Legal
Data Processing Addendum
MANUPRIME's Data Processing Addendum — roles, sub-processors, international transfers, breach notification, audit rights, and return and deletion of data.
Effective 9 September 2026
In short
Our standard DPA, published rather than sent on request. It applies without signature, names our sub-processors through the Privacy Policy, commits to 30 days' notice before we add one, and never uses your data to train a model. If procurement needs a signature, we will sign this text as it stands.
This summary is for orientation only. The full text below is what applies.
1. What this addendum is, and when it applies
This Data Processing Addendum ("DPA") applies where AnantaTech Hub Private Limited processes personal data on your behalf in providing MANUPRIME. It forms part of the agreement between us and takes effect without signature — you do not have to ask for it first.
If your procurement process requires a signed copy, write to us and we will sign this text as it stands. Where your order form or a negotiated agreement says something different, that document prevails over this one.
Roles: for the personal data inside your workspace — your employees, your customers, your suppliers — you are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 and the Controller under the GDPR, and we are the Data Processor. For the personal data we hold about you as our own customer — your billing contact, your enquiry, your support correspondence — we are the Fiduciary or Controller, and the Privacy Policy governs it instead.
2. What we do with your data, and what we will not
We process personal data in your workspace only to provide, secure and support the service, and only on your documented instructions. Your use of the product is itself an instruction: creating a job card, running payroll or raising a dispatch note tells us to process what those actions need.
- We do not use your workspace data for our own purposes.
- We do not use it to train models — ours or any third party’s — or to build features for anyone else.
- We do not pool it with another customer’s data, and we do not share it with other customers.
- We do not sell it, and we do not disclose it for advertising.
- We will tell you if an instruction appears to us to breach data protection law, rather than simply carrying it out.
3. Confidentiality and who can see your data
Access is limited to the people whose role requires it, and is removed when that role ends. Every employee and contractor is under a written confidentiality obligation that survives the end of their engagement.
Our support staff enter a customer workspace to diagnose a problem you have raised, and that access is logged. We do not browse customer data.
4. Security
We maintain reasonable security safeguards appropriate to the data we hold, as required by section 8(5) of the Digital Personal Data Protection Act, 2023 and Rule 8 of the SPDI Rules, 2011. The measures in force are those listed under “How we protect personal data” in the Privacy Policy, which is kept current rather than restated here.
We do not hold a third-party security certification. Where your procurement requires ISO 27001 or SOC 2, we will tell you so plainly rather than leave the question unanswered.
5. Sub-processors
You give general authorisation for us to engage sub-processors. The current list is published under “Who we share personal data with” in the Privacy Policy, and it names each one rather than describing a category.
We impose data protection obligations on every sub-processor that are no less protective than those in this DPA, and we remain liable to you for their processing.
We will give you at least thirty days’ notice before adding or replacing a sub-processor that processes your workspace data. If you reasonably object on data protection grounds within that period we will work with you to find an alternative; where none exists, you may terminate the affected part of the service without penalty for the remainder of the term.
6. International transfers
Customer Data is stored in the region the customer belongs to — Indian customers in India, European customers in the EU, and so on for any market we enter. We are selling into the Indian market today, and every deployment currently runs on cloud infrastructure in India. If you need your data in a specific jurisdiction, name it in the agreement and we will confirm the region before anything is provisioned rather than after.
Some sub-processors operate outside India. Where personal data protected by the GDPR or UK GDPR is transferred outside the European Economic Area or the United Kingdom, we rely on the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum, together with any additional safeguards the transfer requires. Transfers out of India are made in accordance with section 16 of the Digital Personal Data Protection Act, 2023 and any restriction the Central Government notifies under it.
7. Helping you meet your own obligations
Where a data principal or data subject exercises a right against you, the product is the first answer: the export, search and deletion tools let you satisfy most requests without us. Where a request cannot be answered through the product, we will assist you within a reasonable period, taking account of the nature of the processing and the information available to us.
We will give reasonable assistance with data protection impact assessments and with prior consultation of a supervisory authority, where the processing we carry out for you makes one necessary.
8. Personal data breaches
We will notify you without undue delay after becoming aware of a personal data breach affecting your workspace data, with the information we hold at the time rather than waiting for a complete picture, and we will keep you updated as we learn more.
We will not make a public statement identifying you as affected without consulting you first, unless the law requires it of us.
Our own regulatory reporting — to the Data Protection Board of India, to CERT-In within the six hours its Directions of 28 April 2022 specify where they apply, and to any other regulator the law names — is described in the Privacy Policy.
9. Audit
We will make available the information reasonably necessary to demonstrate compliance with this DPA, and will answer a reasonable security questionnaire once in any twelve-month period.
Where that is genuinely not sufficient for your regulator, an audit may be carried out by you or an independent auditor you appoint who is not our competitor: on thirty days’ written notice, once in any twelve-month period, during business hours, subject to confidentiality, and in a manner that does not disrupt the service to our other customers. You bear the cost unless the audit finds a material breach of this DPA.
10. Return and deletion
You can export your data at any time during the term, in open formats, without asking us and without a fee.
On termination the Account Deletion Policy governs what happens: removal from active systems within thirty days of a confirmed request, and from backups within a further ninety days as the rotation reaches them.
We retain what the law separately requires us to keep — invoices and statutory accounting records — and nothing else.
11. Liability, and how this document changes
The limitations and exclusions of liability in the agreement apply to this DPA, and liability under it counts towards those limits rather than sitting on top of them.
We may update this DPA to reflect a change in law, in a supervisory authority’s guidance, or in how the service works. Where a change materially reduces your rights under it we will give at least thirty days’ notice, and the current version always carries the effective date above.
12. Who to contact
Data protection questions, sub-processor objections and audit requests go to Amit Parekh, AnantaTech Hub Private Limited, at contact@anantatechhub.com, or by post to 202, Avadh Shopping Center, Baben, Bardoli – 394601, Dist. Surat, Gujarat, India.
A complaint about how we have handled a request is dealt with under the Grievance Redressal Policy, which names the regulators you can escalate to.
Written with reference to
- Digital Personal Data Protection Act, 2023 (India) — sections 8 and 16
- Information Technology (Reasonable Security Practices) Rules, 2011 (India) — Rule 8
- CERT-In Directions of 28 April 2022 (India)
- General Data Protection Regulation (EU) 2016/679 — Article 28
- UK International Data Transfer Addendum, and the European Commission Standard Contractual Clauses
Questions about this policy can be sent tocontact@anantatechhub.com, or raised with our Grievance Officer under theGrievance Redressal Policy.