1. Introduction and status of this agreement
This Data Processing Agreement, or DPA, forms part of the written agreement under which Rudrriv Solutions Pvt. Ltd, trading as DataConsultant, provides services to a client. That agreement may be a master services agreement, proposal, order form, statement of work, engagement letter or another signed or electronically accepted contract, referred to here as the Service Agreement.
This DPA applies only where we process Client Personal Data on the client’s behalf in connection with the contracted services. It does not govern personal information that we process for our own independent business purposes, such as managing enquiries, contracts, billing, website security or our professional relationship with a client. Such activities should be addressed in our Privacy Policy or other relevant notice.
Important: Publishing this page does not by itself create a client relationship or make this DPA binding. It becomes contractually effective only when it is signed, accepted or incorporated into a Service Agreement by authorised parties.
2. Purpose
The purpose of this DPA is to set out practical responsibilities for processing personal data during DataConsultant service engagements. It addresses client instructions, confidentiality, security, subprocessors, individual requests, incidents, international processing, retention, deletion and related cooperation.
The parties should customise project documentation where the engagement involves unusual data, regulated sectors, sensitive information, large-scale monitoring, automated decision-making or location-specific requirements.
3. Scope and application
This DPA applies to Client Personal Data processed by us in delivering services such as:
- data analytics, business intelligence, dashboards and reporting;
- data strategy, architecture, engineering, integration, migration and automation;
- database, data-quality and data-management consulting;
- artificial intelligence, machine learning and analytical modelling support;
- research, advisory, training and technical support;
- dedicated professionals, project teams and managed data services.
It does not automatically apply to information that is not personal data, data that has been effectively anonymised, or processing outside the agreed service scope.
4. Definitions
- Applicable Data Protection Law means any privacy or data-protection law that applies to the relevant processing.
- Client means the organisation identified as the client in the Service Agreement.
- Client Personal Data means personal data that we process on behalf of the Client under the Service Agreement.
- Controller includes equivalent terms used for an organisation that determines why and how personal data is processed.
- Processor includes equivalent terms used for a service provider that processes personal data on documented instructions.
- Data Subject means the individual to whom personal data relates.
- Personal Data Breach means a security breach that leads to accidental or unlawful loss, alteration, destruction, unauthorised disclosure of, or access to Client Personal Data.
- Subprocessor means a third party engaged by us to process Client Personal Data in support of the services.
5. Roles of the parties
For Client Personal Data, the Client will generally act as controller and DataConsultant will generally act as processor. Where the Client processes data for another organisation, DataConsultant may act as a subprocessor.
Each party remains responsible for identifying the laws that apply to it. The Client remains responsible for the lawfulness, fairness, transparency, accuracy, source and permitted use of Client Personal Data, including providing required notices and obtaining any necessary permissions.
6. Client instructions and responsibilities
The Client will provide documented, lawful and reasonably clear instructions through the Service Agreement, approved project documentation, authorised systems, tickets, email or other agreed channels. The Client will:
- provide only data reasonably necessary for the services;
- ensure it has authority to disclose the data and instruct the processing;
- identify sensitive, regulated or high-risk information before providing access;
- maintain appropriate controls for client-managed systems, accounts and credentials;
- review and approve material configurations, outputs or processing changes where required;
- respond promptly where instructions are incomplete, inconsistent or create material risk.
We may pause affected processing and seek clarification where an instruction appears unlawful, unsafe, outside scope or materially inconsistent with the Service Agreement.
7. DataConsultant’s processing obligations
Subject to the Service Agreement, we will:
- process Client Personal Data only on documented Client instructions or where applicable law requires otherwise;
- use the data only to deliver, support, secure and administer the contracted services;
- limit access to authorised personnel and providers with a need to know;
- maintain confidentiality obligations for people with access;
- provide reasonable information and assistance concerning this DPA;
- inform the Client where we reasonably believe an instruction conflicts with applicable data-protection obligations, unless prohibited from doing so.
