gevox.in

Data Processing Agreement

EFFECTIVE DATE: 16 June 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you (the Data Fiduciary) and Suryansh Sagar, trading as Gevox ("Gevox", the Data Processor). It applies whenever you use Gevox to process personal data about other people ("Customer Data"). For your own account data, Gevox acts as a Data Fiduciary under its Privacy Policy, and this DPA does not cover that.

1. Definitions

Terms used here have the meaning given in the Digital Personal Data Protection Act, 2023 (the "Act"). In particular: a Data Fiduciary decides why and how personal data is processed; a Data Processor processes personal data on a Fiduciary's behalf; a Data Principal is the individual the data is about; Customer Data is the personal data about third parties that you input into Gevox; and a Personal Data Breach is any unauthorised processing, or accidental disclosure, loss, or destruction of personal data.

2. Roles of the parties

You are the Data Fiduciary for Customer Data and decide the purposes and means of its processing. Gevox is your Data Processor and processes Customer Data only to provide the service and on your instructions. Your use of the platform's features is your documented instruction to process Customer Data for those features. Gevox will inform you if, in its opinion, an instruction would infringe the Act.

3. Gevox's obligations as Processor

As your Processor under Section 8 of the Act, Gevox will:

Purpose limitation — process Customer Data only to provide the service, never for its own purposes, and never to train AI models;

Confidentiality — ensure that anyone authorised to process Customer Data is bound by a duty of confidentiality;

Security (Section 8(4) and 8(5)) — apply and maintain reasonable security safeguards, including encrypted authentication and strict access controls so each account reaches only its own data;

Rights assistance (Sections 11 to 14) — provide tools and reasonable help so you can fulfil access, correction, erasure, grievance, and nomination requests from Data Principals;

Breach assistance (Section 8(6)) — notify you without undue delay after becoming aware of a Personal Data Breach affecting Customer Data, with the details then available, so you can meet your duties to the Data Protection Board of India and affected Data Principals.

4. Sub-processors

You authorise Gevox to engage the sub-processors listed on our Sub-Processors page. Gevox places on each of them data-protection obligations no less protective than those in this DPA, and remains responsible for their performance. Before adding or replacing a sub-processor, Gevox will update that page and give you reasonable prior notice, along with a chance to object.

5. Cross-border transfers

Some sub-processors process Customer Data outside India, as marked on the Sub-Processors page. Gevox makes any such transfer in line with Section 16 of the Act. Your core account and compliance records are stored in India.

6. Return and deletion

You may export your Customer Data from within the platform at any time. When your account is closed, Gevox deletes Customer Data within 30 days, unless the law requires it to be retained.

7. Records and audit

Gevox will make available to you the information reasonably necessary to demonstrate its compliance with this DPA. Any audit will be limited to reasonable, proportionate, and confidential means that do not compromise the security or data of other customers.

8. Your responsibilities

You confirm that you have a lawful basis, and any consent the Act requires, for the Customer Data you process through Gevox; that your instructions comply with the Act; and that you input only data you are entitled to. You remain the Data Fiduciary for Customer Data throughout.

9. Liability

Liability under this DPA is subject to the limitations of liability set out in the Terms of Service.

10. Term, precedence and governing law

This DPA runs for as long as Gevox processes Customer Data for you. If there is a conflict between this DPA and the main Terms of Service on the subject of processing Customer Data, this DPA prevails to the extent of that conflict. This DPA is governed by the laws of India, with disputes subject to the courts at Meerut, Uttar Pradesh, India.

11. Contact

For any question about this DPA — or if you need a counter-signed copy for your records — contact our Grievance Officer, Suryansh Sagar, at grievance@gevox.in.

Schedule 1 — Details of processing

Subject matter: Gevox's provision of the compliance platform to you.

Duration: for as long as your account is active.

Nature and purpose: storing, generating, analysing, and managing the compliance records you create.

Types of personal data: contact details and any other personal data you choose to input about third parties — for example, names and emails of individuals affected by a breach or of people who make rights requests.

Categories of Data Principals: your customers, employees, or other individuals whose personal data you input into Gevox.

Sub-processors: as listed on the Sub-Processors page.

Suryansh Sagar, trading as Gevox · 3/200 Rakshapuram, Mawana Road, Meerut, Uttar Pradesh, [250001] · Compliant with the Digital Personal Data Protection Act, 2023