
Data processing agreement
Draft prepared for PineMetric's first customers. Have it reviewed by a lawyer before taking payments. Customers who need a signed copy can ask [email protected].
This agreement is part of the Terms of service between the Customer and Antara Kar ("PineMetric"). It applies when PineMetric processes personal data on the Customer's behalf.
1. Roles
The Customer is the Data Fiduciary (DPDP Act, 2023) or controller (GDPR) of the personal data it puts into PineMetric. PineMetric is its Data Processor or processor.
2. What is processed
| Subject matter | Providing PineMetric: storing, validating and comparing invoice data, files, messages, planner content and calls. |
|---|---|
| Duration | The term of the agreement, plus the deletion period in section 9. |
| People concerned | The Customer's users; people named in invoices and files (such as suppliers' contacts); anyone the Customer's users write about. |
| Kinds of data | Names, business contact details, invoice and payment details, messages and files the Customer uploads, usage and sign-in records. |
| Special categories | None are expected. The Customer should not upload them. |
3. Instructions
PineMetric processes the data only on the Customer's documented instructions — these terms, and the Customer's use and configuration of the service — unless the law requires otherwise, in which case PineMetric tells the Customer first unless the law forbids it.
4. Confidentiality
Everyone at PineMetric who can reach the data is bound to keep it confidential and reaches it only when needed to run or support the service.
5. Security
PineMetric keeps technical and organisational measures appropriate to the risk, including: HTTPS for all traffic; separation of each organisation's data enforced by the database (row-level security); encrypted off-site backups with a weekly restore test; argon2id password hashing; role-based access within each organisation; rate limiting and account lockout; security updates applied automatically; and access to production restricted to named people using keys.
6. Sub-processors
The Customer authorises the sub-processors listed in the Privacy policy. PineMetric binds each to data-protection terms no weaker than these and stays responsible for them. It announces a new sub-processor at least 30 days ahead; the Customer may object on reasonable data-protection grounds, and if the objection cannot be resolved may end the agreement.
7. International transfers
Where personal data subject to the GDPR is transferred to a country without an adequacy decision, the Standard Contractual Clauses (Module 2 or 3, as applicable) and the UK addendum are incorporated by reference. PineMetric does not transfer data to any country restricted under section 16 of the DPDP Act.
8. Help with requests, breaches and assessments
- PineMetric passes on any request from a data principal or data subject it receives about the Customer's data, and helps the Customer answer it.
- PineMetric tells the Customer without undue delay, and in any case within 48 hours of becoming aware, of a personal data breach affecting the Customer's data, with what is known and what is being done, so the Customer can meet its own duties to notify.
- PineMetric gives reasonable help with data protection impact assessments and consultations with authorities.
9. Deletion and return
When the agreement ends, the Customer has 30 days to export its data. After that PineMetric deletes it from the live service within 30 days, and it leaves the backups as they expire (up to 190 days), unless the law requires it to be kept.
10. Audits
PineMetric makes available the information needed to show it meets this agreement, and answers reasonable security questionnaires once a year. Where that is not enough, the Customer may audit, at its own cost, on 30 days' notice, during business hours, through an auditor bound to confidentiality.
11. Order of precedence
If this agreement and the Terms of service conflict on data protection, this agreement wins.