We will not sell Client Personal Data or use it to build unrelated advertising profiles. We will not use Client Personal Data to train a general-purpose artificial intelligence model for unrelated customers unless expressly authorised in writing and lawfully permitted.
8. Processing details
The specific subject matter, duration, purposes, systems, individuals, data categories and locations should be stated in the Service Agreement or project documentation. Unless stated otherwise, processing may include receiving, accessing, organising, validating, transforming, analysing, storing, transmitting, visualising, correcting, exporting, restricting, deleting or otherwise using data as reasonably necessary to provide the services.
Typical data subjects
Depending on the project, data may relate to Client personnel, users, customers, prospects, suppliers, contractors, applicants or other individuals whose information the Client lawfully makes available.
Typical personal-data categories
Depending on the project, data may include business contact details, user or customer identifiers, account information, transaction records, operational records, support communications, website or application activity, survey responses, professional information and project-specific datasets.
9. Confidentiality and authorised access
We will restrict access to Client Personal Data to personnel, consultants, contractors and Subprocessors who require it for authorised work. Such persons will be subject to confidentiality duties under contract, policy, professional obligation or law.
Access permissions should be proportionate to role and scope. The Client remains responsible for permissions and credentials within Client-controlled environments unless their administration is expressly included in our services.
10. Security measures and shared responsibility
We will use technical and organisational measures that are reasonable and proportionate to the nature of the service, available technology, implementation cost, processing context and risks to individuals. Depending on the engagement, measures may include controlled access, authentication, secure configuration, encryption where appropriate and supported, logging, backup, change management, malware protection, vulnerability management, incident procedures and secure deletion practices.
No method of storage, transfer or security is completely risk-free. We do not guarantee that every incident can be prevented or that every system will be continuously available. The Client must promptly report suspected credential compromise, unauthorised access or security weaknesses affecting the services.
11. Subprocessors and third-party tools
The Client authorises us to use Subprocessors where reasonably necessary to deliver the services. These may include cloud infrastructure, data platforms, collaboration tools, source-control systems, analytics tools, support platforms and specialist service providers.
We will require material Subprocessors that process Client Personal Data on our behalf to accept written confidentiality and data-protection obligations appropriate to their role. Project-specific providers, locations and purposes may be identified in the Service Agreement, project documentation or a separate Subprocessor notice.
Third-party products may also be selected, controlled or licensed directly by the Client. Their independent processing is governed by their own terms and privacy practices, and the Client should review those terms before authorising their use.
12. Artificial intelligence, analytics and automated processing
We may use analytics, scripts, automation or artificial intelligence tools where permitted by the Service Agreement and Client instructions. Before using such tools with Client Personal Data, the parties should consider data minimisation, access, confidentiality, vendor terms, data location, retention, output review and whether human oversight is required.
Automated or model-generated outputs may contain errors, omissions, bias or unexpected results. Unless expressly agreed, such outputs are decision-support materials and should not be treated as a substitute for qualified human review, legal advice, financial advice or other professional judgement.
The Client must identify prohibited tools, sensitive datasets, model-training restrictions, explainability requirements or automated-decision limitations before processing begins.
13. Data-subject requests
Taking account of the nature of the processing, we will provide reasonable assistance to help the Client respond to valid requests from individuals concerning Client Personal Data. This may include requests for access, correction, deletion, restriction, portability, objection or withdrawal of consent where applicable.
If we receive a request that clearly relates to Client Personal Data, we will ordinarily refer it to the Client or notify the Client, unless law prohibits us from doing so. The Client remains responsible for verifying identity, determining whether the request is valid and providing the response.
14. Personal Data Breach management
We will notify the Client without undue delay after becoming aware of a confirmed Personal Data Breach affecting Client Personal Data. Information may be provided in stages as the investigation develops.
Where reasonably available, the notice may describe the nature of the incident, affected systems or data, known or estimated impact, containment actions and a contact point for follow-up. Notice does not constitute an admission of fault or liability.
