1. Scope & Applicability
This Data Processing Agreement ("DPA") supplements the Werkora Master Services Agreement ("MSA") entered into between Customer ("Data Fiduciary" or "Tenant") and Werkora Technology (Sole Proprietorship of Abhishek Kumar, GSTIN: 09FKRPK3676J1Z9, 50, Block Z, Sector 12, Noida, Gautam Buddha Nagar, Uttar Pradesh - 201301, India, "Data Processor").
This DPA applies to all processing of Personal Data inputted by Customer into the Werkora Manufacturing ERP platform, including data concerning factory employees, shift workers, contractors, customer representatives, and supplier personnel.
2. Processor Obligations (Section 8, DPDPA 2023)
Werkora warrants and undertakes that it shall:
- Process Solely on Instructions: Process Personal Data exclusively on the documented instructions of the Customer to provide the ERP software, and for no other commercial purpose.
- Ensure Confidentiality: Require all personnel authorized to process Customer Data to commit to strict confidentiality obligations and undergo background security verification.
- Technical & Organizational Safeguards: Implement and maintain reasonable security practices to protect Personal Data against unauthorized access, loss, alteration, or disclosure, including AES-256 database encryption at rest, TLS 1.3 encryption in transit, and logical multi-tenant database isolation.
- Subprocessor Oversight: Engage third-party subprocessors only pursuant to Section 4 of this DPA and maintain full liability for subprocessor compliance.
3. Assistance with Data Principal Requests
Taking into account the nature of the processing, Werkora provides self-service features in the application (including data export and member profile correction) to enable Customer to fulfill its statutory obligations to respond to Data Principal requests under Sections 11–13 of the DPDPA. Where self-service tools are insufficient, Werkora shall provide prompt technical assistance upon written request.
4. Authorized Subprocessors
Customer grants Werkora general authorization to engage subprocessors to deliver cloud hosting, database management, and TLS certificates. The list of authorized subprocessors is publicly available on our Subprocessor Register. Werkora shall notify Customer of any planned changes to subprocessors with reasonable advance notice.
5. Personal Data Breach Notification
In the event of a confirmed Personal Data breach affecting Customer Data, Werkora shall:
- Notify Customer without undue delay upon becoming aware of the breach.
- Provide reasonable details regarding the nature of the incident, estimated categories of data involved, and remedial steps taken.
- Assist Customer in fulfilling its mandatory statutory reporting obligations to the Data Protection Board of India (DPBI) and CERT-In.
6. Data Return & Irreversible Deletion
Upon termination or expiration of the Customer subscription:
- Customer is granted a 30-day window to export all tenant records and personal data.
- Following 30 days, Werkora shall initiate automated cryptographic purging of all live database rows, caches, and backups, retaining only records required by mandatory statutory law (such as 8-year tax invoice retention under the Companies Act, 2013).
7. Audit & Verification Rights
Upon reasonable written notice (not more than once per calendar year), Werkora will make available documentation demonstrating compliance with this DPA, including architecture diagrams, access logs, and third-party security assessment certificates.