Draft pending legal review
This document reflects how TrustShot is built and operated, and is being reviewed by counsel before general availability. Highlighted items are details still to be confirmed. Questions: contact@trustshot.in
1.Roles and scope
This Data Processing Addendum (“DPA”) forms part of the Terms of Service. It applies when TrustShot processes personal data on the Customer’s behalf in providing the service (“Customer Personal Data”).
For Customer Personal Data, the Customer is the Data Fiduciary and TrustShot is the Data Processor, as those terms are used in the Digital Personal Data Protection Act, 2023 (“DPDP Act”). Where the Customer is itself processing on behalf of another fiduciary, TrustShot acts as its sub-processor on the same terms.
2.Details of the processing
| Subject matter | Hosting and operating the Customer’s Trust Center and its administration portal |
|---|---|
| Duration | The subscription term, plus the deletion period in the Terms |
| Data Principals | Customer administrators and staff; visitors who request access to restricted documents; people named in content the Customer uploads (for example a DPO or grievance contact) |
| Personal data | Names, work email addresses, organisation names, one-time code verification events, NDA acceptance records, document access logs including IP address and user agent, and any personal data within uploaded documents |
| Purpose | Only to provide the service to the Customer and its visitors as configured by the Customer |
| Location | India, subject to the Sub-processors list |
3.Processing only on instructions
TrustShot processes Customer Personal Data only on the Customer’s documented instructions, which are these Terms, this DPA and the Customer’s configuration of the service. If an instruction appears to breach the DPDP Act, TrustShot will tell the Customer. TrustShot will not sell Customer Personal Data, use it for its own purposes, or combine it with other data except as needed to provide the service.
4.Customer responsibilities
The Customer is responsible for having a lawful basis, giving any notice required under section 5 of the DPDP Act to visitors of its Trust Center, and responding to its Data Principals. The service lets the Customer display its own privacy notice and grievance contact on its Trust Center for this purpose.
5.Personnel
TrustShot limits access to Customer Personal Data to personnel who need it to provide or support the service, who are bound by confidentiality obligations and trained in data protection, and whose access is logged and removed when no longer needed.
6.Security
TrustShot maintains reasonable security safeguards, including the technical and organisational measures described on the Security page, so as to prevent personal data breach as section 8(5) of the DPDP Act requires. It may update those measures provided the overall level of protection is not reduced.
7.Sub-processors
The Customer authorises the sub-processors listed on the Sub-processors page. TrustShot will give at least 30 days’ notice by email before adding or replacing one. The Customer may object on reasonable data protection grounds; if the parties cannot resolve the objection, the Customer may terminate the affected service and receive a refund of prepaid fees for the remaining term. TrustShot imposes data protection terms on each sub-processor no less protective than this DPA, and remains responsible for their performance.
8.Personal data breach
TrustShot will notify the Customer without undue delay, and in any event within 24 hours of becoming aware, of a personal data breach affecting Customer Personal Data. The notice will describe what is known of the nature and extent of the breach, the data and Data Principals affected, its likely consequences, and the measures taken, with further detail as it becomes available.
This is intended to let the Customer meet its own obligations to inform affected Data Principals and the Data Protection Board of India, and, where applicable, to report to CERT-In and its sectoral regulator. TrustShot will cooperate with those reports and will itself report incidents to CERT-In where its directions require.
9.Data Principal requests
If TrustShot receives a request from a Data Principal relating to Customer Personal Data, it will redirect the Data Principal to the Customer and not respond itself unless the Customer authorises it. TrustShot will provide reasonable assistance, including through the service’s export and deletion functions, to help the Customer respond to requests under sections 11 to 14 of the DPDP Act.
10.Return and deletion
On termination, TrustShot will make Customer Personal Data available for export and then delete it within the periods in the Terms, and will confirm deletion in writing on request. For a free trial that is not converted, deletion happens at the end of the notified grace period. Copies TrustShot must keep by law remain protected under this DPA until deleted.
11.Audits and regulators
TrustShot will make available information reasonably necessary to demonstrate compliance with this DPA, including completing a reasonable security questionnaire once a year and sharing current third-party audit reports or certifications, if any, under confidentiality.
Where the Customer is an entity regulated by the Reserve Bank of India, SEBI, IRDAI or another financial sector regulator and its regulator’s outsourcing or IT directions require it, TrustShot will permit the Customer, its auditors, and the regulator to inspect records and systems relevant to the service, on reasonable notice, during business hours, and subject to the confidentiality of other customers’ data.
12.Liability and precedence
Each party’s liability under this DPA is subject to the limitations in the Terms. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails. A countersigned copy is available on request at contact@trustshot.in.