Standard DPA · Indian DPDP Act & GDPR

Data Processing Agreement

This Data Processing Agreement (“DPA”) forms an integral part of the Master Services Agreement between Cartigram LLP and Subscriber.

1. Scope & Roles

Under applicable data protection laws (including the Indian DPDP Act 2023 and EU GDPR), the Subscriber acts as the Data Fiduciary / Data Controller, and Omnia acts as the Data Processor / Data Processor. Omnia processes personal data solely on documented instructions from the Subscriber.

2. Technical & Organizational Measures (TOMs)

  • Encryption: AES-256 encryption at rest for all database volumes and object storage; TLS 1.3 encryption in transit.
  • Access Control: Granular Role-Based Access Control (RBAC) and mandatory MFA enforcement options.
  • Isolation: Logical PostgreSQL schema isolation preventing cross-tenant data access.
  • Resilience: Continuous WAL replication, daily snapshots, and RPO < 1 hour disaster recovery.

3. Authorized Subprocessor Schedule

SubprocessorRoleLocation
Amazon Web Services (AWS)Cloud Infrastructure & DatabasesMumbai, India (ap-south-1)
Razorpay PaymentsSubscription Payment ProcessingIndia
Resend / AWS SESTransactional Email & OTP AlertsIndia & Global

4. Breach Notification Protocol

In the unlikely event of a confirmed security incident impacting customer personal data, Omnia shall notify the affected Subscriber without undue delay and within 24 hours of discovery, providing details of the incident and mitigation measures taken.