Legal
Data Processing Agreement
Version 1.2 · Effective 10 September 2026 · Version 1.0 reviewed by counsel 7 September 2026
This agreement governs personal data that CivicLayer Technologies Private Limited processes as a Data Processor on behalf of a Customer through the ConsentOS platform. It is incorporated into the ConsentOS Terms of Service. Its framework is the Digital Personal Data Protection Act 2023 ("the Act") and the Digital Personal Data Protection Rules 2025 ("the Rules").
Parties
Processor: CivicLayer Technologies Private Limited, a company incorporated in India under the Companies Act 2013, CIN U62011HR2026PTC146035, registered at H40/8A, Upper Ground Floor, DLF Phase 1, DLF QE, Gurgaon 122002, Haryana, India ("CivicLayer", "we"). CivicLayer operates the ConsentOS platform.
Data Fiduciary: the customer identified in the Order Form or subscription record ("Customer", "you"). The Customer determines the purpose and means of the processing carried out through ConsentOS and is the Data Fiduciary for that processing under Section 2(i) of the Act.
Relationship. CivicLayer acts as a Data Processor under Section 2(k) of the Act for all personal data the Customer or the Customer's data principals submit to the ConsentOS platform. CivicLayer is a separate and independent Data Fiduciary for its own business records, which include the Customer's account, billing, and support data. Those records are governed by the CivicLayer Privacy Policy, not by this agreement.
Order of precedence. This agreement is incorporated into the ConsentOS Terms of Service. Where a term of this agreement conflicts with the Terms of Service on the subject of personal data processing, this agreement governs.
1. Definitions
1.1 "Personal data", "data principal", "Data Fiduciary", "Data Processor", "personal data breach", "Consent Manager", and "Significant Data Fiduciary" carry the meanings given in Section 2 of the Act.
1.2 "Customer Personal Data" means personal data that the Customer, the Customer's users, or the Customer's data principals submit to or generate within the ConsentOS platform, and that CivicLayer processes on the Customer's behalf. It does not include CivicLayer's own account, billing, and support records.
1.3 "Board" means the Data Protection Board of India constituted under Chapter V of the Act.
1.4 "Sub-processor" means a third party engaged by CivicLayer to process Customer Personal Data in the course of providing the ConsentOS platform.
1.5 "Documented Instructions" means the instructions in this agreement, in the Terms of Service, in the Order Form, and in any written instruction the Customer issues through the support channel named in Clause 12.
2. Processing Only on Documented Instructions
2.1 CivicLayer processes Customer Personal Data only on the Customer's Documented Instructions, and only to provide, maintain, secure, and support the ConsentOS platform. This agreement together with the Terms of Service is the "valid contract" required by Section 8(2) of the Act, under which the Customer as Data Fiduciary engages CivicLayer as Data Processor.
2.2 CivicLayer does not determine the purpose of processing Customer Personal Data. CivicLayer does not use Customer Personal Data for its own marketing, for advertising, for resale, or for training any machine learning model.
2.3 The Customer warrants that it has a lawful basis under the Act for each processing activity it directs, that it has given the notice required by Section 5, and that it holds valid consent or another lawful ground under Section 7 where one is required. CivicLayer processes on the Customer's direction and does not verify the Customer's lawful basis.
2.4 Where CivicLayer forms the view that a Documented Instruction would breach the Act or the Rules, CivicLayer notifies the Customer and may pause the affected processing until the instruction is withdrawn or corrected.
2.5 Section 8(1) of the Act leaves the Customer responsible for compliance in respect of processing carried out on its behalf, including processing by CivicLayer. Nothing in this agreement transfers that responsibility to CivicLayer.
3. Confidentiality
3.1 CivicLayer treats Customer Personal Data as confidential information. It is disclosed only to CivicLayer personnel and sub-processors who need it to perform the obligations in this agreement.
3.2 Every person authorised to access Customer Personal Data is bound by a written confidentiality obligation that survives the end of their engagement.
