Legal
Data Processing Agreement
DATA PROCESSING AGREEMENT
Effective Date: 24 July 2026 Last Updated: 24 July 2026
This Data Processing Agreement (“DPA”) is entered into between:
1. Qoptervzn Infocom Private Limited, operating the GrowthMate service and having its principal place of business in Bhandara, Maharashtra, India (“GrowthMate,” “Processor,” “Service Provider,” “we,” “us,” or “our”); and
2. The person or legal entity that has entered into an agreement with GrowthMate for access to or use of the Services (“Customer,” “Controller,” “Business,” “you,” or “your”).
GrowthMate and Customer are individually a “Party” and collectively the “Parties.”
This DPA forms part of and is incorporated into GrowthMate’s Terms of Service, order form, subscription agreement, enterprise agreement, or other written agreement governing Customer’s use of the Services collectively referred to as the “Main Agreement.”
By entering into the Main Agreement, accepting this DPA electronically, creating an account, or using the Services to process Customer Personal Data, Customer agrees to this DPA on behalf of itself and, where applicable, its authorised Affiliates.
1. Purpose
This DPA governs GrowthMate’s Processing of Customer Personal Data on behalf of Customer in connection with GrowthMate’s websites, applications, analytics integrations, dashboards, reports, artificial-intelligence features, alerts, APIs, email and WhatsApp delivery features, and related services collectively referred to as the “Services.”
The purpose of this DPA is to ensure that Customer Personal Data is Processed:
- Only for authorised and documented purposes;
- With appropriate privacy and security protections;
- In accordance with Applicable Data Protection Law;
- Consistently with Customer’s lawful instructions; and
- Subject to appropriate safeguards when transferred internationally.
2. Definitions
2.1 Affiliate
“Affiliate” means an entity that directly or indirectly controls, is controlled by, or is under common control with a Party.
2.2 Applicable Data Protection Law
“Applicable Data Protection Law” means all privacy, data-protection, cybersecurity, breach-notification, and electronic-communications laws applicable to the Processing of Customer Personal Data under the Main Agreement, including, where applicable:
- The Digital Personal Data Protection Act, 2023 of India and its rules, regulations, amendments, and implementing requirements, to the extent in force and applicable;
- Regulation (EU) 2016/679, the General Data Protection Regulation (“EU GDPR”);
- The EU ePrivacy Directive and applicable national implementing laws;
- The United Kingdom General Data Protection Regulation (“UK GDPR”);
- The United Kingdom Data Protection Act 2018;
- The Swiss Federal Act on Data Protection;
- The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (“CCPA”);
- Applicable United States state privacy laws; and
- Any amendment, replacement, or successor legislation applicable to the Processing.
2.3 Controller and Processor
“Controller,” “Processor,” “Data Fiduciary,” “Data Processor,” “Business,” “Service Provider,” and “Contractor” have the meanings assigned to them under Applicable Data Protection Law.
Where no statutory definition applies:
- A Controller determines why and how Personal Data is Processed; and
- A Processor Processes Personal Data on behalf of and under the instructions of a Controller.
2.4 Customer Personal Data
“Customer Personal Data” means Personal Data that GrowthMate Processes on behalf of Customer through the Services.
Customer Personal Data does not include information for which GrowthMate independently determines the purposes and means of Processing, as described in Section 19.
2.5 Data Subject
“Data Subject” means the identified or identifiable individual to whom Personal Data relates and includes a “Data Principal,” “consumer,” or similar protected person under Applicable Data Protection Law.
2.6 Personal Data
“Personal Data” means information relating to an identified or identifiable natural person, household, or device, or any other information defined as personal data, personal information, or a similar term under Applicable Data Protection Law.
2.7 Personal Data Breach
“Personal Data Breach” means a confirmed breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data Processed by GrowthMate.
Unsuccessful attempts or activities that do not compromise Customer Personal Data—including unsuccessful login attempts, port scans, denial-of-service attempts, blocked attacks, and similar events—are not Personal Data Breaches.
2.8 Process or Processing
“Process” or “Processing” means any operation performed on Personal Data, whether by automated means or otherwise, including collecting, receiving, recording, organising, structuring, storing, modifying, retrieving, consulting, using, analysing, aggregating, transmitting, disclosing, restricting, deleting, or destroying Personal Data.
2.9 Restricted Transfer
“Restricted Transfer” means a transfer of Personal Data to a country or recipient for which Applicable Data Protection Law requires an adequacy decision, approved transfer mechanism, contractual safeguard, or other legal protection.
2.10 Standard Contractual Clauses
“EU SCCs” means the European Commission’s Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner and laid before Parliament, as amended or replaced from time to time.
2.11 Subprocessor
“Subprocessor” means a third party appointed by GrowthMate to Process Customer Personal Data on behalf of Customer.
3. Roles of the Parties
3.1 Customer as Controller
Customer is the Controller or Data Fiduciary of Customer Personal Data where Customer determines the purposes and essential means of Processing.
3.2 GrowthMate as Processor
GrowthMate is the Processor, Data Processor, Service Provider, or Contractor when it Processes Customer Personal Data on Customer’s behalf to provide the Services.
