Data Processing Terms (B2B / India-Focused)

Effective Date: December 29, 2025
Last Updated: July 21, 2026

These Data Processing Terms apply where Pravyon acts as a Data Processor (or equivalent processing entity under applicable law) processing personal data on behalf of the Customer, who acts as the Data Fiduciary (or equivalent controller entity).

1. Scope, Purpose, and Roles

  • Scope: These terms govern Pravyon’s processing of personal data input into the Service by the Customer.
  • Roles: The Customer is the Data Fiduciary determining the purpose and means of processing. Pravyon is the Data Processor acting on the Customer's documented instructions (i.e., providing the Service).
  • Customer Responsibility: The Customer warrants it has the lawful right, authority, and necessary consents to collect, use, and share the data with Pravyon.

2. Confidentiality and Security

Pravyon ensures that personnel authorized to access the data are subject to confidentiality obligations. Pravyon will implement reasonable technical and organizational security measures to protect the data against unauthorized access or accidental loss.

3. Sub-processors and Integrations

  • Sub-processors: The Customer authorizes Pravyon to use sub-processors (e.g., cloud hosting) to deliver the Service. Pravyon remains liable for the acts of its sub-processors to the extent required by law.
  • Customer Integrations: Pravyon is not responsible for data processing by third-party integrations explicitly authorized and connected by the Customer.

4. Cooperation and Assistance

  • Data Principal Requests: Pravyon will provide commercially reasonable assistance to help the Customer respond to requests from Data Principals (individuals) exercising their privacy rights.
  • Security Incidents: Pravyon will notify the Customer of confirmed security breaches without undue delay and cooperate to mitigate the impact.
  • Audit: Pravyon will provide information reasonably necessary to demonstrate compliance with these processing obligations upon written request.

5. Return, Export, and Deletion

  • 90-Day Retention: Following the expiry of the Agreement, Pravyon will retain the data for 90 days, during which the Customer may request export.
  • Deletion: After the retention period, Pravyon will delete or anonymize the data, except where required by law to retain it, or where residual copies temporarily remain in backups, logs, disaster-recovery systems, or other residual storage according to legitimate operational, security, and legal retention processes.

6. Term and Liability

These terms survive until Pravyon has deleted the data. Any liability arising under these terms is subject to the Limitation of Liability clause in the main Terms of Service.