3.3 CivicLayer discloses Customer Personal Data to a public authority only where compelled by law. Where CivicLayer is legally permitted to do so, it notifies the Customer before disclosing, and where prior notice is barred, as soon as the bar lifts.
4. Security Safeguards
4.1 CivicLayer maintains reasonable security safeguards to prevent a personal data breach, as required by Section 8(5) of the Act and specified in Rule 6 of the Rules. Rule 6 becomes enforceable on 13 May 2027. CivicLayer operates to it now.
4.2 The safeguards CivicLayer maintains are:
(a) Encryption and masking. Customer Personal Data is encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256.
(b) Access control. Access to Customer Personal Data is restricted to authorised personnel and is scoped per tenant. Platform access is authenticated, and tenant isolation is enforced at the database row level.
(c) Logs and monitoring. Processing events that form part of the consent record and the audit tables are retained in the platform database for at least one year, the period Rule 6(1)(e) prescribes. Operational application logs are held by the log sink named in Clause 5.2 for its configured retention period, which is shorter, and they carry no personal data by design.
(d) Backups and continuity. Customer Personal Data is backed up daily. Backups are retained for 14 days on the database host in the hosting region stated in Clause 5.2, and CivicLayer tests restoration from backup at least once a year and records the result.
(e) Contractual measures with sub-processors. Each sub-processor is engaged under terms that carry security and confidentiality obligations of the standard set out in this Clause 4.
4.3 CivicLayer reviews these safeguards at least annually and on any material change to the platform architecture.
4.4 No transmission over a public network is entirely secure. Clause 4 states the controls CivicLayer maintains, not a guarantee of a particular outcome.
5. Sub-processors
5.1 The Customer authorises CivicLayer to engage the sub-processors listed in Clause 5.2 for the purposes stated against each.
5.2 Sub-processor list as at 7 September 2026:
| Sub-processor | Entity and Location | Purpose | Customer Personal Data Received |
|---|---|---|---|
| HubSpot | HubSpot Inc., United States | CRM and system of record for account and lead contacts | Name, business email, phone, company name, inquiry content |
| Resend | Resend Inc., United States | Transactional and opted-in email delivery | Recipient name and email address, message content, sent-message logs |
| Razorpay | Razorpay Software Private Limited, India | Subscription and implementation fee payments | Name, email, phone, payment instrument details collected by Razorpay directly. CivicLayer receives payment references only |
| Cloudflare (hosting and CDN) | Cloudflare Inc., United States | Website and application hosting, CDN, Workers runtime | Request log data, platform data in transit |
| Cloudflare (Email Routing) | Cloudflare Inc., United States | Inbound mail routing for consentos.in mailboxes | Any content a data principal or Customer sends to a consentos.in address |
| Database and application hosting (self-hosted Supabase) | Oracle Cloud Infrastructure, Asia Pacific (Mumbai) region, India. Verified against Oracle's published IP ranges on 8 September 2026. | Platform database, authentication, and storage | All Customer Personal Data held in the platform |
| Destination mailbox host | Mailbox provider that receives mail forwarded by Cloudflare Email Routing; named in the sub-processor register before the first Order Form is signed | Receipt and storage of inbound mail to consentos.in addresses | Any content a data principal or Customer sends to a consentos.in address |
| Better Stack (log sink) | Better Stack; data location as published by the provider and recorded in the sub-processor register | Application log ingestion and uptime monitoring | Operational log lines (no personal data by design), monitor results |
5.3 The register of record for this list is the sub-processor register published at consentos.in/privacy/#dpa. Where that register and this list diverge, the register is corrected first and this agreement is reissued.
5.4 Change process. CivicLayer gives the Customer at least 30 days' written notice before adding a new sub-processor or replacing an existing one. Notice is sent to the Customer's designated contact and published at https://consentos.in/privacy/#dpa.
