Data Processing Agreement
Standard contractual terms for data processing
1. Introduction
This Data Processing Agreement ("DPA") forms part of the principal agreement between Supersei Technologies Pvt. Ltd. ("Supersei", "we", "us") and the customer entity that has accepted Supersei's Terms of Service or entered into a separate Order Form ("Customer", "you"). Together, Supersei and the Customer are referred to as the "Parties".
This DPA describes the terms under which Supersei processes personal data on behalf of the Customer in connection with the Supersei Growth Engine platform and related services (collectively, the "Services"). It is intended to satisfy the requirements of Article 28 of the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and equivalent data protection legislation in other applicable jurisdictions.
Where there is any conflict between this DPA and the principal agreement with respect to the processing of personal data, the terms of this DPA shall prevail.
2. Scope
This DPA applies whenever Supersei processes personal data that originates from or belongs to the Customer's end users, employees, contacts, or other individuals, and where such processing occurs solely for the purpose of providing the Services to the Customer.
For the avoidance of doubt, this DPA does not apply to:
- Personal data that Supersei processes as a Data Controller in its own right (for example, account registration data, billing contact information, or data processed for Supersei's own analytics and fraud prevention purposes, which is governed by Supersei's Privacy Policy).
- Data that has been fully anonymised such that no individual can be identified, directly or indirectly.
3. Definitions
The following capitalised terms have the meanings set out below. Terms not defined here carry the meaning given to them in the GDPR or the principal agreement.
- Controller
- The natural or legal person, public authority, agency, or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. In the context of this DPA, the Customer acts as the Controller.
- Processor
- A natural or legal person, public authority, agency, or other body which processes personal data on behalf of the Controller. In the context of this DPA, Supersei Technologies Pvt. Ltd. acts as the Processor.
- Sub-processor
- Any Processor engaged by Supersei to carry out specific processing activities on personal data on behalf of the Customer. Sub-processors act under Supersei's instructions and are subject to data protection obligations no less protective than those set out in this DPA.
- Personal Data
- Any information relating to an identified or identifiable natural person ("Data Subject"). An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, or one or more factors specific to the physical, physiological, genetic, mental, economic, cultural, or social identity of that person.
- Processing
- Any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, restriction, erasure, or destruction.
- Data Subject
- An identified or identifiable natural person to whom the personal data relates. In the context of the Services, Data Subjects may include the Customer's end users, employees, prospects, or any other individuals whose data is uploaded to or processed through the Supersei platform.
4. Processing Details
The following describes the key parameters of Supersei's processing of personal data on behalf of the Customer.
4.1 Subject Matter
The provision of AI-powered growth, automation, and analytics Services through the Supersei Growth Engine platform, as more fully described in the applicable Order Form or Terms of Service.
4.2 Duration
Processing commences on the date the Customer first makes personal data available to Supersei (whether by uploading data, connecting integrations, or otherwise) and continues for the duration of the principal agreement, unless earlier termination or data deletion is requested in accordance with Section 10.
4.3 Nature and Purpose of Processing
Personal data is processed for the following purposes:
- Providing, maintaining, and improving the core features of the Supersei Growth Engine platform.
- Executing automated workflows, AI-driven outreach sequences, and marketing automation tasks as configured by the Customer.
- Generating analytics, performance reports, and AI recommendations on behalf of the Customer.
- Facilitating integrations with third-party tools and services as authorised by the Customer.
- Providing customer support and responding to Customer-initiated requests.
4.4 Types of Personal Data
Depending on how the Customer configures and uses the Services, Supersei may process the following categories of personal data:
- Identification data: full name, username, job title, company name.
- Contact data: email address, phone number, mailing address, social media profile URLs.
- Behavioural and engagement data: email open and click events, website visit data, campaign interaction history.
- Commercial data: purchase history, subscription status, deal stage, revenue figures associated with individual contacts.
- Communication content: messages, notes, and other content uploaded or generated within the platform.
- Technical identifiers: IP addresses, device identifiers, cookies, and session data where applicable.
4.5 Categories of Data Subjects
- The Customer's end customers, prospects, and leads.
- The Customer's employees, contractors, and authorised platform users.
- Third-party contacts and partners whose data the Customer uploads into the platform.
5. Obligations of the Processor
Supersei, acting as Processor, commits to the following obligations with respect to personal data processed on behalf of the Customer.
5.1 Processing on Documented Instructions
Supersei will process personal data only on documented instructions from the Customer, as set out in this DPA, the principal agreement, and any configuration settings the Customer establishes within the platform. If Supersei is required by applicable law to process personal data for another purpose, it will inform the Customer of that legal requirement before processing, unless prohibited from doing so by law.
5.2 Confidentiality
Supersei will ensure that all personnel authorised to process personal data on behalf of the Customer are bound by appropriate confidentiality obligations, whether contractual or statutory. Access to personal data is limited to personnel who need such access to perform their job responsibilities in connection with the Services.
5.3 Security Measures (Article 32 GDPR)
Supersei implements appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Full details of these measures are described in Section 8 of this DPA.
