Vahanse Data Processing Agreement (DPA)
Status: DRAFT — FOR LEGAL REVIEW — NOT FOR EXECUTION
Version: 0.9 - Counsel Review Draft
Draft date: 31 August 2026
Operator: Vahanfin Solutions Private Limited (CIN U52290JH2023PTC021512)
Brand: Vahanse
Head office: Vahanfin Solutions Pvt Ltd, Nabibux House, 3rd Floor, Vakola Bridge Road, Santacruz (E), Mumbai 400 055, Maharashtra, India
This document is a Vahanse-specific working draft prepared for Vahanfin Solutions Private Limited (CIN U52290JH2023PTC021512), which operates the Vahanse brand. It is not legal advice and must be reviewed, approved and adapted by qualified Indian counsel before publication, signature or reliance. Commercial values, support contacts, regulatory representations, security commitments, service levels and any customer-specific terms must be validated against actual operations and contracts.
Purpose: Data-processing terms for enterprise, white-label and API customers.
Audience: Business customers for whom Vahanse processes personal data on instructions
1. Parties and Application
This DPA forms part of the Agreement between Customer and Vahanse where Vahanse processes digital personal data on documented instructions of Customer. It does not alter the parties’ independent obligations for processing they separately determine.
2. Legal Framework and Transition
The parties will comply with applicable Indian data-protection law, including provisions of the Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 as and when they commence, and any other applicable privacy/security law.
Because the DPDP framework has staged commencement, the parties will reasonably cooperate to amend operational procedures where a new mandatory obligation takes effect during the contract term.
3. Roles
For Customer Data processed solely on Customer’s instructions, Customer acts in the role that determines purpose/means under applicable law and Vahanse acts as its processor/data processor equivalent. Vahanse may act independently for account administration, billing, security, fraud prevention, legal compliance and its own business records to the extent it determines those purposes lawfully.
4. Processing Instructions
Vahanse will process personal data only to provide, secure and support the Services, comply with documented Customer instructions, and meet legal obligations. If Vahanse believes an instruction violates applicable law, it may suspend the affected processing and notify Customer unless prohibited.
5. Processing Details
The subject matter, duration, nature, purposes, data categories and data-subject categories are described in Annexure 1 and the applicable Order Form. Customer will not instruct Vahanse to process unnecessary or prohibited data.
6. Confidentiality
Personnel authorized to process personal data will be subject to confidentiality obligations and access will be limited according to role and need.
7. Security Measures
Vahanse will maintain reasonable technical and organizational safeguards appropriate to risk and the contracted service, as described in Annexure 2/Security Overview. Vahanse may update controls provided overall protection is not materially reduced.
8. Customer Security Responsibilities
Customer is responsible for user access, endpoint/device security, integration security, credential handling, lawful configuration, secure exports and downstream processing outside Vahanse.
9. Subprocessors
Customer authorizes Vahanse to use subprocessors necessary to provide the Services, subject to written obligations appropriate to the processing. Vahanse will maintain a current Subprocessor List and provide change notice where contractually agreed. Customer may raise a reasonable data-protection objection within the stated notice period.
10. Cross-Border Processing
Vahanse will comply with restrictions or conditions applicable to cross-border processing/transfer under then-applicable Indian law. Hosting/processing locations will be reflected in the Subprocessor List to the extent reasonably known and contractually required.
11. Individual/Data Principal Requests
Where Customer is responsible for responding to an individual request, Vahanse will provide reasonable assistance using available product capabilities, taking into account the nature of processing. If Vahanse receives a request concerning Customer-controlled data, it may redirect the requester to Customer unless law requires otherwise.
12. Correction, Erasure and Retention
Vahanse will implement Customer’s lawful instructions to correct, export or delete data where technically available and not subject to legal retention. Customer acknowledges that backups may retain data for a limited cycle before secure overwrite/deletion.
13. Security Incidents
Vahanse will notify Customer without undue delay after confirming a personal-data breach affecting Customer Data where notification is required by contract or applicable law, and will provide information reasonably available concerning nature, impact, mitigation and remediation.
The final notification time and regulatory workflow should be aligned by counsel with the DPDP Rules as applicable on the relevant incident date.
14. Regulatory Cooperation
The parties will reasonably cooperate with lawful regulatory or Data Protection Board requirements relating to covered processing. Each party remains responsible for its own regulatory communications unless otherwise required.
15. Government Requests
Where legally permitted, Vahanse will notify Customer of a binding government request specifically directed at Customer Data and will disclose only information reasonably required by the request.
16. Audits and Assurance
On reasonable written request, Vahanse will provide available security/privacy information reasonably sufficient to demonstrate compliance with this DPA. On-site audits, if justified, are limited to once annually absent a material incident, subject to confidentiality, security, scheduling and reimbursement of unreasonable external costs.
17. Return and Deletion
At termination, Vahanse will return/export Customer Data using supported methods and then delete it after the agreed transition/retention period, except data Vahanse must retain by law, for unresolved disputes, fraud/security records or permitted independent processing.
18. Liability and Precedence
Liability under this DPA is subject to the Agreement’s liability framework unless law requires otherwise. For conflicts concerning processing of personal data, this DPA controls.
19. Changes in Law
The parties will negotiate in good faith any amendment reasonably required by a binding change in data-protection law, including commencement of additional DPDP Act/Rules provisions.
Annexures / Schedules
- Annexure 1 – Processing Details: data subjects (customer personnel, drivers/vehicle-linked individuals, partner customers); data categories (account, contact, vehicle, compliance, documents, transactions, technical logs); purposes (platform, monitoring, service fulfilment, support, security); duration (contract plus retention).
- Annexure 2 – Security Measures: authentication/access control, encryption in transit, environment/security controls, logging/monitoring, backup, incident response, vulnerability/dependency management, confidentiality and vendor controls – only to the extent actually implemented.
- Annexure 3 – Subprocessors: refer to current Vahanse Subprocessor List.