3.3 Customer Acting as a Processor
Where Customer Processes Personal Data on behalf of another Controller, Customer acts as a Processor and appoints GrowthMate as its Subprocessor.
Customer represents that the relevant Controller has authorised:
- Customer’s use of GrowthMate;
- GrowthMate’s Processing of the relevant Personal Data;
- The appointment of GrowthMate’s Subprocessors; and
- Any international transfers contemplated by the Main Agreement and this DPA.
3.4 Role Determination
The Parties’ roles will be determined by the facts and Applicable Data Protection Law, regardless of the terminology used in this DPA.
Nothing in this DPA changes a Party’s legal role where Applicable Data Protection Law assigns a different role based on the actual Processing activity.
4. Details and Scope of Processing
The subject matter, duration, nature, purpose, Personal Data categories, and Data Subject categories are described in Schedule 1.
GrowthMate will Process Customer Personal Data only:
- During the term of the Main Agreement;
- To provide, maintain, secure, support, and improve the Services as authorised under the Main Agreement;
- To create Customer-requested analytics, reports, alerts, summaries, and recommendations;
- To connect and communicate with Customer-authorised third-party platforms;
- To deliver reports and notifications to Customer-authorised recipients;
- On Customer’s documented instructions; or
- Where required by applicable law.
Customer’s documented instructions include:
- The Main Agreement;
- This DPA;
- Customer’s configuration and use of the Services;
- Customer’s account, integration, reporting, and communication settings;
- Customer’s support requests;
- Customer’s written instructions submitted through authorised channels; and
- Instructions agreed to in writing by the Parties.
5. Customer Obligations
5.1 Lawful Processing
Customer is responsible for ensuring that:
- Customer Personal Data is collected and Processed lawfully;
- Customer has an appropriate legal basis for the Processing;
- Required privacy notices are provided;
- Required consents and authorisations are obtained and maintained;
- Customer’s instructions comply with Applicable Data Protection Law;
- Data Subjects can exercise their applicable rights;
- Customer Personal Data is accurate, relevant, and limited to what is reasonably necessary;
- Customer has authority to connect each analytics, advertising, website, application, business-profile, email, WhatsApp, search, ecommerce, or other account connected to GrowthMate; and
- Reports and communications are sent only to authorised recipients.
5.2 Responsibility for Instructions
Customer is solely responsible for the lawfulness, accuracy, and completeness of its instructions.
GrowthMate is not responsible for determining whether Customer’s intended Processing is lawful, except that GrowthMate will inform Customer where it reasonably believes an instruction infringes Applicable Data Protection Law.
GrowthMate may suspend the affected Processing until the Parties resolve the concern.
5.3 Sensitive Personal Data
The Services are not designed for the Processing of:
- Health or medical records;
- Biometric identifiers;
- Genetic information;
- Precise location information used to identify sensitive visits;
- Government identification numbers;
- Account passwords or authentication secrets;
- Full payment-card information;
- Criminal-history information;
- Information concerning sexual activity or orientation;
- Information revealing race, ethnicity, religion, political opinions, or trade-union membership; or
- Other special-category or sensitive Personal Data.
Customer must not submit such information to the Services unless:
- The Processing is necessary for an expressly supported Service feature;
- The Parties have expressly agreed to the Processing in writing;
- Customer has completed any legally required assessment;
- Customer has obtained all required consents or authorisations; and
- Appropriate additional security measures have been agreed.
5.4 Children’s Data
Customer must not knowingly submit Personal Data relating to children through the Services unless:
- The Processing is lawful;
- It is reasonably necessary for an expressly agreed Service purpose;
- All legally required parental or guardian consents have been obtained; and
- GrowthMate has agreed in writing to the Processing.
5.5 Customer Security
Customer is responsible for:
- Protecting account credentials;
- Configuring appropriate user roles and access permissions;
- Using multifactor authentication where available;
- Promptly removing access for former or unauthorised users;
- Reviewing connected accounts and recipients;
- Securing devices and networks used to access GrowthMate; and
- Promptly notifying GrowthMate of suspected account compromise.
6. GrowthMate’s Processing Obligations
GrowthMate will:
- Process Customer Personal Data only on documented instructions from Customer;
- Process only the Personal Data reasonably necessary to provide the Services;
- Not materially change the purpose of Processing without Customer’s authorisation;
- Inform Customer where GrowthMate reasonably believes an instruction violates Applicable Data Protection Law;
- Maintain appropriate technical and organisational security measures;
- Ensure authorised personnel are subject to confidentiality obligations;
- Provide reasonable assistance with Data Subject requests;
- Provide reasonable assistance with breach notifications, impact assessments, and regulatory consultations;
- Maintain required records relating to its Processing activities;
- Make information reasonably necessary to demonstrate compliance available to Customer;
- Delete or return Customer Personal Data as described in this DPA; and
- Comply with the obligations directly applicable to Processors under Applicable Data Protection Law.
Where applicable law requires GrowthMate to Process Customer Personal Data other than on Customer’s instructions, GrowthMate will notify Customer before Processing unless the law prohibits such notice on important grounds of public interest.
7. Confidentiality
GrowthMate will ensure that personnel authorised to Process Customer Personal Data:
- Are subject to contractual or statutory confidentiality obligations;
- Receive appropriate privacy and security training;
- Access Customer Personal Data only where reasonably necessary for their responsibilities;
- Are subject to appropriate access controls; and
- Process Customer Personal Data only in accordance with GrowthMate’s instructions and this DPA.
