Last updated 7 October 2026
Data processing
What we agree to when we process personal data on a client's behalf.
Version studio-1.0-draft
Who is who
When we build and run something for you, you decide why and how personal data is processed and we act on your instructions. In the language of the DPDP Act you are the data fiduciary and we are the data processor.
We sign a data processing agreement with every client whose data we process. It is not optional and it is not an extra.
What we agree to
To process personal data only on your documented instructions, and to tell you if an instruction appears to us to break the law.
To keep it confidential, and to bind every person who touches it to confidentiality.
To apply the security measures described in our privacy notice: encryption in transit and at rest, logged and restricted access, tested backups.
Not to engage another processor without telling you, and to hold any processor we do engage to these same terms.
To help you answer requests from the people whose data it is, and to help you meet your own breach-reporting duties.
To delete or return the data at the end of the engagement, as you choose.
Incidents
If there is a personal data breach we tell you without undue delay and we report to CERT-In within 6 hours, as the 2022 directions require.
We keep access logs for 180 days and synchronise our clocks to NTP, so that the record of an incident is coherent.
Where processing happens
On Vercel, Supabase and Postmark, which operate outside India as well as inside it. If your project needs processing confined to a particular country, tell us at the first call; it is a design decision and it is cheapest at the start.