Skip to main content
Home Legal
Data Processing Addendum

Data Processing Addendum

Version 1.0 · Effective 22 August 2026

The processing terms that form part of every DECTIFY customer agreement. Written to be signed as-is by an Indian Data Fiduciary, an Australian APP entity, or a GDPR controller.

Global DPDP Act 2023 GDPR Art. 28 APP 8 / s.16C

This Data Processing Addendum ("DPA") is incorporated into and forms part of the Terms and Conditions between DECTIFY Technologies Private Limited ("DECTIFY", "Processor") and the Customer ("Controller"). It requires no separate signature; it applies automatically to every Order Form. Where a Customer requires a countersigned copy, request one from legal@dectify.in.

1. Roles

RegimeCustomer isDECTIFY is
Digital Personal Data Protection Act, 2023 (India)Data FiduciaryData Processor
Privacy Act 1988 (Cth) (Australia)APP entityService provider; overseas recipient under APP 8
GDPR / UK GDPR, where applicableControllerProcessor (Article 28)

DECTIFY acts as a controller in its own right only in respect of account administration, billing and marketing data, which is governed by the Privacy Policy and not by this DPA.

2. Subject matter and details of processing

Subject matterProvision of the DECTIFY Platform, Products and Hardware under the Agreement
DurationThe term of the Agreement, plus the deletion periods in clause 11
Nature and purposeHosting, storage, transmission, indexing, inference, display, and support of Customer Data, for Customer's security, safety, operational and investigative purposes
Categories of data subjectIndividuals present at Customer's Sites — employees, contractors, visitors, customers, members of the public; drivers and vehicle occupants; Customer's Authorised Users
Categories of personal dataVideo and images; facial images; biometric templates and feature vectors; appearance descriptors; registration plates and vehicle characteristics; location, timestamp and camera identifiers; alerts, match decisions and case records; Authorised User account and audit data
Special category / sensitive dataBiometric data used for identification. Treated as sensitive information under s.6 Privacy Act 1988 and as special category data under Article 9 GDPR where that applies

3. Processing on instructions

DECTIFY shall process Customer Data only on Customer's documented instructions, which comprise the Agreement, the configuration Customer sets in the Platform, and any further written instruction Customer gives. DECTIFY shall inform Customer if, in its opinion, an instruction infringes applicable data protection law, and may decline to act on it. Where DECTIFY is required by law to process otherwise, it shall inform Customer before doing so unless the law prohibits that notification.

4. What DECTIFY will not do

  • Sell, licence, rent, trade or otherwise commercially disclose Customer Data.
  • Use Customer Data to train, fine-tune or evaluate any model, absent Customer's written, per-product, revocable opt-in.
  • Pool, federate or cross-match Customer Data with any other customer's data, or build the capability to.
  • Retain Customer Data beyond the Data Retention Schedule.
  • Access Customer's tenancy other than to resolve a reported fault, address a security incident, or at Customer's request — with every access logged to Customer.
  • Disclose Customer Data to any authority except as clause 9 permits.

5. Confidentiality of personnel

DECTIFY shall ensure that persons authorised to process Customer Data are bound by written confidentiality obligations surviving their engagement, are subject to background verification proportionate to their access, receive data protection training, and are granted access strictly on least privilege with quarterly recertification.

6. Security

DECTIFY shall implement appropriate technical and organisational measures, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing and the risks to individuals. The measures are described at India Cybersecurity and Technology s.4 and Australia Cybersecurity and Technology s.2–3, and include pseudonymisation and encryption, confidentiality, integrity, availability and resilience of processing systems, restoration of availability after an incident, and regular testing of effectiveness.

DECTIFY shall not materially decrease the overall security of the Services during the term.

7. Sub-processors

7.1 General authorisation. Customer gives general authorisation for DECTIFY to engage sub-processors, listed with function and location at Sub-processors.

7.2 Notice of change. DECTIFY shall give at least thirty (30) days' notice before adding or replacing a sub-processor, by email to the registered contact and by update to that page. Customers may subscribe to change notifications.

7.3 Objection. Customer may object on reasonable data protection grounds within the notice period. The parties shall discuss in good faith. If DECTIFY cannot accommodate the objection, Customer may terminate the affected Order Form without penalty and receive a pro-rata refund of prepaid Fees for the unused period.

7.4 Flow-down and responsibility. DECTIFY shall impose obligations no less protective than this DPA on each sub-processor by written contract, and remains fully liable to Customer for a sub-processor's performance.

