Data Processing Agreement

This Data Processing Agreement (“Agreement”) defines the legally enforceable obligations between Exotic Informative, acting as the “Processor,” and the organization or individual accepting these terms, acting as the “Controller.” This Agreement regulates how Personal Data is handled while delivering digital transaction and financial processing services.

Responsibilities of the Parties

The Controller decides the purpose, lawful grounds, and manner in which Personal Data is handled and remains accountable for adherence to all relevant data protection regulations.

The Processor shall handle Personal Data only according to written directions issued by the Controller and solely for the execution of authorized financial technology services.

Extent of Data Processing

The Processor is permitted to handle Personal Data exclusively for the following activities:

  • Initiating, validating, and completing electronic financial transactions
    • Identity verification procedures and risk monitoring
    • User authentication processes, including additional security verification
    • Transactional record generation and settlement matching
    • Compliance with directives issued by RBI, NPCI, and applicable financial network authorities

Data Protection Safeguards

The Processor shall apply suitable administrative, technical, and operational controls, including:

  • Compliance with recognized financial data security frameworks
    • Encryption mechanisms for data during storage and transmission
    • Multi-layer access verification for internal systems
    • Robust encryption key governance standards
    • Periodic system security testing, including threat simulations

All personnel authorized to access Personal Data shall be bound by confidentiality obligations and receive regular training on secure data handling procedures.

Rights of Data Subjects

The Processor shall reasonably assist the Controller in responding to individual rights requests under applicable privacy regulations, including:

  • Access to Personal Data
    • Correction of inaccurate information
    • Deletion of Personal Data
    • Transferability of Personal Data
    • Limitation or objection to processing activities

Engagement of Third Parties

The Processor shall not appoint any third-party data handlers without obtaining prior written approval from the Controller.
All authorized third parties must operate under written contracts ensuring protection standards equal to or stronger than those outlined in this Agreement.

Incident Notification

In the event of unauthorized access, disclosure, or loss of Personal Data, the Processor shall inform the Controller within 24 hours of becoming aware of the incident.

The notification shall detail:

  • Description and nature of the incident
    • Types and estimated number of impacted individuals
    • Immediate containment and corrective actions taken
    • Preventive measures planned to avoid recurrence

Oversight and Verification

Upon reasonable advance notice, the Controller may review the Processor’s compliance with this Agreement. The Processor shall provide relevant documentation, security certifications, and internal compliance records upon request.

Data Storage and Disposal

Personal Data shall be stored only for the duration required to fulfill service obligations and regulatory requirements, including retention mandates prescribed by Indian authorities.

Following service termination, the Processor shall permanently erase or return all Personal Data unless continued retention is legally mandated.

Regulatory Updates

The Processor shall notify the Controller without undue delay if legislative or regulatory changes impact its ability to process Personal Data in accordance with this Agreement.

Responsibility and Compensation

Each party shall be accountable for losses resulting from its failure to comply with this Agreement. The Processor agrees to protect and compensate the Controller against penalties, claims, or damages arising from breaches of data protection responsibilities.

Applicable Law and Jurisdiction

This Agreement shall be governed by the laws of India. All disputes shall fall under the exclusive authority of Indian courts.

Modifications

Any revisions to this Agreement must be documented in writing and formally approved by both parties.

Acceptance

By agreeing to these terms, both parties confirm that they have read, understood, and accepted all provisions contained in this Data Processing Agreement.