The confidentiality obligations in this Section survive termination of the Main Agreement.
8. Security Measures
8.1 General Security Obligation
GrowthMate will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, access, use, or other unlawful Processing.
The security measures will take into account:
- The state of the art;
- Reasonable implementation costs;
- The nature, scope, context, and purposes of Processing;
- The volume and sensitivity of Customer Personal Data; and
- The likelihood and severity of risks to Data Subjects.
GrowthMate’s principal security measures are described in Schedule 2.
8.2 Security Updates
GrowthMate may modify its security measures as technologies, risks, and the Services evolve, provided that the modifications do not materially reduce the overall protection of Customer Personal Data.
8.3 No Absolute Security Guarantee
Customer acknowledges that no internet-connected service, storage system, transmission mechanism, or security process can guarantee absolute security.
GrowthMate’s obligations are to maintain appropriate safeguards and respond reasonably to identified risks and incidents, not to guarantee that a security incident can never occur.
9. Personal Data Breaches
9.1 Notification
GrowthMate will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach involving Customer Personal Data.
Where reasonably practicable, GrowthMate will provide initial notification within 48 hours after confirming that a Personal Data Breach has occurred.
9.2 Notification Information
To the extent known and reasonably available, GrowthMate’s notification will include:
- A description of the nature of the Personal Data Breach;
- The categories of affected Customer Personal Data;
- The categories and approximate number of affected Data Subjects, where known;
- The likely consequences of the Personal Data Breach;
- The measures taken or proposed to contain, investigate, and remediate the breach; and
- Contact information for reasonable follow-up questions.
GrowthMate may provide information in phases as its investigation progresses.
9.3 Cooperation
GrowthMate will take reasonable steps to:
- Contain the Personal Data Breach;
- Investigate its cause and scope;
- Mitigate reasonably foreseeable harm;
- Preserve relevant evidence;
- Correct identified security weaknesses; and
- Assist Customer with legally required notifications.
9.4 Customer Responsibility
Customer is responsible for determining:
- Whether notification to a regulator, Data Subject, client, or other party is legally required;
- The content and timing of such notification; and
- Whether other remedial action is necessary.
GrowthMate will not notify Data Subjects or regulators on Customer’s behalf unless:
- Customer instructs GrowthMate to do so;
- The Parties separately agree on the notification;
- Applicable law requires GrowthMate to notify directly; or
- Immediate notification is reasonably necessary to address a serious and imminent risk.
9.5 No Admission
A Personal Data Breach notification does not constitute an admission of fault, liability, or violation by GrowthMate.
10. Data Subject Requests
10.1 Customer Responsibility
Customer is responsible for responding to requests from Data Subjects concerning Customer Personal Data, including requests to:
- Access Personal Data;
- Correct inaccurate Personal Data;
- Delete Personal Data;
- Restrict Processing;
- Object to Processing;
- Withdraw consent;
- Receive portable copies;
- Opt out of sale, sharing, profiling, or targeted advertising; or
- Exercise another right under Applicable Data Protection Law.
10.2 GrowthMate Assistance
Taking into account the nature of the Processing, GrowthMate will provide reasonable technical and organisational assistance to enable Customer to respond to valid Data Subject requests.
GrowthMate may satisfy this obligation by providing:
- Product functionality;
- Account controls;
- Search, export, correction, or deletion tools;
- Documentation;
- Technical support; or
- Reasonable manual assistance where the request cannot be addressed through available functionality.
10.3 Requests Received by GrowthMate
Where GrowthMate directly receives a request relating to Customer Personal Data, GrowthMate will:
- Promptly refer the request to Customer;
- Not substantively respond on Customer’s behalf unless authorised or legally required; and
- Advise the requester to contact Customer where appropriate.
GrowthMate may request information reasonably necessary to verify the request and identify the relevant Customer account.
11. Regulatory Compliance Assistance
Taking into account the nature of Processing and information available to GrowthMate, GrowthMate will provide reasonable assistance with Customer’s obligations relating to:
- Security of Processing;
- Personal Data Breach assessments and notifications;
- Data-protection impact assessments;
- Legitimate-interest or risk assessments;
- Transfer impact assessments;
- Prior consultation with supervisory authorities;
- Regulatory enquiries relating to GrowthMate’s Processing; and
- Demonstrating compliance with Applicable Data Protection Law.
Where assistance requires substantial customised work beyond the ordinary operation of the Services, GrowthMate may charge reasonable fees based on the work involved, unless the assistance is required because of GrowthMate’s breach of this DPA.
12. Data Protection Impact Assessments
Where Customer reasonably determines that GrowthMate’s Processing requires a data-protection impact assessment or similar risk assessment, GrowthMate will provide information reasonably available to it concerning:
- The nature and purpose of Processing;
- Categories of Personal Data and Data Subjects;
- Security safeguards;
- Subprocessor arrangements;
- Data locations and transfers;
- Retention and deletion practices; and
- Relevant risk-mitigation measures.
Customer remains responsible for preparing, approving, and maintaining its assessment.
