logo
  • Home
  • Features
  • How It Works
  • Pricing
  • Contact
  • Login
  • Register Now
Legal

Data Processing Agreement

Effective: 22 July 2026 Last updated: 22 July 2026 Version: 1.0
On this page
  1. About this agreement
  2. Definitions
  3. Roles of the parties
  4. Scope of processing
  5. Our obligations
  6. Your obligations
  7. Security measures
  8. Sub-processors
  9. Data principal requests
  10. Breach notification
  11. Audit & assurance
  12. International transfers
  13. Return & deletion
  14. Liability
  15. Term
  16. How to execute this DPA
  17. Annex A — Processing details
  18. Annex B — Security measures

In plain English

When you use eWorkPulse to monitor your workforce, you are the Data Fiduciary and we are your Processor. This document is the contract that says so, and sets out what we will and won't do with that data.

Professional-services firms — and their procurement teams — routinely need this on file. You can execute it by countersigning as described in Section 16.

1. About this agreement

This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between Neurovia Technologies ("Processor", "we") and the customer organisation ("Data Fiduciary", "you") that subscribes to eWorkPulse.

It applies where we process Personal Data on your behalf in providing the Services, and is written against India's Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 with the Reasonable Security Practices Rules, 2011.

Where this DPA conflicts with the Terms & Conditions on matters of data protection, this DPA prevails.

2. Definitions

  • Personal Data — any data about an identifiable individual processed through the Services.
  • Data Principal — the individual to whom the Personal Data relates, including your employees and contractors.
  • Data Fiduciary — the entity determining the purpose and means of processing. Under this DPA, that is you.
  • Processor — the entity processing on the Data Fiduciary's behalf. Under this DPA, that is us.
  • Sub-processor — a third party we engage to process Personal Data.
  • Personal Data Breach — unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises the confidentiality, integrity or availability of Personal Data.

3. Roles of the parties

You are the Data Fiduciary. You determine which individuals are monitored, what categories of data are collected, the purposes of monitoring, who may access it, and how long it is retained. You are responsible for the lawfulness of that processing, including giving notice to and obtaining any required consent from Data Principals.

We are the Processor. We process Personal Data only on your documented instructions, as set out in this DPA, the Terms & Conditions, and the configuration choices you make within the Services.

We act as Data Fiduciary in our own right only for your account, billing and support information, which is governed by our Privacy Policy rather than this DPA.

4. Scope of processing

The subject matter, duration, nature, purpose, categories of data and categories of Data Principals are described in Annex A.

Your configuration of the Services — which collection features you enable, which retention period you set, who you grant access to — constitutes your documented processing instructions. Additional instructions may be agreed in writing.

If we consider an instruction to infringe applicable data-protection law, we will inform you and may suspend that instruction until it is resolved.

5. Our obligations

We will:

  • process Personal Data only on your documented instructions and for the purpose of providing the Services;
  • not sell Personal Data, disclose it for advertising, or use it to train machine-learning or artificial-intelligence models;
  • not use Personal Data for our own purposes, other than generating aggregated and de-identified statistics that cannot reasonably identify you or any Data Principal;
  • ensure personnel authorised to process Personal Data are bound by confidentiality;
  • implement and maintain the security measures described in Annex B;
  • assist you, taking into account the nature of processing, in responding to Data Principal requests and in meeting your own security, breach-notification and impact-assessment obligations;
  • make available information reasonably necessary to demonstrate compliance with this DPA;
  • notify you without undue delay of any Personal Data Breach affecting your data;
  • delete or return Personal Data on termination, as set out in Section 13.

6. Your obligations

You will:

  • ensure you have a lawful basis for monitoring, and have given all notices and obtained all consents required by law before deploying the Agent;
  • configure the Services proportionately to your stated purpose, enabling only the collection features you can justify;
  • manage access within your organisation so that only authorised personnel can view monitoring data;
  • ensure the accuracy of employee records you enter or import;
  • respond as Data Fiduciary to Data Principal requests and complaints, with our assistance;
  • not send us Personal Data outside the scope of Annex A, and in particular not deliberately route special-category or financial account data through the Services.

We rely on your compliance with this section. Where a claim arises from your failure to give lawful notice or obtain consent, the indemnity in the Terms & Conditions applies.

7. Security measures

We implement appropriate technical and organisational measures to protect Personal Data against Personal Data Breach, described in Annex B and in full in our Data Security Policy.

We may update these measures as technology evolves, provided the overall level of protection is not reduced.

8. Sub-processors

You give general authorisation for us to engage Sub-processors to provide the Services. Each Sub-processor is subject to a written contract imposing data-protection obligations no less protective than this DPA, and we remain responsible to you for their performance.

Our current Sub-processors comprise cloud hosting (Amazon Web Services, Mumbai region), transactional email delivery and payment processing. A current list is available at privacy@eworkpulse.com.

We will give you at least 30 days' notice before adding or replacing a Sub-processor. If you have a reasonable data-protection objection, tell us within that period and we will work in good faith to find an alternative. If we cannot, you may terminate the affected Services with a pro-rata refund of prepaid fees.

Where you connect your own storage (Amazon S3, Google Drive or Microsoft OneDrive), that provider acts under your arrangements, not as our Sub-processor.

9. Data principal requests

Because we are the Processor, requests from your employees about their monitoring data should be directed to you.

If a Data Principal contacts us directly, we will not respond substantively; we will inform them to contact you, and notify you of the request without undue delay.

We will provide reasonable assistance — including access, correction, export and deletion functions within the Services — to help you respond within your statutory timeframes.

