Legal

Data Processing Agreement

Last updated: June 8, 2026

This Data Processing Agreement ("DPA") supplements the Terms of Service and forms part of the agreement between you ("Data Controller") and Ccyfer Technologies ("Data Processor"). This DPA governs the processing of personal data on your behalf through the Platform.
01

Definitions

In this DPA:

"Personal Data" means any information relating to an identified or identifiable natural person processed through the Platform.
"Data Controller" means you, the Ccyfer subscriber, who determines the purposes and means of processing personal data.
"Data Processor" means Ccyfer Technologies, which processes personal data on behalf of the Data Controller.
"Sub-processor" means any third-party processor engaged by Ccyfer to process personal data.
"Applicable Law" means the Digital Personal Data Protection Act 2023 (India), GDPR (EU/UK) where applicable, and any other applicable data protection laws.
02

Nature and Purpose of Processing

Ccyfer processes personal data on your behalf for the following purposes:

Processing ActivityCategories of DataLegal Basis
User account managementNames, emails, business details of your team membersContract performance
AI tool operationBusiness descriptions, audience data, product details you enterContract performance
Platform analyticsUsage patterns, tool interactions (anonymised)Legitimate interest
Client workspace managementClient names, websites, social handles you inputContract performance
Billing and invoicingNames, billing addresses, payment identifiersLegal obligation
Security monitoringLogin events, access logs, IP addressesLegitimate interest
03

Ccyfer's Obligations as Data Processor

As your Data Processor, Ccyfer agrees to:

Process personal data only on your documented instructions and not for any other purpose
Ensure that persons authorised to process personal data have committed to confidentiality
Implement appropriate technical and organisational security measures (see Section 5)
Assist you in responding to data subject requests within required timeframes
Notify you of any personal data breach within 72 hours of becoming aware
Delete or return all personal data upon termination of services, at your option
Make available all information necessary to demonstrate compliance with this DPA
Not engage sub-processors without your prior written consent (see Section 4)
04

Sub-processors

You provide general written authorisation for Ccyfer to engage the following sub-processors. We will notify you 30 days in advance of adding new sub-processors:

Sub-processorLocationProcessing ActivityData Categories
Google Firebase / FirestoreIndia (Mumbai)Database, authentication, file storageAll platform data
Google Cloud PlatformIndia (Mumbai)Hosting, functions, storageAll platform data
Anthropic PBCUSAAI content generation (Claude API)Tool inputs only
OpenRouter Inc.USAAI model routing and fallbackTool inputs only
Stripe / RazorpayUSA / IndiaPayment processingBilling data only

For AI sub-processors located in the USA, data transfers are governed by Standard Contractual Clauses (Module 2: Controller to Processor). Only the minimum necessary data (tool inputs, not full personal profiles) is transferred to AI providers.

05

Security Measures

Ccyfer has implemented the following technical and organisational measures:

Encryption in transit

TLS 1.3 for all data in transit between client and server

Encryption at rest

AES-256 encryption for all stored data (Google Cloud default)

Access controls

Role-based access control; principle of least privilege

Authentication

Multi-factor authentication support; JWT with short expiry

Admin operations

All admin writes via server-side Cloud Functions, not client-side

API key security

All keys stored as environment secrets, never in client code

Audit logging

All admin actions and access events logged with timestamps

Vulnerability management

Regular dependency audits; security patches applied promptly

06

Data Subject Rights Assistance

When you receive a data subject request (access, deletion, correction, portability) relating to personal data processed through the Platform, Ccyfer will:

Provide technical assistance to help you fulfil the request
Make relevant data available for export in structured format (JSON/CSV) within 14 days
Execute deletion of personal data upon your verified instruction within 30 days
Provide audit logs confirming deletion upon request

Note: You remain the Data Controller and are responsible for responding to data subjects. Ccyfer acts only on your instructions.

07

Data Breach Notification

In the event of a personal data breach affecting data processed under this DPA:

Ccyfer will notify you without undue delay and within 72 hours of becoming aware
Notification will include: nature of breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed
You are responsible for notifying relevant authorities and data subjects where required by Applicable Law
Ccyfer will cooperate fully with your breach investigation and response
08

International Transfers

Processing within India occurs on Google Cloud infrastructure in the Mumbai (asia-south1) region. Where personal data is transferred outside India to AI sub-processors in the USA:

Transfers are governed by Standard Contractual Clauses approved under GDPR (binding on Ccyfer where EU data is involved)
Data Processing Agreements are in place with all US sub-processors
Only tool input data necessary for AI generation is transferred; personal profile data remains in India
Transfers comply with India's Digital Personal Data Protection Act 2023 cross-border transfer provisions
09

Retention and Deletion

Ccyfer retains personal data processed under this DPA for:

The duration of the active subscription plus 90 days after account termination
Billing records: 7 years (Indian Income Tax Act requirement)
Security logs: 12 months

Upon termination of the subscription or receipt of a deletion instruction, Ccyfer will delete or irreversibly anonymise all personal data within 30 days and provide written confirmation.

10

Audit Rights

You have the right to audit Ccyfer's compliance with this DPA. Ccyfer will:

Provide written responses to reasonable audit questionnaires within 30 days
Make relevant security documentation available upon request
Allow physical audits by you or your appointed auditor with 30 days' notice, at your cost

Ccyfer may satisfy audit obligations by providing third-party certifications or audit reports in lieu of physical audits.

11

Governing Law

This DPA is governed by the laws of India. Disputes arising under this DPA are subject to the exclusive jurisdiction of the courts of Mumbai, Maharashtra, India.

To exercise your rights under this DPA or for any questions, contact our Data Protection Officer at dpo@ccyfer.in.