Data Processing Agreement (DPA)
Last Updated: December 13, 2025
IMPORTANT: This Data Processing Agreement ("DPA") supplements the Terms of Service and governs the processing of Personal Data and Sensitive Personal Data (including biometric data) by SuperGrid on behalf of the Client. This DPA is required under the Digital Personal Data Protection Act, 2023 and forms part of the contractual relationship between the parties.
PREAMBLE
This Data Processing Agreement is entered into between:
- "Data Fiduciary" or "Client": The organization subscribing to SuperGrid services
- "Data Processor" or "Provider": NeuralNetworki.ng, operator of SuperGrid
WHEREAS:
- Client engages Provider to process Personal Data and Biometric Data on its behalf;
- Such processing must comply with the Digital Personal Data Protection Act, 2023 and other applicable Indian laws;
- The parties wish to establish the terms governing such data processing;
NOW THEREFORE, the parties agree as follows:
1. Definitions and Interpretation
1.1 Definitions
- "Personal Data": Data about an individual who is identifiable by or in relation to such data, as defined under DPDP Act, 2023
- "Sensitive Personal Data": Biometric data, financial data, health data, and other categories defined under IT Rules, 2011
- "Biometric Data": Facial recognition encodings and related biometric information
- "Processing": Any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion
- "Data Principal": The individual (employee) to whom the Personal Data relates
- "Data Breach": Unauthorized access, use, disclosure, modification, or destruction of Personal Data
- "Sub-processor": Third-party service providers engaged by Provider to process Personal Data
1.2 Applicable Laws
This DPA is governed by:
- Digital Personal Data Protection Act, 2023
- Information Technology Act, 2000
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- Any successor or supplementary regulations
2. Roles and Responsibilities
2.1 Client as Data Fiduciary
Client acknowledges and agrees that it is the Data Fiduciary and is responsible for:
- Determining purposes and means of Personal Data processing
- Obtaining valid, informed consent from Data Principals (employees)
- Providing privacy notices to Data Principals
- Ensuring lawful basis for processing under DPDP Act
- Responding to Data Principal rights requests (access, correction, erasure)
- Maintaining records of consent
- Notifying Provider of any consent withdrawals
- Ensuring compliance with sector-specific regulations
2.2 Provider as Data Processor
Provider acknowledges and agrees that it is the Data Processor and will:
- Process Personal Data only on documented instructions from Client
- Not use Personal Data for any purpose other than providing the Service
- Implement appropriate technical and organizational security measures
- Assist Client in responding to Data Principal requests
- Notify Client of Data Breaches within 72 hours
- Delete or return Personal Data upon termination (subject to legal retention)
- Maintain confidentiality of Personal Data
- Provide Client with information necessary to demonstrate compliance
3. Scope of Processing
3.1 Subject Matter
Provision of facial recognition and GPS-based attendance verification services.
3.2 Duration
Duration of the Service Agreement plus retention period as specified in Section 9.
3.3 Nature and Purpose of Processing
- Identity verification through facial recognition
- Location verification through GPS
- Attendance tracking and timesheet generation
- Fraud prevention and detection
- Service improvement and algorithm optimization
3.4 Types of Personal Data
| Category |
Data Elements |
Classification |
| Biometric Data |
Facial encodings (128-dimensional vectors) |
Sensitive Personal Data |
| Location Data |
GPS coordinates, timestamps |
Personal Data |
| Identification |
Name, Employee ID, Mobile number, Email |
Personal Data |
| Attendance |
Clock-in/out times, work hours, dates |
Personal Data |
| Technical |
Device model, OS, IP address, app version |
Personal Data |
3.5 Categories of Data Principals
- Current employees of Client organization
- Former employees (for retention period only)
- Contractors and temporary workers (if applicable)
4. Client Instructions and Processing Limitations
4.1 Documented Instructions
Provider shall process Personal Data only:
- As documented in this DPA and Terms of Service
- As necessary to provide the Service as described
- As instructed in writing by Client's authorized representatives
4.2 Unlawful Instructions
If Provider believes Client's instruction violates applicable law, Provider shall:
- Immediately inform Client
- Suspend processing until lawfulness is confirmed
- Not be liable for any delays resulting from such suspension
4.3 Processing Outside Scope
Provider shall NOT:
- Sell, rent, or trade Personal Data
- Use Personal Data for advertising or marketing (except anonymized aggregated data)
- Share Biometric Data with third parties (except Sub-processors as authorized)
- Process data for purposes unrelated to the Service
- Combine Client's data with data from other clients
5. Security Measures
5.1 Technical Measures
Provider implements the following technical safeguards:
- Encryption in Transit: Industry-standard HTTPS/TLS encryption for all data transmissions
- Secure Storage: Data stored on secure cloud infrastructure in India with access controls
- Authentication: Secure password-based authentication with encrypted credential storage
- Access Logging: System access and data operations logged for monitoring and security review
- Database Security: Secure database configuration with restricted access
- Data Minimization: Only irreversible facial encodings stored (not photographs), limiting potential harm from unauthorized access
5.2 Organizational Measures
- Confidentiality: Personnel with data access bound by confidentiality obligations
- Incident Response: Procedures in place for Data Breach detection and response
- Regular Updates: Security patches and software updates applied regularly
- Vendor Management: Sub-processors selected based on security capabilities
- Backup Procedures: Regular data backups maintained
5.3 Physical Security
- Data hosted on dedicated single-tenant cloud infrastructure in India
- Physical security managed by cloud infrastructure provider
- Cloud facilities include physical access controls, surveillance, and environmental protections
- Client data is isolated and not co-located with other clients' data
5.4 Security Standard
Provider implements reasonable security practices appropriate for the nature and sensitivity of Personal Data processed. The nature of biometric facial encodings (irreversible mathematical representations) inherently limits potential harm compared to storage of actual photographs.
