Data Processing Addendum
Last updated: 05 October 2026
This Data Processing Addendum (the "DPA") forms part of the Terms of Service, or any other written agreement (the "Agreement"), between Dhanamitra Infotech LLP ("Vaanexa" or the "Processor") and the Customer that has accepted it (the "Customer" or the "Controller"). It applies whenever Vaanexa processes personal data on the Customer's behalf. It takes effect automatically when the Customer accepts the Terms of Service, so no separate signature is needed. If you would like a countersigned copy for your records, please write to legal@vaanexa.com.wha
1. Key terms
In this DPA, "Data Protection Laws" means every law that applies to the processing of Customer Personal Data, as amended from time to time. These include India's Digital Personal Data Protection Act, 2023 (the "DPDP Act") and its rules, the Information Technology Act, 2000 and its rules, the EU General Data Protection Regulation (the "GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended (the "CCPA"). They also include other United States state privacy laws.
"Customer Personal Data" means the personal data within Customer Data, as defined in the Terms of Service, that Vaanexa processes for the Customer. "Controller" includes a Data Fiduciary under the DPDP Act and a "business" under the CCPA. "Processor" includes a Data Processor under the DPDP Act and a "service provider" under the CCPA. "Subprocessor" means any third party that Vaanexa engages to process Customer Personal Data. "Personal Data Breach" means a breach of security that leads to the accidental or unlawful destruction, loss or alteration of Customer Personal Data, or its unauthorised disclosure or access. Other terms such as "personal data", "processing" and "data subject" (or "Data Principal") have the meanings given to them in Data Protection Laws.
2. Roles and scope
The Customer is the Controller of Customer Personal Data and Vaanexa is its Processor. If the Customer itself processes the data on behalf of another business, Vaanexa acts as its sub-processor, and the Customer will pass on any relevant instructions. For its own account, billing and usage data, Vaanexa acts as an independent controller under its Privacy Policy, and that data falls outside this DPA. Schedule 1 below describes the processing in detail.
3. The Customer's responsibilities
The Customer is responsible for the lawfulness of Customer Personal Data and of the instructions it gives Vaanexa. Before data reaches Vaanexa, the Customer must have given every notice, and obtained every consent and opt-in, that Data Protection Laws and platform policies require. This includes WhatsApp opt-in and any consent needed for conversion events sent to Meta. The Customer will not instruct Vaanexa to process data in a way that breaks Data Protection Laws. It will not submit special-category or sensitive data, such as health, biometric or financial-account data or children's data, unless the law permits it and the Customer has put the required safeguards in place.
4. Vaanexa's commitments
Vaanexa will process Customer Personal Data only on the Customer's documented instructions. Those instructions are the Agreement, this DPA, and the settings, configuration and API calls the Customer makes in the Services. The only exception is where the law requires otherwise. In that case Vaanexa will tell the Customer before processing, unless the law forbids it. Vaanexa will also tell the Customer if it believes an instruction breaks Data Protection Laws.
Vaanexa will not sell or share Customer Personal Data as those terms are defined in the CCPA. It will not retain, use or disclose that data for any purpose other than providing the Services, and will not combine it with other data except where the CCPA permits. Vaanexa will not use Customer Personal Data to train AI models offered to other customers.
Vaanexa will make sure that everyone authorised to process Customer Personal Data is bound by confidentiality. It will maintain the security measures described in Schedule 2. Taking into account the nature of the processing, Vaanexa will help the Customer respond to data-subject requests, carry out data protection impact assessments, consult regulators where needed and meet its own security obligations. Vaanexa will tell the Customer if it can no longer meet its obligations under Data Protection Laws.
5. Subprocessors
The Customer authorises Vaanexa to use the Subprocessors listed in Schedule 3, and any others engaged in line with this section. Vaanexa will have a written contract with each Subprocessor that protects Customer Personal Data at least as well as this DPA does, and it remains fully responsible for each Subprocessor's performance.
