GRX10← Legal hub
GRX10

Data Processing Addendum (DPA)

GRX10 Solutions Private Limited · Effective 23 July 2026 Publish at https://grx10.com/dpa and offer as a countersignable PDF for enterprise customers.

This DPA forms part of the Terms of Service between GRX10 ("Processor") and the Customer ("Controller") and applies where GRX10 processes personal data on the Customer's behalf.

1. Roles

The Customer is the Controller of Customer Data; GRX10 is the Processor. GRX10 processes personal data only on the Customer's documented instructions (including via the Services' configuration).

2. Scope & duration

Processing lasts for the term of the subscription. Subject matter: provision of the Services. Nature/purpose: hosting, messaging, calling, automation and CRM functions. Data types: contact identifiers, communication content, and usage data. Data subjects: the Customer's contacts, leads and call/message recipients.

3. Confidentiality

GRX10 ensures personnel authorised to process personal data are bound by confidentiality.

4. Security

GRX10 maintains technical and organisational measures appropriate to the risk, including access control, encryption in transit, audit logging, secret and dependency scanning, and reviewed/signed code changes. See the security policy.

5. Subprocessors

The Customer authorises GRX10 to engage the subprocessors listed at SUBPROCESSORS.md. GRX10 imposes data-protection obligations on each and remains liable for their performance. GRX10 will give notice before adding a subprocessor and allow reasonable objection.

6. Data-subject requests

GRX10 will assist the Customer in responding to data-subject requests (access, correction, deletion, portability) taking into account the nature of the processing.

7. Personal-data breach

GRX10 will notify the Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data, with information reasonably available.

8. International transfers

Where transfers occur, GRX10 applies appropriate safeguards via its contracts with subprocessors.

9. Deletion / return

On termination, GRX10 will, at the Customer's choice, delete or return Customer Data within 90 days, except where retention is legally required.

10. Audit

GRX10 will make available information necessary to demonstrate compliance and allow for audits, subject to reasonable confidentiality and frequency limits (attestations/reports satisfy this where available).

11. Governing law

As per the Terms of Service (India).


Drafting aid — review with legal counsel before offering to customers.