Last updated: 28 January 2026
Aligned with Digital Personal Data Protection Act, 2023
Personal data primarily stored within India
AES-256 encryption and TLS 1.2+ protection
This Data Processing Addendum ("DPA") supplements the Terms of Service between Bizalys Infosystems Private Limited ("Processor") and the subscribing entity ("Client" or "Data Fiduciary") for processing of Personal Data under the Digital Personal Data Protection Act, 2023 ("DPDP Act").
Terms defined in the DPDP Act and Terms of Service apply. Additionally:
Client is the Data Fiduciary responsible for:
Bizalys is Data Processor, processing Personal Data only on Client's documented instructions, subject to Bizalys's independent obligations strictly as a Data Processor under applicable law.
Processor shall:
Client shall:
Processor implements reasonable security safeguards including:
Client authorizes use of sub-processors listed in our public Service Providers Directory (also accessible via our Bizalys Trust Centre or available upon written request).
Processor will notify Client of new sub-processors with 30 days' notice. Client may object on reasonable grounds. Processor may offer commercially reasonable alternatives or allow termination without penalty.
Processor remains liable for sub-processor compliance with this DPA.
Personal Data is primarily stored in India. Cross-border transfers will occur only to jurisdictions permitted under DPDP Act, subject to notifications, directions, or restrictions issued by the Central Government from time to time, with appropriate safeguards.
Processor will notify Client of any Personal Data breach without undue delay upon becoming aware. Notification will include: nature of breach, categories of data affected, likely consequences, and measures taken. Processor shall provide necessary information to enable Client's notifications to Data Protection Board and Data Principals as required under DPDP Act. Cooperation in breach response does not constitute admission of liability.
Processor will assist Client in responding to Data Principal requests (access, correction, erasure) by providing relevant data and technical capabilities. Processor will redirect any direct requests from Data Principals to Client. Assistance provided within reasonable time as prescribed under applicable law.
Processor will make available information necessary to demonstrate compliance. Client may request third-party audits with reasonable notice (not more than once annually), at Client's expense, subject to confidentiality and security constraints. Processor may provide audit reports, certifications, or summaries in lieu of on-site audits where appropriate.
Upon termination of Services:
Each party's liability under this DPA is subject to the limitations set forth in the Terms of Service, unless otherwise agreed in an Enterprise SLA. Nothing in this DPA excludes liability for willful misconduct or gross negligence.
This DPA is effective upon acceptance of Terms of Service and continues until all Personal Data is deleted or returned. Provisions relating to confidentiality, liability, and audit rights survive termination.
This DPA is governed by the laws of India. Courts at Nashik, Maharashtra shall have exclusive jurisdiction, subject to arbitration provisions in the Terms of Service. In case of conflict between this DPA and the Terms of Service regarding data protection matters, this DPA prevails.
For DPA inquiries, please contact us at:
2, Dattasiddhi Apartment,
Behind Mahamarg Bus Stand,
Gaikwad Nagar, Mumbai Naka,
Nashik 422002 Maharashtra
Email: support@bizalys.com (Subject: "DPA Inquiry")