6. Sub-processing and Single-Tenant Architecture
6.1 Single-Tenant Model
Architecture: SuperGrid operates on a single-tenant architecture. Each Client receives a dedicated, isolated deployment on cloud infrastructure. Client data is never co-located or shared with other clients' data.
6.2 Authorized Sub-processors
Client authorizes Provider to engage the following categories of Sub-processors:
- Cloud Infrastructure Providers: For dedicated single-tenant hosting and database storage (assigned by Provider based on capacity and performance)
- Communication Services: Email delivery, SMS services (if applicable)
- Payment Processors: For billing and payment processing
Deployment Assignment: Provider selects cloud infrastructure provider for each Client based on availability, performance, and capacity. All infrastructure is located in India.
6.3 Sub-processor Obligations
Provider ensures that Sub-processors:
- Are bound by written contracts with data protection obligations equivalent to this DPA
- Implement appropriate technical and organizational security measures
- Process data only for purposes specified by Provider
- Are located in India (for cloud infrastructure providers)
6.4 Notification of New Sub-processors
- Provider will notify Client at least 30 days before engaging new Sub-processors
- Notification via email to Client's registered address
- Client's specific cloud infrastructure provider will be disclosed during onboarding
6.5 Client Objection
- Client may object to new Sub-processor within 14 days of notification
- Objection must be on reasonable data protection grounds
- If objection cannot be resolved, Client may terminate Service without penalty
6.6 Liability for Sub-processors
Provider remains fully liable to Client for any Sub-processor's failure to fulfill data protection obligations.
7. Data Transfers (Outside India)
7.1 Data Residency
By default, all Personal Data is stored on servers located in India.
7.2 Cross-Border Transfers
If Client consents to international data transfers:
- Transfers only to countries approved under DPDP Act or with adequate safeguards
- Use of Standard Contractual Clauses (SCCs) or equivalent mechanisms
- Prior notice to Data Principals of such transfers
- Client responsible for obtaining any required consents
7.3 Government Access Requests
If Provider receives government or law enforcement requests for Client's data:
- Provider will notify Client immediately (unless legally prohibited)
- Provider will challenge overly broad or unlawful requests
- Provider will disclose only minimum data necessary to comply
- Provider will document all such requests
8. Data Principal Rights
8.1 Client's Responsibility
Client is primarily responsible for responding to Data Principal requests for:
- Access to Personal Data
- Correction of inaccurate data
- Erasure ("right to be forgotten")
- Restriction of processing
- Data portability
- Withdrawal of consent
8.2 Provider's Assistance
Provider will assist Client by:
- Providing technical means for Client to access and export data
- Implementing data deletion within 30 days of Client's instruction
- Providing data in machine-readable format (CSV) for portability requests
- Correcting data upon Client's verified instruction
8.3 Direct Requests to Provider
If Data Principals contact Provider directly:
- Provider will forward request to Client within 5 business days
- Client must respond to Data Principal within timelines required by law (typically 30 days)
8.4 Fees for Assistance
- Reasonable assistance provided at no additional cost
- If requests require significant custom development or manual work, Provider may charge reasonable fees (agreed in advance)
9. Data Retention and Deletion
9.1 Retention During Active Service
Provider retains Personal Data for the following periods during active service:
| Data Type |
Retention Period |
Basis |
| Biometric Encodings |