13. Subprocessors
13.1 General Authorisation
Customer grants GrowthMate general written authorisation to engage Subprocessors to provide the Services.
GrowthMate will maintain a current list of Subprocessors that Process Customer Personal Data and will make that list available electronically or upon Customer’s written request.
13.2 Subprocessor Requirements
Before allowing a Subprocessor to Process Customer Personal Data, GrowthMate will enter into a written agreement requiring the Subprocessor to:
- Process Customer Personal Data only for contracted purposes;
- Maintain confidentiality;
- Implement appropriate security measures;
- Assist with applicable privacy and security obligations;
- Delete or return Customer Personal Data as required; and
- Provide protections materially equivalent to the relevant obligations imposed on GrowthMate under this DPA.
GrowthMate remains responsible for its Subprocessors’ performance of their data-protection obligations to the extent required by Applicable Data Protection Law.
13.3 New Subprocessor Notices
GrowthMate will provide reasonable advance notice of a new Subprocessor that will Process Customer Personal Data.
Where reasonably practicable, notice will be provided at least 15 calendar days before the new Subprocessor begins Processing.
Notice may be provided through:
- Email;
- An account notification;
- A legal or privacy notice;
- A Subprocessor update page; or
- Another reasonable electronic method.
13.4 Customer Objections
Customer may object to a new Subprocessor on reasonable and documented data-protection grounds by notifying GrowthMate before the stated appointment date.
The objection must explain:
- The specific data-protection concern;
- The Personal Data or Processing affected; and
- The reasonable basis for believing that the appointment creates a material compliance risk.
The Parties will work in good faith to resolve the objection.
GrowthMate may address the objection by:
- Providing additional information;
- Applying supplementary safeguards;
- Limiting the Subprocessor’s access;
- Offering a commercially reasonable alternative; or
- Discontinuing the affected Processing.
Where no commercially reasonable resolution is available, Customer may terminate only the affected Service by providing written notice before the Subprocessor begins Processing.
GrowthMate will refund any prepaid fees covering the unused period of the terminated affected Service, unless the objection is frivolous, unrelated to data protection, or based solely on general opposition to outsourcing.
14. International Data Transfers
14.1 General Requirements
GrowthMate may Process Customer Personal Data in India and other countries where GrowthMate or its authorised Subprocessors operate.
GrowthMate will ensure that Restricted Transfers are subject to a lawful transfer mechanism required by Applicable Data Protection Law.
Depending on the circumstances, the transfer mechanism may include:
- An adequacy decision;
- The EU SCCs;
- The UK Addendum;
- The UK International Data Transfer Agreement;
- Binding corporate rules;
- An approved certification or code;
- A legally permitted derogation; or
- Another valid transfer mechanism.
14.2 EU and EEA Transfers
Where Customer Personal Data protected by the EU GDPR is transferred to GrowthMate in a country not recognised as providing adequate protection and no other valid transfer mechanism applies, the EU SCCs are incorporated into this DPA as described in Schedule 4.
14.3 United Kingdom Transfers
Where Customer Personal Data protected by the UK GDPR is transferred to GrowthMate in a country not covered by applicable UK adequacy regulations and no other valid transfer mechanism applies, the UK Addendum is incorporated into this DPA as described in Schedule 4.
14.4 Swiss Transfers
Where Swiss data-protection law applies to a Restricted Transfer, the EU SCCs will apply with the modifications reasonably necessary for compliance with Swiss law, including recognition of the Swiss Federal Data Protection and Information Commissioner as the competent authority where required.
14.5 Transfer Assessments and Supplementary Measures
The Parties will reasonably cooperate with legally required transfer impact or transfer risk assessments.
GrowthMate will provide information reasonably available to it regarding:
- Data locations;
- Transfer mechanisms;
- Subprocessors;
- Security safeguards;
- Government-access request practices; and
- Supplementary technical or organisational measures.
14.6 Transfer Precedence
Where the EU SCCs, UK Addendum, or another mandatory transfer mechanism conflicts with this DPA or the Main Agreement, the mandatory transfer mechanism controls to the extent of the conflict.
15. Government and Legal Requests
Where GrowthMate receives a legally binding request from a court, law-enforcement authority, government agency, or regulator seeking Customer Personal Data, GrowthMate will, to the extent legally permitted:
- Review the request for legal validity;
- Limit disclosure to information legally required;
- Notify Customer before disclosure;
- Provide Customer with available information about the request;
- Redirect the requesting authority to Customer where reasonably appropriate; and
- Challenge or seek clarification of requests that appear unlawful, overbroad, or disproportionate where there are reasonable grounds to do so.
Where GrowthMate is legally prohibited from notifying Customer, GrowthMate will use reasonable efforts to obtain permission to provide notice.
Nothing in this Section requires GrowthMate to take action that would violate applicable law or expose GrowthMate to criminal or material legal penalties.
16. Return and Deletion of Customer Personal Data
16.1 During the Subscription
Customer may access, export, correct, or delete Customer Personal Data using available Service functionality, subject to the Main Agreement and technical limitations.
16.2 After Termination
Following termination or expiration of the Main Agreement, GrowthMate will, at Customer’s choice and subject to available functionality:
- Return or make Customer Personal Data available for export; and
- Delete Customer Personal Data from active production systems.