8. Assistance to Customer

Taking into account the nature of the processing, DECTIFY shall assist Customer, by appropriate technical and organisational measures and insofar as possible, with:

  • Rights requests. Access, correction, erasure and nomination under the DPDP Act; access and correction under APP 12 and 13; the Chapter III rights under the GDPR. Where DECTIFY receives a request directly from an individual concerning Customer Data, it shall not respond substantively, shall promptly forward it to Customer, and shall tell the individual who to approach.
  • Breach notification, under clause 9.
  • Impact assessments and prior consultation, by providing the technical information Customer needs, including model cards and evaluation data.
  • Security, by providing its current attestations and control documentation.

9. Personal data breach

  • DECTIFY shall notify Customer without undue delay and in any event within seventy-two (72) hours of becoming aware of a personal data breach affecting Customer Data.
  • The notification shall describe the nature of the breach, the categories and approximate volume of data and individuals affected, the likely consequences, the measures taken and proposed, and a contact point.
  • Where full information is not available, DECTIFY shall notify on what it knows and update as it learns more, rather than delaying.
  • DECTIFY shall separately report to CERT-In within six (6) hours where the Directions of 28 April 2022 apply, and shall support Customer's own obligations to the Data Protection Board of India, the OAIC under the Notifiable Data Breaches scheme, and any SOCI Act reporting.
  • Notification is not an acknowledgement of fault or liability.

10. Government and law enforcement demands

If DECTIFY receives a binding demand from any authority for Customer Data, it shall — unless legally prohibited — notify Customer promptly and before disclosing, so Customer may seek protective relief; challenge or narrow a demand that is overbroad, defective or unlawful; and disclose only the minimum the process actually compels. Where notification is prohibited, DECTIFY shall use reasonable efforts to have the prohibition lifted and shall notify as soon as it may. The full policy, including the process we require in India and Australia, is at Government and Law Enforcement Requests.

11. Return and deletion

On termination or expiry, Customer may export Customer Data for thirty (30) days in a structured, machine-readable format. Thereafter DECTIFY shall delete it from production systems within thirty (30) days and from backups within a further ninety (90) days. Biometric templates are deleted on the accelerated schedule in the Data Retention Schedule and are not held for the export window. DECTIFY shall certify deletion in writing on request. Deletion is subject only to retention required by law, which shall be limited to the data and period the law requires, with the data remaining protected by this DPA.

12. Audit

DECTIFY shall make available the information necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor it mandates.

Customer may exercise this right once in any twelve-month period on thirty (30) days' notice, subject to confidentiality and to reasonable measures protecting other customers' data and DECTIFY's security. DECTIFY's current independent attestations may be accepted in satisfaction. Following a personal data breach, or where a regulator directs, an audit may be conducted on shorter notice and outside that frequency limit. A regulator's statutory audit right is not limited by this clause.

13. International transfers

13.1 India. Transfer outside India is permitted under section 16 of the DPDP Act except to a country restricted by notification. DECTIFY monitors the restricted list and will migrate away from any provider that becomes non-permissible.

13.2 Australia. DECTIFY is an overseas recipient under APP 8. DECTIFY contractually commits to handle Australian personal information consistently with the APPs, and Customer's accountability under section 16C is preserved rather than displaced. Customer Data from Australian deployments is hosted in an Australian region by default.

13.3 GDPR. Where the GDPR applies, the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), are incorporated by reference, with Customer as data exporter and DECTIFY as data importer. Clause 7 (docking) is included; clause 9 option 2 (general authorisation) applies with a thirty-day notice period; clause 11 optional redress is not adopted; clause 17 governing law and clause 18 forum are the law and courts of Ireland; Annexes I, II and III are populated by clauses 2, 6 and 7 of this DPA and the Sub-processors page. The UK International Data Transfer Addendum applies where UK GDPR governs. Where this DPA conflicts with the SCCs, the SCCs prevail.

14. Liability and precedence

Liability under this DPA is subject to clause 13 of the Terms and Conditions, save for any liability that cannot lawfully be limited. In the event of conflict, this DPA prevails over the Terms and Conditions in respect of the processing of personal data, and the SCCs prevail over this DPA where they apply.

15. Changes

DECTIFY may update this DPA to reflect a change in law, in regulator guidance, or in an approved transfer mechanism, on thirty (30) days' notice. A change that materially reduces Customer's protection will not be made without Customer's agreement.

Contact

Questions about this document: legal@dectify.in

DECTIFY Technologies Pvt. Ltd., New Delhi, India