Traiq Tech's commitment to processing personal data lawfully, securely, and in accordance with GDPR, India's DPDPA, and applicable international standards.
This Data Processing Agreement ("DPA") forms part of the Master Subscription Agreement or Order Form between Traiq Tech Private Limited ("Processor") and the Customer ("Controller"). This DPA governs the processing of personal data by Traiq Tech on behalf of the Customer in connection with the enterprise ERP platform and associated services.
The Customer, as data controller, determines the purposes and means of processing personal data entered into or managed through the Traiq Tech platform. Traiq Tech, as data processor, processes such data only on documented instructions from the Customer and in accordance with this DPA, the Terms of Service, and applicable data protection legislation including the EU General Data Protection Regulation (GDPR), the UK GDPR, India's Digital Personal Data Protection Act 2023 (DPDPA), and other applicable privacy laws.
Where Traiq Tech processes data for its own operational purposes (such as security monitoring, platform analytics, or billing administration) independently of Customer instructions, it acts as a data controller for such processing and its Privacy Policy applies. Such independent processing does not involve Customer content.
The subject matter, nature, purpose, and categories of personal data processed under this DPA are specified in Schedule 1 (Processing Details) appended to each Customer's Order Form. Enterprise customers may request a pre-populated Schedule 1 reflecting their specific deployment configuration from their account manager or from dpa@traiq-tech.com.
Traiq Tech processes personal data of EEA, UK, and Swiss data subjects in compliance with GDPR (EU 2016/679), UK GDPR, and the Swiss Federal Act on Data Protection. Our processing controls are designed to satisfy the accountability and transparency requirements of GDPR Chapter IV, including records of processing activities (RoPA), data protection impact assessments (DPIAs) for high-risk processing, and privacy-by-design and by-default principles embedded in our platform architecture.
We facilitate Customer compliance with GDPR by providing: (a) configurable data subject access request (DSAR) workflows; (b) automated data deletion and anonymization tools; (c) audit logs suitable for accountability demonstration; (d) consent management integrations; (e) configurable retention policies; and (f) data residency controls for EEA data within EU-based AWS regions.
International transfers of EEA personal data from the EEA to India are conducted under EU Standard Contractual Clauses (SCCs) — specifically, the 2021 Module 2 (controller-to-processor) SCCs as issued by the European Commission. Transfer Impact Assessments (TIAs) are maintained for all such transfers and are available to enterprise customers upon request. Supplementary measures include end-to-end encryption, access controls, and technical and organizational measures described in Schedule 2.
Enterprise customers subject to GDPR may request a copy of our Records of Processing Activities (RoPA) related to their deployment, a copy of executed SCCs, and our most recent DPIA template for common deployment scenarios. These documents are provided under NDA and are available from dpa@traiq-tech.com.
Aligned with GDPR
Our platform is designed to support Customer GDPR compliance. EEA data transfers use 2021 EU SCCs. DPIAs, RoPA, and TIA documentation are available to enterprise customers on request.
Traiq Tech implements and maintains technical and organizational security measures appropriate to the risk of processing personal data, as required by Article 32 GDPR and equivalent provisions in applicable laws. These measures are documented in Schedule 2 (Technical and Organizational Measures, or TOMs) of the DPA and include encryption at rest (AES-256) and in transit (TLS 1.2+), strict access controls with MFA enforcement, network segmentation, vulnerability management, and 24/7 security monitoring.
Our security program undergoes regular internal audits and periodic third-party assessments. We maintain operational controls aligned with ISO 27001 principles and SOC 2-style practices. Security assessment reports (executive summaries) are made available to enterprise customers under NDA upon written request. We commit to notifying the Customer without undue delay if we become aware of any security incident affecting personal data processed under this DPA.
Data isolation between customers is enforced at both the logical and cryptographic level. Each tenant environment uses separate encryption key hierarchies managed via AWS KMS with HSM backing. Production access by Traiq Tech personnel requires dual-approval authorization, is logged with full audit trails, and is subject to quarterly access reviews. No Traiq Tech employee has standing access to production Customer data.
Platform penetration testing is conducted at least annually by qualified third-party security firms. Customers may also request permission to conduct their own penetration tests against their tenant environment under a formal written authorization agreement. Unauthorized security testing of the platform is prohibited and may result in access suspension.
Personal data processed under this DPA may be transferred to and processed in countries outside the Customer's home jurisdiction. Traiq Tech's primary infrastructure operates in AWS regions: ap-south-1 (Mumbai, India), eu-west-1 (Dublin, Ireland), and ap-southeast-1 (Singapore). Customers may elect a primary data region at onboarding, and data residency boundaries are contractually enforced.
For transfers of EEA personal data to India (Traiq Tech's headquarters), we rely on EU Standard Contractual Clauses (2021 Modules 2 and 3 as applicable). For transfers to Singapore and other APAC jurisdictions, we apply the ASEAN Model Contractual Clauses as supplementary contractual safeguards. For UK data transfers post-Brexit, we apply the UK International Data Transfer Agreement (IDTA).
All transfer mechanisms are accompanied by documented Transfer Impact Assessments (TIAs) evaluating the legal landscape in the destination country. Where TIAs identify elevated risk, supplementary technical measures (such as additional encryption layers, access restriction, or pseudonymization) are applied. TIAs are reviewed annually and upon changes in applicable law.
Traiq Tech engages sub-processors to deliver specific components of the Services. All sub-processors are bound by data processing agreements that impose obligations at least as stringent as this DPA. The current list of authorized sub-processors is maintained at traiq-tech.com/dpa/subprocessors and includes the following primary entities: Amazon Web Services, Inc. (cloud infrastructure — Ireland, Mumbai, Singapore); Stripe, Inc. (payment processing — US/EU); Twilio Inc. / SendGrid (transactional communications — US); Datadog, Inc. (infrastructure monitoring — EU); and Intercom, Inc. (customer support — EU/US).
