Data Processing Agreement

Last updated: June 2026

Download option: Enterprise customers on Scale or Enterprise plans may request a signed PDF of this DPA for their compliance records. Email [email protected] with subject "DPA Request".

1. Parties and Scope

This Data Processing Agreement ("DPA") is entered into between:

  • Data Controller: The customer organisation using Anverith AI ("you", "Customer").
  • Data Processor: Anverith AI Technologies, Pune, India ("Anverith", "we").

This DPA forms part of the Terms of Service and applies to all personal data processed by Anverith on behalf of the Customer in connection with providing the Anverith AI compliance platform.

2. Categories of Personal Data

Anverith processes the following categories of personal data on behalf of the Customer:

  • Employee names and work email addresses (for user accounts)
  • AI system descriptions and risk classifications
  • Compliance evidence documents (may contain personal data uploaded by Customer)
  • Compliance scores and gap analysis results
  • Audit log entries (user actions within the platform)

Anverith does not knowingly process special categories of personal data (sensitive data under DPDP Act, including health, financial, or biometric data) unless explicitly included by the Customer in uploaded evidence documents.

3. Purpose of Processing

Anverith processes personal data solely to:

  • Provide AI compliance scanning, scoring, and gap analysis services.
  • Generate compliance reports and AI Impact Assessments.
  • Maintain the Evidence Vault and Trust Passport features.
  • Send transactional notifications and alerts.
  • Provide customer support.

Anverith will not process Customer personal data for any other purpose, including training AI models or sharing with third parties for marketing.

4. Data Processor Obligations

Anverith agrees to:

  • Process personal data only on documented Customer instructions.
  • Ensure personnel authorised to process personal data are bound by confidentiality obligations.
  • Implement appropriate technical and organisational security measures (AES-256 encryption, TLS 1.3, PostgreSQL RLS, bcrypt password hashing).
  • Assist the Customer in fulfilling data subject rights requests (access, correction, erasure) within 30 days.
  • Notify the Customer without undue delay (maximum 72 hours) upon becoming aware of a personal data breach.
  • Delete or return all Customer personal data within 30 days of contract termination, subject to legal retention requirements.
  • Make available all information necessary to demonstrate compliance with applicable data protection law.

5. Sub-Processors

Anverith uses the following sub-processors to provide the Service. Customer provides general authorisation for these sub-processors:

Sub-ProcessorPurposeLocationSafeguards
AWS (S3, SES, KMS)File storage, Email, EncryptionIndia (ap-south-1)ISO 27001, SOC 2
Supabase / PostgreSQLDatabaseUS / EUSOC 2, ISO 27001
AnthropicAI report generationUSEnterprise privacy terms
RazorpayPayment processing (INR)IndiaPCI DSS, RBI compliant
StripePayment processing (USD)US / EUPCI DSS, SOC 2
RailwayApplication hostingUSSOC 2
SentryError monitoring (no PII)USSOC 2

Anverith will notify Customers of any intended changes to sub-processors at least 30 days before the change takes effect, providing an opportunity to object.

6. International Data Transfers

Customer data is primarily stored in India (AWS ap-south-1). Some data may be processed in the US by Anthropic (AI processing) and Supabase (database). Anverith ensures appropriate safeguards for international transfers, including Standard Contractual Clauses (SCCs) with sub-processors where required.

7. Security Measures

Anverith maintains the following security measures:

  • Encryption at rest: AES-256 via AWS KMS for all files; bcrypt (12 rounds) for passwords.
  • Encryption in transit: TLS 1.3 enforced for all connections.
  • Access control: PostgreSQL Row-Level Security (RLS) ensuring tenant data isolation. JWT-based authentication with refresh token rotation.
  • Audit logging: Immutable audit log of all user actions.
  • Vulnerability management: Regular dependency audits, security header enforcement.
  • Incident response: 72-hour breach notification commitment.

8. Data Retention and Deletion

Upon termination of the Customer's subscription, Anverith will:

  • Delete all Customer personal data from active systems within 30 days.
  • Delete backup copies within 90 days.
  • Retain audit logs for 7 years as required by applicable law (accessible only to Anverith compliance team).
  • Retain payment records for 8 years as required by Indian GST law.

Customers may request earlier deletion by contacting [email protected].

9. Governing Law

This DPA is governed by the laws of India, including the Digital Personal Data Protection Act 2023 and the Information Technology Act 2000. For EU customers, this DPA also incorporates the requirements of GDPR Article 28.

10. Contact

For DPA-related queries, contact our Data Protection Officer at [email protected].