Unless another period is stated in the Main Agreement, Customer must request an export before termination or within any post-termination retrieval period made available by GrowthMate.
16.3 Deletion Period
Unless Applicable Data Protection Law or the Main Agreement requires another period, GrowthMate will delete Customer Personal Data from active systems within 30 days after the applicable deletion request or end of the retrieval period.
Customer Personal Data retained in encrypted, isolated, or disaster-recovery backups may remain until overwritten through GrowthMate’s ordinary backup cycle, which will ordinarily not exceed 90 days after deletion from active systems.
During that period, backup data will:
- Remain protected under this DPA;
- Be placed beyond ordinary business use;
- Not be restored except for disaster recovery, security, or legal necessity; and
- Be deleted or overwritten according to the applicable backup cycle.
16.4 Legally Required Retention
GrowthMate may retain limited Customer Personal Data where required by applicable law, court order, regulatory obligation, fraud-prevention requirement, or binding platform requirement.
Retained data will:
- Be limited to what is legally required;
- Remain protected under this DPA;
- Not be Processed for unrelated purposes; and
- Be deleted when the legal retention requirement ends.
17. Audit and Compliance Information
17.1 Compliance Information
Upon reasonable written request, GrowthMate will provide information reasonably necessary to demonstrate compliance with this DPA.
GrowthMate may provide:
- Security documentation;
- Privacy and security questionnaires;
- Subprocessor information;
- Relevant policies and summaries;
- Independent assessment reports, if available;
- Vulnerability-management summaries;
- Data-flow information; or
- Other reasonably appropriate evidence.
GrowthMate may redact information that:
- Relates to other customers;
- Contains security-sensitive details;
- Is legally privileged;
- Is subject to confidentiality obligations; or
- Could create a material security risk if disclosed.
17.2 Audit Rights
Where the information provided under Section 17.1 is insufficient to demonstrate compliance, Customer may conduct an audit subject to the following conditions:
- Customer must provide at least 30 days’ written notice, unless a regulator or confirmed Personal Data Breach requires shorter notice;
- The audit must be conducted during normal business hours;
- The audit must not unreasonably interfere with GrowthMate’s operations;
- Customer must first use available documentation and remote-review procedures;
- The audit must be limited to systems and Processing relevant to Customer Personal Data;
- The auditor must be independent, appropriately qualified, and bound by confidentiality;
- The audit must not include access to other customers’ information;
- The audit must not involve penetration testing, vulnerability exploitation, source-code access, or destructive testing without separate written authorisation; and
- Customer must provide GrowthMate with a copy of the final audit report.
Unless GrowthMate has materially breached this DPA, Customer will bear its own audit costs and reimburse GrowthMate’s reasonable costs of supporting an audit that requires substantial personnel time.
17.3 Audit Frequency
Customer may conduct no more than one audit in any 12-month period unless:
- A confirmed Personal Data Breach materially affecting Customer Personal Data has occurred;
- A competent regulator requires an additional audit; or
- Customer has reasonable evidence of GrowthMate’s material noncompliance.
18. Artificial Intelligence and Automated Analysis
18.1 Customer Instructions
Where Customer enables artificial-intelligence or automated-analysis features, Customer instructs GrowthMate to Process Customer Personal Data as reasonably necessary to generate:
- Summaries;
- Reports;
- Explanations;
- Forecasts;
- Recommendations;
- Anomaly alerts;
- Performance observations; and
- Other requested outputs.
18.2 Human Review
Customer is responsible for reviewing AI-generated outputs before relying on them for material business, financial, advertising, legal, employment, or other decisions.
18.3 Model Training
GrowthMate will not use Customer Personal Data to train a general-purpose artificial-intelligence model for the benefit of unrelated third parties unless:
- Customer expressly opts in;
- The Processing is separately disclosed and lawfully authorised; or
- The information has been aggregated or de-identified so that it is no longer Personal Data under Applicable Data Protection Law.
GrowthMate may use de-identified or aggregated service information to improve the Services, provided that GrowthMate does not attempt to re-identify the information.
18.4 AI Providers
An AI technology provider that Processes Customer Personal Data on GrowthMate’s behalf will be treated as a Subprocessor and subject to Section 13.
19. GrowthMate as an Independent Controller
GrowthMate may independently Process limited Personal Data as a Controller or Data Fiduciary where it determines the purposes and means of Processing.
Such Processing may include:
- Account registration and administration;
- Contract and customer-relationship management;
- Subscription, invoicing, tax, and payment administration;
- Customer-support records;
- Security monitoring;
- Fraud and abuse prevention;
- Legal and regulatory compliance;
- Enforcing the Main Agreement;
- Service-level analytics that do not consist of Customer-directed Processing;
- Product communications;
- Corporate records; and
- Establishing, exercising, or defending legal claims.
GrowthMate’s independent Controller Processing is governed by GrowthMate’s Privacy Policy and Applicable Data Protection Law rather than the Processor obligations in this DPA.
GrowthMate will not treat Customer Personal Data as independent Controller data merely to avoid its obligations under this DPA.