5.4 Sub-processor Management
Supersei will not engage a new Sub-processor or materially change the role of an existing Sub-processor without providing prior notice to the Customer in accordance with Section 6. All Sub-processors are subject to written data protection obligations no less protective than those in this DPA.
5.5 Assistance with Data Subject Rights
Taking into account the nature of the processing, Supersei will assist the Customer, by appropriate technical and organisational measures, in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under applicable data protection law. These rights include, but are not limited to, the right of access, rectification, erasure, restriction of processing, data portability, and objection. Customers may submit data subject request assistance queries to legal@supersei.ai.
5.6 Assistance with Controller Obligations
Supersei will assist the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments, and prior consultation), taking into account the nature of the processing and the information available to Supersei.
5.7 Personal Data Breach Notification
In the event that Supersei becomes aware of a confirmed personal data breach affecting Customer data, Supersei will notify the Customer without undue delay and, where feasible, no later than 72 hours after becoming aware of the breach. Notification will include, to the extent then known: a description of the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences of the breach, and the measures taken or proposed to address the breach. Breach notifications shall be sent to the Customer's designated security or privacy contact on record.
5.8 Data Return and Deletion
Upon termination or expiry of the principal agreement, or upon written request by the Customer, Supersei will, at the Customer's election, either return all personal data to the Customer in a commonly used, machine-readable format or securely delete and destroy all copies of personal data in Supersei's possession or control. Deletion will occur within 30 days of the relevant trigger event, except where retention is required by applicable law, in which case Supersei will continue to protect the retained data in accordance with this DPA.
6. Sub-processors
6.1 Authorisation and Notice
The Customer provides a general written authorisation for Supersei to engage Sub-processors. Supersei will maintain an up-to-date list of its current Sub-processors, available on request or published at a designated URL provided to enterprise customers. Supersei will provide at least 30 days' prior written notice before adding a new Sub-processor or making a material change to an existing Sub-processor's role.
6.2 Right to Object
The Customer may object to the addition of a new Sub-processor or a material change to an existing Sub-processor on reasonable data protection grounds by notifying Supersei in writing within 14 days of receiving the notice described above. If the Customer objects and Supersei cannot accommodate the objection through reasonable technical or commercial means, the Customer may terminate the affected Services by providing written notice, without penalty, within 30 days of the objection.
6.3 Current Sub-processor Categories
Supersei currently engages Sub-processors in the following categories. Specific entity names and processing locations are provided in the full Sub-processor list available to enterprise customers on request.
- Cloud infrastructure and hosting: Amazon Web Services (AWS) is used for core infrastructure, compute, storage, and managed database services. Data is stored in AWS regions selected in accordance with the Customer's data residency requirements where applicable.
- Payment processing: Payment gateway and billing providers process payment card and transaction data for the purpose of subscription and invoice management. These providers are PCI DSS compliant. Supersei does not store full payment card numbers on its own systems.
- Communication and messaging APIs: Third-party communication service providers are used to deliver transactional emails, SMS notifications, and in-app messaging as part of the Services or for operational notifications. These providers process only the data necessary to deliver the relevant communication.
- Customer support tooling: Helpdesk and support ticketing platforms that may process limited personal data shared by the Customer or its users in the course of raising support requests.
- Monitoring and observability: Application performance monitoring and error tracking tools that may process technical identifiers and logs in order to maintain the reliability and security of the Services.
7. International Transfers
Where the processing of personal data involves a transfer of personal data to a country outside the European Economic Area ("EEA"), the United Kingdom, or another jurisdiction that has been designated as providing an adequate level of data protection, Supersei will ensure that such transfers are carried out subject to appropriate safeguards in accordance with applicable data protection law.
The primary mechanism for such transfers is the use of the Standard Contractual Clauses ("SCCs") adopted by the European Commission (Commission Implementing Decision (EU) 2021/914), which are hereby incorporated into this DPA by reference. Where the UK GDPR applies, Supersei relies on the UK International Data Transfer Addendum issued by the UK Information Commissioner's Office ("ICO") as an additional or alternative mechanism.
Where Supersei relies on an adequacy decision or another lawful transfer mechanism in place of the SCCs, it will document and be prepared to evidence this upon request. Supersei will conduct or cooperate with the Customer in conducting transfer impact assessments where required by applicable law or requested by the Customer on reasonable grounds.
8. Security Measures
Supersei implements and maintains the following technical and organisational measures designed to ensure a level of security appropriate to the risk presented by the processing of personal data.
8.1 Encryption
- All personal data is encrypted in transit using TLS 1.2 or higher across all public-facing endpoints and internal service communications.
- Personal data at rest is encrypted using AES-256 or equivalent industry-standard encryption within Supersei's storage infrastructure.
- Encryption keys are managed through a dedicated key management service with separation of duties between key custodians and data processors.
8.2 Access Control
- Access to systems processing personal data is governed by a formal access control policy based on the principle of least privilege and role-based access control ("RBAC").
