1. Parties and roles
This Data Processing Addendum is intended to apply between the customer and OpsVision AI Systems Pvt. Ltd. (OVASPL) when OVASPL processes customer personal data to provide the OpsVision service. The customer generally acts as controller or data fiduciary for customer personal data. OVASPL generally acts as processor or data processor for that data.
2. Processing instructions
OVASPL will process customer personal data to provide, secure, support, monitor, maintain, and improve the service; connect customer-authorized cloud accounts; generate findings and reports; support approval workflows; comply with law; and perform documented customer instructions under the agreement.
3. Categories of data
Processed data may include business contact information, user account data, authentication and audit metadata, cloud inventory metadata, security findings, compliance evidence, cost and usage metadata, support communications, and any content submitted by customer users. Customers should avoid submitting unnecessary personal data, secrets, passwords, private keys, regulated personal data, or sensitive personal data.
4. AI-assisted processing
OVASPL may use AI-assisted systems to classify, summarize, recommend, draft reports, and prepare remediation plans. AI-assisted output is not a legal, audit, security, or engineering guarantee. Customers remain responsible for reviewing output and approving any action that modifies their cloud resources.
5. Security measures
OVASPL will maintain reasonable technical and organisational measures intended to protect customer personal data, including access controls, encryption in transit, logging, least-privilege operating practices, and internal controls appropriate to the service. Exact security commitments may be further described in an order form, security exhibit, or Enterprise agreement.
6. Subprocessors
OVASPL may use subprocessors for cloud hosting, storage, security monitoring, support, analytics, AI-assisted processing, billing, and operational tooling. Subprocessors should be bound by confidentiality, security, and data-protection obligations appropriate to the processing they perform.
7. Data subject and grievance requests
Where an individual exercises rights under applicable law, OVASPL will reasonably assist the customer in responding to requests that relate to customer personal data processed through the service, subject to identity verification, customer authorization, technical feasibility, and legal obligations.
8. Deletion and return
At termination or upon verified customer request, OVASPL will delete or return customer personal data in accordance with the agreement, product capabilities, backup retention, legal retention requirements, security obligations, and legitimate dispute-resolution needs.
9. International transfers
The SaaS operating model is designed around India-region hosting for Indian customers where applicable. Some subprocessors or AI providers may process data outside India where needed to provide the service, subject to contractual and technical safeguards.
10. Legal review
This DPA is a working template. Customer-specific DPA terms, liability caps, audit rights, subprocessors, breach notice timing, dispute venue, and transfer mechanisms should be finalized through counsel and the applicable order form or Enterprise agreement.