Data Processing Agreement (DPA)

Last Updated: December 13, 2025

IMPORTANT: This Data Processing Agreement ("DPA") supplements the Terms of Service and governs the processing of Personal Data and Sensitive Personal Data (including biometric data) by SuperGrid on behalf of the Client. This DPA is required under the Digital Personal Data Protection Act, 2023 and forms part of the contractual relationship between the parties.

PREAMBLE

This Data Processing Agreement is entered into between:

WHEREAS:

NOW THEREFORE, the parties agree as follows:

1. Definitions and Interpretation

1.1 Definitions

1.2 Applicable Laws

This DPA is governed by:

2. Roles and Responsibilities

2.1 Client as Data Fiduciary

Client acknowledges and agrees that it is the Data Fiduciary and is responsible for:

2.2 Provider as Data Processor

Provider acknowledges and agrees that it is the Data Processor and will:

3. Scope of Processing

3.1 Subject Matter

Provision of facial recognition and GPS-based attendance verification services.

3.2 Duration

Duration of the Service Agreement plus retention period as specified in Section 9.

3.3 Nature and Purpose of Processing

3.4 Types of Personal Data

Category Data Elements Classification
Biometric Data Facial encodings (128-dimensional vectors) Sensitive Personal Data
Location Data GPS coordinates, timestamps Personal Data
Identification Name, Employee ID, Mobile number, Email Personal Data
Attendance Clock-in/out times, work hours, dates Personal Data
Technical Device model, OS, IP address, app version Personal Data

3.5 Categories of Data Principals

4. Client Instructions and Processing Limitations

4.1 Documented Instructions

Provider shall process Personal Data only:

4.2 Unlawful Instructions

If Provider believes Client's instruction violates applicable law, Provider shall:

4.3 Processing Outside Scope

Provider shall NOT:

5. Security Measures

5.1 Technical Measures

Provider implements the following technical safeguards:

5.2 Organizational Measures

5.3 Physical Security

5.4 Security Standard

Provider implements reasonable security practices appropriate for the nature and sensitivity of Personal Data processed. The nature of biometric facial encodings (irreversible mathematical representations) inherently limits potential harm compared to storage of actual photographs.

6. Sub-processing and Single-Tenant Architecture

6.1 Single-Tenant Model

Architecture: SuperGrid operates on a single-tenant architecture. Each Client receives a dedicated, isolated deployment on cloud infrastructure. Client data is never co-located or shared with other clients' data.

6.2 Authorized Sub-processors

Client authorizes Provider to engage the following categories of Sub-processors:

Deployment Assignment: Provider selects cloud infrastructure provider for each Client based on availability, performance, and capacity. All infrastructure is located in India.

6.3 Sub-processor Obligations

Provider ensures that Sub-processors:

6.4 Notification of New Sub-processors

6.5 Client Objection

6.6 Liability for Sub-processors

Provider remains fully liable to Client for any Sub-processor's failure to fulfill data protection obligations.

7. Data Transfers (Outside India)

7.1 Data Residency

By default, all Personal Data is stored on servers located in India.

7.2 Cross-Border Transfers

If Client consents to international data transfers:

7.3 Government Access Requests

If Provider receives government or law enforcement requests for Client's data:

8. Data Principal Rights

8.1 Client's Responsibility

Client is primarily responsible for responding to Data Principal requests for:

8.2 Provider's Assistance

Provider will assist Client by:

8.3 Direct Requests to Provider

If Data Principals contact Provider directly:

8.4 Fees for Assistance

9. Data Retention and Deletion

9.1 Retention During Active Service

Provider retains Personal Data for the following periods during active service:

Data Type Retention Period Basis
Biometric Encodings During active employment AND active subscription (deleted when either ends) Service operation
Attendance Records During active employment AND active subscription (deleted when either ends) Service operation
Location Data Stored with associated attendance records Service operation
Account Data During Client's active subscription Service operation

9.2 Client's Retention Responsibilities

IMPORTANT - Client Obligations:

9.3 Deletion Upon Termination

Upon Service termination or account closure:

9.4 Exceptions to Deletion

Provider will retain data beyond standard deletion periods ONLY if:

In such cases, Provider will notify Client and retain only the minimum data necessary.

9.5 Secure Deletion Methods

10. Data Breach Notification and Liability Exclusion

CRITICAL - NO LIABILITY FOR DATA BREACHES:

Provider shall have ZERO liability for any data breach, security incident, unauthorized access, or data loss, regardless of cause. Client expressly assumes all data breach risks and waives all claims against Provider.

10.1 Provider's Notification Obligations (No Liability)

Provider will use reasonable efforts to notify Client of data breaches, but failure to notify does NOT create liability. In the event of a breach Provider becomes aware of, Provider may (but is not obligated to):

Client acknowledges that breach notification is a courtesy, not a contractual obligation, and Provider bears zero liability for notification failures.

10.2 Client's Obligations

Client is responsible for:

10.3 Cooperation

11. Audits and Compliance

11.1 Documentation

Provider will maintain documentation of:

11.2 Client's Audit Rights

Client may audit Provider's compliance with this DPA:

11.3 Third-Party Certifications

In lieu of direct audit, Client may rely on:

11.4 Regulatory Audits

If data protection authorities request audit of Provider:

12. Liability and Indemnification

12.1 Allocation of Liability

Provider is liable for:

Client is liable for:

12.2 Liability Cap and Exclusions

Provider's liability under this DPA is strictly limited as follows:

Client acknowledges this limitation is a fundamental basis of the agreement and pricing, and Client has obtained insurance to cover risks exceeding this cap.

12.3 Exceptions to Liability Cap (Extremely Limited)

The liability cap does NOT apply ONLY to:

IMPORTANT: Provider's ordinary negligence, gross negligence, security failures, data breaches, and all other claims remain subject to the ₹10,000 liability cap.

Breach of confidentiality is subject to the liability cap. Insurance availability does NOT increase Provider's liability.

12.4 Indemnification

Client indemnifies Provider against claims arising from:

13. Term and Termination

13.1 Term

This DPA commences on the Service start date and continues until termination of the Service Agreement.

13.2 Survival

The following provisions survive termination:

14. Amendments

This DPA may be amended:

15. Confidentiality

Both parties agree to keep confidential:

16. Governing Law and Disputes

17. Severability

If any provision of this DPA is held invalid or unenforceable:

18. Entire Agreement

This DPA, together with the Terms of Service and Privacy Policy, constitutes the entire agreement regarding data processing. This DPA supersedes any conflicting terms in the Service Agreement regarding data protection.

19. Contact for DPA Matters

Data Protection Officer / Compliance Contact: Samnit Mehandiratta, Founder
Company: NeuralNetworki.ng
Email: hello@neuralnetworki.ng
Phone: +91 87458 84947


SIGNATURE AND ACCEPTANCE

BY CLICKING "I ACCEPT" OR BY USING THE SERVICE, CLIENT ACKNOWLEDGES THAT IT HAS READ, UNDERSTOOD, AND AGREES TO BE BOUND BY THIS DATA PROCESSING AGREEMENT.

For Enterprise Clients: A signed copy of this DPA can be requested for execution. Contact hello@neuralnetworki.ng with subject line "DPA Execution Request" to receive a PDF version for wet signature or DocuSign.

This Data Processing Agreement is effective as of the Service commencement date and forms an integral part of the contractual relationship between the parties.