Data Processing Addendum
Forms part of the Enterprise Agreement. Records how AtoZAIx processes personal data on behalf of an institution under the Digital Personal Data Protection Act, 2023 and, where it applies, the GDPR.
Why this document exists separately
In a consumer purchase, AtoZAIx decides why and how a learner data is processed. In an institutional deployment that decision belongs to the institution: it chooses who is enrolled, what is uploaded and what the platform is used for. AtoZAIx then acts on the institution instructions. This addendum records that reversal of roles and the obligations that follow from it.
1. Scope & Roles
This addendum applies where AtoZAIx PRIVATE LIMITED processes personal data on behalf of a Customer under a signed Order Form incorporating the Enterprise Agreement. Terms defined there have the same meaning here.
| Category of data | Customer role | AtoZAIx role |
|---|---|---|
| Learner and administrator personal data submitted through the Customer account | Data Fiduciary (DPDP) / Controller (GDPR) | Data Processor |
| Billing and contract contact details of the Customer organisation | Controller | Independent Controller |
| Security logs, abuse signals and aggregated service telemetry | Not applicable | Independent Controller, for legitimate security and service-integrity purposes |
Where an individual signs up directly rather than through the Customer account, that individual relationship is governed by the consumer Privacy Policy and this addendum does not apply to it.
2. Processing Instructions
AtoZAIx processes Customer personal data only on the documented instructions of the Customer. The Enterprise Agreement, this addendum and the Customer configuration of the Service together constitute those instructions.
AtoZAIx may process outside those instructions only where required by law, in which case it will inform the Customer of that requirement before processing, unless the law prohibits it from doing so. If AtoZAIx forms the view that an instruction infringes applicable data protection law, it will inform the Customer without undue delay and may suspend that processing.
Personnel authorised to process Customer personal data are bound by confidentiality obligations that survive the end of their engagement, and are granted access only to the extent their role requires.
3. Nature of the Processing
| Element | Particulars |
|---|---|
| Subject matter | Provision of the AtoZAIx AI learning platform to the Customer Authorised Users. |
| Duration | The Subscription Term, plus the export and deletion windows in clause 11. |
| Nature and purpose | Account provisioning and authentication; generation of personalised courses, explanations and assessments; retrieval over documents the user uploads; progress tracking and reporting; support; billing; security and abuse prevention. |
| Categories of Data Principal | Learners including, where the Customer enrols them, children under 18; teachers, trainers and administrators; Customer billing and procurement contacts. |
| Categories of personal data | Identity and contact data (name, email address); authentication data (hashed credentials, session tokens); learning profile and preferences; usage and progress records; prompts, questions and chat transcripts; the content of documents an Authorised User uploads; assessment attempts and scores; device, browser and IP data captured in security logs; billing contact and transaction records. |
| Special or sensitive data | Not requested by the Service and not required for it to function. The Customer must not configure the Service to collect health, biometric, caste, religious or similar categories, and must instruct its Authorised Users not to include them in uploads or prompts. |
| Automated decision-making | The Service adapts learning content to a learner profile. It does not produce decisions with legal or similarly significant effects. Any grading, progression or certification decision is made by the Customer, on human review. |
4. Customer Duties
The Customer warrants and undertakes that it will:
- Establish and maintain a lawful basis for the processing it instructs, and give each Data Principal the notice required by section 5 of the DPDP Act, in clear and plain language, before enrolment.
- Obtain and record any consent required, including the verifiable parental consent addressed in clause 5.
- Enrol only individuals it is entitled to enrol, and deprovision them promptly when the relationship ends.
- Keep the personal data it submits accurate and limited to what the purpose requires.
- Not submit special or sensitive categories of personal data, and not use the Service for any purpose the notice given to Data Principals does not cover.
- Respond, as Data Fiduciary, to requests and complaints from its own Data Principals, using the tools AtoZAIx provides.
5. Children Under 18
The obligation sits with the Customer
The DPDP Act treats every individual under eighteen as a child. Before a child personal data may be processed, verifiable consent must be obtained from a parent or lawful guardian, and tracking, behavioural monitoring and targeted advertising directed at children are prohibited.
AtoZAIx does not operate a parental consent mechanism and does not verify the age of an Authorised User. Where the Customer enrols a Learner under 18, obtaining, recording and being able to evidence that verifiable consent is the Customer responsibility, and must be completed before access is granted. The Customer must retain those records for the Subscription Term and for as long afterwards as the law requires, and must produce them to AtoZAIx or to a regulator on request.
On its side, AtoZAIx undertakes that it will:
- Not serve advertising within the Service, to any user.
- Not build behavioural or advertising profiles of Learners, and not sell or share Customer personal data for advertising.