10. Breach notification

On becoming aware of a Personal Data Breach affecting your Personal Data, we will notify you without undue delay and in any event within 72 hours, providing the information available at that time, including:

  • the nature of the breach and, where possible, the categories and approximate number of Data Principals and records affected;
  • the likely consequences;
  • the measures taken or proposed to address it and mitigate adverse effects;
  • a contact point for further information.

Where full details are not immediately available, we will provide them in phases as the investigation progresses. As Data Fiduciary, you are responsible for notifying the Data Protection Board of India and affected Data Principals; we will provide the information you need to do so.

11. Audit & assurance

We will make available information reasonably necessary to demonstrate compliance with this DPA, including our Data Security Policy and responses to reasonable security questionnaires.

You may audit our compliance no more than once per twelve months (and additionally following a confirmed Personal Data Breach affecting your data), on at least 30 days' written notice, during business hours, without unreasonably disrupting our operations, and subject to confidentiality. Audits must not extend to data belonging to other customers.

Where we hold a relevant independent audit report or certification, providing it satisfies this obligation. See Certifications & assurance in our Data Security Policy for current status.

12. International transfers

Personal Data is stored and processed in India (AWS Asia Pacific, Mumbai) by default.

Limited transfers outside India may occur where a Sub-processor such as an email-delivery provider operates internationally, or where you direct data to storage you control in another jurisdiction. Any such transfer is made in accordance with applicable law and under appropriate contractual safeguards.

We will not transfer Personal Data to a jurisdiction restricted by the Central Government under the DPDP Act.

13. Return & deletion

During the subscription you may export Personal Data at any time through the Services.

On termination you have 30 days to export. We then delete or irreversibly anonymise Personal Data within 90 days of termination, except where retention is required by law. Backups are purged on their own rotation within 35 days.

On written request we will confirm deletion.

14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in the Terms & Conditions. Nothing in this DPA limits liability that cannot be limited under applicable law.

15. Term

This DPA takes effect when you accept the Terms & Conditions or execute it separately, and continues for as long as we process Personal Data on your behalf. Sections concerning confidentiality, deletion and liability survive termination.

16. How to execute this DPA

If your procurement process requires a signed DPA:

  1. Email privacy@eworkpulse.com with your registered entity name, address and signatory details.
  2. We will return a countersigned PDF of this DPA, completed with both parties' particulars.
  3. If you require your own DPA template instead, send it and we will review it.

Our particulars for the purposes of this DPA:

ProcessorNeurovia Technologies
Registered office319, Globe Estate NEXT, MIDC, Vikas Naka,
Dombivli (East), Thane – 421203,
Maharashtra, India
Contact for this DPAprivacy@eworkpulse.com
Governing lawIndia; courts at Thane, Maharashtra (see Terms & Conditions, Section 19)

Annex A — Processing details

Subject matterProvision of the eWorkPulse workforce-intelligence platform.
DurationThe subscription term, plus the deletion period in Section 13.
Nature of processingCollection, storage, organisation, aggregation, analysis, display, export and deletion.
PurposeWorkforce productivity analytics, capacity planning, attendance and activity reporting, billing verification, security and compliance monitoring — as determined by you.
Categories of Data PrincipalsYour employees, contractors and other personnel whose devices run the Agent; your administrator users.
Categories of Personal Data Identity and employment data (name, work email, department, team, designation, OS username).
Activity data (application names, window titles, browser URLs where available, active/idle time, timestamps).
Screenshots, where enabled by you.
Device and network data (device name, operating system, hardware specification, connected USB devices, local and public IP address, MAC address, installed software).
Special-category dataNot intentionally processed. Screenshots may incidentally capture such data depending on what is on screen; you should configure sensitive-content blurring and retention accordingly.
LocationIndia — AWS Asia Pacific (Mumbai), subject to Section 12.

Annex B — Security measures

Summarised here; described in full in our Data Security Policy.

AreaMeasure
Encryption in transitTLS 1.2+ for all agent, browser, mobile and API traffic.
Encryption at restAES-256 for database volumes and object storage.
CredentialsPasswords stored only as bcrypt hashes with per-password salt; third-party storage credentials encrypted.
AuthenticationSigned JWT sessions with bounded lifetime; HttpOnly and Secure cookies in production.
Access controlRole-based access; least privilege; individually attributed production access; periodic review.
Tenant isolationEvery record bound to an organisation; every query scoped to the authenticated session's organisation.
Data minimisationPer-organisation controls to disable screenshots, application tracking, web tracking and idle tracking; enforced on the device before transmission.
Screenshot protectionOptional sensitive-content blurring applied before storage; authenticated-only image delivery; automated retention-based deletion.
BackupsEncrypted daily backups retained on rotation within the same jurisdiction.
Change managementVersion control, peer review before production, separated environments, dependency vulnerability monitoring.
Incident responseDocumented process; customer notification within 72 hours of confirming a Personal Data Breach.
Related documents
Privacy Policy Terms & Conditions Data Security Policy Contact us
logo

Next-generation workforce intelligence platform for remote & hybrid teams. Real data. Real insights. No micromanagement.

Product
  • All Features
  • How It Works
  • Pricing
  • Request Demo
Legal
  • Privacy Policy
  • Terms & Conditions
  • Data Security Policy
  • Data Processing Agreement
Company
  • Contact Sales
  • Support
  • Privacy Enquiries
Privacy Policy·Terms & Conditions·Data Security·DPA © 2026 Neurovia Technologies. All rights reserved.