Legal

Data Processing Agreement

Last updated: 21 September 2026 · BPS FutureTech (OPC) Private Limited

Parties & roles

This Data Processing Agreement (“DPA”) forms part of the Terms between the customer (Controller / Data Fiduciary for end-user and operational personal data it decides purposes for) and BPS FutureTech (OPC) Private Limited (“Processor”) for BPS CA.

Where Indian DPDP terminology differs from GDPR-style labels, “Controller” maps to Data Fiduciary and “Processor” maps to Data Processor as applicable to the processing activity.

Subject matter & duration

The Processor hosts and processes personal data solely to provide BPS CA (authentication, inventory/reconciliation workflows, document storage, billing support metadata) for the term of the subscription and the retention windows in our Privacy Policy.

Nature of processing

Processing includes storage, retrieval, transmission, encryption in transit, access control, backup, and deletion per documented instructions. The Processor does not use customer personal data for independent marketing profiles.

Types of personal data & data subjects

May include staff names, emails, phone numbers, addresses, and optional family contact names; partner/customer names and invoices you upload; and technical identifiers. Sensitive national government IDs (including Aadhaar) are out of scope — the product does not collect them.

Instructions & confidentiality

The Processor processes personal data only on documented instructions (including configuration inside the product and this DPA), unless required by law. Personnel with access are bound by confidentiality obligations.

Security measures

Measures include HTTPS (TLS 1.2+), Argon2id password hashing, database-backed sessions, RBAC, tenant isolation with PostgreSQL RLS on core ledgers, hosting on Oracle Cloud Infrastructure region ap-hyderabad-1 (Hyderabad, India), and AES-256-CBC encrypted offsite DR archives on AWS S3 region ap-south-2 (Hyderabad, India) for AES-256-CBC encrypted DR archives only.

Admin and Super Admin accounts must use authenticator MFA (TOTP) with one-time backup codes in production. Accountant and client portals use password plus email OTP. WebAuthn/passkeys are not offered.

Sub-processors

Current sub-processors used to deliver the service:

  • Oracle Cloud Infrastructure (OCI) — Primary compute, PostgreSQL, and MinIO object storage
  • Amazon Web Services (AWS) S3 — Encrypted offsite disaster-recovery archives (ap-south-2 only)
  • Dodo Payments — Subscription checkout and billing mandates
  • Resend — Transactional email including login OTP and support notices

Sub-processor changes

Customers will be informed of material sub-processor changes via product notice or email where practicable. The same list is summarized in the Privacy Policy and Terms.

Assistance, breach notice & deletion

The Processor will assist with reasonable data-subject requests and security inquiries directed through support@bpsfuturetech.com or grievance@bpsfuturetech.com. Security incidents affecting personal data will be notified without undue delay after confirmation.

Upon termination, personal data is deleted or returned per the Privacy Policy retention schedule (target 90 days after closure for account personal data, subject to legal holds).

Governing law

This DPA is governed by the laws of India. Disputes follow the dispute clause in the Terms of Service.

Related: Security · Privacy Policy · Terms of Service