Data Processing Agreement
Version 1.0 · Effective 16 August 2026 · Last updated 16 August 2026
1. Parties and scope#
This Data Processing Agreement ("DPA") is entered into between:
(1) Rudra Parmar, a sole proprietor carrying on business under the trade name "Praxida", of 307A, Sai Shangrila, Sulabh Nagar Road, Killa Pardi, Valsad, Gujarat 396125, India ("Praxida", the "Processor"); and
(2) The subscribing firm identified in the applicable subscription or order ("Firm", the "Data Fiduciary").
This DPA forms part of and is subject to the Praxida Terms of Service (the "Agreement"). It governs Praxida's processing of Personal Data on behalf of the Firm in the course of providing the Service.
In the event of conflict between this DPA and the Agreement in relation to the processing of Personal Data, this DPA prevails.
2. Definitions#
Terms used but not defined here have the meaning given in the Agreement or in the Digital Personal Data Protection Act, 2023.
"Applicable Data Protection Law" means the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, the Information Technology Act, 2000 and rules made thereunder, and any other data protection law applicable to the processing.
"Client Personal Data" means Personal Data relating to the Firm's End Clients and their personnel that the Firm, its Authorised Users, or its Portal Users enter into or upload to the Service.
"Data Fiduciary", "Data Processor", "Data Principal", and "Personal Data Breach" have the meanings given under the DPDP Act.
"Processing" means any operation performed on Personal Data, including collection, storage, use, retrieval, disclosure, erasure, and destruction.
"Sub-processor" means a third party engaged by Praxida to process Client Personal Data.
3. Roles of the parties#
3.1 The Firm is the Data Fiduciary in respect of Client Personal Data. The Firm determines the purposes and means of processing, decides what data is recorded in the Service, and is responsible for the lawfulness of that processing.
3.2 Praxida is the Data Processor in respect of Client Personal Data, processing it solely on the Firm's behalf and in accordance with this DPA.
3.3 Praxida acts as Data Fiduciary in respect of data about the Firm and its Authorised Users themselves — account details, billing information, support correspondence, and technical usage data — which is governed by the Praxida Privacy Policy and not by this DPA.
3.4 Nothing in this DPA makes Praxida a Data Fiduciary in respect of Client Personal Data, and Praxida does not determine the purposes of its processing.
4. Firm obligations and warranties#
The Firm warrants and undertakes that:
4.1 it has a valid lawful basis under Applicable Data Protection Law — consent or a legitimate use — for all Client Personal Data it processes through the Service, and has given all notices required of a Data Fiduciary;
4.2 it has the authority to disclose Client Personal Data to Praxida and to instruct the processing described in this DPA;
4.3 its instructions to Praxida will not cause Praxida to breach Applicable Data Protection Law;
4.4 it will not enter into the Service any Personal Data beyond what is necessary for the purposes described in Annexure A, and in particular will not upload categories of data outside the scope of the Service without prior written agreement;
4.5 it is responsible for configuring roles, permissions, and portal access appropriately, for reviewing them periodically, and for revoking access promptly when a user's entitlement ends. Praxida provides access controls; the Firm determines who may access what;
4.6 it will maintain the confidentiality of credentials issued to its Authorised Users and Portal Users;
4.7 where it processes the Personal Data of a child or a person with a disability having a lawful guardian, it has obtained verifiable consent as required under the DPDP Act; and
4.8 it will respond to Data Principal requests concerning Client Personal Data as the Data Fiduciary, with Praxida's assistance under clause 9.
5. Praxida's processing obligations#
5.1 Documented instructions. Praxida will process Client Personal Data only:
(a) as necessary to provide, maintain, secure, and support the Service under the Agreement; (b) in accordance with the Firm's documented instructions, of which the Agreement, this DPA, and use of the Service's features constitute the initial and complete set; and (c) where required by law, in which case Praxida will notify the Firm before processing unless legally prohibited from doing so.
5.2 If Praxida considers an instruction to breach Applicable Data Protection Law, it will inform the Firm without undue delay and may suspend performance of that instruction.
