**DATA PROCESSING AGREEMENT**

for PrimeHR (a product of Techstuff Private Limited)

# 1\. Parties

This Data Processing Agreement ("DPA" or "Agreement") is entered into between:

* Techstuff Private Limited, a company incorporated under the laws of India, having its registered office at First Floor, 95-C, Aaradhya Height, Gopur Square, Vaishali Nagar, Indore, Madhya Pradesh 452009, India ("Processor", "Techstuff", "we"), operating the PrimeHR HRMS platform; and

* **\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_**, having its registered office at **\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_** ("Fiduciary", "Customer", "you"),

each a "Party" and together the "Parties", collectively in connection with the Master Services Agreement / Subscription Agreement dated **\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_\_** between the Parties (the "Principal Agreement") for use of the PrimeHR platform ("Services").

This DPA supplements and forms part of the Principal Agreement. In the event of conflict between this DPA and the Principal Agreement regarding the processing of Personal Data, this DPA prevails.

# 2\. Definitions

* "DPDP Act" means the Digital Personal Data Protection Act, 2023 (India), and the Digital Personal Data Protection Rules, 2025 notified thereunder, as amended from time to time.

* "Data Principal" means the individual to whom the Personal Data relates, i.e., the Customer's employees, field staff, and other individuals whose data is processed through PrimeHR.

* "Data Fiduciary" means the entity that, alone or with others, determines the purpose and means of processing Personal Data: the Customer, in respect of its employees' data.

* "Data Processor" means the entity that processes Personal Data on behalf of a Data Fiduciary: Techstuff, in respect of the Services.

* "Personal Data" means any data about an individual who is identifiable by or in relation to such data, processed through the Services, including the categories described in Annex A.

* "Personal Data Breach" means any unauthorized or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to Personal Data that compromises its confidentiality, integrity, or availability.

* "Sub-processor" means any third party engaged by Techstuff to process Personal Data in connection with the Services, as listed in Annex C.

# 3\. Roles of the Parties

3.1  For the purposes of the DPDP Act, the Customer is the Data Fiduciary and Techstuff is the Data Processor in respect of Personal Data of the Customer's employees, field staff, and other Data Principals processed through the Services.

3.2  Techstuff shall process Personal Data only on documented instructions from the Customer, including instructions conveyed through the Customer's configuration of the Services (e.g., enabling GPS-based check-in for Field Force, enabling Time Tracking monitoring), except where required to do so by applicable law, in which case Techstuff shall inform the Customer of that legal requirement before processing, unless prohibited from doing so.

3.3  Techstuff shall not process Personal Data for any purpose other than: (a) providing and maintaining the Services; (b) complying with the Customer's documented instructions; and (c) complying with applicable law. Techstuff shall not use Personal Data for its own product analytics across customers, advertising, profiling, or any secondary purpose without the Customer's prior written consent.

# 4\. Nature, Purpose, and Categories of Processing

4.1  The nature, purpose, categories of Data Principals, and categories of Personal Data processed under this Agreement are described in Annex A (Description of Processing).

4.2  Techstuff shall process Personal Data only for the duration of the Principal Agreement and solely to the extent necessary to provide the Services.

# 5\. Confidentiality

5.1  Techstuff shall ensure that all personnel authorised to process Personal Data are bound by confidentiality obligations, whether by contract or as a statutory duty, and are trained on data protection requirements relevant to their role.

5.2  Access to Personal Data within PrimeHR shall be restricted on a role and need-to-know basis, as configured through the Customer's Roles & Permissions settings and Techstuff's internal access controls.

# 6\. Security of Processing

6.1  Techstuff shall implement and maintain appropriate technical and organisational measures to protect Personal Data against Personal Data Breach, having regard to the state of the art, the costs of implementation, and the nature, scope, and sensitivity of the Personal Data processed. These measures are described in Annex B (Security Measures) and include, at minimum:

* Encryption of Personal Data in transit (TLS) and at rest;

* Role-based access control (RBAC) restricting data visibility by module and organisational role;

* Comprehensive audit logging of access to and actions on Personal Data;

* Logical segregation of each Customer's data within the PrimeHR platform;

* Defined data retention and secure deletion procedures;

* Periodic internal security review of the platform and infrastructure.

6.2  Techstuff shall promptly notify the Customer of any material change to the security measures described in Annex B that reduces the level of protection afforded to Personal Data.

