1. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed by Ziyo on behalf of the Brand.
- "Data Controller" means the Brand that determines the purposes and means of processing Personal Data.
- "Data Processor" means Ziyo, which processes Personal Data on behalf of the Data Controller.
- "Data Subject" means the Consumer whose Personal Data is being processed.
- "Sub-Processor" means any third party engaged by Ziyo to process Personal Data on behalf of the Controller.
- "Applicable Law" means the Digital Personal Data Protection Act, 2023 (DPDPA), the EU General Data Protection Regulation (GDPR), and any other applicable data protection legislation.
2. Scope & Purpose of Processing
Ziyo processes Personal Data on behalf of the Brand for the following purposes:
- Creating and managing consumer accounts who claim rewards.
- Processing reward claims and distributing payouts.
- Storing consumer reward balances and transaction histories.
- Providing analytics dashboards (aggregated and anonymized where possible).
- Fraud detection and prevention.
- Sending notifications related to reward programs.
3. Categories of Personal Data
| Category | Data Types | Purpose |
|---|---|---|
| Identity | Name, email, phone, Google profile | Account creation, authentication |
| Payment | UPI ID, bank account, IFSC | Processing payouts |
| Transaction | Claim records, reward balances, redemption codes | Reward fulfillment, audit trail |
| Device & Location | IP address, device type, approximate location | Fraud prevention, security |
| Communication | Notification preferences, support tickets | Service communications |
4. Processor Obligations
Ziyo shall:
- Process Personal Data only on documented instructions from the Brand, including with regard to transfers of Personal Data to a third country, unless required to do so by applicable law.
- Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption, access controls, and regular security assessments.
- Not engage another processor (Sub-Processor) without prior specific or general written authorization of the Brand.
- Assist the Brand in ensuring compliance with obligations related to data subject rights, breach notification, and data protection impact assessments.
- At the choice of the Brand, delete or return all Personal Data after the end of the provision of services, and delete existing copies unless applicable law requires storage.
- Make available to the Brand all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections by the Brand or an auditor mandated by the Brand.
5. Authorized Sub-Processors
The Brand hereby provides general authorization for Ziyo to engage the following Sub-Processors:
| Sub-Processor | Purpose | Location |
|---|---|---|
| Neon Database | Database hosting (PostgreSQL) | Singapore |
| Cloudflare Workers | Application hosting & CDN | Global edge network |
| Razorpay | Payment processing | India |
| Google (OAuth) | Authentication services | Global |
| Upstash (Redis) | Caching & rate limiting | Global edge network |
Ziyo will notify the Brand at least 30 days before adding or replacing a Sub-Processor, providing the Brand the opportunity to object to such changes.
6. Technical & Organizational Security Measures
- Encryption in Transit: TLS 1.3 for all API communications.
- Encryption at Rest: AES-256 for database storage (via cloud provider).
- Access Control: Role-based access with MFA for production systems. Least-privilege principle enforced.
- Authentication: Cryptographically signed session tokens with configurable expiry.
- CSRF Protection: All mutating API requests require CSRF tokens.
- Audit Logging: All admin actions and data access are logged.
- Incident Response: Documented incident response plan with 72-hour breach notification.
- Vulnerability Management: Regular security reviews and dependency audits.
7. Data Subject Rights Assistance
Ziyo will assist the Brand in fulfilling its obligations to respond to data subject requests for access, rectification, erasure, data portability, restriction, and objection. Ziyo provides the following self-service tools:
- Data Export: Consumers can export their data via the dashboard Settings → Export My Data feature.
- Account Deletion: Consumers can delete their account via the dashboard Settings → Delete Account feature.
- Profile Update: Consumers can update their profile via the dashboard Settings page.
8. Data Breach Notification
In the event of a personal data breach, Ziyo will notify the Brand without undue delay and no later than 48 hours after becoming aware of the breach. The notification will include:
- The nature of the breach, including categories and approximate number of data subjects and records affected.
- The likely consequences of the breach.
- The measures taken or proposed to address the breach and mitigate its effects.
- Contact information for the Ziyo data protection team.
9. Data Retention & Deletion
- Personal Data is retained for the duration of the Brand's active subscription plus 8 years for financial compliance (Indian Income Tax Act, GST laws).
- Upon account deletion, Personal Data is anonymized (PII replaced with non-identifiable values) while financial records are preserved for legal compliance.
- Upon termination of the DPA, Ziyo will, at the Brand's choice, return or delete all Personal Data within 90 days, unless retention is required by applicable law.
10. International Data Transfers
Personal Data may be transferred to and processed in India and Singapore (where our infrastructure is hosted). For Brands subject to the GDPR, such transfers are made under Standard Contractual Clauses (SCCs) as approved by the European Commission. A copy of the applicable SCCs is available upon request by emailing support@ziyo.in.
11. Term & Termination
This DPA remains in effect for as long as Ziyo processes Personal Data on behalf of the Brand. Either party may terminate this DPA by terminating the underlying Terms of Service. Upon termination, the data retention and deletion provisions in Section 9 shall apply.
12. Contact
For DPA-related inquiries, Sub-Processor objections, or audit requests:
Ziyo — Data Protection
Email: support@ziyo.in
Response time: Within 15 business days