20. United States State Privacy Requirements
Where GrowthMate Processes personal information subject to the CCPA or another applicable United States state privacy law on Customer’s behalf:
- Customer is the Business or Controller;
- GrowthMate is the Service Provider, Contractor, or Processor;
- Customer discloses personal information to GrowthMate only for the limited and specified business purposes described in the Main Agreement and Schedule 1;
- GrowthMate will not sell or share Customer Personal Data;
- GrowthMate will not retain, use, or disclose Customer Personal Data outside the direct business relationship with Customer except as permitted by law;
- GrowthMate will not retain, use, or disclose Customer Personal Data for a commercial purpose other than providing the Services and permitted operational purposes;
- GrowthMate will not combine Customer Personal Data with personal information obtained from another person or from GrowthMate’s independent interactions with a consumer except where legally permitted for the contracted business purpose;
- GrowthMate will provide the same level of privacy protection required of applicable service providers or processors;
- GrowthMate will notify Customer if it determines that it can no longer meet its applicable legal obligations;
- Customer may take reasonable and appropriate steps to verify that GrowthMate uses Customer Personal Data consistently with Customer’s obligations; and
- Customer may require GrowthMate to stop and remediate unauthorised use of Customer Personal Data.
GrowthMate certifies that it understands and will comply with the restrictions in this Section.
21. Records and Regulatory Cooperation
GrowthMate will maintain records of Processing to the extent required by Applicable Data Protection Law.
GrowthMate will reasonably cooperate with competent data-protection authorities in relation to GrowthMate’s Processing of Customer Personal Data.
If a regulator contacts GrowthMate concerning Customer’s Processing, GrowthMate may refer the regulator to Customer unless GrowthMate is legally required to respond directly.
22. Liability
Each Party’s liability arising from or relating to this DPA is subject to the exclusions, limitations, and liability caps in the Main Agreement, except:
- To the extent such limitation is prohibited by Applicable Data Protection Law;
- For liability arising under the EU SCCs or UK Addendum where those instruments prohibit the limitation; or
- Where the Main Agreement expressly states otherwise.
Nothing in this DPA limits a Data Subject’s rights or remedies under mandatory Applicable Data Protection Law.
23. Indemnification
Any indemnification obligations relating to privacy, security, or Personal Data will be governed by the Main Agreement.
Where the Main Agreement does not contain an indemnification clause, each Party remains responsible for its own acts, omissions, instructions, legal obligations, and violations of Applicable Data Protection Law.
24. Term and Termination
This DPA begins when Customer accepts the Main Agreement or when GrowthMate first Processes Customer Personal Data on Customer’s behalf, whichever occurs first.
This DPA remains effective until GrowthMate has deleted or returned all Customer Personal Data, except for provisions that expressly or by their nature survive termination.
The following provisions survive termination:
- Confidentiality;
- Legally required retention;
- International-transfer protections;
- Audit obligations relating to Processing during the term;
- Liability;
- Governing law; and
- Any other provision intended to survive.
25. Order of Precedence
In the event of a conflict, the following order of precedence applies:
1. The EU SCCs or UK Addendum, where applicable; 2. Any other mandatory transfer mechanism; 3. This DPA; 4. The Main Agreement; 5. Other policies or documentation incorporated into the Main Agreement.
The higher-priority document controls only to the extent of the conflict.
26. Amendments
GrowthMate may update this DPA where reasonably necessary to:
- Comply with changes in law;
- Adopt an updated transfer mechanism;
- Reflect changes to the Services;
- Improve privacy or security protections;
- Address regulatory guidance; or
- Correct an ambiguity or administrative issue.
GrowthMate will not materially reduce the overall protection of Customer Personal Data during an active paid subscription without reasonable notice, unless the change is required by law or needed to address an urgent security risk.
Where a change materially and adversely affects Customer’s data-protection rights, Customer may object by contacting GrowthMate within the notice period.
27. Governing Law
Except where the EU SCCs, UK Addendum, or mandatory Applicable Data Protection Law requires otherwise, this DPA is governed by the governing-law and dispute-resolution provisions of the Main Agreement.
Where the Main Agreement does not identify a governing law, this DPA will be governed by the laws of India, and the courts having jurisdiction over Bhandara, Maharashtra, India will have jurisdiction, subject to any mandatory rights available under Applicable Data Protection Law.
28. Electronic Acceptance and Authority
This DPA may be accepted:
- Electronically;
- Through acceptance of the Main Agreement;
- Through an order form;
- Through continued authorised use of the Services; or
- By signature.
The person accepting this DPA represents that they have authority to bind Customer and any Customer Affiliates receiving the Services.
29. Contact Information
Questions, requests, or notices relating to this DPA may be sent to:
Qoptervzn Infocom Private Limited Operating as GrowthMate Bhandara, Maharashtra, India
Grievance Officer: Alok Diwate, Director Email: [email protected]
SCHEDULE 1
DETAILS OF PROCESSING
1. Parties
Controller / Data Exporter: The Customer identified in the Main Agreement or applicable order form.
Processor / Data Importer: Qoptervzn Infocom Private Limited, operating GrowthMate, Bhandara, Maharashtra, India.
2. Subject Matter
Processing Customer Personal Data to provide GrowthMate’s analytics, reporting, monitoring, integration, automation, artificial-intelligence, alert, communication, support, and related SaaS services.