During active employment AND active subscription (deleted when either ends) |
Service operation |
| Attendance Records |
During active employment AND active subscription (deleted when either ends) |
Service operation |
| Location Data |
Stored with associated attendance records |
Service operation |
| Account Data |
During Client's active subscription |
Service operation |
9.2 Client's Retention Responsibilities
IMPORTANT - Client Obligations:
- Legal Retention Requirements: Client acknowledges it is legally required to retain attendance and payroll records for 7 years under Indian law (Income Tax Act, Companies Act)
- Client's Responsibility: This retention obligation belongs to the CLIENT (as Data Fiduciary), NOT to Provider
- Export Functionality: Provider provides CSV export functionality to enable Client to fulfill legal retention requirements
- Regular Exports: Client should regularly export data (recommended: monthly) to ensure compliance with legal retention obligations
- No Long-Term Archive: Provider does NOT serve as Client's long-term data archive or legal record custodian
9.3 Deletion Upon Termination
Upon Service termination or account closure:
- 30-Day Export Window: Provider will provide Client with 30 days to export all data via CSV download
- Client Notification: Provider will notify Client of upcoming data deletion at least 7 days before the 30-day window expires
- Deletion After Export Window: After the 30-day export period, Provider will permanently delete ALL Personal Data including:
- Biometric facial encodings
- Attendance records
- Location data
- Account information
- No Further Access: After deletion, data cannot be recovered
- Deletion Certification: Provider will provide written certification of deletion upon Client's request
9.4 Exceptions to Deletion
Provider will retain data beyond standard deletion periods ONLY if:
- Required by law, court order, or regulatory authority
- Needed for ongoing legal disputes, investigations, or litigation involving Provider
- Necessary to defend against legal claims against Provider
- Subject to preservation orders or data holds
In such cases, Provider will notify Client and retain only the minimum data necessary.
9.5 Secure Deletion Methods
- Database records permanently deleted (not just marked for deletion)
- Backups purged according to backup retention schedule (maximum 90 days after deletion)
- Biometric encodings securely erased from all systems
- No data recovery possible after deletion process completes
10. Data Breach Notification and Liability Exclusion
CRITICAL - NO LIABILITY FOR DATA BREACHES:
Provider shall have ZERO liability for any data breach, security incident, unauthorized access, or data loss, regardless of cause. Client expressly assumes all data breach risks and waives all claims against Provider.
10.1 Provider's Notification Obligations (No Liability)
Provider will use reasonable efforts to notify Client of data breaches, but failure to notify does NOT create liability. In the event of a breach Provider becomes aware of, Provider may (but is not obligated to):
- Best Effort Notification: Attempt to notify Client via email within 72 hours (not guaranteed)
- Incident Report: Provide available information about the breach (if known and available)
- No Guarantee: Provider does NOT guarantee breach detection, timely notification, or accuracy of breach information
- No Remediation Obligation: Provider has no obligation to remediate breaches, provide credit monitoring, or bear notification costs
Client acknowledges that breach notification is a courtesy, not a contractual obligation, and Provider bears zero liability for notification failures.
10.2 Client's Obligations
Client is responsible for:
- Assessing whether notification to Data Principals is required under applicable law
- Notifying Data Principals if legally required
- Notifying relevant authorities (Data Protection Board, CERT-In, etc.)
