This DPA forms part of, and is incorporated by reference into, the Rebota Terms of Service. It is accepted automatically by creating and continuing to use a Rebota business account — see Section 14. If your organisation requires a manually countersigned copy for procurement purposes, contact us at support@rebota.in.
1. Parties
This Data Processing Agreement ("DPA") is entered into between:
- Rebota Technologies, operating as "Rebota", with its registered address at Narhe, Pune, Maharashtra - 411041, India (the "Processor"); and
- the business entity that has created a Rebota account and, by doing so, agrees to this DPA (the "Fiduciary", "Customer" or "you"),
together the "Parties". Capitalised terms not defined here have the meaning given in the Rebota Terms of Service.
2. Subject Matter & Duration
The Processor processes personal data on behalf of the Fiduciary solely to provide the Rebota project-management and ERP Service. This DPA applies for as long as the Processor processes personal data on the Fiduciary's behalf, and survives termination to the extent Sections 8 and 9 require.
3. Roles of the Parties
- The Fiduciary is the Data Fiduciary (as defined in the DPDP Act, 2023) for all personal data of its own employees, site workers, vendors, subcontractors and clients that it enters into the Service.
- The Processor processes that data only on the Fiduciary's documented instructions — given by using the Service's features (e.g. entering a worker's phone number to enable attendance tracking is an instruction to process that number for that purpose).
- For the Fiduciary's own account data (its authorised users' names, emails, phone numbers, login activity), the Processor is itself the Data Fiduciary under its Privacy Policy, and this DPA does not apply to that category.
4. Nature, Purpose & Categories of Data
Nature and purpose
Storage, retrieval, structuring and transmission of the personal data below, to operate the project management, procurement, quality/safety, workforce and billing modules of the Service as configured by the Fiduciary.
Categories of personal data
- Identity and contact data of the Fiduciary's workers, vendors and clients (name, phone, email, address);
- Employment/engagement data (trade, wage, attendance, contract type);
- Financial data of vendors (bank account, IFSC, PAN) — encrypted at rest by the Processor;
- Partial identity documents (last 4 digits of Aadhaar only).
Categories of data subjects
- The Fiduciary's site workers and labour;
- The Fiduciary's vendors, subcontractors and their contact persons;
- The Fiduciary's clients and client contact persons;
- The Fiduciary's own authorised users/teammates, to the extent processed on the Fiduciary's instruction.
5. Processor Obligations
- Process personal data only on the Fiduciary's documented instructions, unless required to do otherwise by applicable Indian law — in which case the Processor will inform the Fiduciary of that legal requirement before processing, unless the law prohibits such notice.
- Ensure that persons authorised to process the personal data are bound by confidentiality obligations.
- Implement appropriate technical and organisational security measures — at minimum those in Section 6.
- Not engage a sub-processor without the Fiduciary's prior general authorisation (Section 7).
- Assist the Fiduciary in responding to Data Principal requests (access, correction, erasure) regarding data processed under this DPA.
- Assist the Fiduciary with its own security and breach-notification obligations under the DPDP Act.
- At the Fiduciary's election, delete or return all personal data after the Service ends, subject to Section 8.
- Make available information reasonably necessary to demonstrate compliance, and contribute to audits (Section 11).
6. Security Measures
The Processor maintains, at minimum:
- Encryption in transit (TLS) for all data exchanged with the Service;
- Application-layer AES-256-GCM encryption at rest for vendor bank account number, IFSC and PAN;
- Salted-hash password storage — no plaintext or reversibly-encrypted passwords;
- Role-based access control scoped to project membership;
- Security-event logging retained for CERT-In's mandated 180-day minimum, stored in India;
- A documented incident-response process, including the notifications in Section 12;
- Periodic review of these measures without reducing the overall level of security below what's described here.
7. Sub-processors
The Fiduciary provides general authorisation for the Processor to engage the following sub-processors, each bound by written terms providing at least the same level of data protection as this DPA:
- Razorpay — payment processing (subscription billing only);
- Meta Platforms, Inc. (WhatsApp Business Cloud API) — message/OTP delivery, where enabled;
- Hosting provider — infrastructure hosting (India region);
- SMS gateway provider — OTP/SMS delivery, where configured.
The Processor will give at least 30 days' notice before adding or replacing a sub-processor, via email or in-app notice, during which the Fiduciary may object on reasonable data-protection grounds. If unresolved, the Fiduciary may terminate the affected part of the Service without penalty.
8. Statutory Retention Overrides
Notwithstanding Sections 5(7) and 9, the Processor may retain specific records beyond the Fiduciary's deletion instruction where Indian law requires it directly (e.g. GST-relevant transaction records for 6 years, or CERT-In-mandated security logs for 180 days) — see our Data Retention & Deletion Policy for the full schedule. Any such record is retained solely for that statutory purpose, access-restricted, and deleted at the end of the applicable period.
9. Return & Deletion of Data
On termination, or earlier at the Fiduciary's written request, the Processor will, within 30 days and subject to Section 8: (a) provide a reasonable opportunity to export data in a standard format (CSV/Excel exports are available throughout the Service and at termination), and (b) delete or anonymise the remaining personal data from active systems. Backup copies are purged on the standard backup-rotation schedule, not exceeding 90 days after deletion from the active system.
10. Liability & Indemnity
Each Party is liable for damages caused by its own non-compliance with the DPDP Act and this DPA. The Processor's liability under this DPA is subject to the limitation-of-liability clause in the Terms of Service. Nothing in this DPA limits either Party's liability for breach of confidentiality, death or personal injury caused by negligence, or fraud.
11. Audit Rights
On reasonable prior written notice (not less than 30 days), and no more than once per year (unless following a security incident), the Fiduciary may request evidence of the Processor's compliance with this DPA — such as a summary of security measures or a mutually agreed third-party audit report — at the Fiduciary's cost for anything beyond the Processor's standard documentation.
12. Breach Notification
The Processor will notify the Fiduciary without undue delay, and in any case within 48 hours of becoming aware, of any personal data breach affecting the Fiduciary's data. This is in addition to, and does not replace, the Processor's own obligation to report qualifying incidents to CERT-In within 6 hours.
13. Governing Law & Jurisdiction
This DPA is governed by the laws of India. The courts at Pune, Maharashtra have exclusive jurisdiction over any dispute arising from it, subject to any dispute-resolution clause in the Terms of Service.
14. Acceptance
This DPA is accepted by the Fiduciary by creating and continuing to use a Rebota account. Enterprise customers requiring a manually countersigned copy should contact support@rebota.in.