DatA+Back to site

Data Processing Addendum

Last updated: 29 July 2026

This Addendum forms part of the Terms of Service and takes effect automatically when you connect a website, analytics property or ad account on behalf of a client. You do not need to sign or return anything. If your client requires a countersigned copy, email privacy@datapls.in.

1. Parties and roles

This Addendum applies where you ("Customer") use DatA+ ("Processor") to process personal data on behalf of someone else, typically your clients' Search Console, Analytics and Ads data.

For that data the Customer is the controller (Data Fiduciary under India's DPDP Act 2023) and DatA+ is the processor (Data Processor). DatA+ processes it only on the Customer's documented instructions. Using the service as it is designed constitutes those instructions; anything else must be agreed in writing. If DatA+ is required by law to process personal data otherwise, it will tell the Customer first unless the law forbids it.

Where DatA+ decides how data is used, such as the Customer's own account and billing details, DatA+ is the controller and its Privacy Policy applies instead.

2. Details of the processing

3. Confidentiality

DatA+ keeps personal data confidential, limits access to those who need it to run the service, and binds anyone with access to confidentiality obligations. Access to production data is limited to the operator.

4. Security measures

DatA+ maintains technical and organisational measures appropriate to the risk, including:

5. Subprocessors

The Customer gives general authorisation for DatA+ to engage the subprocessors listed in the Privacy Policy: Google, Neon, Vercel, Google Gemini, Anthropic, Resend and Razorpay. DatA+ imposes data-protection obligations on each that are equivalent to those in this Addendum, and remains liable to the Customer for their performance.

DatA+ will give the Customer at least 30 days' notice by email before adding or replacing a subprocessor. If the Customer reasonably objects on data-protection grounds within that period, the Customer may terminate the affected service and receive a pro-rata refund of any prepaid unused fees.

6. Assisting the Customer

Taking into account the nature of the processing and the information available to it, DatA+ will assist the Customer in:

If a data subject contacts DatA+ directly about data processed for the Customer, DatA+ will not respond substantively but will forward the request to the Customer without undue delay.

7. Personal data breaches

DatA+ will notify the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting the Customer's data. The notice will describe the nature of the breach, the categories and approximate number of data subjects and records affected so far as known, the likely consequences, and the measures taken or proposed. DatA+ will keep the Customer updated as more becomes known, so the Customer can meet its own 72-hour deadline under the GDPR and its obligations to the Data Protection Board of India under the DPDP Act.

8. Deletion and return

The Customer may export its data at any time from the app, in CSV, Markdown or JSON. On termination, DatA+ deletes the Customer's personal data on the following schedule:

These periods are enforced by an automated job that runs nightly. DatA+ may retain data where law requires, currently only billing records for Indian tax purposes, which contain no analytics data.

9. International transfers

DatA+ operates from India and its subprocessors operate in the European Union and the United States, so personal data may be transferred internationally. Where the GDPR applies, the parties rely on the European Commission's Standard Contractual Clauses (Module Two, controller to processor), which are incorporated into this Addendum by reference, or on an adequacy decision where one exists. Where the UK GDPR applies, the UK International Data Transfer Addendum applies to those Clauses.

10. Audits

DatA+ will make available to the Customer the information reasonably necessary to demonstrate compliance with this Addendum, and will contribute to audits conducted by the Customer or an auditor it appoints. Audits must be requested with reasonable notice, must happen no more than once a year unless a breach or a supervisory authority requires otherwise, must not unreasonably disrupt the service, and are at the Customer's cost.

11. Liability and precedence

Each party's liability under this Addendum is subject to the limitations in the Terms of Service. If this Addendum conflicts with those Terms in relation to the processing of personal data, this Addendum prevails. If it conflicts with the Standard Contractual Clauses, the Clauses prevail.

12. Contact

privacy@datapls.in