Vaanexa will give the Customer at least 30 days' notice before adding or replacing a Subprocessor, by email to the account owner or through the app. In a genuine emergency, such as keeping the Services secure or available, Vaanexa will give as much notice as it reasonably can. The Customer may object on reasonable data-protection grounds during the notice period, and the parties will discuss the objection in good faith. If they cannot resolve it, the Customer may terminate the affected Services and receive a refund of any prepaid fees for the unused period.
Some third parties are chosen and directed by the Customer itself: for example, Meta when the Customer connects its own WhatsApp Business Account, or the Customer's own payment gateway. Such third parties are recipients chosen by the Customer, not Subprocessors of Vaanexa.
6. Personal Data Breaches
If Vaanexa becomes aware of a Personal Data Breach affecting Customer Personal Data, it will notify the Customer without undue delay and in any case within 72 hours. The notice will describe, as far as is then known, the nature of the breach and the categories and approximate number of individuals and records affected. It will also describe the likely consequences and the steps taken or proposed to deal with the breach. Vaanexa will take reasonable steps to contain the breach and fix its cause. It will help the Customer meet its own obligations to notify the Data Protection Board of India, other supervisory authorities and affected individuals. Vaanexa will separately report cyber-security incidents to CERT-In within the six-hour window that CERT-In's directions require. Notifying a breach is not an admission of fault or liability.
7. Requests from individuals
Vaanexa gives the Customer self-service tools to respond to requests from data subjects and Data Principals. They include a complete data export, deletion of individual contacts, recording of opt-outs, and configurable retention periods for messages, contacts and webhook logs. If Vaanexa receives a request directly from an individual about Customer Personal Data, it will pass the request to the Customer. It will not respond itself unless the Customer authorises it or the law requires it.
8. Retention, return and deletion
While the Agreement is in force, the Customer controls how long Customer Personal Data is kept through the retention settings and deletion tools in the Services. When the Agreement ends, the Customer has 30 days to export its data. After that, Vaanexa deletes Customer Personal Data from its live systems, and removes it from backups within a further 90 days. Vaanexa keeps data for longer only where the law requires it. Any such data remains protected by this DPA and is not processed further. On request, Vaanexa will confirm the deletion in writing.
9. Audits
Vaanexa will make available the information reasonably needed to show that it complies with this DPA, such as security documentation, completed security questionnaires and, where available, independent audit reports or certifications. If that information is not enough, or a regulator requires it, the Customer may conduct an audit no more than once every twelve months. The Customer must give at least 30 days' written notice and carry out the audit during business hours, at its own cost and under confidentiality. The audit must be conducted so that it does not disrupt other customers or compromise their data.
10. International transfers
Customer Personal Data is primarily hosted in India. Subprocessors may process it in the countries listed in Schedule 3. Transfers out of India comply with the DPDP Act and any restrictions notified under it.
Some transfers come from the European Economic Area, the United Kingdom or Switzerland to Vaanexa in a country without an adequacy decision. For those transfers, the parties incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914) by reference. Module Two applies where the Customer is a controller, and Module Three where the Customer is a processor. For those clauses, the following choices apply: the docking clause in Clause 7 applies; Option 2 of Clause 9 applies, with the notice period set out in section 5 of this DPA; the optional wording in Clause 11 does not apply; the governing law and courts are those of Ireland; the schedules to this DPA complete the appendix to the clauses.
For transfers from the United Kingdom, the UK International Data Transfer Addendum also applies, and either party may end it as Table 4 of the Addendum allows. For transfers from Switzerland, the clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner acts as the competent authority. Vaanexa will make sure that any onward transfer to a Subprocessor receives an equivalent level of protection.
11. California
To the extent the CCPA applies, Vaanexa acts as the Customer's service provider or contractor. Vaanexa certifies that it understands and will comply with the restrictions set out in section 4. It will tell the Customer if it can no longer meet its obligations under the CCPA. The Customer may take reasonable steps to stop and remedy any unauthorised use of personal information.
