Data Processing Addendum (DPA)
Last Updated: 11 September 2026
1. Purpose
This Data Processing Addendum ("DPA") forms part of the agreement between RemARkablyAI Private Limited ("Processor") and the Customer ("Controller") where applicable data protection laws require such an arrangement.
2. Scope
This DPA applies to personal information processed by RemARkablyAI on behalf of Customers while providing the Services.
3. Roles
Where applicable:
- The Customer acts as the Controller.
- RemARkablyAI acts as the Processor.
Each party is responsible for complying with its obligations under applicable data protection laws.
4. Processing
RemARkablyAI processes personal information only:
- On documented instructions from the Customer.
- As necessary to provide the Services.
- As required by applicable law.
5. Confidentiality
RemARkablyAI will ensure that personnel authorised to process personal information are subject to appropriate confidentiality obligations.
6. Security
RemARkablyAI maintains reasonable technical and organisational measures designed to protect personal information against unauthorised access, disclosure, alteration, or destruction.
If RemARkablyAI confirms a security incident affecting Customer Personal Data, it will notify the affected Customer without undue delay, with a target of 48 hours where reasonably practicable, and provide available information needed for the Customer's response.
7. Sub-processors
RemARkablyAI uses Google services for authentication, communications, analytics, hosting, and operational infrastructure; Cloudflare for content delivery, service security, and managed storage; and Razorpay for subscription and payment processing.
RemARkablyAI remains responsible for ensuring that such providers are subject to appropriate contractual obligations where required.
8. Data Subject Requests
Where appropriate, RemARkablyAI will provide reasonable assistance to Customers in responding to lawful access, correction, deletion, restriction, or regulatory requests relating to personal information.
9. Data Retention and Deletion
Upon termination of the Services, active Customer Personal Data will be returned or deleted within 30 days unless the agreement, applicable law, or a lawful preservation requirement requires longer retention. Copies in routine backups expire through the applicable backup-retention cycle.
10. Changes
We may update this DPA where necessary to reflect legal or operational changes.
Material changes will be communicated where appropriate.
11. Contact
Questions regarding this DPA may be directed to: