Legal & Compliance
Data Processing Agreement
- Effective date
- 1 April 2020
- Last updated
- 28 July 2026
Data Processing Agreement
How Azmarq processes personal data on behalf of its customers, and the protections that apply.
Draft framework for legal review. This is a summary DPA suitable for publishing as a policy and for incorporation into customer contracts. A full executable DPA with signature blocks and detailed annexes (data categories, security measures, standard contractual clauses) should be prepared with counsel. Not legal advice.
1. Roles
Who does what with the data.
When Azmarq Technovation Pvt. Ltd. ("Azmarq", "Processor") transmits or processes personal data that a customer ("Controller" / "Data Fiduciary") submits or routes through the Services, Azmarq acts as a Data Processor on the Controller's documented instructions. The Controller is responsible for the lawfulness of the data and instructions. This DPA supplements the Terms of Service.
2. Scope and instructions
The basis on which we process.
Azmarq processes personal data only to provide the Services and as instructed by the Controller in the Terms, the applicable order form/MSA, and this DPA, and as required by applicable law. We will inform the Controller if, in our reasonable opinion, an instruction breaches applicable data-protection law.
3. Subject matter, duration, nature, and purpose
What the processing involves.
The processing concerns the transmission and management of business communications and related engagement features (including WhatsApp, RCS, SMS/SMPP, voice, email, CTWA, My CDP, Journeys/Drips, Unified Inbox, commerce flows, and AI Agent Studio as enabled by the Controller); it lasts for the term of the Services; and it covers the categories of data principals and personal data set out in Annex A (typically message recipients and message content/metadata, profile and event data, and agent/AI transcripts provided by the Controller).
4. Confidentiality
Keeping data restricted.
Azmarq ensures that personnel authorised to process personal data are bound by confidentiality and process it only as instructed.
5. Security measures
How we protect the data.
Azmarq maintains a security programme certified to ISO/IEC 27001:2022 and independently assessed under SOC 2 Type II, applying technical and organisational measures including encryption in transit and at rest, access controls, segregation, logging, monitoring, and testing (summarised in Annex B).
6. Sub-processors
Our use of third parties.
The Controller authorises Azmarq to engage sub-processors to provide the Services. Current sub-processors are listed in our Sub-processors page. Azmarq imposes data-protection obligations on sub-processors no less protective than those in this DPA and remains responsible for their performance. We will give notice of intended additions or replacements and a reasonable opportunity to object.
7. Data principal rights and assistance
Helping the Controller meet its obligations.
Taking into account the nature of the processing, Azmarq will provide reasonable assistance to help the Controller respond to data-principal requests and to meet its obligations regarding security, breach notification, and impact assessments.
8. Personal data breach
What happens if data is compromised.
Azmarq will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, with information reasonably available to support the Controller's own notification obligations.
9. Cross-border transfers
Moving data across borders.
Where processing involves transfers across borders, Azmarq applies the transfer mechanisms required by applicable law. Production infrastructure for Indian traffic is hosted in AWS Mumbai to support data localisation.
10. Return and deletion
What happens at the end.
On termination or expiry, Azmarq will, at the Controller's choice and subject to legal retention requirements, delete or return the personal data it processes on the Controller's behalf.
11. Audits
Verifying compliance.
Azmarq will make available information reasonably necessary to demonstrate compliance, including its certifications and audit reports, and will allow for audits subject to reasonable notice, confidentiality, and scope limitations.
12. Annexes
Details to be completed.
- Annex A — categories of data principals and personal data; nature and purpose of processing.
- Annex B — technical and organisational security measures.
- Annex C — approved sub-processors (see Sub-processors page).
Contact: dpo@azmarq.com / legal@azmarq.com.