This Data Processing Addendum ("DPA") forms part of the Terms of Service or other written agreement ("Agreement") between DhyanaTech Inc. and its customers.
1. Definitions
- "Controller" means the Customer who determines the purposes and means of processing Personal Data.
- "Processor" means DhyanaTech Inc., which processes Personal Data on behalf of the Controller.
- "Personal Data" means any information relating to an identified or identifiable individual.
- "Processing" has the meaning given under applicable data protection laws.
2. Roles of the Parties
Customer acts as the Data Controller.
DhyanaTech Inc. acts as the Data Processor.
DhyanaTech processes Personal Data solely for the purpose of providing the services described in the Agreement and in accordance with Customer's documented instructions.
3. Scope of Processing
3.1 Categories of Data
Personal Data processed may include:
- User names, email addresses, and account credentials
- Business contact information
- Operational and transactional records entered by users
- System logs and audit records
- Data transmitted via authorized third-party integrations
3.2 Purpose of Processing
- Providing, operating, and supporting DhyanaTech services
- Authentication and access control
- Communication and notifications
- System monitoring and improvement
3.3 Duration
Processing continues for the duration of the Agreement and any reasonable backup retention period thereafter.
4. Customer Obligations
Customer represents and warrants that:
- It has all necessary rights, permissions, and legal bases to provide Personal Data to DhyanaTech
- It is responsible for compliance with applicable laws relating to Personal Data collected and processed through the services
- It is responsible for the security and lawful use of third-party integrations enabled at its direction
5. Processor Obligations
DhyanaTech shall:
- Process Personal Data only in accordance with this DPA and the Agreement
- Ensure personnel with access to Personal Data are bound by confidentiality obligations
- Implement commercially reasonable technical and organizational safeguards
- Not sell or disclose Personal Data except as required to provide the services or by law
6. Security Measures
DhyanaTech maintains commercially reasonable safeguards, including:
- Encryption of data in transit
- Role-based access controls
- Principle of least privilege
- Secure cloud hosting environments
- Logging and monitoring of system access
DhyanaTech does not guarantee absolute security but commits to industry-standard practices appropriate to its size and stage.
7. Sub-Processors
7.1 Authorization
Customer authorizes DhyanaTech Inc. to engage sub-processors to process Personal Data as necessary to provide the Services.
7.2 Current Sub-Processors
As of the Effective Date, DhyanaTech's sub-processors include, but are not limited to:
- Supabase - database, authentication, storage
- Vercel - application hosting and delivery
- Stripe - payment processing
- SendGrid - transactional email
- Anthropic - AI processing services
- Google Maps - mapping and geolocation services
- GitHub - source code management and CI/CD
7.3 Sub-Processor Changes & Notification
DhyanaTech may add or replace sub-processors from time to time. DhyanaTech will provide notice of any material changes to its sub-processors by email or by updating its website or documentation.
7.4 Objection Rights
Customer may object to a new sub-processor on reasonable data protection grounds by providing written notice within thirty (30) days of receiving notice. If the parties cannot resolve the objection within a reasonable period, Customer may terminate the affected Services without penalty.
8. Customer-Directed Integrations
Where Customer connects third-party services (including but not limited to ADP Workforce Now and QuickBooks Online):
- Customer provides and controls API credentials
- DhyanaTech accesses such data solely to perform the requested integration
- DhyanaTech is not responsible for the security, availability, or compliance of those third-party platforms
9. Data Breach Notification
In the event of a confirmed security incident affecting Personal Data, DhyanaTech shall:
- Notify Customer without undue delay after becoming aware
- Provide information reasonably necessary for Customer to assess impact
- Cooperate in remediation efforts
10. Data Subject Rights Assistance
To the extent required by applicable law, DhyanaTech will reasonably assist Customer in responding to data subject requests, provided such assistance does not require disproportionate effort or violate applicable law.
11. Data Return or Deletion
Upon termination of the Agreement:
- Customer may request export of its data in a reasonable format
- DhyanaTech will delete or anonymize Personal Data within a commercially reasonable period, subject to backup retention policies and legal obligations
12. Audits
Customer may request reasonable information regarding DhyanaTech's data protection practices. On-site audits are not permitted unless required by law or agreed in writing.
13. Limitation of Liability
This DPA does not expand or modify the liability limitations set forth in the Agreement.
14. Governing Law
This DPA shall be governed by the laws specified in the Agreement.
15. Precedence
In the event of a conflict between this DPA and the Agreement, this DPA shall control with respect to data protection matters only.
16. Acceptance
This DPA is effective upon execution of the Agreement or upon Customer's use of the services.
DhyanaTech Inc.
Email: hello@dhyanatech.com
Website: www.dhyanatech.com
