Skip to main content

Legal · Updated April 2026

Data Processing Addendum

This DPA forms part of the agreement between Customer (“Data Fiduciary” / “Controller”) and Autobotix (“Data Processor”) for the processing of personal data in connection with the Services. It is aligned with India's DPDP Act, 2023 and the EU GDPR.

1. Roles

Customer determines the purposes and means of processing. Autobotix processes personal data only on documented Customer instructions, as required to deliver the Services.

2. Subject Matter & Duration

Processing covers personal data submitted to the Services by or on behalf of Customer, for the duration of the subscription and any agreed retention period thereafter.

3. Categories of Data Subjects & Data

  • End users, customers, prospects, and personnel of the Customer.
  • Identifiers, contact data, communications, behavioural and usage data.
  • No special-category data unless explicitly agreed in writing.

4. Sub-processors

Customer authorises Autobotix to engage sub-processors listed at autobotix.pro/sub-processors. We notify Customer of any new sub-processor at least 30 days in advance and impose equivalent data-protection obligations.

5. Security Measures

  • Encryption in transit (TLS 1.3) and at rest (AES-256).
  • Role-based access control with least-privilege principle.
  • Continuous logging, monitoring, and quarterly access reviews.
  • Annual penetration testing and SOC 2-aligned controls.

6. Data Subject Rights & Assistance

Autobotix will assist Customer in responding to data principal / data subject requests (access, correction, erasure, portability, objection) within statutory timelines.

7. Breach Notification

Autobotix notifies Customer without undue delay — and in any event within 48 hours — of becoming aware of a personal-data breach, with sufficient detail to satisfy DPDP and GDPR notification duties.

8. International Transfers

Where personal data is transferred outside India or the EEA, Autobotix implements appropriate safeguards, including Standard Contractual Clauses and supplementary measures where required.

9. Audits

Customer may request an annual audit on reasonable notice. Autobotix may satisfy this obligation by providing a recent independent audit report.

10. Return & Deletion

On termination, Autobotix will, at Customer's choice, return or delete personal data within 60 days, except where retention is legally required.

11. Contact