1. Overview and incorporation
This Data Processing Agreement (the “DPA”) forms part of, and is governed by, the agreement between you (the “Customer”) and Subhx Infotech OPC Pvt Ltd, a One Person Company incorporated under the Companies Act, 2013 in India (“Subhx”, “we”, “us” or “our”), governing the Customer's use of the SubhX Nexus platform (the “Service”). It applies whenever we process personal data on the Customer's behalf in the course of providing the Service.
Where there is a conflict between this DPA and the Terms & Conditions on a matter of personal-data processing, this DPA prevails. Capitalised terms not defined here have the meaning given in our Terms & Conditions.
2. Definitions and roles
The parties use the following terms, aligned with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”) and common data-protection usage:
- Data Fiduciary / Controller
- The Customer, who alone or jointly determines the purpose and means of processing the personal data submitted to the Service. The Customer is the Data Fiduciary in respect of the personal data of its employees, candidates and contacts.
- Data Processor
- Subhx, which processes personal data only on the Customer's documented instructions in order to provide the Service. Subhx is a Data Processor and does not determine the purposes of processing.
- Data Principal / Subject
- The identified or identifiable individual to whom the personal data relates — typically the Customer's employees, candidates or other personnel.
- Personal Data
- Any data about an individual who is identifiable by or in relation to such data, as processed by us on the Customer's behalf through the Service.
- Sub-processor
- A third party engaged by Subhx to process personal data in connection with the Service, as described in our published Sub-processors list.
3. Scope and details of processing
The subject-matter of processing is the provision of the SubhX Nexus HR and project-management Service. The processing has the following characteristics:
- Nature and purpose
- Hosting, storage, transmission, organisation, retrieval, display, back-up and deletion of Customer Data solely to operate, secure, maintain, support and improve the Service.
- Duration
- For the term of the Customer's subscription, plus any post-termination export and deletion window described in Section 11.
- Categories of Data Principals
- The Customer's employees, HR staff, managers, administrators, job candidates and other personnel whose data the Customer chooses to add.
- Categories of Personal Data
- Identity and contact details, employment and payroll records, attendance and leave data, documents uploaded for onboarding, KYC identifiers (where the Customer enables KYC features), project, task and communication records, and usage metadata.
- Special-category / sensitive data
- Any sensitive identifiers (such as government IDs used for KYC) are processed only at the Customer's instruction; the Customer is responsible for ensuring a valid lawful basis and any required notices for such data.
4. Our obligations as Processor
- Process personal data only on the Customer's documented instructions, including those given through the Service's configuration and administrative controls, unless we are required to do otherwise by applicable law (in which case we will inform the Customer where lawful to do so).
- Ensure that personnel authorised to process personal data are bound by appropriate confidentiality obligations and are trained on their data-protection responsibilities.
- Implement and maintain appropriate technical and organisational security measures as described in our Security Practices, and not materially diminish the overall security of the Service during the term.
- Assist the Customer, taking into account the nature of processing, in responding to requests from Data Principals and in meeting the Customer's obligations regarding security, breach notification and, where applicable, data-protection impact assessments.
- Make available information reasonably necessary to demonstrate compliance with this DPA, and not use Customer personal data for our own purposes, including advertising or model training, except as permitted by the Customer or required by law.
5. Customer obligations as Fiduciary
- Ensure that there is a valid lawful basis for the personal data submitted to the Service, and that any required notices to and consents from Data Principals have been given.
- Provide instructions for processing that comply with applicable law, and not instruct us to process personal data in a way that would breach the DPDP Act or other applicable law.
- Configure roles, permissions and retention settings appropriately, and manage which of its users may access the workspace and the personal data within it.
- Respond, as Data Fiduciary, to communications from Data Principals and regulators, using the assistance we provide under this DPA where needed.
6. Sub-processors
The Customer authorises us to engage Sub-processors to support the Service. We maintain a current list of Sub-processors describing each provider category, its purpose, the data shared and its location. We impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance.
We will give the Customer a reasonable means to be informed of intended changes to the Sub-processor list and an opportunity to object on reasonable, data-protection grounds. The current list is available at our Sub-processors page.
7. Assisting with Data Principal rights
The Service provides administrative tools that allow the Customer to access, correct, export and delete personal data within its workspace, which support the Customer in meeting Data Principal requests directly. Where the Customer cannot fulfil a request through those tools, we will provide reasonable assistance taking into account the nature of the processing and the information available to us.
If we receive a request directly from a Data Principal relating to Customer Data, we will, unless legally prohibited, advise the individual to contact the Customer and will not respond substantively except on the Customer's instruction.
8. Security and personal-data breaches
- We maintain reasonable security safeguards designed to protect personal data against unauthorised or accidental access, disclosure, alteration, loss or destruction, as detailed in our Security Practices.
- On becoming aware of a personal-data breach affecting Customer Data, we will notify the Customer without undue delay and provide information reasonably available to us to help the Customer meet its own notification obligations under the DPDP Act and the rules made under it.
- Our notification of, or response to, a breach is not an acknowledgement of fault or liability. The Customer remains responsible, as Data Fiduciary, for assessing and making any notifications required of it by law.
9. Location of processing and transfers
Personal data processed through the Service is hosted in India. Where any limited transfer or onward processing outside India is necessary (for example, for a Sub-processor category such as error monitoring), we will do so only as permitted by applicable law and subject to appropriate safeguards. The Customer can identify any such processing from the Sub-processors list.
10. Audits and demonstrating compliance
We will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA, including relevant security documentation and summaries of controls. Where the Customer reasonably requires an audit, the parties will agree in advance a scope, timing and confidentiality terms that do not compromise the security or confidentiality of other customers' data, and audits will be conducted no more than once per year except where required by a regulator or following a confirmed breach.
11. Return and deletion on termination
- On expiry or termination of the subscription, the Customer may, for a period of 30 days, export its Customer Data using the Service's export tools or by request to support@subhx.in.
- After that window, we will delete or anonymise Customer Data within our active systems in accordance with our retention practices, except where retention is required by applicable law, in which case we will continue to protect it and process it only for that purpose.
- Residual copies in routine backups are purged in line with our backup-rotation cycle.
12. Liability, governing law and contact
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms & Conditions. This DPA is governed by the laws of India, and the courts at the place of our registered office in India have exclusive jurisdiction, consistent with the Terms & Conditions. For any question about this DPA, contact us below.
Subhx Infotech OPC Pvt Ltd
- Product
- SubhX Nexus
- support@subhx.in
- Jurisdiction
- India