Data Processing Agreement
The terms on which Sammati processes personal data on your behalf as your Data Processor under India’s Digital Personal Data Protection Act, 2023.
Version v1.0-draft · Last updated 19 July 2026
1. Parties, roles and scope
This Data Processing Agreement ("DPA") forms part of the agreement between the customer identified in the order form ("Customer", the Data Fiduciary) and Arborworld India Private Limited ("Sammati", the Data Processor) under which Sammati provides the Sammati consent and privacy platform (the "Service").
Under the Digital Personal Data Protection Act, 2023 ("DPDP Act") the Customer determines the purposes and means of processing Personal Data and is the Data Fiduciary. Sammati processes Personal Data only on the Customer’s documented instructions and is the Data Processor. Where the Customer is itself a processor for a third party, Sammati acts as sub-processor and these terms flow down accordingly.
If any term of this DPA conflicts with the main agreement in respect of the processing of Personal Data, this DPA prevails.
2. Definitions
"Personal Data", "Data Principal", "Data Fiduciary", "Data Processor", "processing" and "Personal Data Breach" have the meanings given in the DPDP Act. "Applicable Data Protection Law" means the DPDP Act, the DPDP Rules, 2025, and any other data protection law applicable to the processing.
"Customer Personal Data" means Personal Data that Sammati processes on the Customer’s behalf under the Service, as described in Annex A.
3. Processing on documented instructions
Sammati processes Customer Personal Data only to provide and support the Service and on the Customer’s documented instructions, including as set out in this DPA, the main agreement, and the Customer’s configuration of the Service. Sammati will not process Customer Personal Data for its own purposes.
Sammati will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law, and may suspend performance of an instruction that it reasonably believes to be unlawful until the Customer confirms or amends it.
Sammati will not sell Customer Personal Data and will not use it to train third-party AI models.
4. Nature of processing and purpose limitation
The subject matter, duration, nature and purpose of processing, the types of Personal Data and the categories of Data Principals are described in Annex A (Details of Processing).
The Service records and manages consent artifacts on a tamper-evident, hash-chained ledger. Consent artifacts are immutable once written; Sammati does not alter recorded consent records except to append new events as instructed.
5. Confidentiality
Sammati ensures that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and are granted access on a least-privilege, need-to-know basis.
6. Security safeguards
Sammati implements and maintains appropriate technical and organisational measures to protect Customer Personal Data, taking into account the state of the art and the risk to Data Principals. Current measures include those summarised in Annex B (Security Measures).
These measures include encryption of Personal Data in transit and at rest, envelope encryption of sensitive fields under managed keys (with optional customer-managed keys), strict tenant isolation enforced at the database layer, and masking of Personal Data (such as phone numbers and email addresses) in application logs.
7. Sub-processors
The Customer authorises Sammati to engage the sub-processors listed at sammati.io/legal/subprocessors to process Customer Personal Data. That list, as updated from time to time, is incorporated into this DPA by reference.
Sammati imposes data-protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible to the Customer for each sub-processor’s performance. Before adding or replacing a sub-processor that processes Personal Data, Sammati will update the published list and, for customers who have subscribed to notifications, provide advance notice. The Customer may object to a new sub-processor on reasonable data-protection grounds as set out in the main agreement.
8. Assistance with Data Principal rights
Taking into account the nature of the processing, Sammati provides the Customer with the functionality and reasonable assistance necessary to respond to Data Principal requests to access, correct, complete, update or erase their Personal Data, to withdraw consent, and to raise grievances, as required by the DPDP Act.
If a Data Principal contacts Sammati directly regarding Customer Personal Data, Sammati will, unless legally prohibited, refer the request to the Customer rather than responding directly.
9. Personal Data Breach notification
Sammati notifies the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provides information reasonably available to it to help the Customer meet its own notification obligations to the Data Protection Board of India and affected Data Principals under the DPDP Act and DPDP Rules.
Sammati’s notification is not an acknowledgement of fault or liability.
10. Return and deletion
On expiry or termination of the Service, and at the Customer’s choice, Sammati returns or deletes Customer Personal Data within [30] days, save to the extent retention is required by law. The Customer may also export its data and trigger erasure through the Service during the term.
Where consent-ledger records must be retained to preserve the integrity of the audit chain or to meet a legal obligation, Sammati retains only the minimum records necessary for the minimum period required and confirms the basis to the Customer.
11. Audits and information
Sammati makes available to the Customer information reasonably necessary to demonstrate compliance with this DPA, including relevant certifications and third-party reports where available. On reasonable prior notice, and no more than [once per year] absent a Personal Data Breach or regulatory requirement, the Customer may audit Sammati’s processing, subject to confidentiality and to reasonable limits that protect other customers and Sammati’s security.
12. International transfers
Customer Personal Data is hosted in India (AWS Asia Pacific, Mumbai, ap-south-1). Certain sub-processors listed at sammati.io/legal/subprocessors may process limited data outside India (for example, AI inference and email delivery). Any such transfer is carried out consistently with the DPDP Act and any restrictions notified by the Central Government, and subject to appropriate safeguards.
13. Liability and governing law
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the main agreement.
This DPA is governed by the laws of India and subject to the jurisdiction of the courts at [City], India.
- Subject matter
- Provision of the Sammati consent and privacy platform to the Customer.
- Duration
- For the term of the main agreement, plus any return/deletion period in § 10.
- Nature and purpose
- Collecting, recording, storing and managing consent and preference data; generating notices; supporting Data Principal rights; audit logging on a hash-chained ledger.
- Categories of Data Principals
- The Customer’s end users / customers, and, where applicable and lawfully permitted, minors under verified parental consent.
- Types of Personal Data
- Identifiers and contact details (e.g. name, phone, email), consent and preference records, notice interactions, and metadata such as timestamps and IP address. The Customer must not submit special categories of data except as supported and configured.
- Encryption in transit (TLS) and at rest; envelope encryption of sensitive fields under managed keys, with optional customer-managed KMS keys (BYOK).
- Tenant isolation enforced at the database layer; every query is scoped to a tenant identifier.
- PII masking in logs, phone numbers and email addresses are masked in all application log output.
- Immutable, hash-chained consent ledger; each entry is chained to the previous by cryptographic hash to make tampering evident.
- Least-privilege access controls, secret management, and network controls (WAF, DDoS mitigation) at the edge.
- Continuous monitoring, alerting, and tested backup / point-in-time recovery.
The current list of authorised sub-processors is published and maintained at sammati.io/legal/subprocessors and is incorporated into this DPA by reference (§ 7).
Ready to sign?
Request a countersigned copy of this DPA for your compliance records, or review who processes your data first.