The Client is responsible for deciding whether notification to individuals, regulators, customers or other parties is required, except where law directly places that obligation on us. We will provide reasonable cooperation based on available information and the agreed service scope.
15. Compliance assistance and assessments
Taking account of the nature of processing and information available to us, we will provide reasonable assistance with security reviews, risk or impact assessments, records of processing, transfer assessments and regulator enquiries relating to the services.
Extensive, bespoke, repetitive or out-of-scope assistance may require a separate statement of work, agreed timetable and reasonable fees, unless the assistance is required because of our material breach of this DPA.
16. Information and audit requests
On reasonable written request, we will make available information reasonably necessary to assess our performance of this DPA. The parties should first use existing questionnaires, summaries, policies, technical documentation and other available evidence.
Where additional verification is legally required and existing information is insufficient, the Client may request a proportionate review by itself or an independent qualified reviewer. Any review must be agreed in advance, protect other clients’ information, avoid unnecessary disruption, respect security and confidentiality restrictions, and be limited to processing relevant to the Client.
Nothing requires us to disclose another client’s data, privileged material, source code, credentials, detailed vulnerability information or information whose disclosure would weaken security or violate law or contract.
17. International and cross-border processing
DataConsultant may provide services internationally and may process Client Personal Data in countries where authorised personnel or approved Subprocessors operate. Processing locations and any Client restrictions should be documented for the engagement.
Where applicable law requires a specific mechanism or safeguard for a cross-border transfer, the parties will cooperate in good faith to document an appropriate arrangement. This DPA does not state that any particular transfer mechanism automatically applies to every engagement.
18. Return, deletion and retention
During the engagement, the Client may request return or export of Client Personal Data through available features or an agreed delivery method. Following termination or expiry, we will return or delete Client Personal Data within a reasonable period, subject to the Service Agreement, Client instructions, technical limitations and legal retention obligations.
Data may remain temporarily in backup, logging, security or disaster-recovery systems until normal deletion or overwrite cycles are completed. Such data will remain subject to appropriate protection and will not be used for unrelated purposes.
We may retain limited business records, such as instructions, approvals, invoices, project evidence, dispute records or security logs, where reasonably necessary for legal, accounting, tax, security or claims purposes.
19. Sensitive, regulated and children’s data
The Client must not provide sensitive, health, biometric, financial-authentication, government-identity, criminal-offence, children’s or similarly high-risk data unless the Service Agreement or an approved statement of work expressly identifies the data and required controls.
Where such processing is approved, the Client remains responsible for establishing lawful authority, required notices, consents, age-related requirements and sector-specific obligations. Additional access, location, encryption, logging, retention or review controls should be documented before processing begins.
20. Legal and government requests
If we receive a binding legal request for Client Personal Data, we will, where legally permitted, notify the Client before disclosure and provide reasonable information about the request. We may seek clarification or challenge an apparently invalid or excessive request where lawful and reasonable.
Nothing in this DPA requires either party to obstruct lawful process, violate legal obligations or place personnel or systems at risk.
21. DataConsultant’s independent processing
We may process limited personal information for our own business purposes, including managing enquiries, contracts, billing, accounting, tax, fraud prevention, service security, legal claims, supplier management, personnel administration and relationship management.
For those activities, we may act as an independent controller or equivalent organisation. Such processing is governed by our Privacy Policy, applicable notices and relevant law, rather than the processor obligations in this DPA.
22. Liability, warranties and service limitations
Liability connected with this DPA is governed by the exclusions, caps, remedies, indemnities and procedures in the Service Agreement, except where mandatory law does not permit a limitation.
We do not promise uninterrupted processing, perfect security, error-free datasets, complete accuracy or guaranteed business outcomes. Data quality, analytical results and model outputs may depend on source data, assumptions, third-party systems and Client decisions.
23. Relationship with contracts and other policies
This DPA supplements the Service Agreement. Privacy, confidentiality, intellectual property, data ownership, service scope, payment, liability, security and termination may also be governed by separate agreements or policies.
