legal.py), and this text has not been reviewed by a lawyer.
Do not present this to a customer as a binding agreement until both are done.
This Addendum forms part of the Terms of Service between [TO BE COMPLETED — legal_name] (the Processor) and the subscribing firm (the Fiduciary). It applies wherever the Processor handles personal data on the Fiduciary's behalf. Where it conflicts with the Terms, this Addendum prevails.
Under the Digital Personal Data Protection Act 2023:
The Processor will not process the data for any purpose of its own. It does not use it to develop or train anything, and does not disclose it to anyone except as set out below.
| Subject matter | Provision of practice-management software to a chartered accountancy firm |
|---|---|
| Duration | For as long as the subscription is live, plus the retention period in clause 8 |
| Nature and purpose | Storage, organisation, retrieval, export and backup, so that the Fiduciary can run its practice |
| Categories of data | Names, addresses, email addresses, telephone numbers, PANs, GSTINs, TANs, DINs, dates of birth where entered, bank and payment references where entered, portal usernames and passwords where the Fiduciary chooses to store them, staff attendance, leave and salary records |
| Categories of data principal | The Fiduciary's clients, the individuals behind those clients, and the Fiduciary's own partners and staff |
The Processor maintains, at a minimum:
The Processor cannot open the Fiduciary's dashboard at will. Support access must be granted by an administrator of the Fiduciary, and:
There is no mechanism by which the Processor can grant itself this access.
The Fiduciary authorises the Processor to engage sub-processors for hosting and for outbound email. Each is bound by obligations no less protective than these. The Processor remains liable for their acts and omissions.
The Processor will give at least 30 days' notice before adding or replacing a sub-processor. If the Fiduciary reasonably objects on data-protection grounds and the objection cannot be resolved, the Fiduciary may terminate and receive a refund of fees for the unexpired period.
The Processor will assist the Fiduciary, at no charge for reasonable requests, to:
On becoming aware of a personal data breach affecting the Fiduciary's data, the Processor will notify the Fiduciary without undue delay and in any event within 72 hours, with what is known of the nature of the breach, the categories and approximate number of records, the likely consequences and the measures taken. The Processor will not make a public statement identifying the Fiduciary without consulting it first, unless required by law.
Once in any twelve-month period, on 30 days' notice, the Fiduciary may ask for written answers about the measures in clause 3 and a copy of any current third-party security assessment. Anything beyond that — an on-site inspection — will be arranged at reasonable cost and in a way that does not put other firms' data at risk.
All personal data is stored and processed in India. The Processor will not transfer it outside India without first telling the Fiduciary and putting lawful safeguards in place.
Liability under this Addendum is subject to the limits in the Terms of Service, save that nothing limits either party's liability to a data principal or to the Data Protection Board of India under the DPDP Act.
[TO BE COMPLETED — grievance_officer], Grievance Officer
[TO BE COMPLETED — grievance_email]
[TO BE COMPLETED — legal_name], [TO BE COMPLETED — address]