3. Duration
For the duration of the Main Agreement and any limited period necessary to return, export, secure, or delete Customer Personal Data, subject to legal retention requirements.
4. Nature of Processing
Processing operations may include:
- Collection and receipt;
- Authentication and account connection;
- Retrieval through APIs;
- Recording and organisation;
- Structuring and classification;
- Storage and hosting;
- Consultation and access;
- Analysis and aggregation;
- Comparison and correlation;
- Attribution and performance measurement;
- Report and dashboard generation;
- AI-assisted summarisation and recommendation;
- Anomaly and issue detection;
- Transmission to authorised recipients;
- Export;
- Restriction;
- De-identification;
- Backup and recovery; and
- Deletion or destruction.
5. Purposes of Processing
GrowthMate Processes Customer Personal Data to:
- Provide the Services;
- Connect Customer-authorised accounts and platforms;
- Retrieve authorised analytics, advertising, search, business, ecommerce, website, application, and performance information;
- Display dashboards and reports;
- Generate summaries, alerts, recommendations, and forecasts;
- Measure and analyse traffic, engagement, conversions, campaigns, revenue, and business performance;
- Deliver reports through email, WhatsApp, dashboards, exports, or supported channels;
- Provide technical and customer support;
- Maintain service security and integrity;
- Detect fraud, abuse, errors, and technical issues;
- Back up and recover Customer data;
- Comply with Customer’s documented instructions; and
- Perform other Processing expressly agreed in writing.
6. Categories of Data Subjects
Data Subjects may include:
- Customer account owners;
- Customer administrators and authorised users;
- Customer employees, contractors, and agency personnel;
- Customer’s clients and client representatives;
- Visitors to Customer websites or applications;
- Customer prospects, leads, and customers;
- Users who interact with Customer campaigns;
- Purchasers and subscribers;
- Report and notification recipients;
- Business contacts;
- Support requesters; and
- Other individuals whose Personal Data Customer lawfully submits to the Services.
7. Categories of Personal Data
Depending on Customer’s configuration, Customer Personal Data may include:
- Names;
- Business contact information;
- Email addresses;
- Telephone or WhatsApp numbers;
- Job titles, organisation names, and account roles;
- Internal account or customer identifiers;
- Online and advertising identifiers;
- Cookie identifiers;
- Device, browser, operating-system, and application information;
- Internet Protocol addresses;
- Approximate geographic information;
- Website and application usage events;
- Page, session, engagement, navigation, and referral information;
- Campaign, advertisement, keyword, audience, attribution, and conversion information;
- Search and website-performance information;
- Lead and funnel-stage information;
- Transaction, order, revenue, subscription, and product-performance information;
- Business-profile and listing information;
- Report configuration and recipient information;
- Customer-provided labels, notes, and metadata;
- Support communications;
- Log and diagnostic data; and
- Other Personal Data submitted or connected by Customer through supported Service functionality.
8. Special Categories
No intentional Processing of special-category, highly sensitive, or regulated Personal Data is contemplated unless separately agreed in writing.
9. Frequency
Processing may occur continuously, periodically, on demand, or according to Customer-configured reporting and synchronisation schedules.
10. Retention
Customer Personal Data is retained for the term of the Main Agreement and deleted or returned in accordance with Section 16, Customer’s settings, applicable platform requirements, and legally required retention periods.
SCHEDULE 2
TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
GrowthMate will maintain security measures appropriate to the Services and Processing risks. Measures may include the following.
1. Information-Security Governance
- Documented security policies and procedures;
- Defined security responsibilities;
- Periodic review of security controls;
- Risk assessment and remediation processes; and
- Management oversight of material security risks.
2. Access Control
- Role-based access controls;
- Least-privilege access;
- Unique user accounts;
- Authentication requirements;
- Multifactor authentication for privileged access where reasonably available;
- Periodic review of access privileges;
- Prompt revocation of unnecessary access; and
- Restricted production-data access.
3. Personnel Security
- Confidentiality obligations;
- Appropriate employee and contractor screening where lawful;
- Security and privacy awareness training;
- Acceptable-use requirements; and
- Disciplinary processes for policy violations.
4. Encryption and Transmission Security
- Encryption of Customer Personal Data in transit using industry-standard secure transport protocols;
- Encryption at rest where appropriate and technically supported;
- Secure handling of encryption keys and secrets; and
- Protection of credentials and authentication tokens.
5. Application and Infrastructure Security
- Secure development practices;
- Code review appropriate to the nature of changes;
- Dependency and vulnerability management;
- Security testing;
- Segregation of development and production environments where appropriate;
- Protection against common web-application attacks;
- Secure configuration practices; and
- Change-management controls.
6. Logging and Monitoring
- Logging of relevant security and administrative activities;
- Monitoring for suspicious or unauthorised behaviour;
- Alerting for material security events;
- Restricted access to logs; and
- Retention of relevant logs according to security and legal requirements.
7. Tenant and Data Separation
- Logical separation of customer accounts and data;
- Authorisation controls designed to prevent cross-customer access;
- Environment separation where appropriate; and
- Testing of access-control boundaries.
8. Availability and Resilience
- Backup procedures;
- Recovery capabilities;
- Monitoring of service availability;
- Incident and outage response procedures;
- Capacity and resource management; and
- Business-continuity and disaster-recovery planning appropriate to the Services.