12. General
Each party's liability under this DPA is subject to the limits in the Agreement, except where Data Protection Laws do not allow those limits. If documents conflict, they take priority in this order: first the Standard Contractual Clauses, then this DPA, then the Agreement. This DPA remains in force for as long as Vaanexa processes Customer Personal Data.
Schedule 1: Details of the processing
The Controller and data exporter is the Customer named in its Vaanexa account, contactable through the account owner's email address. The Processor and data importer is Dhanamitra Infotech LLP (Vaanexa), [REGISTERED ADDRESS LINE], Greater Noida West, Uttar Pradesh, India, contactable at privacy@vaanexa.com.
The subject matter of the processing is the provision of the Vaanexa AI revenue platform under the Agreement. It lasts for the term of the Agreement plus the deletion periods in section 8. The processing involves hosting, storing, transmitting, organising and analysing Customer Data, and processing it with AI. This supports: omnichannel messaging; AI replies, drafts, summaries and lead qualification; customer-relationship and lead management; campaigns and automation flows; advertising and conversion tracking; sales tools such as quotes, invoices and payment links; appointment booking, analytics and customer support.
The individuals concerned are the Customer's End Customers, prospects and leads, social-media users who interact with the Customer's pages and accounts, and the Customer's own Users and staff. The categories of personal data are: names, phone numbers, email addresses and social-media handles and identifiers; message content and media; call recordings and transcripts, where voice features are enabled; lead-form answers; order, quote, invoice and appointment details; tags, notes and lead scores; device and IP information contained in webhook payloads; hashed identifiers used for conversion events.
No special-category or sensitive data is intended to be processed. Data is transferred continuously while the Services are in use, and is retained as the Customer configures, or otherwise as described in section 8.
Schedule 2: Security measures
Vaanexa protects Customer Personal Data with the following technical and organisational measures: access is role-based, so admins can set exactly what each User can see and do, and every User can turn on two-factor authentication; Vaanexa staff get least-privilege access, and only authorised personnel can reach production systems; passwords are stored only as salted hashes; login and password-reset endpoints are rate-limited; data travels over TLS 1.2 or higher; channel access tokens, payment-gateway credentials and other secrets are encrypted at rest; every record is tied to the business it belongs to, and every database query is filtered by that business, keeping each Customer's data separate; sensitive actions, such as exports, deletions, opt-outs, role changes and business erasure, are recorded in audit logs; security logs are kept for at least 180 days; erasing an entire business requires the admin's password and the business name typed out in full; databases are backed up regularly, and object storage is managed and redundant; systems are monitored with alerting, and protected against denial-of-service attacks through a content delivery network; incoming webhooks are verified by signature, inputs are validated, and software dependencies are kept up to date; only the context an AI request needs is sent to the AI provider, whose enterprise terms forbid training on our data; a documented incident-response process covers detecting, escalating and notifying breaches; staff with access are bound by confidentiality and trained in security awareness.
Schedule 3: Subprocessors
Vaanexa currently uses the following Subprocessors: a hosting provider with a data centre in India, for application servers, the database and job queues; Cloudflare, Inc., for object storage, content delivery and protection against attacks, operating globally; Google LLC, for the Gemini API that powers AI features, processing data in the United States and other countries; Cashfree Payments India Private Limited, in India, for billing Vaanexa subscriptions (this involves only Customer account and billing data); an email delivery provider, for transactional emails.
Three further providers are used only if a Customer enables voice features: Exotel Techcom Private Limited in India for telephony, Deepgram, Inc. in the United States for speech-to-text, and ElevenLabs, Inc. in the United States for text-to-speech.
Meta Platforms (WhatsApp, Instagram, Facebook and Threads) and any payment gateway the Customer connects are recipients that the Customer chooses and directs, under the Customer's own agreements with those providers.