5.5 The Customer may object to a new sub-processor within the notice period on reasonable data protection grounds. CivicLayer will work with the Customer to find an alternative. Where no alternative is available, the Customer may terminate the affected subscription without penalty and receive a pro-rated refund of prepaid fees for the unused term.
5.6 CivicLayer remains liable to the Customer for the acts and omissions of its sub-processors in respect of Customer Personal Data, subject to Clause 11.
6. Personal Data Breach
6.1 On becoming aware of a personal data breach affecting Customer Personal Data, CivicLayer notifies the Customer without delay. The notification states what CivicLayer knows at the time: the nature and extent of the breach, the categories and approximate volume of personal data affected, the timing and circumstances, the measures taken, and the contact point for further information.
6.2 CivicLayer provides the Customer with the information and assistance the Customer needs to discharge its own obligations under Rule 7 of the Rules, which are:
- (a) to intimate each affected data principal without delay, in a concise and plain-language form, describing the breach, its likely consequences, the mitigation measures taken, the safety measures the data principal may take, and the contact point for queries; and
- (b) to intimate the Board without delay with a description of the breach, and then to give the Board the detailed particulars Rule 7 specifies within 72 hours of becoming aware of the breach, or within a longer period the Board allows on a written request.
6.3 Rule 7 attaches to any personal data breach. It sets no risk threshold and no severity filter. Neither party may withhold intimation on the ground that it has assessed the breach as low risk.
6.4 Rule 7 becomes enforceable on 13 May 2027. The obligations in this Clause 6 are contractual and apply from the effective date of this agreement, so that both parties operate to the Rule 7 standard through the preparation window.
6.5 Where the incident is also a reportable cyber security incident, the CERT-In Directions of 28 April 2022 require reporting within six hours of noticing the incident. That obligation is in force today. CivicLayer reports incidents affecting its own infrastructure and gives the Customer the information the Customer needs for any report of its own.
6.6 CivicLayer does not notify the Board or the Customer's data principals on the Customer's behalf unless the Customer instructs it to do so in writing. The intimation obligations under Rule 7 sit with the Customer as Data Fiduciary.
7. Assistance with Data Principal Rights
7.1 CivicLayer provides platform functionality and reasonable operational assistance so the Customer can respond to a data principal exercising a right under Chapter III of the Act:
- (a) Section 11, the right to access information about the personal data being processed, the processing activities, and the identities of other Data Fiduciaries and processors with whom the data has been shared;
- (b) Section 12, the right to correction, completion, updating, and erasure of personal data, subject to the retention carve-out in Section 8(7) where retention is required for a legal purpose;
- (c) Section 13, the right of grievance redressal, including a response within the period the Rules prescribe; and
- (d) Section 14, the right to nominate another individual to exercise these rights on the data principal's behalf.
7.2 Where a data principal contacts CivicLayer directly about Customer Personal Data, CivicLayer does not respond on the merits. It redirects the data principal to the Customer and informs the Customer without delay.
7.3 Assistance under this Clause is included in the subscription. Where a request calls for engineering work beyond the platform's standard rights functionality, CivicLayer will quote that work before starting it.
8. Audits and Evidence
8.1 CivicLayer makes available the information reasonably needed to demonstrate compliance with this agreement. That information consists of the current security documentation, the sub-processor register, the log retention configuration, and a written response to the Customer's due diligence questionnaire.
8.2 The Customer may request one audit in any 12-month period, on 30 days' written notice, conducted remotely during business hours, and subject to confidentiality terms. An audit may not extend to CivicLayer's other customers' data or to CivicLayer's own business records.
8.3 Where a regulator or the Board directs an inspection that covers Customer Personal Data, CivicLayer cooperates and informs the Customer where it is legally permitted to do so.
8.4 The Customer bears the cost of an audit it initiates, unless the audit finds a material breach of this agreement by CivicLayer.
