This Data Processing Agreement ("DPA") is entered into between:
together the "Parties". Capitalised terms not defined here have the meaning given in the Rebota Terms of Service.
The Processor processes personal data on behalf of the Fiduciary solely to provide the Rebota project-management and ERP Service. This DPA applies for as long as the Processor processes personal data on the Fiduciary's behalf, and survives termination to the extent Sections 8 and 9 require.
Storage, retrieval, structuring and transmission of the personal data below, to operate the project management, procurement, quality/safety, workforce and billing modules of the Service as configured by the Fiduciary.
The Processor maintains, at minimum:
The Fiduciary provides general authorisation for the Processor to engage the following sub-processors, each bound by written terms providing at least the same level of data protection as this DPA:
| Sub-processor | Purpose | Data | Location | When |
|---|---|---|---|---|
| Razorpay Software Private Limited | Subscription payment processing | Name, email, phone, billing address and payment amount. Card, UPI and net-banking credentials are entered on Razorpay's own page and never reach Rebota's servers. | India | When you make a payment |
| Hostinger International Ltd | Application and database hosting | All data stored in your account, at rest and in transit through the hosting infrastructure. | India | Always |
| Meta Platforms, Inc. (WhatsApp Business Cloud API) | WhatsApp message and OTP delivery | Recipient phone number and the content of the message sent. | Outside India (United States and Meta global infrastructure) | When WhatsApp notifications are enabled |
| Sandbox / Quicko Infosoft Private Limited (GST Suvidha Provider) | e-Invoice (IRN) registration and e-Way Bill generation with the Government of India's Invoice Registration Portal | Supplier and buyer GSTIN, legal name and address, invoice number and date, line items, HSN codes, quantities, rates, taxable value and tax amounts — the full contents of the invoice being registered. | India | When e-invoicing or e-way bills are enabled for your GSTIN |
| The AI provider configured for your account (Google Gemini, OpenAI, Anthropic or Groq) | Answering questions put to the in-app assistant | The text of your question, and the business context needed to answer it, which may include figures and record details from your account. | Outside India (provider-dependent) | Only when an AI provider is configured and the assistant is used |
| SMS gateway provider | OTP and transactional SMS delivery | Recipient phone number and message content. | India | When SMS delivery is configured |
The Processor will give at least 30 days' notice before adding or replacing a sub-processor, via email or in-app notice, during which the Fiduciary may object on reasonable data-protection grounds. If unresolved, the Fiduciary may terminate the affected part of the Service without penalty.
Notwithstanding Sections 5(7) and 9, the Processor may retain specific records beyond the Fiduciary's deletion instruction where Indian law requires it directly (e.g. GST-relevant transaction records for 6 years, or CERT-In-mandated security logs for 180 days) — see our Data Retention & Deletion Policy for the full schedule. Any such record is retained solely for that statutory purpose, access-restricted, and deleted at the end of the applicable period.
On termination, or earlier at the Fiduciary's written request, the Processor will, within 30 days and subject to Section 8: (a) provide a reasonable opportunity to export data in a standard format (CSV/Excel exports are available throughout the Service and at termination), and (b) delete or anonymise the remaining personal data from active systems. Backup copies are purged on the standard backup-rotation schedule, not exceeding 90 days after deletion from the active system.
Each Party is liable for damages caused by its own non-compliance with the DPDP Act and this DPA. The Processor's liability under this DPA is subject to the limitation-of-liability clause in the Terms of Service. Nothing in this DPA limits either Party's liability for breach of confidentiality, death or personal injury caused by negligence, or fraud.
On reasonable prior written notice (not less than 30 days), and no more than once per year (unless following a security incident), the Fiduciary may request evidence of the Processor's compliance with this DPA — such as a summary of security measures or a mutually agreed third-party audit report — at the Fiduciary's cost for anything beyond the Processor's standard documentation.
The Processor will notify the Fiduciary without undue delay, and in any case within 48 hours of becoming aware, of any personal data breach affecting the Fiduciary's data. This is in addition to, and does not replace, the Processor's own obligation to report qualifying incidents to CERT-In within 6 hours.
This DPA is governed by the laws of India. The courts at Pune, Maharashtra have exclusive jurisdiction over any dispute arising from it, subject to any dispute-resolution clause in the Terms of Service.
This DPA is accepted by the Fiduciary by creating and continuing to use a Rebota account. Enterprise customers requiring a manually countersigned copy should contact support@rebota.in.