Login

Data Processing Agreement

Version 1.0 · Effective 9 October 2026

1. Parties, roles and scope

This Data Processing Agreement (“DPA”) is between the business using yekar.enterprises (“the business”) and Yekar Technologies Pvt Ltd, Building number 245, Sector 20 HUDA, Kaithal, Haryana (“Yekar”, “we”). It forms part of the Terms of Service and is accepted with them. Terms used here have the meaning given in the Digital Personal Data Protection Act, 2023 (“the Act”) and the Digital Personal Data Protection Rules, 2025.

For the personal data the business and its staff enter in yekar.enterprises or that the service creates for them (“Customer Data”), the business is the data fiduciary and Yekar is its data processor.

  • Whose data: the business's staff; its suppliers and customers where they are individuals or sole proprietors; and the contact people at its suppliers and customers.
  • What data: staff names, logins, email addresses, mobile numbers and roles, their sessions and who recorded what in the audit log and records; party names, GSTIN, PAN, phone numbers, email addresses, bank account details, addresses, notes and uploaded documents; contact people's names, roles, phone numbers and email addresses; supplier and customer names on orders; purchase-order documents and whatever they print.
  • Purpose: providing the yekar.enterprises service to the business for its operations, and nothing else.

2. The business as data fiduciary

The business decides why and how Customer Data is processed. It is responsible for:

  • giving its staff and the people whose details it records any notice the Act requires, and obtaining any consent the Act requires;
  • the lawfulness, accuracy and completeness of what it records and uploads;
  • deciding how long records are kept and telling us in writing when records must be erased;
  • answering requests and grievances from the people whose data it records;
  • notifying the Data Protection Board of India and affected people of a personal data breach, with our help under section 7;
  • deciding who on its staff gets a login and whether they are an admin, and deactivating logins promptly.

3. Instructions

We process Customer Data only on the business's documented instructions. These are the Terms of Service, this DPA, the business's use of the service's features, and written requests from an admin. We do not use Customer Data for our own purposes: no selling, no advertising and no analytics on identifiable data. If we believe an instruction breaks the law, we tell the business. If the law requires us to process Customer Data otherwise, we tell the business first unless the law forbids it.

AI assistance is optional. Only when the business sets it up do we send a purchase-order document it attaches to Yekar.AI, so an agent can read its lines into a draft for a person to check. Yekar.AI uses each document only to read its lines for that business, does not keep it beyond the extraction session and does not use it to train models.

4. Confidentiality of our personnel

We ensure that everyone at Yekar who can access Customer Data is bound by a written duty of confidentiality and accesses it only to operate, support or restore the service. Our admin console shows our team business-level details and staff contact details needed for support; it does not open a business's records, and our team does not sign in to a business's app.

5. Security safeguards

We maintain reasonable security safeguards to prevent a personal data breach. Today these include:

  • each business's records separated by Postgres row-level security, with requests served by a database role that cannot bypass it;
  • individual logins with admin and staff roles; passwords stored only as argon2id hashes; sign-in locked for 15 minutes after five failures in 10 minutes; one-time codes that expire after 10 minutes;
  • sessions in HttpOnly, Secure cookies that end 30 days after their last use and when a person is deactivated; refusal of requests started by another site;
  • HTTPS for every connection to the service, and TLS between the application and the database;
  • records that are corrected by a reversal rather than edited, and an audit log of sign-ins and changes that cannot be altered or deleted, holding ids rather than contact details;
  • uploaded documents reached only through links that check access and expire after five minutes;
  • database backups with point-in-time recovery.

We review these safeguards and will not reduce their overall protection during the agreement.

6. Sub-processors

We use only the sub-processors on our published Sub-processors page, each under a written contract that protects Customer Data at least as strictly as this DPA. We give the business at least 30 days' notice before adding or replacing a sub-processor, by updating that page and writing to the business's admins. The business may object on reasonable data protection grounds; if we cannot address the objection, the business may end the agreement. We remain responsible to the business for our sub-processors.

7. Personal data breaches

If we become aware of a personal data breach affecting Customer Data, we notify the business without undue delay and in any event within 24 hours, with what happened, the data and people affected as far as known, what we have done to contain it, and a contact. We then give the business the facts and help it needs to notify the Data Protection Board of India and affected people within the time the Rules require, and we keep the logs needed to investigate.

8. Help with requests from data principals

We help the business answer requests to access, correct or erase personal data, grievances and nominations, so it can meet the Rules' time limits. Admins can correct staff and party details in the app. Where the service has no function for a request, such as a full copy of one person's data or an erasure, we carry it out on an admin's written instruction. If someone writes to us directly about the business's records, we pass the request to the business and do not answer it ourselves.

9. Where Customer Data is processed

The database and application servers run in Singapore; uploaded documents use Cloudflare R2 with an Asia-Pacific location preference, which does not guarantee storage in India; see the Sub-processors page for each provider. We transfer Customer Data outside India only to countries to which transfer is not restricted by the Central Government under section 16 of the Act, and we will move or stop processing if a country we use becomes restricted.

10. Deletion or return at the end

When the agreement ends, we return Customer Data to the business as set out in the Terms of Service, then delete it from the service, including uploaded documents, within 30 days and confirm in writing, unless the law requires us to keep it. Database backups are not edited; they expire within 35 days. Until they expire, backups stay protected under this DPA and are used only to restore the service.

11. Records and audits

We keep records of our processing for the business. Once a year, or after a personal data breach, the business may ask us to answer a reasonable written questionnaire about our compliance with this DPA, and may inspect on reasonable notice as agreed in its order form.

12. Term and contacts

This DPA lasts as long as we process Customer Data for the business. Our contact for this DPA is the Grievance Officer, [email protected]. The business's contact is its admin who accepted this DPA, unless the business names another in writing.