Traiq Tech will provide at least 30 days' advance written notice to enterprise customers before engaging a new sub-processor or materially changing an existing sub-processor's role. Notice will be sent to the security/privacy contact designated in the Customer's account settings and via the compliance notification feed in the admin console. Enterprise customers may object to a new sub-processor by submitting written notice to dpa@traiq-tech.com within 30 days of notification.
If a Customer objects to a new sub-processor and Traiq Tech cannot reasonably accommodate the objection (such as by providing an alternative sub-processor or restricting the relevant processing), the Customer may terminate the affected Services with a pro-rated refund of prepaid fees for the remaining subscription period. This remedy constitutes the Customer's sole remedy for objection to sub-processor changes absent a specific DPA provision.
In the event that Traiq Tech becomes aware of a personal data breach affecting Customer data processed under this DPA, Traiq Tech will notify the Customer without undue delay — and in any event within 72 hours of confirming the breach — to the extent this is technically and operationally feasible. Initial notifications will be sent to the Customer's designated security/privacy contact via the administrative console and via email.
Breach notifications will include, to the extent known at the time: (a) a description of the nature of the breach, including categories and approximate number of data subjects and records affected; (b) the name and contact details of Traiq Tech's data protection point of contact; (c) the likely consequences of the breach; and (d) measures taken or proposed to address the breach and mitigate its possible adverse effects.
Traiq Tech will cooperate fully with the Customer in any breach investigation and will provide additional information as it becomes available. We will also assist the Customer in meeting their own breach notification obligations to supervisory authorities and affected data subjects where required by GDPR (Article 33-34) or DPDPA. The Customer remains responsible for notifying data subjects and regulators in accordance with applicable law.
Traiq Tech maintains a formal Incident Response Plan with defined escalation paths, investigation playbooks, and communication templates. All security incidents are logged, tracked, and reviewed by the Security team for root cause analysis and remediation. Post-incident reports are shared with affected enterprise customers following closure of the incident.
72-hour notification commitment
We commit to notifying enterprise customers of confirmed personal data breaches within 72 hours of discovery, as required by GDPR Article 33. Notification goes to your designated security contact in the admin console.
Traiq Tech personnel who have access to personal data processed under this DPA are bound by confidentiality obligations — either through their employment contracts or through explicit confidentiality agreements — that survive the termination of their engagement with Traiq Tech. Personnel access to Customer data is granted only to the extent necessary to perform their roles in delivering the Services.
Traiq Tech maintains confidentiality of Customer data and will not disclose Customer data to third parties except: (a) as required to deliver the Services with authorized sub-processors; (b) as required by applicable law, court order, or government authority (subject to notification of the Customer to the extent legally permissible); or (c) with the Customer's express written consent.
Where Traiq Tech receives a compelled disclosure request from a government authority, law enforcement, or court, we will: (a) notify the Customer promptly if legally permitted to do so; (b) cooperate with any Customer efforts to seek a protective order or other legal remedy; and (c) disclose only the minimum data required to comply with the legal obligation.
Enterprise customers subject to GDPR or other regulatory audit obligations have the right to audit Traiq Tech's compliance with this DPA, subject to reasonable notice and procedural requirements. Audits are conducted at most once per calendar year, unless a confirmed security incident requires more frequent assessment. Customers must provide at least 30 days' advance written notice and agree to Traiq Tech's standard audit engagement terms, including confidentiality obligations and reasonable cost allocation.
As an alternative to direct customer audits, Traiq Tech will make available third-party audit reports, certifications, and security assessment summaries to satisfy Customer and regulatory audit requirements. Available documentation includes: ISO 27001-aligned audit summaries; SOC 2-style operational assessment reports; penetration test executive summaries; and platform security questionnaire responses (aligned with CSA CAIQ, SIG Lite, and other standard vendor assessment frameworks).
Customers may also submit written security questionnaires (including standard frameworks such as SIG Core, CAIQ, VSAQ, or custom enterprise security questionnaires) to security@traiq-tech.com. We commit to providing substantive responses within 20 business days. Questionnaire responses are provided under mutual NDA and may not be shared externally without Traiq Tech's written consent.
Upon termination or expiration of the subscription or this DPA, Traiq Tech will, at the Customer's election: (a) return all Customer personal data in a standard, machine-readable format (JSON or CSV export); or (b) securely delete all Customer personal data from production systems, backups, and archives. The Customer has 90 days from the effective termination date to request export or to specify their preferred deletion approach.
Deletion is performed using cryptographic erasure (destruction of encryption keys) for data at rest, making encrypted data irrecoverable, supplemented by logical deletion from all database records and application caches. Backup media is rotated and overwritten according to our backup retention schedule, with all backups containing Customer data purged within 90 days of the deletion request.
Following completion of the deletion process, Traiq Tech will provide the Customer with a written Certificate of Deletion confirming that all Customer personal data has been deleted or rendered irrecoverable. This certificate will specify the deletion methods used, the data categories covered, and the date of completion. Retention of data beyond this period is permissible only where required by applicable law, in which case the Customer will be notified of the applicable legal basis and retention period.
Enterprise customers may request in-term deletion of specific data categories (e.g., deletion of archived user records from former employees) via the administrative console's Data Management module or by submitting a formal deletion request to dpa@traiq-tech.com. Targeted deletion requests will be processed within 30 days.
Traiq Tech is built from the ground up for enterprise security and compliance requirements. Our controls are designed to help your organization meet GDPR, DPDPA, and sector-specific regulatory obligations.
Have questions about our security posture? Our team responds within one business day.