PineMetric

Data processing agreement

Effective 1 October 2026 · Version 1.0

Draft prepared for PineMetric's first customers. Have it reviewed by a lawyer before taking payments. Customers who need a signed copy can ask [email protected].

This agreement is part of the Terms of service between the Customer and Antara Kar ("PineMetric"). It applies when PineMetric processes personal data on the Customer's behalf.

1. Roles

The Customer is the Data Fiduciary (DPDP Act, 2023) or controller (GDPR) of the personal data it puts into PineMetric. PineMetric is its Data Processor or processor.

2. What is processed

Subject matterProviding PineMetric: storing, validating and comparing invoice data, files, messages, planner content and calls.
DurationThe term of the agreement, plus the deletion period in section 9.
People concernedThe Customer's users; people named in invoices and files (such as suppliers' contacts); anyone the Customer's users write about.
Kinds of dataNames, business contact details, invoice and payment details, messages and files the Customer uploads, usage and sign-in records.
Special categoriesNone are expected. The Customer should not upload them.

3. Instructions

PineMetric processes the data only on the Customer's documented instructions — these terms, and the Customer's use and configuration of the service — unless the law requires otherwise, in which case PineMetric tells the Customer first unless the law forbids it.

4. Confidentiality

Everyone at PineMetric who can reach the data is bound to keep it confidential and reaches it only when needed to run or support the service.

5. Security

PineMetric keeps technical and organisational measures appropriate to the risk, including: HTTPS for all traffic; separation of each organisation's data enforced by the database (row-level security); encrypted off-site backups with a weekly restore test; argon2id password hashing; role-based access within each organisation; rate limiting and account lockout; security updates applied automatically; and access to production restricted to named people using keys.

6. Sub-processors

The Customer authorises the sub-processors listed in the Privacy policy. PineMetric binds each to data-protection terms no weaker than these and stays responsible for them. It announces a new sub-processor at least 30 days ahead; the Customer may object on reasonable data-protection grounds, and if the objection cannot be resolved may end the agreement.

7. International transfers

Where personal data subject to the GDPR is transferred to a country without an adequacy decision, the Standard Contractual Clauses (Module 2 or 3, as applicable) and the UK addendum are incorporated by reference. PineMetric does not transfer data to any country restricted under section 16 of the DPDP Act.

8. Help with requests, breaches and assessments

9. Deletion and return

When the agreement ends, the Customer has 30 days to export its data. After that PineMetric deletes it from the live service within 30 days, and it leaves the backups as they expire (up to 190 days), unless the law requires it to be kept.

10. Audits

PineMetric makes available the information needed to show it meets this agreement, and answers reasonable security questionnaires once a year. Where that is not enough, the Customer may audit, at its own cost, on 30 days' notice, during business hours, through an auditor bound to confidentiality.

11. Order of precedence

If this agreement and the Terms of service conflict on data protection, this agreement wins.