Legal

Data Processing Addendum

Last updated 24 May 2026. This DPA template is prepared for OpsVision AI Systems Pvt. Ltd. (OVASPL) and should be reviewed by counsel before production use.

1. Parties and roles

This Data Processing Addendum is intended to apply between the customer and OpsVision AI Systems Pvt. Ltd. (OVASPL) when OVASPL processes customer personal data to provide the OpsVision service. The customer generally acts as controller or data fiduciary for customer personal data. OVASPL generally acts as processor or data processor for that data.

2. Processing instructions

OVASPL will process customer personal data to provide, secure, support, monitor, maintain, and improve the service; connect customer-authorized cloud accounts; generate findings and reports; support approval workflows; comply with law; and perform documented customer instructions under the agreement.

3. Categories of data

Processed data may include business contact information, user account data, authentication and audit metadata, cloud inventory metadata, security findings, compliance evidence, cost and usage metadata, support communications, and any content submitted by customer users. Customers should avoid submitting unnecessary personal data, secrets, passwords, private keys, regulated personal data, or sensitive personal data.

4. AI-assisted processing

OVASPL may use AI-assisted systems to classify, summarize, recommend, draft reports, and prepare remediation plans. AI-assisted output is not a legal, audit, security, or engineering guarantee. Customers remain responsible for reviewing output and approving any action that modifies their cloud resources.

5. Security measures

OVASPL will maintain reasonable technical and organisational measures intended to protect customer personal data, including access controls, encryption in transit, logging, least-privilege operating practices, and internal controls appropriate to the service. Exact security commitments may be further described in an order form, security exhibit, or Enterprise agreement.

6. Subprocessors

OVASPL may use subprocessors for cloud hosting, storage, security monitoring, support, analytics, AI-assisted processing, billing, and operational tooling. Subprocessors should be bound by confidentiality, security, and data-protection obligations appropriate to the processing they perform.

7. Data subject and grievance requests

Where an individual exercises rights under applicable law, OVASPL will reasonably assist the customer in responding to requests that relate to customer personal data processed through the service, subject to identity verification, customer authorization, technical feasibility, and legal obligations.

8. Deletion and return

At termination or upon verified customer request, OVASPL will delete or return customer personal data in accordance with the agreement, product capabilities, backup retention, legal retention requirements, security obligations, and legitimate dispute-resolution needs.

9. International transfers

The SaaS operating model is designed around India-region hosting for Indian customers where applicable. Some subprocessors or AI providers may process data outside India where needed to provide the service, subject to contractual and technical safeguards.

10. Legal review

This DPA is a working template. Customer-specific DPA terms, liability caps, audit rights, subprocessors, breach notice timing, dispute venue, and transfer mechanisms should be finalized through counsel and the applicable order form or Enterprise agreement.