9. Incident Response
- Documented incident-response procedures;
- Defined escalation paths;
- Investigation and containment processes;
- Evidence preservation;
- Internal and external communication procedures;
- Remediation tracking; and
- Post-incident review where appropriate.
10. Vulnerability Management
- Processes for identifying vulnerabilities;
- Risk-based remediation priorities;
- Security updates and patches;
- Dependency monitoring;
- Responsible handling of vulnerability reports; and
- Periodic assessment of security control effectiveness.
11. Subprocessor Security
- Privacy and security due diligence;
- Written data-protection obligations;
- Risk-based review of material vendors;
- Restrictions on Subprocessor use of Customer Personal Data; and
- Appropriate transfer safeguards.
12. Data Lifecycle Controls
- Collection limitation;
- Retention controls;
- Account-level deletion functionality where available;
- Secure deletion or destruction;
- Backup lifecycle controls; and
- Restrictions on the use of deleted or expired data.
13. Physical Security
Where GrowthMate or a Subprocessor operates physical infrastructure, measures may include:
- Controlled facility access;
- Visitor procedures;
- Environmental protections;
- Equipment safeguards; and
- Secure media disposal.
Where infrastructure is hosted by a cloud provider, GrowthMate may rely on that provider’s physical and environmental security controls.
SCHEDULE 3
SUBPROCESSORS
Customer provides general authorisation for GrowthMate to use Subprocessors as described in Section 13.
GrowthMate’s Subprocessors may perform the following categories of services:
- Cloud hosting and infrastructure;
- Database hosting;
- Content-delivery and network services;
- Authentication and identity management;
- Monitoring, logging, and error tracking;
- Analytics and performance monitoring;
- Artificial-intelligence model or API processing;
- Email delivery;
- WhatsApp or messaging delivery;
- Customer support;
- Payment and subscription administration;
- Security and fraud prevention;
- Backup and disaster recovery; and
- Other technical services reasonably necessary to operate GrowthMate.
GrowthMate will provide Customer with the current legal names, processing locations, and functions of applicable Subprocessors electronically or upon written request to [[email protected]](mailto:[email protected]).
Before making this DPA available for production or enterprise contracting, GrowthMate should maintain a current Subprocessor register containing, at minimum:
| Subprocessor | Service Provided | Processing Location | Data Categories | | ------------------------------------------------------ | ---------------- | ------------------- | --------------- | | To be maintained in GrowthMate’s Subprocessor register | As applicable | As applicable | As applicable |
SCHEDULE 4
INTERNATIONAL TRANSFER TERMS
Part A: EU Standard Contractual Clauses
Where the EU SCCs apply:
1. Applicable Module
- Module Two: Controller to Processor applies where Customer is a Controller and GrowthMate is a Processor.
- Module Three: Processor to Processor applies where Customer is a Processor and GrowthMate is a Subprocessor.
2. Clause 7
The optional docking clause in Clause 7 applies.
3. Clause 9
For Clause 9:
- Option 2, general written authorisation, applies; and
- The advance-notice period for new Subprocessors is 15 calendar days where reasonably practicable.
4. Clause 11
The optional language in Clause 11 does not apply unless the Parties expressly agree otherwise.
5. Clause 17
Option 1 applies.
The governing law for the EU SCCs will be the law of Ireland.
6. Clause 18
The courts of Ireland will have jurisdiction under Clause 18(b).
7. Annex I.A—List of Parties
Data Exporter: Customer and any authorised Customer Affiliate subject to the EU GDPR.
The exporter’s contact details are those stated in the Main Agreement or applicable order form.
Data Importer: Qoptervzn Infocom Private Limited, operating GrowthMate, Bhandara, Maharashtra, India.
Contact: Grievance Officer, Alok Diwate Email: [email protected]
8. Annex I.B—Description of Transfer
The description of the transfer is contained in Schedule 1 of this DPA.
9. Annex I.C—Competent Supervisory Authority
The competent supervisory authority will be determined in accordance with Clause 13 of the EU SCCs.
10. Annex II—Security Measures
The technical and organisational measures are described in Schedule 2.
11. Annex III—Subprocessors
The authorised Subprocessors are described in Schedule 3 and GrowthMate’s current Subprocessor register.
Part B: UK Addendum
Where the UK Addendum applies:
- The Parties identified in Schedule 4, Part A are the exporter and importer;
- The selected EU SCC Module is determined under Part A, Section 1;
- The information required by Tables 1 through 3 of the UK Addendum is deemed completed using the Main Agreement, Schedule 1, Schedule 2, Schedule 3, and Part A of this Schedule;
- The EU SCCs are the “Approved EU SCCs”;
- Either Party may end the UK Addendum as permitted by its mandatory terms when an approved revision requires termination or replacement; and
- The mandatory clauses of the UK Addendum are incorporated without modification.
Part C: Replacement Transfer Mechanisms
If a transfer mechanism used under this Schedule is invalidated, replaced, or no longer legally sufficient, the Parties will cooperate in good faith to implement a valid replacement mechanism.
GrowthMate may update this Schedule to incorporate an approved replacement mechanism, provided that the update does not materially reduce the protection of Customer Personal Data.