5.3 Purpose limitation. Praxida will not process Client Personal Data for its own purposes. Specifically, Praxida will not:
(a) sell, rent, licence, or otherwise disclose Client Personal Data to any third party except as permitted by clause 7; (b) use Client Personal Data to train, fine-tune, or evaluate any artificial intelligence or machine learning model; (c) use Client Personal Data for advertising, marketing, profiling, or benchmarking; (d) disclose Client Personal Data to any other Firm or subscriber; or (e) retain Client Personal Data beyond the periods in clause 11.
5.4 Aggregated data. Praxida may generate aggregated, de-identified statistics about use of the Service, provided such statistics cannot reasonably be used to identify the Firm, any End Client, or any individual, and are not derived from the content of documents.
6. Confidentiality and personnel#
6.1 Praxida will treat Client Personal Data as confidential and will not disclose it except as permitted by this DPA.
6.2 Access by Praxida personnel is restricted to individuals who require it to perform their role, are bound by written confidentiality obligations surviving termination of their engagement, and have been made aware of the confidential nature of the data.
6.3 Support access. Praxida personnel do not routinely access Client Personal Data. Access occurs only with the Firm's request or consent for support purposes, where necessary to investigate a security incident or suspected breach of the Agreement, or where required by law. Administrative access events are logged.
6.4 Praxida acknowledges that Client Personal Data may be subject to professional confidentiality obligations binding on the Firm, including under the rules of the Institute of Chartered Accountants of India, and will handle it accordingly.
7. Sub-processors#
7.1 The Firm gives general authorisation to Praxida's engagement of Sub-processors, subject to this clause.
7.2 The Sub-processors engaged as at the effective date are listed in Annexure C.
7.3 Praxida will impose on each Sub-processor written obligations no less protective than those in this DPA, and remains fully liable to the Firm for each Sub-processor's performance.
7.4 Changes. Praxida will give the Firm at least 15 days' notice before engaging a new Sub-processor that will process Client Personal Data, by email to the registered account address and by updating the published list.
7.5 Objection. The Firm may object on reasonable data-protection grounds within the notice period. The parties will discuss in good faith. If no resolution is reached, the Firm may terminate the affected subscription without penalty and receive a pro-rata refund of prepaid fees for the unused term.
8. Security#
8.1 Praxida will implement and maintain reasonable security safeguards appropriate to the nature, scope, and risk of the processing, as described in Annexure B.
8.2 Praxida will review and, where appropriate, update those safeguards. Praxida may modify a safeguard provided the overall level of protection is not materially reduced.
8.3 The Firm has reviewed the safeguards in Annexure B and considers them appropriate to the Client Personal Data it processes through the Service, taking account of the state of the art and the cost of implementation.
8.4 Firm-side responsibility. Security of the Firm's own devices, networks, email accounts, and credentials is the Firm's responsibility. Praxida is not responsible for unauthorised access arising from compromised Firm credentials, misconfigured permissions set by the Firm, or access granted by the Firm to a person not entitled to it.
9. Assistance with Data Principal rights#
9.1 The Service provides functionality enabling the Firm to access, correct, export, and delete Client Personal Data. The Firm should use that functionality in the first instance to respond to Data Principal requests.
9.2 Where a request cannot be fulfilled through the Service, Praxida will provide reasonable assistance on written request, taking into account the nature of the processing.
9.3 If Praxida receives a request from a Data Principal relating to Client Personal Data, it will not respond substantively. It will acknowledge receipt, inform the individual that the Firm is the Data Fiduciary, and forward the request to the Firm without undue delay.
9.4 Assistance under this clause is provided without charge for reasonable requests. Praxida may charge for assistance requiring significant manual effort, on prior notice.
10. Personal Data Breach#
10.1 Praxida will notify the Firm without undue delay, and in any event within 24 hours, of becoming aware of a Personal Data Breach affecting Client Personal Data.