# 7\. Sub-processors

7.1  The Customer provides general authorisation for Techstuff to engage the Sub-processors listed in Annex C for the purposes described therein.

7.2  Techstuff shall enter into a written agreement with each Sub-processor imposing data protection obligations substantially equivalent to those set out in this DPA.

7.3  Techstuff remains fully liable to the Customer for the performance of each Sub-processor's obligations relating to Personal Data.

# 8\. Assistance with Data Principal Rights

8.1  Techstuff shall, taking into account the nature of the processing, provide reasonable technical and organisational assistance to the Customer to enable the Customer to respond to requests from Data Principals to exercise their rights under the DPDP Act, including the right to access, correct, update, and erase their Personal Data.

8.2  Where a Data Principal submits a request directly to Techstuff regarding data processed on the Customer's behalf, Techstuff shall promptly forward the request to the Customer and shall not respond directly, save to acknowledge receipt, unless otherwise instructed by the Customer.

8.3  Techstuff shall provide functionality within PrimeHR to enable the Customer to action Data Principal rights requests (access, correction, erasure) within the timelines prescribed under the DPDP Rules.

# 9\. Personal Data Breach Notification

9.1  Techstuff shall notify the Customer without undue delay, and in any event within 24 hours of becoming aware, of any Personal Data Breach affecting the Customer's Personal Data.

9.2  Such notification shall, to the extent then known, describe: (a) the nature of the breach; (b) the categories and approximate number of Data Principals and records affected; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address the breach and mitigate its effects.

9.3  Techstuff shall reasonably cooperate with the Customer in investigating the breach and in any notification the Customer is required to make to the Data Protection Board of India or affected Data Principals.

# 10\. Data Retention and Deletion

10.1  Techstuff shall retain Personal Data only for as long as necessary to provide the Services and in accordance with the retention schedule set out in Annex A, or as instructed by the Customer, whichever is shorter.

10.2  On termination or expiry of the Principal Agreement, or earlier upon the Customer's written request, Techstuff shall, at the Customer's election, delete or return all Personal Data (including copies held by Sub-processors) within 60 days, save where retention is required by applicable law, in which case Techstuff shall isolate and protect the data from further processing. Statutory records that the Customer is independently required to retain under applicable law (e.g., payroll or tax records) shall be exported to the Customer prior to deletion; Techstuff shall not retain such records on the Customer's behalf beyond this 60-day period.

# 11\. Cross-Border Data Transfer

11.1  Techstuff shall inform the Customer of the primary hosting region(s) for Personal Data processed through the Services, as set out in Annex B.

11.2  Techstuff shall not transfer Personal Data to any country or territory notified as restricted by the Central Government under the DPDP Act without the Customer's prior written consent and appropriate safeguards.

# 12\. Audit and Compliance

12.1  Techstuff shall make available to the Customer, on reasonable written request and no more than once per year (or following a Personal Data Breach), information reasonably necessary to demonstrate compliance with this DPA, including summaries of security assessments or audit reports where available.

12.2  Techstuff shall permit and reasonably cooperate with audits or inspections conducted by the Customer or its authorised third-party auditor, subject to 30 days' prior written notice, confidentiality, and scheduling that does not unreasonably disrupt Techstuff's operations. Audits shall occur no more than once per calendar year, save that Techstuff shall additionally permit an audit following a Personal Data Breach or a bona fide regulatory inquiry concerning the Services. The scope of any such audit shall be limited to the security measures described in Annex B, specifically access control, encryption, audit logging, and data retention practices, and shall not extend to source code, shared infrastructure, or the data of other customers. Each Party shall bear its own costs in connection with such audits.

# 13\. Liability and Indemnification

13.1  Each Party shall indemnify, defend, and hold harmless the other Party from and against any claims, damages, fines, or regulatory penalties arising out of that Party's breach of its obligations under this Agreement or the DPDP Act. Without limiting the foregoing: (a) the Processor shall be liable for damages caused by processing that fails to comply with obligations under the DPDP Act specifically directed at Data Processors, or that is carried out outside or contrary to the Fiduciary's lawful documented instructions; and (b) the Fiduciary shall be liable for damages arising from its unlawful instructions to the Processor or its own non-compliance with the DPDP Act as Data Fiduciary. Nothing in this clause shall be construed to make either Party liable for the other's independent violations of the DPDP Act.

# 14\. Term and Termination

14.1  This DPA commences on the effective date of the Principal Agreement and remains in effect for so long as Techstuff processes Personal Data on behalf of the Customer under the Principal Agreement.

14.2  Termination of the Principal Agreement automatically terminates this DPA, without prejudice to obligations that by their nature survive termination (including Sections 9, 10, and 13).

# 15\. Governing Law and Dispute Resolution

15.1  This Agreement shall be governed by the laws of India, and the courts at Indore, Madhya Pradesh shall have exclusive jurisdiction over any disputes arising out of or in connection with this Agreement.

# 16\. Signatures

IN WITNESS WHEREOF, the Parties have executed this Data Processing Agreement as of the date last signed below.

| For Techstuff Private Limited | For the Customer |
| :---- | :---- |
| Name: **Ajay Patidar** | Name: |
| Title: **Co-Founder** | Title: |
| Signature:  | Signature: |
| Date: | Date: |

# Annex A: Description of Processing

## A.1 Categories of Data Principals

* Customer's employees (permanent, contract, probationary)

* Field Force / field employees

## A.2 Categories of Personal Data

| PrimeHR Module | Data Captured | Retention (default) |
| :---- | :---- | :---- |
| Employee Directory / Profile | Name, contact details, DOB, gender, blood group, marital status, PAN, Aadhaar, bank/IFSC details | 2 years |
| Attendance Calendar / Matrix | Check-in/out timestamps, status codes, device/IP metadata | 2 years |
| Field Force: Live Map / Route History | GPS coordinates, route trail, visit duration, timestamps | 90 days (rolling) |
| Time Tracking | Activity/idle status; screenshot and keystroke monitoring data, where enabled by the Customer | 90 days (rolling) |
| Payroll | Salary components, bank account, PF/PT/ESIC/UAN, TDS declarations | 7 years (aligns with Income Tax Act 6-yr and PF/ESI 5–7-yr requirements; longer of the two applied as baseline) |
| Documents | ID proofs, certificates, uploaded files | 3 years post-employment |

*Retention periods for GPS route history and Time Tracking are rolling windows (oldest data purged as new data is captured), consistent with DPDP data minimisation principles for continuous monitoring data.*

## A.3 Purpose of Processing

To provide HRMS functionality to the Customer, including employee records management, attendance and leave tracking, payroll processing, field force and visit management, and related reporting, as configured by the Customer within the Services.

## A.4 Frequency

Continuous, for the duration of the Principal Agreement.

# Annex B: Security Measures

| Control Area | Measure |
| :---- | :---- |
| Encryption in transit | TLS enforced on all client-server and service-to-service communication |
| Encryption at rest | Firebase/Firestore: Google-managed default encryption at rest. MongoDB Atlas: default encryption at rest (AWS-managed). |
| Access control | Role-based access control (RBAC) via Roles & Permissions module; module- and record-level scoping |
| Audit logging | Centralized audit trail logging user actions across modules (viewable under Reports \> Audit Logs) |
| Data segregation | Logical segregation of each Customer's data within the multi-tenant platform |
| Hosting / data residency | MongoDB Atlas: AWS Mumbai (ap-south-1), India. Firebase/Firestore: Mumbai (asia-south1), India. |
| Backup & recovery | Weekly data backups; retained for 3 months. |
| Vulnerability management | Dependency and infrastructure vulnerabilities are tracked via npm audit; critical/high-severity vulnerabilities are patched within 7 days of disclosure, medium within 30 days. Cloud infrastructure (Firebase/GCP) inherits Google's patching cadence for underlying platform vulnerabilities. |
| Third-party security assessment | Internal security review process in place. Third-party penetration test planned for Q4 2026, following completion of current roadmap priorities. |
| Personnel | Confidentiality undertakings for personnel with access to Personal Data; access on a need-to-know basis |

# Annex C: Approved Sub-processors

| Sub-processor | Purpose | Location of Processing |
| :---- | :---- | :---- |
| Google Firebase / GCP | Application hosting, database (Firestore), file storage, authentication | Mumbai (asia-south1), India |
| MongoDB Atlas (AWS) | Application database | AWS Mumbai (ap-south-1), India |
| Twilio SendGrid | Transactional email delivery (notifications, alerts, reports) | Global (United States) |

*This list is maintained by Techstuff and shall be kept current and made available to the Customer in accordance with Section 7\.*