Data Processing Agreement

This Data Processing Agreement ("DPA") forms part of the Terms of Service between DispatchO ("DispatchO", "processor") and the business using DispatchO ("Customer", "data fiduciary"). It applies whenever DispatchO processes personal data inside the Customer's account. If this DPA and the Terms conflict on data protection, this DPA wins.

1. Roles

The Customer decides why and how personal data in its account is used and is the data fiduciary. DispatchO processes that data only on the Customer's behalf and is the data processor. Terms such as "personal data", "data principal" and "personal data breach" have the meanings given in the Digital Personal Data Protection Act, 2023 and its Rules.

2. What is processed

Purpose Providing DispatchO: recording and storing packing videos, evidence details, review, sharing with the Customer's customers, claim packs, API and webhooks, and support.
Duration For as long as the Customer uses DispatchO, then until each video's retention period ends and deletion described in section 9.
Data principals The Customer's staff (account users, packers), the Customer's buyers and clients (people orders are for, and people videos are shared with), and anyone else who appears in a packing video.
Personal data Names, work emails and roles of users; sign-in and activity records; video and audio of the packing area; order details such as order number, customer name, city, items and serial numbers; email addresses videos are shared with; viewing records.
Special care The service is not designed for sensitive data such as health or financial account details. The Customer should not record it.

3. Instructions

DispatchO processes the Customer's personal data only on the Customer's documented instructions. The Terms, this DPA and the Customer's use of the app's features are those instructions. If DispatchO is required by law to process data in another way, it will tell the Customer first unless the law forbids it.

4. Customer's duties

The Customer is responsible for having a lawful basis for recording and sharing, for giving notice to its staff and customers, and for the accuracy of the data it sends to DispatchO.

5. Confidentiality

DispatchO makes sure everyone it lets process the Customer's personal data is bound by confidentiality and only accesses it where needed to provide or support the service.

6. Security

DispatchO keeps reasonable security safeguards in place, including:

  • encryption in transit (HTTPS) for all traffic;
  • hashed passwords, and encryption at rest for stored secrets such as order-system keys;
  • role-based access within each Customer account, and strict separation between Customers' data;
  • write-once storage and a SHA-256 fingerprint for every video, so tampering can be detected;
  • activity logs of recording, review, sharing and viewing;
  • rate limits and monitoring to prevent abuse;
  • regular backups of the service database.

7. Personal data breaches

If DispatchO becomes aware of a personal data breach affecting the Customer's data, it will notify the Customer without undue delay, and within 48 hours where possible. The notice will describe what happened, the data and people likely affected, the steps taken, and a contact person. DispatchO will give reasonable help so the Customer can notify the Data Protection Board of India and affected people as the law requires.

8. Helping the Customer

DispatchO will give reasonable help to the Customer in responding to data principals' requests (access, correction, erasure, grievances) and in meeting its own legal duties, taking into account what DispatchO can do as a processor. If a data principal contacts DispatchO directly about the Customer's data, DispatchO will pass the request to the Customer.

9. Retention and deletion

  • Videos are deleted automatically at the end of the retention period chosen by the Customer's plan. Because videos are held in write-once storage to keep them tamper-evident, they cannot be deleted before that date. The Customer accepts this as part of its instructions.
  • Other personal data is deleted or anonymised within 12 months after the Customer's account closes, or sooner on the Customer's written request where the law allows, except records DispatchO must keep by law (for example billing records).
  • For 30 days after the account closes, the Customer can ask for claim packs or exports.

10. Sub-processors

The Customer allows DispatchO to use the sub-processors below. DispatchO binds each one to data protection terms at least as protective as this DPA and remains responsible for them. DispatchO will announce new sub-processors on this page at least 15 days before they start. The Customer may object on reasonable data protection grounds; if we cannot resolve the objection, the Customer may end the affected service and receive a refund of prepaid fees for the unused period.

Sub-processor What it does Location
Contabo GmbH Servers, database and video storage India (Mumbai)
Brevo Sending service emails (sign-in, share links, codes, alerts) European Union

A payment provider will be added here before online payments start.

11. Transfers outside India

Data is hosted in India (Mumbai). Service emails are sent through Brevo in the European Union, which receives the recipient's email address and the message. DispatchO transfers personal data outside India only where the law allows it and will tell the Customer before changing the hosting region.

12. Audits

On reasonable written request, no more than once a year, DispatchO will answer the Customer's security and data protection questions and share relevant documents. Further audits can be agreed in writing, at the Customer's cost, with reasonable notice and confidentiality.

13. Liability

Each party's liability under this DPA is subject to the limits in the Terms.

14. Contact

Data protection questions: DispatchO team, contact@dispatcho.in. A signed copy of this DPA is available on request from contact@dispatcho.in.