10.2 The notification will describe, to the extent known: the nature and extent of the breach, the categories and approximate number of Data Principals and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where full information is not immediately available, Praxida will provide it in phases without undue further delay.
10.3 Praxida will provide reasonable assistance to enable the Firm to discharge its own obligations as Data Fiduciary, including intimating affected Data Principals and reporting to the Data Protection Board of India within the timelines prescribed by the DPDP Rules.
10.4 Praxida will take reasonable steps to contain, investigate, and remediate the breach, and will maintain a record of it.
10.5 Praxida will not make any public statement identifying the Firm in connection with a breach without the Firm's prior written consent, unless required by law.
10.6 Notification under this clause is not an admission of fault or liability by either party.
11. Retention, return, and deletion#
11.1 Praxida will retain Client Personal Data for the duration of the Firm's subscription.
11.2 Export. For 30 days following termination or expiry, Praxida will, on the Firm's written request, provide an export of Client Personal Data in a commonly used machine-readable format.
11.3 Deletion. After that period, Praxida will delete Client Personal Data from active systems. During the beta period Praxida operates no independent backups (see Annexure B), so no residual copy persists once data is removed from active systems.
11.4 Praxida may retain Client Personal Data where required by law, or where reasonably necessary to establish, exercise, or defend legal claims. Retained data remains subject to clauses 5, 6, and 8.
11.5 On written request, Praxida will confirm deletion.
12. Location of processing and transfers#
12.1 Client Personal Data is stored at rest in India (Mumbai region).
12.2 Certain Sub-processors listed in Annexure C operate infrastructure or corporate entities outside India, and limited processing — principally application hosting, request routing, and email delivery — occurs outside India as described in that Annexure.
12.3 Praxida will not transfer Client Personal Data to any country in respect of which such transfer has been restricted by the Central Government under the DPDP Act, and will comply with any conditions notified in respect of cross-border transfer.
12.4 Where a Sub-processor is located outside India, Praxida will ensure contractual protections requiring a level of protection consistent with this DPA.
13. Records, audit, and information#
13.1 Praxida will maintain records of its processing of Client Personal Data sufficient to demonstrate compliance with this DPA.
13.2 On reasonable written request, and not more than once in any twelve-month period except following a Personal Data Breach, Praxida will provide information reasonably necessary to demonstrate compliance, including a description of its security safeguards and any third-party assessment reports it holds.
13.3 Where the information provided is not sufficient to demonstrate compliance, the Firm may request an audit. Any audit will be: on at least 30 days' written notice; during business hours; conducted so as to minimise disruption; subject to confidentiality obligations; and at the Firm's cost, save where the audit reveals material non-compliance by Praxida.
13.4 Praxida may require that an audit be conducted by an independent third-party auditor, subject to reasonable objection to the identity of that auditor.
13.5 Audit rights do not extend to any data, systems, or premises relating to another subscriber, and Praxida will not permit access that would compromise the confidentiality of any other subscriber's data.
14. Liability#
14.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, including the aggregate liability cap.
14.2 Nothing in this DPA limits either party's direct statutory liability to a Data Principal or to the Data Protection Board of India under Applicable Data Protection Law.
14.3 The Firm indemnifies Praxida against any claim, penalty, or loss arising from the Firm's breach of clause 4, including any claim that Client Personal Data was processed without a valid lawful basis.
15. Term, changes, and general#
15.1 This DPA takes effect on the effective date and continues for as long as Praxida processes Client Personal Data on the Firm's behalf. Clauses 6, 11, 12, 13, and 14 survive termination.
15.2 Praxida may update this DPA where necessary to reflect changes in Applicable Data Protection Law, a change of Sub-processor, or a material change to the Service. Material changes will be notified at least 15 days in advance. Changes will not materially reduce the protections afforded to Client Personal Data.
15.3 If any provision is held invalid or unenforceable, it will be modified to the minimum extent necessary or severed, and the remainder continues in force.
15.4 This DPA is governed by the laws of India, and disputes are subject to the dispute resolution and jurisdiction provisions of the Agreement.
