Sub-processors
Everyone who touches Customer Data on our behalf, what they do, and where they are. Thirty days' notice before this list changes.
This page is the authoritative list required by clause 7 of the Data Processing Addendum. Every entity named here is bound by written contract to obligations no less protective than that DPA, and DECTIFY remains fully liable to Customers for their performance.
Get told before it changes. Subscribe to sub-processor change notifications by emailing privacy@dectify.in with the subject "sub-processor notifications" and the addresses to notify. We give at least thirty (30) days' notice before adding or replacing a sub-processor, and you may object on reasonable data protection grounds — with a right to terminate the affected Order Form without penalty if we cannot accommodate you.
1. Infrastructure and hosting
These providers store and process Customer Data, including video, plate reads and biometric templates.
| Sub-processor | Function | Data location | Data categories |
|---|---|---|---|
| [primary cloud provider] | Compute, object storage, managed database for the HUB | India (Mumbai / Hyderabad); Australia (Sydney) | All Customer Data |
| [secondary / DR provider] | Disaster recovery and backup storage | Same region as primary | All Customer Data (encrypted backups) |
| [CDN provider] | Content delivery and DDoS protection for the web tier | Global edge; no Customer Data at rest | Request metadata, IP addresses |
2. Platform services
| Sub-processor | Function | Data location | Data categories |
|---|---|---|---|
| [identity provider] | Authentication, SSO and MFA for Authorised Users | [region] | Account identifiers, authentication events |
| [transactional email provider] | Alert and system email delivery | [region] | Email address, message content |
| [SMS / push provider] | Alert notification delivery | [region] | Phone number, message content |
| [observability provider] | Application logging, metrics and error tracking | [region] | Service Data; no video, plates or templates |
3. Business operations
These providers process personal data DECTIFY controls — account contacts, enquiries, billing — and do not access Customer Data.
| Sub-processor | Function | Data location | Data categories |
|---|---|---|---|
| [CRM provider] | Customer relationship management | [region] | Business contact details, correspondence |
| [support desk provider] | Support ticketing | [region] | Contact details, ticket content |
| [billing / payments provider] | Invoicing and payment processing | [region] | Billing contact and transaction data |
| [web analytics provider] | Website analytics, subject to cookie consent | [region] | Website usage data — see Cookie Policy |
4. DECTIFY affiliates
DECTIFY Technologies Private Limited currently has no subsidiaries or affiliates, and no Australian entity. All processing by DECTIFY personnel is performed from India. If an affiliate is established, it will be added here with thirty days' notice like any other sub-processor.
5. What is not on this list
- No data brokers, advertising networks, insurers, credit bureaux, tenancy databases or employment-screening services. Not now, and adding one would require notice under clause 7.2 of the DPA — which is a commitment we do not intend to test.
- No third-party model or inference APIs process Customer Data. Inference runs on DECTIFY-controlled infrastructure. Video, faces, templates and plates are not sent to an external model provider.
- No government agency. Authorities are not sub-processors. Disclosure to an authority happens only under compulsion, as described at Government and Law Enforcement Requests.
6. How we select and monitor them
- Security assessment before engagement, requiring ISO/IEC 27001, SOC 2 Type II or equivalent independent attestation for any provider touching personal data.
- Written contract imposing the Vendor Terms and the DPA, including 12-hour incident notification to us — tight enough that our own six-hour CERT-In clock remains achievable.
- Data residency committed contractually, not merely configured.
- Annual review of attestations, and reassessment on any material change to the service.
- Removal where a provider cannot maintain the standard, or becomes non-permissible under section 16 of the DPDP Act.
7. Change log
| Date | Change | Notice given |
|---|---|---|
| 22 August 2026 | Initial publication of this list | — |
Historic versions are available from privacy@dectify.in on request.
Contact
Questions about this document: legal@dectify.in
DECTIFY Technologies Pvt. Ltd., New Delhi, India