Legal
Data Processing Agreement
How we process your clients' personal data on your behalf.
Effective [Effective date]
Draft template
This is a standard template that a lawyer has not yet reviewed. Highlighted items in [brackets] are still to be filled in. Until this notice is removed, the page is a draft and not a final agreement. Questions: legal@vakeelos.com.
1. Parties and purpose
This Data Processing Agreement ("DPA") is between the advocate, chamber or firm that has agreed to the VakeelOS Terms of Service (the "Customer") and VarVik Technologies Private Limited (CIN U62099TS2026PTC221797), with its registered office at B7 1609, My Home Avatar, Puppalaguda, Narsingi, Rangareddy, Telangana 500089, India ("VarVik"). It forms part of the Terms and applies whenever VarVik processes Customer Personal Data to provide VakeelOS.
Under the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), the Customer is the Data Fiduciary and VarVik is the Data Processor for Customer Personal Data.
2. Definitions
- "Customer Personal Data" means personal data that the Customer or its users put into VakeelOS, or that VakeelOS fetches for them, and that VarVik processes on the Customer's behalf.
- "Data Principal", "Data Fiduciary", "Data Processor", "personal data", "processing" and "personal data breach" have the meanings given in the DPDP Act.
- "Sub-processor" means a third party that VarVik engages to process Customer Personal Data.
- "Board" means the Data Protection Board of India.
3. Scope of processing
VarVik processes Customer Personal Data only to provide, secure and support VakeelOS for the Customer. It does so for as long as the Customer uses VakeelOS and for the 30 days after that described in this DPA. Annex 1 lists the data and the Data Principals involved.
4. The Customer's responsibilities
The Customer will:
- have a lawful basis under the DPDP Act, such as consent or a legitimate use, for the personal data it puts into VakeelOS;
- give Data Principals any notice the DPDP Act requires;
- give VarVik only lawful instructions; and
- respond to requests from Data Principals who use their rights, with VarVik's help where needed.
5. VarVik's obligations
VarVik will:
- process Customer Personal Data only on the Customer's documented instructions, which include the Terms, this DPA and the Customer's use of VakeelOS features, and tell the Customer if it believes an instruction breaks the law;
- make sure everyone who processes Customer Personal Data is bound by confidentiality;
- maintain the security safeguards in Annex 2;
- help the Customer respond to Data Principals and meet its own obligations under the DPDP Act, as far as the nature of the processing allows;
- not sell Customer Personal Data or use it for advertising; and
- not use Customer Personal Data to train AI models, and not allow its Sub-processors to do so.
6. Sub-processors
The Customer authorises VarVik to use the Sub-processors listed in Annex 3. VarVik will give at least [Sub-processor notice period, e.g. 15 days] of notice before it adds or replaces a Sub-processor. If the Customer objects on reasonable data protection grounds, the parties will discuss it in good faith. If they cannot resolve it, the Customer may end the affected part of the Service and receive a pro-rata refund of fees it prepaid for that part.
VarVik will bind each Sub-processor to data protection terms at least as protective as this DPA, and it remains responsible for the work its Sub-processors do.
7. Where data is processed
VarVik hosts Customer Personal Data in Mumbai, India. It will not transfer Customer Personal Data outside India except to the Sub-processors and locations listed in Annex 3, and only where the DPDP Act and any restrictions notified under it allow.
8. Personal data breaches
VarVik will notify the Customer without undue delay, and in any event within [Breach notice window, e.g. 48 hours], after it becomes aware of a personal data breach affecting Customer Personal Data. The notice will describe, as far as is then known, what happened, the data and Data Principals likely to be affected, the likely consequences and the steps taken to contain the breach. VarVik will update the Customer as it learns more.
The Customer is responsible for informing the Board and the affected Data Principals as the DPDP Act requires, and VarVik will give it the information and help it reasonably needs to do so. VarVik will also report cyber incidents to CERT-In as the law requires.
9. Information and audits
VarVik will make available the information reasonably needed to show that it meets this DPA, including summaries of any independent security assessments it has. If that is not enough, the Customer may audit VarVik's compliance once a year. The Customer must give at least [Audit notice period, e.g. 30 days] of written notice, carry out the audit during business hours and at its own cost, and sign a confidentiality agreement. An audit must not give access to other customers' data.
10. Return and deletion
When the Customer's account ends, VarVik keeps Customer Personal Data for 30 days and exports it to the Customer on request during that time. It then deletes the data from live systems within [Deletion time from live systems, e.g. 30 days] and from backups within [Deletion time from backups, e.g. 90 days], unless the law requires it to keep some of it. On request, VarVik will confirm the deletion in writing.
11. Liability
Each party's liability under this DPA is subject to the limits in the Terms of Service.
12. Term and precedence
This DPA lasts for as long as VarVik processes Customer Personal Data. If it conflicts with the Terms on any matter of personal data, this DPA prevails.
13. Annex 1: Details of processing
| Item | Details |
|---|---|
| Data Principals | The Customer's clients and their representatives; opposing parties, witnesses and other people named in matters; the Customer's advocates, juniors, clerks and staff |
| Categories of data | Names and contact details; CNR numbers, case details, hearing dates and orders; documents, notes and drafts; invoices and payment status; account and usage data of the Customer's users |
| Data that needs extra care | Documents in a matter may contain financial, health, criminal proceedings or family information, or data about children. VarVik processes it only as part of the Customer's matters. |
| Nature and purpose | Storage, retrieval, syncing with court portals, search, AI-assisted drafting and research, reminders and invoicing, as the Customer uses these features |
| Duration | The life of the Customer's account and the 30 days after it ends, followed by deletion as this DPA describes |
14. Annex 2: Security safeguards
VarVik maintains the following safeguards. It may update them, provided the overall level of protection does not fall:
- encryption of Customer Personal Data in transit and at rest;
- separation of each customer's data from other customers' data;
- role-based access for the Customer's users, with one-time password sign-in;
- least-privilege access for VarVik staff, with access logged and reviewed;
- security logs kept for at least 180 days, in line with CERT-In directions;
- regular encrypted backups, with restores tested;
- patching and vulnerability management for the systems that run VakeelOS; and
- an incident response process that covers the breach notices in this DPA.
15. Annex 3: Sub-processors
| Sub-processor | Purpose | Location |
|---|---|---|
| [Cloud hosting provider] | Hosting, storage and backups | Mumbai, India |
| [AI model providers] | AI drafting and research features | [Where AI providers process prompts] |
| [WhatsApp messaging provider] | WhatsApp reminders | [Where the messaging provider processes data] |
| [Email delivery provider] | Account and notification emails | [Where the email provider processes data] |