- Restrict processing of Learner data to delivering, securing and supporting the learning service the Customer has purchased.
- Provide the Customer, on request, the information it needs to complete its own consent notices and any data protection impact assessment.
6. Security Measures
AtoZAIx implements and maintains technical and organisational measures appropriate to the risk presented by the processing. The measures currently in place include:
| Control area | Measure |
|---|---|
| Tenant isolation | Row-level security enforced in the database, so a row is reachable only by the account that owns it. Privileged operations run through defined, audited server-side functions rather than direct table access. |
| Encryption | TLS for all data in transit. Encryption at rest for the primary database, object storage and backups, provided by the underlying cloud platform. |
| Authentication | Authorisation Code flow with PKCE, server-issued session tokens, and configurable session lifetime. Passwords are stored only as salted hashes by the identity provider. |
| Authorisation | Entitlements and usage quotas are evaluated server-side and cannot be altered from the client. Administrative access is limited to named personnel on a least-privilege basis. |
| Application hardening | Content Security Policy, input validation on server boundaries, bot verification on public forms, and validation of uploaded files by extension, declared MIME type and file signature. |
| Availability | Managed platform backups with point-in-time recovery, and rate controls that protect shared capacity from a single account. |
| Monitoring | Application error monitoring and request logging, retained for a limited period and used for security and reliability purposes only. |
| Change management | Version-controlled deployments, code review before merge, and an automated test suite executed on every change. |
AtoZAIx may update these measures over time, provided the level of protection is not materially reduced. A current description is available under confidentiality on request.
7. Breach Notification
On becoming aware of a personal data breach affecting Customer personal data, AtoZAIx will notify the Customer without undue delay and in any event within forty-eight hours of confirming the breach. The notification will describe, so far as then known, the nature of the breach, the categories and approximate number of Data Principals and records affected, the likely consequences, and the measures taken or proposed.
AtoZAIx will provide the assistance the Customer reasonably requires to meet its own duties to notify the Data Protection Board of India and affected Data Principals, and will cooperate with any reporting required under the CERT-In Directions of 28 April 2022, including the six-hour reporting requirement for reportable cyber incidents affecting AtoZAIx own systems.
Notification is not, of itself, an admission of fault or liability.
8. Sub-processors
The Customer gives general authorisation for AtoZAIx to engage the sub-processors listed below. Each is engaged under a written contract imposing data protection obligations no less protective than those in this addendum, and AtoZAIx remains fully liable to the Customer for their performance.
| Sub-processor | Function | Data processed | Primary location |
|---|---|---|---|
| Supabase Inc. | Primary database, authentication, object storage and serverless functions | All Customer personal data held at rest | India (Mumbai region) |
| Google LLC | Gemini models for generation, embeddings and speech synthesis | Prompts, chat context and the text of uploaded documents, in transit at the time of the request | Global |
| Vercel Inc. | Web hosting, edge routing and serverless API endpoints | Request metadata, IP address, and form submissions such as enterprise enquiries | Global edge network |
| Railway Corp. | Gateway route in front of the AI request path | Prompt payloads in transit | United States |
| Cashfree Payments India Private Limited | Payment processing and invoicing | Billing contact details and transaction records. Card and bank credentials are entered directly with the gateway and are never received or stored by AtoZAIx. | India |
| Cloudflare, Inc. | Bot verification on public forms | IP address and a challenge token | Global |
| Resend (Plus Five Five, Inc.) | Transactional email such as receipts and account notices | Recipient email address and message content | United States |
| Functional Software, Inc. (Sentry) | Application error monitoring, where enabled | Error diagnostics and a pseudonymous user identifier | United States |
| Google LLC (Analytics) | Aggregate product analytics on the public website | Pseudonymous usage events and truncated IP address | Global |
| NewsData.io | Ingestion of public news content for the news feature | No Customer personal data is transmitted; requests are outbound topic queries only | Global |
| Google LLC (Fonts) | Delivery of web fonts used by the interface | IP address and browser user agent, transmitted by the browser when a font is fetched | Global |
AtoZAIx will give the Customer at least thirty days notice before adding or replacing a sub-processor that will process Customer personal data. Where the Customer has a reasonable, documented data protection objection, it may raise it within that period, and the parties will discuss it in good faith. If no resolution is reached and AtoZAIx proceeds, the Customer may terminate the affected subscription and receive a pro-rated refund of prepaid fees for the unexpired term.
Notice of changes is sent to the data protection contact stated in the Order Form. Customers may subscribe to change notices by writing to support@atozaix.com.
9. International Transfers
Customer personal data is held at rest in India. Certain processing necessarily involves transfer outside India, in particular the transmission of a prompt and its context to a model provider at the moment a request is made, and the operation of a global edge network and transactional email.