- Multi-factor authentication ("MFA") is enforced for all administrative access to production systems and cloud infrastructure.
- User access rights are reviewed periodically and revoked promptly upon change of role or termination of employment or engagement.
- Privileged access sessions to production environments are logged and subject to audit.
8.3 Monitoring and Incident Detection
- Supersei maintains centralised logging and security information and event management ("SIEM") capabilities to detect and alert on anomalous or potentially malicious activity.
- Automated vulnerability scanning and dependency auditing are performed on a continuous or regular scheduled basis.
- Penetration testing is conducted at least annually by qualified internal or third-party testers, with material findings remediated within agreed timelines.
- A formal incident response plan is maintained and tested periodically to ensure readiness in the event of a security incident or data breach.
8.4 Backup and Recovery
- Customer data is backed up regularly, with backup frequency and retention periods appropriate to the criticality of the data and defined in Supersei's internal data management policy.
- Backups are encrypted and stored in a geographically separate location from the primary data store.
- Backup restoration procedures are tested periodically to verify data integrity and recovery time objectives.
8.5 Organisational Measures
- All Supersei personnel with access to personal data receive mandatory data protection and security awareness training upon onboarding and on an annual basis thereafter.
- Supersei maintains internal data protection policies, a data inventory, and a record of processing activities in accordance with Article 30 of the GDPR.
- A designated data protection point of contact oversees compliance with data protection obligations and is available to handle queries from Customers and regulators.
9. Audit Rights
Supersei will make available to the Customer all information reasonably necessary to demonstrate compliance with the obligations set out in this DPA, and will allow for and contribute to audits, including inspections, conducted by the Customer or a third-party auditor mandated by the Customer.
In the first instance, Supersei will endeavour to satisfy the Customer's audit requirements by providing responses to reasonable information security questionnaires, copies of relevant certifications (such as ISO 27001 or SOC 2 Type II reports where obtained), or summaries of third-party penetration test results.
Where the Customer requires an on-site or more detailed audit beyond the information provided above, the following conditions apply:
- The Customer must provide Supersei with at least 30 days' prior written notice specifying the scope, proposed timing, and the identity of any third-party auditor.
- Audits must be conducted during normal business hours and in a manner that minimises disruption to Supersei's operations and the services provided to other customers.
- Third-party auditors must enter into a confidentiality agreement with Supersei before commencing any audit activities.
- The Customer shall bear the reasonable costs of any audit it initiates, including Supersei's costs of facilitating the audit, unless the audit reveals a material breach of this DPA by Supersei.
- Audits may not be conducted more than once per calendar year, except where required by a supervisory authority or where a material breach of this DPA has been identified.
10. Term and Termination
This DPA is co-terminous with the principal agreement between Supersei and the Customer. It comes into effect on the date personal data is first processed by Supersei on the Customer's behalf and remains in force until the principal agreement expires or is terminated, or until all personal data processed under this DPA has been returned or deleted in accordance with this section.
Upon expiry or termination of the principal agreement, or upon written request by the Customer at any time:
- Supersei will cease all processing of personal data covered by this DPA, except to the extent required by applicable law.
- Within 30 days of the termination date or receipt of the Customer's written request (whichever is earlier), Supersei will, at the Customer's election:
- Return all personal data to the Customer in a structured, commonly used, machine-readable format (such as CSV or JSON); or
- Securely delete and destroy all personal data, including copies held by Sub-processors, and provide the Customer with written confirmation of such deletion.
- Where Supersei is required by applicable law to retain certain personal data beyond the 30-day period, it will notify the Customer of the legal basis and the specific data to be retained, and will continue to protect such data in accordance with this DPA until it is deleted.
The provisions of this DPA that by their nature should survive termination — including obligations of confidentiality, audit rights in relation to the termination period, and data deletion obligations — shall continue in force until fully discharged.
11. How to Execute This DPA
For most customers, the obligations and protections described in this DPA are incorporated by reference into Supersei's standard Terms of Service and are binding on both Parties upon acceptance of those terms.
Enterprise customers who require a separately countersigned DPA — for example, to satisfy internal procurement requirements, satisfy the requirements of a specific regulator, or to agree to supplementary terms — may request a signed agreement as follows:
- Send a request to legal@supersei.ai with the subject line "DPA Execution Request — [Your Company Name]".
- Please include your company's registered name, jurisdiction of incorporation, and any specific requirements or addenda you require (for example, SCCs in a particular module configuration, or a UK Addendum).
- Supersei's legal team will respond within 5 business days with a draft DPA for review. Negotiation and countersignature will follow through Supersei's standard e-signature process.
If you have questions about data protection, this DPA, or Supersei's privacy practices more generally, you may contact us at:
Supersei Technologies Pvt. Ltd.Data Protection Contact
legal@supersei.ai
Supersei reserves the right to update this DPA summary from time to time to reflect changes in applicable law, our Sub-processors, or our security practices. Material changes will be communicated to Customers in advance in accordance with the notice provisions of the principal agreement.