Skip to main content
Home Legal
Sub-processors

Sub-processors

Version 1.0 · Effective 22 August 2026

Everyone who touches Customer Data on our behalf, what they do, and where they are. Thirty days' notice before this list changes.

Global 30-day change notice Objection right

This page is the authoritative list required by clause 7 of the Data Processing Addendum. Every entity named here is bound by written contract to obligations no less protective than that DPA, and DECTIFY remains fully liable to Customers for their performance.

Get told before it changes. Subscribe to sub-processor change notifications by emailing privacy@dectify.in with the subject "sub-processor notifications" and the addresses to notify. We give at least thirty (30) days' notice before adding or replacing a sub-processor, and you may object on reasonable data protection grounds — with a right to terminate the affected Order Form without penalty if we cannot accommodate you.

1. Infrastructure and hosting

These providers store and process Customer Data, including video, plate reads and biometric templates.

Sub-processorFunctionData locationData categories
[primary cloud provider]Compute, object storage, managed database for the HUBIndia (Mumbai / Hyderabad); Australia (Sydney)All Customer Data
[secondary / DR provider]Disaster recovery and backup storageSame region as primaryAll Customer Data (encrypted backups)
[CDN provider]Content delivery and DDoS protection for the web tierGlobal edge; no Customer Data at restRequest metadata, IP addresses

2. Platform services

Sub-processorFunctionData locationData categories
[identity provider]Authentication, SSO and MFA for Authorised Users[region]Account identifiers, authentication events
[transactional email provider]Alert and system email delivery[region]Email address, message content
[SMS / push provider]Alert notification delivery[region]Phone number, message content
[observability provider]Application logging, metrics and error tracking[region]Service Data; no video, plates or templates

3. Business operations

These providers process personal data DECTIFY controls — account contacts, enquiries, billing — and do not access Customer Data.

Sub-processorFunctionData locationData categories
[CRM provider]Customer relationship management[region]Business contact details, correspondence
[support desk provider]Support ticketing[region]Contact details, ticket content
[billing / payments provider]Invoicing and payment processing[region]Billing contact and transaction data
[web analytics provider]Website analytics, subject to cookie consent[region]Website usage data — see Cookie Policy

4. DECTIFY affiliates

DECTIFY Technologies Private Limited currently has no subsidiaries or affiliates, and no Australian entity. All processing by DECTIFY personnel is performed from India. If an affiliate is established, it will be added here with thirty days' notice like any other sub-processor.

5. What is not on this list

  • No data brokers, advertising networks, insurers, credit bureaux, tenancy databases or employment-screening services. Not now, and adding one would require notice under clause 7.2 of the DPA — which is a commitment we do not intend to test.
  • No third-party model or inference APIs process Customer Data. Inference runs on DECTIFY-controlled infrastructure. Video, faces, templates and plates are not sent to an external model provider.
  • No government agency. Authorities are not sub-processors. Disclosure to an authority happens only under compulsion, as described at Government and Law Enforcement Requests.

6. How we select and monitor them

  • Security assessment before engagement, requiring ISO/IEC 27001, SOC 2 Type II or equivalent independent attestation for any provider touching personal data.
  • Written contract imposing the Vendor Terms and the DPA, including 12-hour incident notification to us — tight enough that our own six-hour CERT-In clock remains achievable.
  • Data residency committed contractually, not merely configured.
  • Annual review of attestations, and reassessment on any material change to the service.
  • Removal where a provider cannot maintain the standard, or becomes non-permissible under section 16 of the DPDP Act.

7. Change log

DateChangeNotice given
22 August 2026Initial publication of this list—

Historic versions are available from privacy@dectify.in on request.

Contact

Questions about this document: legal@dectify.in

DECTIFY Technologies Pvt. Ltd., New Delhi, India