Data Processing Addendum

The terms on which Mallah Software Services Private Limited processes personal data as a Data Processor on a Customer's instruction, as section 8(2) of the Digital Personal Data Protection Act, 2023 requires to be under a valid contract.

Contractualv1.0In force from 9 September 2026

Drafted against

  • Digital Personal Data Protection Act, 2023 — sections 2(i), 2(k), 8(1), 8(2), 8(5), 8(6) and 8(7)
  • Information Technology Act, 2000 — sections 43A and 72A
  • CERT-In Directions dated 28 April 2022

1.When this applies

This Addendum forms part of the Terms of Service and applies whenever Mallah Software Services Private Limited processes personal data on behalf of a Customer. It takes effect automatically — a Customer does not have to sign it to rely on it, and its terms are the same for every Customer. A countersigned copy is available on request for a Customer whose own compliance file needs one.

Section 8(1) of the Digital Personal Data Protection Act, 2023 makes the Data Fiduciary responsible for compliance including where processing is carried out by a Data Processor on its behalf, and section 8(2) permits such engagement only under a valid contract. This is that contract.

TermMeaning here
Data FiduciaryThe Customer. It decides the purpose and means of processing the personal data it puts into its workspace.
Data ProcessorMallah Software Services Private Limited. We process on the Customer's instruction and for no purpose of our own.
Data PrincipalThe individual the personal data relates to — a director, employee, officer, counterparty signatory or professional named in the workspace.
Customer Personal DataPersonal data within Customer content: entity masters, obligations, notes, uploaded evidence, meeting records and contracts under review.

2.Subject matter, duration, nature and purpose

Subject matter
The provision of Lawzer — statutory compliance management software — to the Customer.
Duration
The subscription term, plus the export and deletion windows in clause 9. Processing ends when the data is returned or deleted.
Nature of processing
Storage, organisation, structuring, retrieval, computation (applicability, due dates, penalty exposure, health scoring), transmission of notifications, and erasure. No processing beyond what the software does or what the Customer asks support to do.
Purpose
To let the Customer identify, schedule, assign, evidence and evidence-trail its statutory obligations, and to vet its contracts.
Categories of Data Principal
Directors, designated partners, key managerial personnel, employees whose payroll or headcount data affects applicability, company secretaries and chartered accountants working the file, authorised signatories, and counterparty signatories in documents under review.
Categories of personal data
Names, designations, professional membership numbers, DIN/DPIN, work contact details, and whatever appears in documents the Customer uploads as evidence. No special categories are sought — see clause 4.

3.What we undertake

  1. To process Customer Personal Data only on the Customer's documented instructions, which its use of the software and its support requests constitute, and for no independent purpose of our own.
  2. Not to sell, rent or trade it, not to use it for advertising, and not to use it to train any machine-learning model made available to any other party.
  3. To implement and maintain the security safeguards required by section 8(5) of the Act, as set out in the Information Security Policy, and not to reduce them during the term.
  4. To restrict access to those of our personnel who need it to provide or support the service, to bind them to confidentiality that survives their employment, and to log the access.
  5. To assist the Customer in meeting its own obligations under the Act — including in answering a Data Principal exercising rights under sections 11 to 14, and in a data protection impact assessment where the Customer must carry one out.
  6. To tell the Customer, without undue delay, if in our opinion an instruction would cause us to breach the Act, rather than carry it out silently.
  7. To make available the information the Customer reasonably needs to demonstrate our compliance with this Addendum, and to submit to an audit on the terms in clause 8.

4.What the Customer undertakes

The division of responsibility only works if the Customer discharges the Data Fiduciary side of it. The Customer therefore confirms that:

  1. It has a lawful basis under the Act for every item of personal data it puts into its workspace, and has given the notice section 5 requires.
  2. It will not put into the workspace any personal data it does not need for a compliance purpose — and specifically will redact an Aadhaar number to its last four digits before uploading an Aadhaar-bearing document, and will not upload biometric or health data, which the service is not designed to hold.
  3. It is responsible for the accuracy of what it enters, and for the roles it assigns to its own Users.
  4. It will answer a Data Principal who approaches it, and will not direct that person to us for data that is in its own workspace — we are not entitled to alter another organisation's statutory records on a third party's instruction.
  5. It will keep its own retention decisions under review, and will delete what it no longer needs rather than leave it in the workspace indefinitely.

