Data Processing Agreement (DPA)

doAttendance / AttendSafe SaaS — Template for B2B customers | DPDP Act 2023 aligned

How to use: Fill in the bracketed fields, have both parties sign, and store a copy with your contract. This template describes doAttendance as the Data Processor and your organization as the Data Fiduciary under India’s DPDP Act 2023.

Related: Employee Privacy Policy

Privacy Policy

1. Parties

Data Fiduciary (Customer): [Legal entity name], registered at [Address] (“Customer”).

Data Processor (Provider): [Your company legal name], operator of the doAttendance / AttendSafe platform (“Processor”).

Effective date: [Date]

2. Subject matter & duration

Processor provides cloud attendance, leave, payroll, and related HR automation services to Customer. Processing continues for the subscription term and up to 30 days after termination (data export window), unless law requires longer retention.

3. Nature & purpose of processing

CategoryExamplesPurpose
Identity & employmentName, employee ID, email, department, roleAccount management, payroll, access control
Biometric (face)Face embedding vectors only — no photos retainedAttendance verification, anti-fraud
Location & networkGPS at check-in/out, WiFi BSSID, geofence statusCampus / remote work verification
DeviceDevice UUID, model, SIM binding metadataDevice binding, audit trail
Attendance eventsCheck-in/out timestamps, shift, statusPayroll, compliance reporting

4. Customer instructions

Processor shall process personal data only on documented instructions from Customer (this DPA, the MSA/subscription, and in-product configuration). Customer is responsible for lawful basis, employee notices, and consent where required.

5. Security measures

6. Sub-processors

Customer authorizes Processor to engage sub-processors for hosting, email/SMS, payment collection, and push notifications. Processor will maintain an up-to-date list on request and notify Customer of material changes where contractually required.

7. International transfers

Primary hosting is intended for India data residency. If processing occurs outside India, Processor shall implement appropriate safeguards and disclose locations in the order form or annex.

8. Data subject rights

Processor assists Customer in responding to employee requests (access, correction, erasure) via in-product tools: profile export, admin deletion workflows, and privacy audit logs. Requests from data principals should be directed to Customer as fiduciary.

9. Breach notification

Processor shall notify Customer without undue delay after becoming aware of a personal data breach affecting Customer’s tenant, including nature of breach, categories of data, and remediation steps.

10. Deletion & return

11. Audits

Upon reasonable notice, Processor shall provide summaries of relevant certifications or audit reports (e.g. SOC 2 when available) or allow Customer to review Processor’s security documentation subject to confidentiality.

12. Liability

Liability caps and indemnities are as set out in the main subscription agreement. Each party remains responsible for its own compliance obligations under applicable law.

13. Signatures

Customer (Data Fiduciary)
Name: [Name] · Title: [Title] · Date: [Date] · Signature: _______________________

Processor
Name: [Name] · Title: [Title] · Date: [Date] · Signature: _______________________