Skip to content

Data Processing Addendum

How Eleserv Softech Pvt Ltd processes personal data on your behalf as your processor.

Last updated 30 September 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the Customer (controller / data fiduciary) and Eleserv Softech Pvt Ltd (processor) for Customer360. It applies whenever we process personal data of the Customer's website visitors or leads.

1. Scope and instructions

  • Subject matter: analytics, consent logging, visitor intelligence, engagement and lead handling for the Customer's websites.
  • Duration: the term of the subscription plus the deletion period below.
  • Data subjects: visitors of the Customer's websites and people who submit forms or leads.
  • Data categories: pseudonymous identifiers, browsing and event data, device data, approximate location, consent choices, and contact details voluntarily submitted.
  • We process personal data only on the Customer's documented instructions: the Service configuration counts as such instructions: unless the law requires otherwise, in which case we will tell the Customer where permitted.

2. Our obligations

  • People with access are bound by confidentiality and access is limited by role.
  • We maintain appropriate technical and organisational measures, including encryption in transit and of sensitive fields at rest, tenant isolation, two-factor authentication for staff, rate limiting, backups and audit logging.
  • We assist the Customer, taking into account the nature of the processing, with data-subject requests (including per-visitor deletion in the dashboard), security, breach notification and impact assessments.
  • We notify the Customer without undue delay (and in any case within 72 hours) after becoming aware of a personal data breach affecting its data.
  • Data stays in the region the Customer selected (India, EU or US) or in the Customer's own database.

3. Sub-processors

The Customer authorises us to use sub-processors for hosting, databases and email delivery, and: only if the Customer switches on AI summaries: an AI provider (Anthropic) that receives aggregate statistics without personal data, under written terms at least as protective as this DPA. We will give notice of new sub-processors in the Service or by email, and the Customer may object on reasonable data-protection grounds. Integrations the Customer enables (for example advertising or CRM tools) are the Customer's own recipients, not our sub-processors.

4. International transfers

Where data is transferred across borders, we rely on a lawful transfer mechanism (for example the EU Standard Contractual Clauses for EU personal data), and follow any restriction notified by the Government of India under the DPDP Act.

5. Audits

On reasonable written request, and no more than once a year unless required by a regulator or after a breach, we will provide information necessary to demonstrate compliance with this DPA, including security documentation.

6. Deletion and return

Raw analytics are deleted automatically after the plan's retention period. At the end of the subscription the Customer can export its reports; we then delete the Customer's personal data within 90 days, except consent records kept as legal proof and records we must keep by law.

7. Customer responsibilities

The Customer is responsible for the lawfulness of the processing it instructs, including providing notices, obtaining valid consent, configuring the consent banner for its audience and not sending sensitive personal data.

Contact

Questions about these documents or your data: use the contact option inside your workspace.