doAttendance / AttendSafe SaaS — Template for B2B customers | DPDP Act 2023 aligned
How to use: Fill in the bracketed fields, have both parties sign, and store a copy with your contract. This template describes doAttendance as the Data Processor and your organization as the Data Fiduciary under India’s DPDP Act 2023.
Related: Employee Privacy Policy
Data Fiduciary (Customer): [Legal entity name], registered at [Address] (“Customer”).
Data Processor (Provider): [Your company legal name], operator of the doAttendance / AttendSafe platform (“Processor”).
Effective date: [Date]
Processor provides cloud attendance, leave, payroll, and related HR automation services to Customer. Processing continues for the subscription term and up to 30 days after termination (data export window), unless law requires longer retention.
| Category | Examples | Purpose |
|---|---|---|
| Identity & employment | Name, employee ID, email, department, role | Account management, payroll, access control |
| Biometric (face) | Face embedding vectors only — no photos retained | Attendance verification, anti-fraud |
| Location & network | GPS at check-in/out, WiFi BSSID, geofence status | Campus / remote work verification |
| Device | Device UUID, model, SIM binding metadata | Device binding, audit trail |
| Attendance events | Check-in/out timestamps, shift, status | Payroll, compliance reporting |
Processor shall process personal data only on documented instructions from Customer (this DPA, the MSA/subscription, and in-product configuration). Customer is responsible for lawful basis, employee notices, and consent where required.
org_id; optional PostgreSQL RLS and dedicated DB per enterprise tenantCustomer authorizes Processor to engage sub-processors for hosting, email/SMS, payment collection, and push notifications. Processor will maintain an up-to-date list on request and notify Customer of material changes where contractually required.
Primary hosting is intended for India data residency. If processing occurs outside India, Processor shall implement appropriate safeguards and disclose locations in the order form or annex.
Processor assists Customer in responding to employee requests (access, correction, erasure) via in-product tools: profile export, admin deletion workflows, and privacy audit logs. Requests from data principals should be directed to Customer as fiduciary.
Processor shall notify Customer without undue delay after becoming aware of a personal data breach affecting Customer’s tenant, including nature of breach, categories of data, and remediation steps.
Upon reasonable notice, Processor shall provide summaries of relevant certifications or audit reports (e.g. SOC 2 when available) or allow Customer to review Processor’s security documentation subject to confidentiality.
Liability caps and indemnities are as set out in the main subscription agreement. Each party remains responsible for its own compliance obligations under applicable law.
Customer (Data Fiduciary)
Name: [Name] · Title: [Title] · Date: [Date] · Signature: _______________________
Processor
Name: [Name] · Title: [Title] · Date: [Date] · Signature: _______________________