Data Processing Agreement
In plain English
When you use eWorkPulse to monitor your workforce, you are the Data Fiduciary and we are your Processor. This document is the contract that says so, and sets out what we will and won't do with that data.
Professional-services firms — and their procurement teams — routinely need this on file. You can execute it by countersigning as described in Section 16.
1. About this agreement
This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between Neurovia Technologies ("Processor", "we") and the customer organisation ("Data Fiduciary", "you") that subscribes to eWorkPulse.
It applies where we process Personal Data on your behalf in providing the Services, and is written against India's Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 with the Reasonable Security Practices Rules, 2011.
Where this DPA conflicts with the Terms & Conditions on matters of data protection, this DPA prevails.
2. Definitions
- Personal Data — any data about an identifiable individual processed through the Services.
- Data Principal — the individual to whom the Personal Data relates, including your employees and contractors.
- Data Fiduciary — the entity determining the purpose and means of processing. Under this DPA, that is you.
- Processor — the entity processing on the Data Fiduciary's behalf. Under this DPA, that is us.
- Sub-processor — a third party we engage to process Personal Data.
- Personal Data Breach — unauthorised processing, or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access, that compromises the confidentiality, integrity or availability of Personal Data.
3. Roles of the parties
You are the Data Fiduciary. You determine which individuals are monitored, what categories of data are collected, the purposes of monitoring, who may access it, and how long it is retained. You are responsible for the lawfulness of that processing, including giving notice to and obtaining any required consent from Data Principals.
We are the Processor. We process Personal Data only on your documented instructions, as set out in this DPA, the Terms & Conditions, and the configuration choices you make within the Services.
We act as Data Fiduciary in our own right only for your account, billing and support information, which is governed by our Privacy Policy rather than this DPA.
4. Scope of processing
The subject matter, duration, nature, purpose, categories of data and categories of Data Principals are described in Annex A.
Your configuration of the Services — which collection features you enable, which retention period you set, who you grant access to — constitutes your documented processing instructions. Additional instructions may be agreed in writing.
If we consider an instruction to infringe applicable data-protection law, we will inform you and may suspend that instruction until it is resolved.
5. Our obligations
We will:
- process Personal Data only on your documented instructions and for the purpose of providing the Services;
- not sell Personal Data, disclose it for advertising, or use it to train machine-learning or artificial-intelligence models;
- not use Personal Data for our own purposes, other than generating aggregated and de-identified statistics that cannot reasonably identify you or any Data Principal;
- ensure personnel authorised to process Personal Data are bound by confidentiality;
- implement and maintain the security measures described in Annex B;
- assist you, taking into account the nature of processing, in responding to Data Principal requests and in meeting your own security, breach-notification and impact-assessment obligations;
- make available information reasonably necessary to demonstrate compliance with this DPA;
- notify you without undue delay of any Personal Data Breach affecting your data;
- delete or return Personal Data on termination, as set out in Section 13.
6. Your obligations
You will:
- ensure you have a lawful basis for monitoring, and have given all notices and obtained all consents required by law before deploying the Agent;
- configure the Services proportionately to your stated purpose, enabling only the collection features you can justify;
- manage access within your organisation so that only authorised personnel can view monitoring data;
- ensure the accuracy of employee records you enter or import;
- respond as Data Fiduciary to Data Principal requests and complaints, with our assistance;
- not send us Personal Data outside the scope of Annex A, and in particular not deliberately route special-category or financial account data through the Services.
We rely on your compliance with this section. Where a claim arises from your failure to give lawful notice or obtain consent, the indemnity in the Terms & Conditions applies.
7. Security measures
We implement appropriate technical and organisational measures to protect Personal Data against Personal Data Breach, described in Annex B and in full in our Data Security Policy.
We may update these measures as technology evolves, provided the overall level of protection is not reduced.
8. Sub-processors
You give general authorisation for us to engage Sub-processors to provide the Services. Each Sub-processor is subject to a written contract imposing data-protection obligations no less protective than this DPA, and we remain responsible to you for their performance.
Our current Sub-processors comprise cloud hosting (Amazon Web Services, Mumbai region), transactional email delivery and payment processing. A current list is available at privacy@eworkpulse.com.
We will give you at least 30 days' notice before adding or replacing a Sub-processor. If you have a reasonable data-protection objection, tell us within that period and we will work in good faith to find an alternative. If we cannot, you may terminate the affected Services with a pro-rata refund of prepaid fees.
Where you connect your own storage (Amazon S3, Google Drive or Microsoft OneDrive), that provider acts under your arrangements, not as our Sub-processor.
9. Data principal requests
Because we are the Processor, requests from your employees about their monitoring data should be directed to you.
If a Data Principal contacts us directly, we will not respond substantively; we will inform them to contact you, and notify you of the request without undue delay.
We will provide reasonable assistance — including access, correction, export and deletion functions within the Services — to help you respond within your statutory timeframes.
10. Breach notification
On becoming aware of a Personal Data Breach affecting your Personal Data, we will notify you without undue delay and in any event within 72 hours, providing the information available at that time, including:
- the nature of the breach and, where possible, the categories and approximate number of Data Principals and records affected;
- the likely consequences;
- the measures taken or proposed to address it and mitigate adverse effects;
- a contact point for further information.
Where full details are not immediately available, we will provide them in phases as the investigation progresses. As Data Fiduciary, you are responsible for notifying the Data Protection Board of India and affected Data Principals; we will provide the information you need to do so.
11. Audit & assurance
We will make available information reasonably necessary to demonstrate compliance with this DPA, including our Data Security Policy and responses to reasonable security questionnaires.
You may audit our compliance no more than once per twelve months (and additionally following a confirmed Personal Data Breach affecting your data), on at least 30 days' written notice, during business hours, without unreasonably disrupting our operations, and subject to confidentiality. Audits must not extend to data belonging to other customers.
Where we hold a relevant independent audit report or certification, providing it satisfies this obligation. See Certifications & assurance in our Data Security Policy for current status.
12. International transfers
Personal Data is stored and processed in India (AWS Asia Pacific, Mumbai) by default.
Limited transfers outside India may occur where a Sub-processor such as an email-delivery provider operates internationally, or where you direct data to storage you control in another jurisdiction. Any such transfer is made in accordance with applicable law and under appropriate contractual safeguards.
We will not transfer Personal Data to a jurisdiction restricted by the Central Government under the DPDP Act.
13. Return & deletion
During the subscription you may export Personal Data at any time through the Services.
On termination you have 30 days to export. We then delete or irreversibly anonymise Personal Data within 90 days of termination, except where retention is required by law. Backups are purged on their own rotation within 35 days.
On written request we will confirm deletion.
14. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms & Conditions. Nothing in this DPA limits liability that cannot be limited under applicable law.
15. Term
This DPA takes effect when you accept the Terms & Conditions or execute it separately, and continues for as long as we process Personal Data on your behalf. Sections concerning confidentiality, deletion and liability survive termination.
16. How to execute this DPA
If your procurement process requires a signed DPA:
- Email privacy@eworkpulse.com with your registered entity name, address and signatory details.
- We will return a countersigned PDF of this DPA, completed with both parties' particulars.
- If you require your own DPA template instead, send it and we will review it.
Our particulars for the purposes of this DPA:
| Processor | Neurovia Technologies |
|---|---|
| Registered office | 319, Globe Estate NEXT, MIDC, Vikas Naka, Dombivli (East), Thane – 421203, Maharashtra, India |
| Contact for this DPA | privacy@eworkpulse.com |
| Governing law | India; courts at Thane, Maharashtra (see Terms & Conditions, Section 19) |
Annex A — Processing details
| Subject matter | Provision of the eWorkPulse workforce-intelligence platform. |
|---|---|
| Duration | The subscription term, plus the deletion period in Section 13. |
| Nature of processing | Collection, storage, organisation, aggregation, analysis, display, export and deletion. |
| Purpose | Workforce productivity analytics, capacity planning, attendance and activity reporting, billing verification, security and compliance monitoring — as determined by you. |
| Categories of Data Principals | Your employees, contractors and other personnel whose devices run the Agent; your administrator users. |
| Categories of Personal Data |
Identity and employment data (name, work email, department, team, designation, OS username). Activity data (application names, window titles, browser URLs where available, active/idle time, timestamps). Screenshots, where enabled by you. Device and network data (device name, operating system, hardware specification, connected USB devices, local and public IP address, MAC address, installed software). |
| Special-category data | Not intentionally processed. Screenshots may incidentally capture such data depending on what is on screen; you should configure sensitive-content blurring and retention accordingly. |
| Location | India — AWS Asia Pacific (Mumbai), subject to Section 12. |
Annex B — Security measures
Summarised here; described in full in our Data Security Policy.
| Area | Measure |
|---|---|
| Encryption in transit | TLS 1.2+ for all agent, browser, mobile and API traffic. |
| Encryption at rest | AES-256 for database volumes and object storage. |
| Credentials | Passwords stored only as bcrypt hashes with per-password salt; third-party storage credentials encrypted. |
| Authentication | Signed JWT sessions with bounded lifetime; HttpOnly and Secure cookies in production. |
| Access control | Role-based access; least privilege; individually attributed production access; periodic review. |
| Tenant isolation | Every record bound to an organisation; every query scoped to the authenticated session's organisation. |
| Data minimisation | Per-organisation controls to disable screenshots, application tracking, web tracking and idle tracking; enforced on the device before transmission. |
| Screenshot protection | Optional sensitive-content blurring applied before storage; authenticated-only image delivery; automated retention-based deletion. |
| Backups | Encrypted daily backups retained on rotation within the same jurisdiction. |
| Change management | Version control, peer review before production, separated environments, dependency vulnerability monitoring. |
| Incident response | Documented process; customer notification within 72 hours of confirming a Personal Data Breach. |