Legal

Data Processing Agreement

Last updated: 3 October 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Vaanika AI and business customers who use the Services to process personal data of their own users.

01Roles of the parties

The customer is the Data Fiduciary (or Controller) and decides why and how personal data is processed.

Vaanika is the Data Processor and processes personal data only on the customer's documented instructions.

02Scope of processing

Subject matter: providing AI assistants for voice, chat and messaging.

Types of data: names, phone numbers, email addresses, conversation content, recordings and transcripts.

Data subjects: the customer's end users, employees and contacts.

Duration: for the term of the agreement, plus any retention period the customer sets.

03Vaanika's obligations

Process personal data only to provide the Services and as instructed by the customer.

Ensure that staff with access to personal data are bound by confidentiality.

Help the customer respond to data subject requests and meet its legal obligations.

04Security measures

Vaanika maintains technical and organisational measures including encryption at rest and in transit, access controls, MFA, logging, vulnerability management and regular audits.

05Sub-processors

The customer authorises Vaanika to use sub-processors listed on our Trust & Security page. We will give at least 30 days' notice before adding a new sub-processor, and the customer may object on reasonable grounds.

Vaanika remains responsible for the performance of its sub-processors.

06Personal data breaches

Vaanika will notify the customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach, with the information needed to meet reporting duties.

07International transfers

Personal data is stored in India by default. Any transfer outside India will comply with the DPDP Act and, where applicable, the EU GDPR Standard Contractual Clauses.

08Audits

Vaanika will make available its SOC 2 and ISO 27001 reports and reasonable information needed to show compliance with this DPA, once a year or after a breach.

09Return and deletion of data

At the end of the agreement, Vaanika will delete or return all personal data within 30 days, unless the law requires us to keep it.