- Managing public relations and communications
10.3 Cooperation
- Parties will cooperate in good faith to investigate and remediate breaches
- Provider will provide reasonable assistance to Client for regulatory reporting
- Neither party shall make public statements without prior consultation (except as legally required)
11. Audits and Compliance
11.1 Documentation
Provider will maintain documentation of:
- Data processing activities
- Security measures implemented
- Sub-processors engaged
- Data Breaches and responses
- Staff training records
11.2 Client's Audit Rights
Client may audit Provider's compliance with this DPA:
- Frequency: Once per year (or more if required by data protection authority)
- Notice: 30 days' advance written notice
- Scope: Limited to verification of security measures and DPA compliance
- Timing: During business hours to minimize disruption
- Costs: Client bears costs of audit (unless audit reveals material breach)
- Confidentiality: Auditors must sign NDAs
11.3 Third-Party Certifications
In lieu of direct audit, Client may rely on:
- SOC 2 Type II reports (if available)
- ISO 27001 certifications (if available)
- Cloud provider compliance certifications and security reports
11.4 Regulatory Audits
If data protection authorities request audit of Provider:
- Provider will notify Client within 48 hours
- Provider will cooperate fully with authorities
- Provider will share audit findings with Client (unless prohibited by law)
12. Liability and Indemnification
12.1 Allocation of Liability
Provider is liable for:
- Breaches of this DPA caused by Provider's acts or omissions
- Unauthorized processing by Provider
- Inadequate security measures resulting in Data Breach (to extent caused by Provider's negligence)
- Sub-processor failures (Provider remains liable)
Client is liable for:
- Failure to obtain proper consent from Data Principals
- Unlawful processing instructions to Provider
- Failure to respond to Data Principal requests
- Violations of employment laws or labor regulations
- Discrimination or wrongful termination claims related to facial recognition
12.2 Liability Cap and Exclusions
Provider's liability under this DPA is strictly limited as follows:
- Complete Exclusion: To the maximum extent permitted by law, Provider has ZERO liability for any damages or losses arising from data processing, data breaches, security incidents, or service failures
- Absolute Cap: Where complete exclusion is not permitted, Provider's maximum aggregate liability shall not exceed the LESSER of: (a) ₹10,000 (Ten Thousand Rupees), OR (b) fees paid by Client in the 1 month immediately preceding the claim
- Per Incident and Aggregate: This cap applies both per incident and in aggregate for all claims during the entire relationship
- No Consequential Damages: Provider shall NOT be liable for indirect, consequential, punitive, or special damages under any circumstances
Client acknowledges this limitation is a fundamental basis of the agreement and pricing, and Client has obtained insurance to cover risks exceeding this cap.
12.3 Exceptions to Liability Cap (Extremely Limited)
The liability cap does NOT apply ONLY to:
- Provider's intentional and willful criminal conduct (gross negligence is STILL subject to the cap)
- Provider's fraudulent misrepresentation made with intent to deceive
IMPORTANT: Provider's ordinary negligence, gross negligence, security failures, data breaches, and all other claims remain subject to the ₹10,000 liability cap.
Breach of confidentiality is subject to the liability cap. Insurance availability does NOT increase Provider's liability.
12.4 Indemnification
Client indemnifies Provider against claims arising from:
- Client's failure to obtain employee consent
- Client's violation of employment or labor laws
- Client's unlawful processing instructions
- Employment disputes or wrongful termination claims
13. Term and Termination
13.1 Term
This DPA commences on the Service start date and continues until termination of the Service Agreement.
13.2 Survival
The following provisions survive termination:
- Section 9 (Data Retention and Deletion)
- Section 10 (Data Breach Notification) - for 90 days
- Section 11 (Audits) - for 1 year
- Section 12 (Liability and Indemnification)
- Section 15 (Confidentiality) - for 5 years
14. Amendments
This DPA may be amended:
- By mutual written agreement of the parties
- To comply with changes in data protection laws (Provider will notify Client 30 days in advance)
- Material changes require Client's explicit consent
15. Confidentiality
Both parties agree to keep confidential:
- All Personal Data processed under this DPA
- Security measures and technical implementation details
- Terms of this DPA (except as required by law or regulators)
- Data Breach details (until public disclosure is required or permitted)
16. Governing Law and Disputes
- Governing Law: Laws of India, specifically DPDP Act 2023 and IT Act 2000
- Jurisdiction: Courts of Delhi, India
- Dispute Resolution: Good-faith negotiation (30 days) followed by arbitration under Terms of Service Section 15.3
17. Severability
If any provision of this DPA is held invalid or unenforceable:
- The provision shall be reformed to minimum extent necessary to make it enforceable
- If reformation is not possible, the provision shall be severed
- Remaining provisions remain in full force and effect
18. Entire Agreement
This DPA, together with the Terms of Service and Privacy Policy, constitutes the entire agreement regarding data processing. This DPA supersedes any conflicting terms in the Service Agreement regarding data protection.
19. Contact for DPA Matters
Data Protection Officer / Compliance Contact: Samnit Mehandiratta, Founder
Company: NeuralNetworki.ng
Email: hello@neuralnetworki.ng
Phone: +91 87458 84947
SIGNATURE AND ACCEPTANCE
BY CLICKING "I ACCEPT" OR BY USING THE SERVICE, CLIENT ACKNOWLEDGES THAT IT HAS READ, UNDERSTOOD, AND AGREES TO BE BOUND BY THIS DATA PROCESSING AGREEMENT.
For Enterprise Clients: A signed copy of this DPA can be requested for execution. Contact hello@neuralnetworki.ng with subject line "DPA Execution Request" to receive a PDF version for wet signature or DocuSign.
This Data Processing Agreement is effective as of the Service commencement date and forms an integral part of the contractual relationship between the parties.