Last updated: 30 June 2026
This Data Processing Agreement ("DPA") supplements the Terms of Service between ADS Infra Solutions Pvt Ltd (trading as QuantProc, the "Processor") and the Customer ("Controller"). It applies wherever the Processor processes Personal Data on behalf of the Controller in connection with the Services (QuantProc ERP, Skils, ProcureAI).
In the event of a conflict between this DPA and the Terms of Service on a data protection matter, this DPA prevails.
| Subject matter | Provision of QuantProc SaaS products to the Controller. |
|---|---|
| Duration | For the term of the Controller's subscription and the post-cancellation data-retention period (30 days), after which data is deleted. |
| Nature and purpose | Storing, displaying, transmitting and backing up Personal Data to deliver the Services; AI-assisted processing where the Controller uses AI features (BOQ mapping, vendor matching, talent scoring). |
| Types of Personal Data | Employee and HR data (name, contact, employment details, skills, salary); vendor and client identity data (name, GSTIN, Aadhaar reference, contact); project and financial records containing individual identifiers; usage logs; authentication credentials (hashed). |
| Categories of data subjects | Controller's employees, contractors, vendors, clients, project stakeholders, and platform users. |
The Controller warrants that: (a) it has a lawful basis for processing and for instructing the Processor; (b) it has provided all required notices to, and obtained all required consents from, data principals; and (c) its instructions to the Processor comply with applicable law.
The Processor shall:
The Processor maintains technical and organisational measures appropriate to the risk, including:
A detailed description of security measures is available in our Security page. The Processor may update security measures over time, provided the overall level of protection is not materially reduced.
The Controller provides general authorisation for the Processor to engage the following sub-processors. The Processor will notify the Controller of any intended change (addition or replacement) at least 14 days in advance, giving the Controller the opportunity to object.
| Sub-processor | Location | Purpose |
|---|---|---|
| DigitalOcean LLC | India (Bangalore — ISO 27001 & SOC 2 Type II) | Cloud infrastructure, compute, storage, managed PostgreSQL database |
| Razorpay Software Pvt Ltd | India | Payment processing for subscriptions and ProcureAI marketplace transactions |
| Sandbox.co.in (Decentro Tech) | India | Aadhaar OKYC and GST verification for KYC onboarding |
| Anthropic, PBC | USA | AI language model API (Claude) — used for BOQ make-mapping, vendor categorisation, and AI Assist features. Data sent: BOQ line descriptions, approved make lists. No personal identifiers are transmitted. |
The Processor will assist the Controller in fulfilling data principal rights requests by: (a) providing the Controller with technical means to export, correct, or delete data via the platform; and (b) promptly forwarding to the Controller any rights request received directly by the Processor from a data principal. The Controller is responsible for responding to such requests within the statutory timeframe.
In the event of a Personal Data breach that is likely to result in a risk to data principals, the Processor will notify the Controller without undue delay and within 72 hours of becoming aware. The notification will include: (a) a description of the breach; (b) the categories and approximate number of data principals and records affected; (c) the likely consequences; and (d) the measures taken or proposed. The Controller is responsible for notifying the Data Protection Board of India (DPBI) and any other competent authority as required by applicable law.
Personal Data is primarily stored and processed within India (DigitalOcean, Bangalore). Where any transfer occurs to a country outside India (e.g., Anthropic API calls to the USA), the Processor ensures appropriate safeguards — including contractual protections and data minimisation — are in place, and will obtain the Controller's approval before transferring personal identifiers outside India.
The Controller may, not more than once per year and upon 30 days' written notice, request an audit of the Processor's processing activities. The Processor will provide written responses to audit questionnaires and, where required, facilitate an inspection by the Controller or its designated auditor, subject to reasonable confidentiality protections for data of other customers.
On expiry or termination of the subscription, the Processor will retain Personal Data for a maximum of 30 days during which the Controller may export its data. After that period, the Processor will securely delete or anonymise all Personal Data, except where retention is required by applicable Indian law (e.g., GST record-keeping obligations of 8 years for financial records).
Each party's liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA limits either party's liability for wilful misconduct or fraud.
This DPA remains in force for as long as the Processor processes Personal Data on behalf of the Controller under the Terms of Service. Obligations of confidentiality and security survive termination.
This DPA is governed by the laws of India. Disputes are subject to the jurisdiction of the courts of Gurgaon, Haryana.
To receive a countersigned PDF DPA for your records, enterprise procurement, or regulatory compliance, email crm@quantproc.com with subject "DPA Request — [your organisation name]". Include: organisation name, GSTIN, primary contact name and email. We return signed copies within 3 business days.