Vendor Terms
What DECTIFY requires of its suppliers. If you sell to us, or process anything on our behalf, these are the obligations you take on.
These Vendor Terms apply to every supplier, contractor, consultant and sub-processor engaged by DECTIFY Technologies Private Limited ("DECTIFY"), and are incorporated into each purchase order, statement of work and supply agreement unless a signed agreement expressly displaces them.
They exist because our obligations to our customers are only as good as our supply chain. Almost everything here is a flow-down of something we have promised someone else.
1. Information security
1.1 Baseline controls
Vendor shall maintain, and evidence on request, at minimum:
- A documented information security programme, with a named owner, reviewed annually.
- Multi-factor authentication on every account with access to DECTIFY data or systems.
- Role-based access control on least privilege, with quarterly recertification and revocation within twenty-four (24) hours of a personnel change.
- Encryption of DECTIFY data in transit (TLS 1.2 or higher) and at rest (AES-256 or equivalent).
- Documented patch management, with critical patches applied to internet-facing systems within forty-eight (48) hours of availability.
- Centralised logging with a minimum one hundred and eighty (180) day retention, sufficient to reconstruct access to DECTIFY data.
- Annual penetration testing by a qualified third party, and remediation of critical and high findings.
- Background verification of personnel proportionate to their access, before access is granted.
- Security awareness training on joining and annually.
- A tested incident response plan and a documented business continuity plan.
1.2 Certification
Vendors processing personal data or holding privileged access shall hold ISO/IEC 27001 certification, a current SOC 2 Type II report, or an equivalent independent attestation, and shall furnish it annually. Where a vendor holds none, DECTIFY may require a security assessment as a condition of engagement and may decline to proceed.
1.3 Segregation
DECTIFY data shall be logically segregated from other clients' data, shall not be commingled, and shall not be used for any purpose other than performing the services.
2. Incident notification — the clocks
Vendor shall notify DECTIFY within twelve (12) hours of becoming aware of any actual or suspected security incident, personal data breach, or unauthorised access affecting DECTIFY data or systems. Twelve hours is not arbitrary: DECTIFY must report to CERT-In within six hours of our awareness, and a customer may have a twelve-hour SOCI Act obligation. A vendor that notifies us late causes us to breach a statutory obligation.
Notification shall be to security@dectify.in and shall not be delayed pending investigation. Vendor shall provide what it knows, update as it learns more, preserve evidence, cooperate fully with DECTIFY's investigation and with any regulator, and shall not make any public statement or notify any regulator or individual about an incident affecting DECTIFY data without DECTIFY's prior written consent, except where independently required by law.
3. Data protection
- Where Vendor processes personal data on DECTIFY's behalf, Vendor is a Data Processor under the Digital Personal Data Protection Act, 2023 and, where applicable, a processor under Article 28 of the GDPR. The Data Processing Addendum applies and is incorporated.
- Vendor shall process only on DECTIFY's documented instructions, and shall tell us if an instruction appears to breach applicable law.
- Vendor shall not engage a sub-processor without DECTIFY's prior written authorisation, and shall impose these obligations on any authorised sub-processor by written contract.
- Vendor shall assist DECTIFY in responding to Data Principal and individual rights requests, in conducting impact assessments, and in meeting breach notification obligations.
- Vendor shall not transfer DECTIFY data across a border without prior written authorisation, and shall comply with section 16 of the DPDP Act and Australian Privacy Principle 8.
- Personnel with access shall be bound by written confidentiality obligations surviving their engagement.
- On termination, Vendor shall return or delete all DECTIFY data within thirty (30) days and certify deletion in writing.
4. Confidentiality
Vendor shall treat all DECTIFY information as confidential, use it solely to perform the services, disclose it only to personnel who need it and are bound by equivalent obligations, and protect it with no less than reasonable care. These obligations survive for five (5) years after termination, and indefinitely for trade secrets, source code, model weights and any biometric data.
5. Anti-bribery and anti-corruption
Vendor shall not offer, give, request or accept any undue advantage, and shall comply with the Prevention of Corruption Act, 1988 (India), the Criminal Code Act 1995 (Cth) (Australia), and where applicable the UK Bribery Act 2010 and the US Foreign Corrupt Practices Act.
Vendor shall maintain accurate books and records, shall not make facilitation payments, and shall disclose any actual or potential conflict of interest, including any relationship between Vendor's personnel and DECTIFY's personnel or a DECTIFY customer's decision-makers. Where DECTIFY is bidding for public work, Vendor shall comply with any integrity pact DECTIFY has signed.
