Back to Home

Data Processing Agreement

Last updated: May 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between you ("Data Controller" / "Brand") and Ziyo ("Data Processor") and governs the processing of personal data that you provide to or through the Service.

1. Definitions

  • "Personal Data" means any information relating to an identified or identifiable natural person that is processed by Ziyo on behalf of the Brand.
  • "Data Controller" means the Brand that determines the purposes and means of processing Personal Data.
  • "Data Processor" means Ziyo, which processes Personal Data on behalf of the Data Controller.
  • "Data Subject" means the Consumer whose Personal Data is being processed.
  • "Sub-Processor" means any third party engaged by Ziyo to process Personal Data on behalf of the Controller.
  • "Applicable Law" means the Digital Personal Data Protection Act, 2023 (DPDPA), the EU General Data Protection Regulation (GDPR), and any other applicable data protection legislation.

2. Scope & Purpose of Processing

Ziyo processes Personal Data on behalf of the Brand for the following purposes:

  • Creating and managing consumer accounts who claim rewards.
  • Processing reward claims and distributing payouts.
  • Storing consumer reward balances and transaction histories.
  • Providing analytics dashboards (aggregated and anonymized where possible).
  • Fraud detection and prevention.
  • Sending notifications related to reward programs.

3. Categories of Personal Data

CategoryData TypesPurpose
IdentityName, email, phone, Google profileAccount creation, authentication
PaymentUPI ID, bank account, IFSCProcessing payouts
TransactionClaim records, reward balances, redemption codesReward fulfillment, audit trail
Device & LocationIP address, device type, approximate locationFraud prevention, security
CommunicationNotification preferences, support ticketsService communications

4. Processor Obligations

Ziyo shall:

  • Process Personal Data only on documented instructions from the Brand, including with regard to transfers of Personal Data to a third country, unless required to do so by applicable law.
  • Ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
  • Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including encryption, access controls, and regular security assessments.
  • Not engage another processor (Sub-Processor) without prior specific or general written authorization of the Brand.
  • Assist the Brand in ensuring compliance with obligations related to data subject rights, breach notification, and data protection impact assessments.
  • At the choice of the Brand, delete or return all Personal Data after the end of the provision of services, and delete existing copies unless applicable law requires storage.
  • Make available to the Brand all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits and inspections by the Brand or an auditor mandated by the Brand.

5. Authorized Sub-Processors

The Brand hereby provides general authorization for Ziyo to engage the following Sub-Processors:

Sub-ProcessorPurposeLocation
Neon DatabaseDatabase hosting (PostgreSQL)Singapore
Cloudflare WorkersApplication hosting & CDNGlobal edge network
RazorpayPayment processingIndia
Google (OAuth)Authentication servicesGlobal
Upstash (Redis)Caching & rate limitingGlobal edge network

Ziyo will notify the Brand at least 30 days before adding or replacing a Sub-Processor, providing the Brand the opportunity to object to such changes.

6. Technical & Organizational Security Measures

  • Encryption in Transit: TLS 1.3 for all API communications.
  • Encryption at Rest: AES-256 for database storage (via cloud provider).
  • Access Control: Role-based access with MFA for production systems. Least-privilege principle enforced.
  • Authentication: Cryptographically signed session tokens with configurable expiry.
  • CSRF Protection: All mutating API requests require CSRF tokens.
  • Audit Logging: All admin actions and data access are logged.
  • Incident Response: Documented incident response plan with 72-hour breach notification.
  • Vulnerability Management: Regular security reviews and dependency audits.

7. Data Subject Rights Assistance

Ziyo will assist the Brand in fulfilling its obligations to respond to data subject requests for access, rectification, erasure, data portability, restriction, and objection. Ziyo provides the following self-service tools:

  • Data Export: Consumers can export their data via the dashboard Settings → Export My Data feature.
  • Account Deletion: Consumers can delete their account via the dashboard Settings → Delete Account feature.
  • Profile Update: Consumers can update their profile via the dashboard Settings page.

8. Data Breach Notification

In the event of a personal data breach, Ziyo will notify the Brand without undue delay and no later than 48 hours after becoming aware of the breach. The notification will include:

  • The nature of the breach, including categories and approximate number of data subjects and records affected.
  • The likely consequences of the breach.
  • The measures taken or proposed to address the breach and mitigate its effects.
  • Contact information for the Ziyo data protection team.

9. Data Retention & Deletion

  • Personal Data is retained for the duration of the Brand's active subscription plus 8 years for financial compliance (Indian Income Tax Act, GST laws).
  • Upon account deletion, Personal Data is anonymized (PII replaced with non-identifiable values) while financial records are preserved for legal compliance.
  • Upon termination of the DPA, Ziyo will, at the Brand's choice, return or delete all Personal Data within 90 days, unless retention is required by applicable law.

10. International Data Transfers

Personal Data may be transferred to and processed in India and Singapore (where our infrastructure is hosted). For Brands subject to the GDPR, such transfers are made under Standard Contractual Clauses (SCCs) as approved by the European Commission. A copy of the applicable SCCs is available upon request by emailing support@ziyo.in.

11. Term & Termination

This DPA remains in effect for as long as Ziyo processes Personal Data on behalf of the Brand. Either party may terminate this DPA by terminating the underlying Terms of Service. Upon termination, the data retention and deletion provisions in Section 9 shall apply.

12. Contact

For DPA-related inquiries, Sub-Processor objections, or audit requests:

Ziyo — Data Protection

Email: support@ziyo.in

Response time: Within 15 business days