Standard DPA · Indian DPDP Act & GDPR
Data Processing Agreement
This Data Processing Agreement (“DPA”) forms an integral part of the Master Services Agreement between Cartigram LLP and Subscriber.
1. Scope & Roles
Under applicable data protection laws (including the Indian DPDP Act 2023 and EU GDPR), the Subscriber acts as the Data Fiduciary / Data Controller, and Omnia acts as the Data Processor / Data Processor. Omnia processes personal data solely on documented instructions from the Subscriber.
2. Technical & Organizational Measures (TOMs)
- Encryption: AES-256 encryption at rest for all database volumes and object storage; TLS 1.3 encryption in transit.
- Access Control: Granular Role-Based Access Control (RBAC) and mandatory MFA enforcement options.
- Isolation: Logical PostgreSQL schema isolation preventing cross-tenant data access.
- Resilience: Continuous WAL replication, daily snapshots, and RPO < 1 hour disaster recovery.
3. Authorized Subprocessor Schedule
| Subprocessor | Role | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud Infrastructure & Databases | Mumbai, India (ap-south-1) |
| Razorpay Payments | Subscription Payment Processing | India |
| Resend / AWS SES | Transactional Email & OTP Alerts | India & Global |
4. Breach Notification Protocol
In the unlikely event of a confirmed security incident impacting customer personal data, Omnia shall notify the affected Subscriber without undue delay and within 24 hours of discovery, providing details of the incident and mitigation measures taken.