If documents conflict concerning Client Personal Data, a signed project-specific data-protection agreement or mandatory transfer document will take precedence to the extent of that conflict, followed by this DPA and then the general Service Agreement, unless the parties agree otherwise in writing.
24. Term and termination
This DPA continues while we process Client Personal Data under the Service Agreement. Duties concerning confidentiality, security, return or deletion, lawful retention, liability and cooperation will continue for as long as relevant Client Personal Data remains in our possession or control.
25. Changes to this DPA
We may update this standard DPA periodically to reflect changes in our services, technology practices, risk management or legal obligations. The latest version will be published on our website with a revised “Last updated” date.
For an active engagement, the version incorporated into the Service Agreement will continue to apply unless the parties accept an updated version or the Service Agreement provides another update process.
Frequently asked questions
1. Does this DPA apply to every website visitor?
No. It mainly applies when DataConsultant processes personal data on behalf of a client under a Service Agreement. Website visitor information is generally handled under the Privacy Policy and Cookie Policy.
2. When does this DPA become binding?
It becomes binding when signed, electronically accepted, attached to or incorporated into a Service Agreement by authorised parties. Publication alone does not create a contract.
3. Who decides why Client Personal Data is processed?
The Client generally decides the purposes and essential instructions. DataConsultant processes the data to provide the agreed services, subject to the Service Agreement and applicable obligations.
4. Can DataConsultant use third-party cloud or analytics tools?
Yes, where reasonably necessary and permitted by the engagement. Material providers that process Client Personal Data should be subject to appropriate written obligations, and project-specific tools may be documented separately.
5. Will Client Personal Data be used to train AI models?
We will not use Client Personal Data to train a general-purpose model for unrelated customers unless the Client expressly authorises this in writing and the activity is lawfully permitted.
6. Can a Client provide sensitive or regulated data?
Only where the data and required controls are expressly approved in the Service Agreement or statement of work. Clients should not provide high-risk data by default.
7. What happens if there is a data incident?
We will notify the Client without undue delay after becoming aware of a confirmed Personal Data Breach affecting Client Personal Data and will provide available information in stages if necessary.
8. Does DataConsultant support international clients?
Yes. Processing may occur in more than one country where authorised personnel or Subprocessors operate. Any location restrictions or required transfer arrangements should be documented for the engagement.
9. Can a Client request an audit?
A Client may request reasonable information and, where legally necessary and existing documentation is insufficient, a proportionate review subject to advance agreement, confidentiality, security and scope limitations.
10. What happens to data when services end?
Subject to the Service Agreement and legal requirements, we will return or delete Client Personal Data within a reasonable period. Temporary copies may remain in protected backup or logging systems until normal deletion cycles complete.
11. Do signed project documents override this page?
Yes, where applicable. A signed data-processing addendum, statement of work, transfer document or Service Agreement may contain more specific terms and may take precedence in the event of a conflict.
12. How can a Client raise a privacy or processing question?
Use the notice method in the Service Agreement or contact the privacy, legal or data-protection contact listed below.
Contact information
Contractual notices should be sent using the notice method stated in the Service Agreement. Privacy, security and data-processing questions may also be directed to:
Business: Rudrriv Solutions Pvt. Ltd, trading as DataConsultant
Registered address: India
Country or jurisdiction: India
Privacy email: support@dataconsultant.in
Legal email: support@dataconsultant.in
Data Protection Officer or privacy lead: support@dataconsultant.in
Website: https://dataconsultant.in
Legal Review Recommended
This DPA is published as DataConsultant’s standard data-processing framework. Any engagement-specific processing details, security requirements or international-transfer terms must be recorded in the applicable Service Agreement, order form or signed addendum.
Clients and other parties should obtain independent professional or legal advice where the application of privacy, data-protection, employment, sector-specific or cross-border rules is uncertain.
Back to top