6. Sanctions and trade controls
Vendor represents that neither it, nor any of its owners, directors or personnel involved in the engagement, is a person designated under sanctions administered by the United Nations, India's Ministry of External Affairs, the Australian Department of Foreign Affairs and Trade, the US Office of Foreign Assets Control, or the European Union — nor owned or controlled by, or acting on behalf of, such a person.
Vendor shall comply with all applicable export control and trade sanctions law, shall not route DECTIFY data or goods through a restricted destination, and shall notify DECTIFY immediately if this representation ceases to be true. DECTIFY may terminate immediately, without liability, on a breach of this clause.
7. Modern slavery and labour standards
Vendor shall ensure that no forced labour, bonded labour, indentured labour, child labour or human trafficking occurs in its operations or supply chain, consistent with the Modern Slavery Act 2018 (Cth), the Bonded Labour System (Abolition) Act, 1976 and the Child and Adolescent Labour (Prohibition and Regulation) Act, 1986.
Vendor shall pay at least the applicable minimum wage, respect freedom of association, provide a safe workplace, and not require workers to surrender identity documents or pay recruitment fees. Vendor shall permit DECTIFY, on reasonable notice, to audit compliance, and shall provide supply chain information DECTIFY needs to support a customer's own modern slavery reporting. A substantiated finding is grounds for immediate termination.
8. Hardware and component suppliers
In addition to the above, suppliers of hardware, components or firmware shall:
- Provide a software bill of materials in SPDX or CycloneDX format for any firmware or embedded software.
- Ship no default, shared or hard-coded credentials, and support first-boot credential rotation.
- Support signed firmware, verified boot and authenticated over-the-air update with rollback protection.
- Disclose any component originating from a jurisdiction subject to procurement restriction in India or Australia, and any beneficial ownership relevant to those restrictions.
- Commit to a security support period and notify DECTIFY at least twelve (12) months before end of support.
- Notify DECTIFY of any vulnerability in a supplied component within twelve (12) hours of becoming aware.
- Meet applicable product compliance requirements — BIS and WPC in India, the Regulatory Compliance Mark and Radiocommunications Act device compliance in Australia — and provide evidence.
- Participate in e-waste take-back under the E-Waste (Management) Rules, 2022 and the applicable Australian schemes.
9. Insurance
Vendor shall maintain, with reputable insurers, cover appropriate to the engagement, and shall provide certificates on request: public liability, professional indemnity or errors and omissions where services are advisory or technical, cyber liability where DECTIFY data is processed, product liability where goods are supplied, and workers' compensation as required by law.
10. Audit
DECTIFY may, on thirty (30) days' notice and no more than once in any twelve-month period, audit Vendor's compliance with these Vendor Terms — or accept a current independent attestation in place of an audit. Where DECTIFY has reasonable grounds to suspect a breach, or following a security incident, an audit may be conducted on shorter notice and outside that frequency limit. Vendor shall cooperate and provide reasonable access to records, systems and personnel. Where a DECTIFY customer or a regulator holds a statutory audit right that reaches Vendor, Vendor shall submit to it.
11. Compliance with DECTIFY policies
Vendor shall comply with the Acceptable Use Policy in respect of any DECTIFY technology it accesses, and shall not use DECTIFY data or technology for any purpose that policy prohibits. A vendor who becomes aware of a suspected breach of that policy by anyone shall report it to abuse@dectify.in.
12. Term, termination and consequences
DECTIFY may terminate immediately for a material breach of clauses 2, 3, 5, 6 or 7, and otherwise on thirty (30) days' notice for a breach not cured. On termination Vendor shall return or delete DECTIFY data and certify deletion within thirty (30) days, return all DECTIFY property, and provide reasonable transition assistance at the rates in force.
13. Indemnity and liability
Vendor shall indemnify DECTIFY against loss arising from Vendor's breach of these Vendor Terms, from its infringement of a third party's intellectual property, or from a security incident or personal data breach caused by Vendor's act or omission — including regulatory penalties, notification costs, forensic costs and reasonable legal costs. Vendor's liability under clauses 2, 3, 5, 6 and 7 is not subject to any cap in the supply agreement.
14. Publicity and governing law
Vendor shall not name DECTIFY as a customer, or use DECTIFY's marks, without prior written consent. These Vendor Terms are governed by the laws of India, with the courts at New Delhi having exclusive jurisdiction, unless the supply agreement provides otherwise.
15. Contact
Vendor security and compliance matters: vendors@dectify.in. Security incidents, at any hour: security@dectify.in.
Contact
Questions about this document: legal@dectify.in
DECTIFY Technologies Pvt. Ltd., New Delhi, India