Annexure A — Details of Processing#
Subject matter. Provision of the Praxida practice management platform to the Firm.
Duration. The term of the Firm's subscription, plus the retention periods in clause 11.
Nature of processing. Collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure to authorised users, transmission, erasure, and destruction — by automated means, for the purpose of providing the Service.
Purpose. Enabling the Firm to manage its professional practice: tracking statutory compliance obligations and deadlines, managing tasks and workflow, storing and sharing documents, operating a restricted client portal, recording digital signature certificate custody, and managing fees, invoices, and receivables.
Categories of Data Principals.
- The Firm's End Clients, where the End Client is an individual
- Directors, partners, proprietors, authorised signatories, and personnel of the Firm's End Clients
- Portal Users granted access on behalf of an End Client
Categories of Personal Data. As determined by the Firm, which may include:
- Name, contact details, address
- Tax and business identifiers such as PAN, GSTIN, CIN, TAN
- Compliance registration details, filing history, and status records
- Contents of documents uploaded by the Firm or by Portal Users, which may include financial statements, bank statements, invoices, tax notices, and correspondence
- Task records, notes, comments, and workflow history
- Fee, invoice, receipt, and outstanding balance records
- Digital signature certificate custody records — holder identity, custody movements, expiry dates
Special categories. The Service is not designed for, and the Firm should not enter, data revealing health, biometric, or genetic information, or data relating to children. Praxida does not store any digital signature private key or signing credential.
Frequency. Continuous, for the duration of the subscription.
Annexure B — Security Safeguards#
Access control
- Row-level security policies enforcing tenant isolation at the database layer, so that a Firm cannot access another Firm's data through the interface or through direct API calls
- Role-based permissions enforced within the database rather than only in the application interface
- Portal Users restricted to a single End Client's records, and to content explicitly marked visible
- Least-privilege administrative access, restricted to authorised personnel
- Credentials stored as salted hashes by the authentication provider and not readable by Praxida
Encryption
- TLS for all data in transit
- Encryption at rest for the database and document storage
Application and infrastructure
- Private document storage, served only through authenticated and authorisation-checked requests
- Rate limiting on publicly reachable endpoints
- Server-side credentials held as environment secrets, never exposed to client code
- Scheduled job endpoints protected by bearer-token authentication
Monitoring and assurance
- Logging of authentication events and material data changes
- Automated test suite verifying database-level isolation policies, executed before deployment of changes affecting data access
Resilience
During the beta period Praxida operates no independent restorable backups of the platform database, and cannot restore Client Personal Data that is lost, corrupted, or deleted. The Controller remains responsible for retaining its own copies of source records and must not rely on the Service as a sole system of record. Praxida will implement daily backups with a defined retention period before the Service is offered on a general-availability basis, and will amend this Annexure and notify the Controller when it does.
Certifications. Praxida does not currently hold ISO 27001, SOC 2, or equivalent third-party certification. Praxida's principal infrastructure provider maintains SOC 2 Type II and ISO 27001 certification for the underlying platform; that certification covers the provider's platform and does not extend to Praxida's application.
Annexure C — Approved Sub-processors#
| Sub-processor | Purpose | Personal Data processed | Location |
|---|---|---|---|
| Supabase | Database, authentication, object storage | All Client Personal Data | Data at rest in India (Mumbai, ap-south-1); provider entity outside India |
| Vercel | Application hosting, content delivery, serverless execution | Data in transit; technical and request logs | Global edge infrastructure; provider in the United States |
| Resend | Transactional and reminder email delivery | Recipient email addresses and message content | United States |
Signature block#
(For use where the DPA is executed as a standalone document. Omit where incorporated by reference into the Terms of Service.)
For Rudra Parmar (Processor)
Name: ______________________ Designation: ______________________ Date: ______________________ Signature: ______________________
For the Firm (Data Fiduciary)
Firm name: ______________________ Name: ______________________ Designation: ______________________ Date: ______________________ Signature: ______________________