9. Cross-border Transfers
9.1 Several sub-processors listed in Clause 5.2 are incorporated outside India, so Customer Personal Data is transferred outside India in the course of providing the platform.
9.2 The statutory cross-border regime under Section 16 of the Act and Rule 15 of the Rules commences on 13 May 2027. It is not in force at the date of this agreement. Nothing in this agreement should be read as stating that these transfers are authorised under Section 16 today. The accurate position is that transfers are currently permitted by default, that the safeguards are contractual, and that the statutory regime commences on 13 May 2027.
9.3 Under Section 16(1) the Central Government may, by notification, restrict transfers to specified countries. No such notification has been issued at the date of this agreement. CivicLayer monitors for notifications and will inform the Customer if one affects a sub-processor in Clause 5.2.
9.4 Each cross-border sub-processor is engaged under a data processing agreement carrying contractual transfer safeguards. Adding a sub-processor that receives Customer Personal Data outside India requires a written transfer safeguard note before the transfer starts, recorded in the sub-processor register published at consentos.in/privacy/#dpa.
9.5 Sectoral law may impose a stricter localisation requirement than the Act. Where the Customer is subject to a requirement of that kind, including an RBI directive on payment data storage, the Customer states it in writing before onboarding so that the deployment can be scoped to it.
10. Return and Deletion
10.1 The Customer may export Customer Personal Data at any point during the subscription and for 90 days after termination or account closure takes effect. This matches the export window in the Terms of Service, Section 7.
10.2 CivicLayer retains Customer Personal Data for that 90-day window for the sole purpose of servicing an export request.
10.3 After the 90-day window ends, CivicLayer deletes Customer Personal Data on the retention schedule stated in the Privacy Policy, except where retention for a longer period is required by law. Where a legal retention requirement applies, CivicLayer retains only what the law requires, for only as long as the law requires it, and the rest of this Clause continues to apply to everything else.
10.4 Deletion extends to sub-processor systems. Backup copies are deleted on the backup rotation cycle rather than on demand. The copy on the database host is retained for 14 days and an encrypted offsite copy in India is retained for 35 days, so a deleted record persists in backups for at most 35 days.
10.5 On written request, CivicLayer confirms deletion in writing.
11. Liability
11.1 Each party's liability under this agreement is subject to the limitations and exclusions in Section 8 of the ConsentOS Terms of Service. This agreement does not raise, lower, or create a separate cap.
11.2 Nothing in this agreement limits a liability that cannot be limited under Indian law.
11.3 A financial penalty imposed on a party by the Board under the Schedule to the Act is borne by the party whose act or omission gave rise to it.
12. Notices, Governing Law, and Jurisdiction
12.1 Notices under this agreement are sent to the Customer's designated contact in the Order Form, and to CivicLayer at info@consentos.in.
12.2 CivicLayer's Grievance Officer contact is published in the Privacy Policy, Section 9.
12.3 This agreement is governed by the laws of India.
12.4 The courts at Gurgaon, Haryana have exclusive jurisdiction over any dispute arising out of this agreement.
Amendment history
Version 1.2, 10 September 2026. Clause 10.4 stated a single 14 day backup rotation. Encrypted offsite copies of the database are now written daily to Amazon Web Services Asia Pacific (Mumbai), India, with a 30 day deletion lock and a 35 day expiry, alongside the 14 day copy on the host. The clause states both windows. Clause 4(d) is unchanged. No transfer safeguard is triggered: both copies are in India.
Version 1.1, 8 September 2026. Clause 5.2 named the United Kingdom as the hosting region for the platform database. The database is in Oracle Cloud Infrastructure, Asia Pacific (Mumbai) region, India, verified against Oracle's published IP ranges on 8 September 2026. The incorrect region came from a registry lookup during the 21 August 2026 infrastructure audit. No personal data was moved. The record was wrong, not the hosting. This amendment corrects a statement of fact and has not been re-reviewed by counsel.
Version 1.0, 7 September 2026. First publication.