Those transfers are made in reliance on section 16 of the DPDP Act, which permits transfer to any country other than one the Central Government has restricted by notification. AtoZAIx will monitor such notifications and, if a listed sub-processor location is restricted, will migrate the affected processing or notify the Customer so it can decide whether to continue.
Where the GDPR applies to a transfer, AtoZAIx relies on the European Commission Standard Contractual Clauses, which are incorporated into this addendum by reference and, where the UK Addendum applies, on the UK International Data Transfer Addendum. Module Two applies where the Customer is a controller and AtoZAIx a processor.
10. Data Principal Rights
The Customer, as Data Fiduciary, is responsible for responding to requests from its Data Principals. AtoZAIx will assist by:
- Providing self-service access, correction and export tools within the Service.
- Passing on to the Customer, without undue delay, any request AtoZAIx receives directly from one of the Customer Data Principals, rather than responding to it itself.
- Providing reasonable technical assistance where a request cannot be satisfied through the self-service tools, taking into account the nature of the processing and the information available to AtoZAIx.
- Effecting erasure or correction on the Customer documented instruction.
Assistance beyond what is reasonable, or requested with disproportionate frequency, may be chargeable at the AtoZAIx then-current professional services rate, on prior written notice.
11. Retention & Deletion
- Customer personal data is retained for the Subscription Term and made available for export for thirty days after it ends.
- AtoZAIx deletes Customer personal data from production systems within thirty days after the export window closes, or earlier on the Customer written instruction.
- Data present in routine encrypted backups is removed as those backups age out of the rotation, and remains subject to this addendum until it does.
- Security and audit logs are retained for a limited period proportionate to their purpose, and are not used for any other purpose.
- AtoZAIx may retain records required by tax, accounting, fraud-prevention or limitation law, for no longer than the prescribed period, and will keep them protected and segregated from active processing.
- A written certificate of deletion is provided on request.
12. Audit & Assurance
AtoZAIx will make available the information reasonably necessary to demonstrate compliance with this addendum, ordinarily by responding to a security questionnaire and providing its current description of technical and organisational measures.
Where that is insufficient to satisfy a specific regulatory obligation, the Customer may audit, or appoint an independent auditor bound by confidentiality to audit, on at least thirty days written notice, during business hours, no more than once in any twelve-month period, and in a manner that does not compromise the confidentiality or security of other customers. The Customer bears the cost of the audit unless it reveals a material breach of this addendum. An additional audit may be conducted following a confirmed personal data breach.
13. AI Processing & No Training
Customer data is not used to train models
AtoZAIx does not use Customer personal data or Customer Data to train, fine-tune or evaluate artificial intelligence models, and contracts with its model providers on paid API terms under which submitted content is not used to improve or train their models.
Prompts, conversation context and the extracted text of uploaded documents are transmitted to the model provider for the sole purpose of generating a response to that request. Where the Service caches generated content to reduce cost and latency, personalised or user-identifying content is excluded from any shared cache.
Documents an Authorised User uploads are processed into text segments and numerical embeddings that are stored against that user account, so the material can be retrieved in later sessions. Those segments and embeddings are Customer personal data and are covered by the retention and deletion terms in clause 11.
14. Grievance & Contact
Questions, requests and complaints about the processing of personal data may be raised with the AtoZAIx Grievance Officer at support@atozaix.com, marked for the attention of the Grievance Officer.
| Stage | Commitment |
|---|---|
| Acknowledgement | Within 24 hours of receipt, as required by Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. |
| Disposal of the complaint | Within 15 days of receipt, under the same Rule. |
| Data Principal requests received directly | Passed to the Customer as Data Fiduciary without undue delay, under clause 10, rather than answered by AtoZAIx. |
| Escalation | A Data Principal who is not satisfied may complain to the Data Protection Board of India under section 13(3) of the DPDP Act, after first raising the matter with the Data Fiduciary. |
Notices under this addendum and under the Enterprise Agreement are sent to the same address, and to the Customer data protection contact recorded in the Order Form.
15. Liability & Precedence
The limitations and exclusions of liability in the Enterprise Agreement apply to this addendum and to any claim arising from it, to the extent permitted by applicable data protection law.
Where this addendum conflicts with the Enterprise Agreement on the subject of personal data, this addendum prevails. Where an incorporated set of Standard Contractual Clauses conflicts with this addendum, those clauses prevail to the extent of the conflict.
Data protection enquiries, including requests for a signed copy of this addendum, should be addressed to support@atozaix.com.
The Enterprise Agreement Set
Enterprise Agreement
Master commercial terms
Data Processing Addendum
You are reading this document
Service Level Agreement
Uptime, support, credits
For a signed contract, a security questionnaire, or a redlined copy of these documents, write to support@atozaix.com.