5.Personal data breach

Section 8(6) of the Act puts the notification duty on the Data Fiduciary, which for Customer Personal Data is the Customer. It cannot discharge that duty if we are slow, so:

  1. We will notify the Customer without undue delay, and in any event within 24 hours of becoming aware of a personal data breach affecting its data.
  2. The notification will state what we know: what happened, when, which categories of data and roughly how many records, what we have done, what we are still doing, and what we recommend the Customer do.
  3. We will not delay a notification in order to make it complete. A first notice with gaps, followed by updates, is more useful to a Customer with a statutory clock running than a full report that arrives late.
  4. We will separately report a reportable cyber incident to CERT-In within six hours of noticing it, as the Directions of 28 April 2022 require, and tell the Customer that we have.
  5. We will not notify a Data Principal on the Customer's behalf unless the Customer asks us to in writing, because the notification is the Customer's to make and its wording is the Customer's to control.
  6. We will preserve the evidence and give the Customer what it reasonably needs for its own report to the Data Protection Board.

6.Sub-processors

We engage sub-processors for infrastructure, storage, email and monitoring. Each is named, with what it does and where it processes, on the Sub-processors page. By accepting the Terms of Service the Customer authorises those.

  1. Every sub-processor is bound by written terms imposing obligations no less protective than this Addendum.
  2. We remain liable to the Customer for a sub-processor's acts and omissions as if they were our own.
  3. We will give at least thirty days' notice before adding or replacing one, by email to workspace administrators and by updating the Sub-processors page.
  4. A Customer with a reasonable, data-protection-based objection may raise it within that period. We will work to resolve it; if we cannot, the Customer may terminate the affected subscription and receive a pro-rated refund of the unused term.

7.Location and cross-border transfer

Customer Personal Data is stored in India — the production database, the evidence vault and the backups. Section 16 of the Act permits transfer outside India except to a country notified as restricted, and we will not transfer to a notified country.

Limited technical metadata — error traces and outbound email envelopes — may be processed outside India by the sub-processors identified as such. Customer content is not included. A Customer requiring strict in-India-only processing for every component should say so; it is available on an enterprise plan and is recorded in the order form.

8.Audit and assurance

  • On request we provide our current security documentation, penetration-test summary and sub-processor list. For most Customers, and for most auditors, that answers it.
  • A Customer may audit our processing of its data once in any twelve-month period, on thirty days' notice, at its own cost, during business hours, under confidentiality, and without access to another Customer's data or to our security controls in a way that would compromise them.
  • Where a regulator or the Data Protection Board requires an audit, we will cooperate without the notice period and without charge.
  • We will answer a security questionnaire once per year per Customer at no charge.

9.Return and deletion

  1. During the term, the Customer may export its data at any time from within the application.
  2. On termination, read and export access continues for thirty days.
  3. After that, Customer Personal Data is erased from live systems within sixty days, and from backups as the thirty-five-day rolling window passes.
  4. We will certify the deletion in writing on request.
  5. Where we must retain something for our own legal reason — our books of account, our tax records, or logs we must keep for 180 days under the CERT-In Directions — we retain only that, only for the statutory period, and process it for no other purpose. The Privacy Policy lists each case and its period.
  6. A Customer may ask for earlier deletion, and we will act within thirty days of a verified request from an administrator.

10.Liability and contact

The limits in clause 10 of the Terms of Service apply to this Addendum, except that nothing limits a liability that cannot lawfully be limited — including under section 72A of the Information Technology Act, 2000 for a disclosure in breach of a lawful contract, or a penalty imposed on us in our own right under section 33 of the Digital Personal Data Protection Act, 2023.

Notices under this Addendum go to contact@lawzer.in and to the Customer's workspace administrators.

Where this Addendum conflicts with the rest of the Terms of Service on a matter of personal data, this Addendum prevails.

Read next