved tools only
-
Security awareness practices and onboarding for team members
-
Logging, monitoring, and incident-response procedures
Annex B — Technical and organizational measures
WhatsApp Business
Purpose
Client / candidate communications
All Places,
Location
Formspree
Purpose
Form submission handling
All Places,
Location
VS Code
Purpose
App & Web Development
All Places,
Location
Controller:___________________________________________Date:________________________________________________
Processor (Geekynd Pvt Ltd): ____________________________________________________ Date: ________________________________________
Signed for and on behalf of the parties:
