Legal
Data Processing Addendum (DPA)
Effective date: 17 July 2026 · Last updated: 17 July 2026 · Version 2026-07-17.1
This Data Processing Addendum ("DPA") forms part of the Terms of Use between you ("Controller" / "Data Fiduciary") and Drushtant Infoweb Pvt. Ltd. ("Processor" / "Data Processor"), operator of Bizmitra Notify. It applies where we process personal data of your end-recipients on your behalf, and reflects the requirements of GDPR Article 28 and the DPDP Act, 2023.
For enterprise customers we can provide a signable DPA including the EU Standard Contractual Clauses and UK Addendum. Request one at privacy@bizmitra.io.
1. Roles
For Customer Data containing personal data of your recipients, you are the Controller/Data Fiduciary and we are the Processor/Data Processor. You are responsible for the lawfulness of your instructions and for having a valid legal basis and consents to process and message those individuals.
2. Subject-matter & scope
- Subject-matter: provision of the Bizmitra Notify notification services.
- Duration: for the term of your account plus any legally required retention.
- Nature & purpose: transmission, queuing, delivery and logging of notifications you initiate.
- Types of data: recipient identifiers (e.g. email, phone, device token), message content and metadata you submit.
- Categories of data subjects: your customers, employees, contacts and other recipients.
3. Our obligations as Processor
- Process personal data only on your documented instructions (including the Terms and use of the Service), unless required by law.
- Ensure persons authorised to process data are under confidentiality obligations.
- Implement appropriate technical and organisational security measures (Art. 32).
- Assist you, taking into account the nature of processing, with data-subject requests and with your obligations on security, breach notification and data-protection impact assessments.
- Notify you without undue delay after becoming aware of a personal-data breach.
- At your choice, delete or return personal data at the end of services, subject to legal retention.
- Make available information to demonstrate compliance and allow for audits, subject to reasonable safeguards.
4. Sub-processors
You authorise us to engage sub-processors (e.g. cloud hosting, messaging carriers, payment and analytics providers) to deliver the Service. We impose data-protection terms on them no less protective than this DPA and remain responsible for their performance. We will maintain a current list of sub-processors and give you a way to be informed of changes so you can object on reasonable data-protection grounds. Request the current list at privacy@bizmitra.io.
5. International transfers
Where processing involves transfers out of the EEA/UK, the parties rely on the Standard Contractual Clauses (and UK Addendum) or another lawful transfer mechanism. See the Privacy Policy for details.
6. Assisting with data-subject / Data Principal rights
We will, taking into account the nature of the processing, provide reasonable assistance to help you respond to requests to exercise rights of access, correction, erasure, restriction, portability, objection and grievance redressal.
7. Liability
Each party's liability under this DPA is subject to the limitations in the Terms of Use, to the extent permitted by law.
8. Contact
Data-protection matters: privacy@bizmitra.io, Drushtant Infoweb Pvt. Ltd., [[Registered office address]], Gondal, Gujarat, India.