Legal

Data Processing Agreement

Standard terms under which QuantProc (as processor) processes personal data on behalf of customers (as controllers). Aligned to the DPDP Act 2023 and GDPR Article 28.

Last updated: 30 June 2026

This is the standard web version of our DPA. For a countersigned PDF with executed schedules — required for GDPR Article 28 compliance, enterprise procurement, and government tenders — email crm@quantproc.com with subject "DPA Request". We aim to return a signed copy within 3 business days.

1. Parties and scope

This Data Processing Agreement ("DPA") supplements the Terms of Service between ADS Infra Solutions Pvt Ltd (trading as QuantProc, the "Processor") and the Customer ("Controller"). It applies wherever the Processor processes Personal Data on behalf of the Controller in connection with the Services (QuantProc ERP, Skils, ProcureAI).

In the event of a conflict between this DPA and the Terms of Service on a data protection matter, this DPA prevails.

2. Definitions

  • "Personal Data" — any information relating to an identified or identifiable natural person ("data principal" under the DPDP Act 2023; "data subject" under GDPR).
  • "Processing" — any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
  • "DPDP Act" — the Digital Personal Data Protection Act 2023 (India).
  • "GDPR" — Regulation (EU) 2016/679 of the European Parliament and of the Council, where applicable.
  • "Sub-processor" — any third party engaged by the Processor to process Personal Data on behalf of the Controller.

3. Details of processing

Subject matterProvision of QuantProc SaaS products to the Controller.
DurationFor the term of the Controller's subscription and the post-cancellation data-retention period (30 days), after which data is deleted.
Nature and purposeStoring, displaying, transmitting and backing up Personal Data to deliver the Services; AI-assisted processing where the Controller uses AI features (BOQ mapping, vendor matching, talent scoring).
Types of Personal DataEmployee and HR data (name, contact, employment details, skills, salary); vendor and client identity data (name, GSTIN, Aadhaar reference, contact); project and financial records containing individual identifiers; usage logs; authentication credentials (hashed).
Categories of data subjectsController's employees, contractors, vendors, clients, project stakeholders, and platform users.

4. Controller obligations

The Controller warrants that: (a) it has a lawful basis for processing and for instructing the Processor; (b) it has provided all required notices to, and obtained all required consents from, data principals; and (c) its instructions to the Processor comply with applicable law.

5. Processor obligations

The Processor shall:

  • Process Personal Data only on documented instructions from the Controller (the Terms of Service and this DPA constituting such instructions), except where required by law.
  • Ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations.
  • Not process Personal Data for any purpose other than providing the Services, including not selling or sharing it for advertising.
  • Assist the Controller in meeting its obligations to respond to data principal requests (access, correction, deletion, portability) within the timeframes required by applicable law.
  • Promptly inform the Controller if any instruction would, in the Processor's opinion, violate applicable data protection law.

6. Security measures

The Processor maintains technical and organisational measures appropriate to the risk, including:

  • Encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256).
  • Field-level encryption for sensitive identifiers (Aadhaar tokens, hashed credentials).
  • Role-based access controls and least-privilege provisioning.
  • Immutable audit logs of all write operations on Personal Data.
  • Regular vulnerability assessments and annual penetration testing by an empanelled CERT-In firm (planned).
  • Business continuity and disaster recovery with geographically separated encrypted backups.

A detailed description of security measures is available in our Security page. The Processor may update security measures over time, provided the overall level of protection is not materially reduced.

7. Sub-processors

The Controller provides general authorisation for the Processor to engage the following sub-processors. The Processor will notify the Controller of any intended change (addition or replacement) at least 14 days in advance, giving the Controller the opportunity to object.

Sub-processorLocationPurpose
DigitalOcean LLCIndia (Bangalore — ISO 27001 & SOC 2 Type II)Cloud infrastructure, compute, storage, managed PostgreSQL database
Razorpay Software Pvt LtdIndiaPayment processing for subscriptions and ProcureAI marketplace transactions
Sandbox.co.in (Decentro Tech)IndiaAadhaar OKYC and GST verification for KYC onboarding
Anthropic, PBCUSAAI language model API (Claude) — used for BOQ make-mapping, vendor categorisation, and AI Assist features. Data sent: BOQ line descriptions, approved make lists. No personal identifiers are transmitted.

8. Data principal / data subject rights

The Processor will assist the Controller in fulfilling data principal rights requests by: (a) providing the Controller with technical means to export, correct, or delete data via the platform; and (b) promptly forwarding to the Controller any rights request received directly by the Processor from a data principal. The Controller is responsible for responding to such requests within the statutory timeframe.

9. Personal data breach notification

In the event of a Personal Data breach that is likely to result in a risk to data principals, the Processor will notify the Controller without undue delay and within 72 hours of becoming aware. The notification will include: (a) a description of the breach; (b) the categories and approximate number of data principals and records affected; (c) the likely consequences; and (d) the measures taken or proposed. The Controller is responsible for notifying the Data Protection Board of India (DPBI) and any other competent authority as required by applicable law.

10. International data transfers

Personal Data is primarily stored and processed within India (DigitalOcean, Bangalore). Where any transfer occurs to a country outside India (e.g., Anthropic API calls to the USA), the Processor ensures appropriate safeguards — including contractual protections and data minimisation — are in place, and will obtain the Controller's approval before transferring personal identifiers outside India.

11. Audit and inspection rights

The Controller may, not more than once per year and upon 30 days' written notice, request an audit of the Processor's processing activities. The Processor will provide written responses to audit questionnaires and, where required, facilitate an inspection by the Controller or its designated auditor, subject to reasonable confidentiality protections for data of other customers.

12. Retention and deletion

On expiry or termination of the subscription, the Processor will retain Personal Data for a maximum of 30 days during which the Controller may export its data. After that period, the Processor will securely delete or anonymise all Personal Data, except where retention is required by applicable Indian law (e.g., GST record-keeping obligations of 8 years for financial records).

13. Liability

Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits either party's liability for wilful misconduct or fraud.

14. Term

This DPA remains in force for as long as the Processor processes Personal Data on behalf of the Controller under the Terms of Service. Obligations of confidentiality and security survive termination.

15. Governing law

This DPA is governed by the laws of India. Disputes are subject to the jurisdiction of the courts of Gurgaon, Haryana.

Request a signed DPA

To receive a countersigned PDF DPA for your records, enterprise procurement, or regulatory compliance, email crm@quantproc.com with subject "DPA Request — [your organisation name]". Include: organisation name, GSTIN, primary contact name and email. We return signed copies within 3 business days.