Data processing agreement
Last updated 9 October 2026
This Data Processing Agreement ("DPA") is between Anqulas ("Anqulas Docs", "we"), the provider of the Anqulas Docs service, and the firm that has accepted our terms of service (the "Customer"). It forms part of those terms and applies automatically from the moment the Customer creates an account. If anything here conflicts with the terms on the handling of personal data, this DPA prevails.
1. Definitions
- DPDP Act: the Digital Personal Data Protection Act, 2023 and the rules made under it.
- Client Data: personal data the Customer, its staff or its clients put into Anqulas Docs, such as names, contact details, uploaded documents, comments and invoices.
- Data Principal, Data Fiduciary, Data Processor and Personal Data Breach have the meanings in the DPDP Act.
- Sub-processor: a third party we engage that processes Client Data for us.
2. Roles
For Client Data the Customer is the Data Fiduciary: it decides which documents to collect, from whom, and why. Anqulas Docs is the Customer's Data Processor and processes Client Data only to provide the service. For the Customer's own account and billing details, Anqulas Docs is the Data Fiduciary, as described in our privacy policy.
3. Customer's responsibilities
- Have a lawful basis, and give any notice the DPDP Act requires, for the Client Data it collects.
- Collect only documents it needs for its professional work, and keep its staff logins secure.
- Obtain its clients' opt-in before sending them WhatsApp messages.
- Answer requests from its own clients (access, correction, erasure), using the tools Anqulas Docs provides.
4. Our obligations
- Instructions. We process Client Data only on the Customer's documented instructions: the terms, this DPA, and what the Customer does in the product. We never sell Client Data, use it for advertising, or use it to train machine-learning models.
- Confidentiality. Everyone at Anqulas Docs who can access Client Data is bound by confidentiality, and access is limited to what is needed to run and support the service.
- Security. We maintain the reasonable security safeguards in Annex B, and keep them at least as strong during the agreement.
- Support access. We look at a Customer's Client Data only when the Customer asks us to (for example to investigate a problem), when the law requires it, or to protect the service from abuse.
- Assistance. We help the Customer meet its duties to Data Principals, on security and on breaches, through the product's features (export, deletion, the activity log) and, where those are not enough, on request.
5. Sub-processors
The Customer authorises the Sub-processors in Annex C. We impose data-protection terms on each that are no less protective than this DPA and remain responsible for their work. We will give the Customer at least 15 days' notice by email before adding or replacing a Sub-processor that handles Client Data. If the Customer objects on reasonable data-protection grounds and we cannot address the objection, the Customer may end the subscription and receive a pro-rata refund of the unused period.
6. Where data is stored
Client Data is stored in the region stated to the Customer on request. We do not transfer Client Data to any country to which the Government of India has restricted transfers under section 16 of the DPDP Act.
7. Personal data breaches
If we become aware of a Personal Data Breach affecting the Customer's Client Data, we will notify the Customer's admin without undue delay and in any event within 24 hours, with what we know of its nature, the data and people affected, its likely consequences, and the steps taken. We will keep the Customer updated and help it notify the Data Protection Board and affected Data Principals within the time the DPDP Act requires. We report cyber security incidents to CERT-In as Indian law requires.
8. Deletion and return
- The Customer can export its documents and data at any time during the subscription.
- When the subscription ends, Client Data stays available for export for at least 90 days. We then delete it from live systems after emailing the Customer's admins at least 14 days and again 3 days in advance, and from backups as they expire, within a further 90 days.
- The Customer may ask for deletion at any time, in the product (Plan and billing) or in writing. Client Data is then deleted from live systems 7 days later, a period in which the Customer can cancel, and from backups as they expire.
- We keep only what the law requires us to keep, such as our own billing records, and only for that long.
- Deletion covers Client Data we hold. Copies the Customer has had sent to its own Google Drive (Annex C) are in the Customer's Google account, outside our systems; deleting the workspace or disconnecting Google Drive does not delete them, and the Customer deletes them there if it wishes.
9. Audits and information
On reasonable written request, no more than once a year (or after a Personal Data Breach), we will answer the Customer's security questionnaire and provide information needed to show compliance with this DPA. Any on-site audit must be agreed in advance, at the Customer's cost, and must not expose other customers' data.
10. Liability, term and law
Each party's liability under this DPA is subject to the limits in the terms of service. This DPA lasts as long as we process Client Data for the Customer. It is governed by the laws of India, and the courts that have jurisdiction under the terms decide any dispute.
A Customer that needs a countersigned copy, or additional terms required by law in its country, can request them at the email address on our contact page.
Annex A: Details of processing
| Subject matter | Collecting, storing, reviewing and sharing documents between the Customer and its clients; reminders; invoices. |
|---|---|
| Duration | The subscription, plus the deletion periods in section 8. |
| Data Principals | The Customer's staff; its clients and their contact persons; people named in uploaded documents. |
| Personal data | Names, email addresses, phone numbers; documents the Customer requests, which may include PAN, Aadhaar, bank statements, salary and tax records and other financial information; comments; invoice details; which statutory returns each client files and their filing status and acknowledgement numbers; digital signature certificate details (holder name and PAN, validity, token serial, who holds the token) and, only if the Customer switches it on, token PINs; sign-in and activity records (IP address, browser, times). |
| Operations | Storage, retrieval, display, transmission to the Customer's clients by email and WhatsApp, export, deletion. |
Annex B: Security safeguards
- Encryption in transit (HTTPS/TLS) for every connection; stored files encrypted at rest by the storage provider.
- Tenant isolation enforced by the database itself (row-level security), in addition to the application, so one firm's queries cannot return another firm's data.
- Two-step sign-in (authenticator app) required for every staff account; passwords stored only as Argon2id hashes; sign-in rate limiting and lockout.
- Sessions end after 60 minutes idle and 12 hours in total; exporting data and changing staff access require the password and a code again.
- Client links are single-purpose, expire, and can be revoked; files are fetched only through short-lived signed links.
- Uploads are checked by file type and content, with optional virus scanning; email and WhatsApp credentials are encrypted (AES-256-GCM).
- Digital signature token PINs are stored only if the Customer switches that on, encrypted (AES-256-GCM), shown only to the Customer's administrators after they re-enter their password and a code, never included in lists or exports, and every viewing is recorded in the activity log.
- An activity log of sign-ins, uploads, reviews, exports and changes, visible to the Customer.
- Regular backups by the database provider; production access limited to named Anqulas Docs personnel.
Annex C: Sub-processors
| Sub-processor | Purpose |
|---|---|
| Vercel Inc. | Application hosting |
| Supabase Inc. | Database and document storage |
| Email delivery provider | Sending emails for firms that have not connected their own mail server. A firm that uses its own SMTP server sends through that server instead. |
| Meta Platforms (WhatsApp Business Platform) | Only when the Customer turns on WhatsApp messages, through the Customer's own WhatsApp Business account. |
| Google LLC (Firebase Cloud Messaging) | Only for staff who use the Anqulas Docs Android app with notifications on: delivers each notification (a client's name and the period, never documents) to their phone. |
Google Drive (Customer-instructed transfer). If the Customer connects its Google Drive, we copy documents the Customer approves to the Customer's own Google account, on the Customer's instruction. Google is then the Customer's provider, not our Sub-processor: those copies are held under the Customer's agreement with Google, and Google's terms apply to them. Access is limited to the files and folders we create there (scope drive.file). The Customer can stop it at any time by disconnecting; copies already made stay in its Drive (see section 8).
Payment providers (PhonePe, PayPal) process the Customer's own billing details, not Client Data, and are covered by our privacy policy.
Anqulas Docs