DPA
Our standard Data Processing Addendum. It forms part of the agreement between us whenever we process personal data on your behalf, and you can countersign it by email.
Last updated: · Applies to SupportCentral Enterprise, operated by Support IT Ventures.
1. Roles and scope
You are the Data Fiduciary (controller) for the personal data contained in your content. Support IT Ventures is the Data Processor. This addendum applies for as long as we process that data, and prevails over the main terms in the event of a conflict about data protection.
2. Subject matter and duration
Subject matter: the provision of SupportCentral Enterprise. Duration: the term of your subscription, plus the 90-day retrieval window. Nature and purpose: hosting, storing, transmitting and displaying your content so that your team can run a service desk.
3. Categories of data and data principals
Data principals: your employees, contractors and any person who contacts your desk. Categories: names, work and personal contact details, employment attributes such as department and manager, the content of support requests and any attachments your users upload, and records of equipment issued to a person.
4. Our obligations
- Process personal data only on your documented instructions, which include your configuration of the service.
- Ensure people authorised to process it are bound by confidentiality.
- Implement the technical and organisational measures described in our security page and in our privacy policy.
- Assist you, taking into account the nature of processing, in responding to data-principal requests and in meeting your own security and breach-notification obligations.
- Notify you without undue delay after becoming aware of a personal data breach affecting your content, with the information you need to meet your own obligations.
- At your choice, delete or return your content at the end of the service, subject to any retention the law requires of us.
5. Sub-processing
You give general authorisation for the sub-processors listed on our sub-processors page. We impose equivalent obligations on each, remain responsible for their performance, and give 30 days' notice before adding one, with a right for you to object and terminate.
6. Location and transfers
Your content is stored and processed in India. We will not transfer it outside India without telling you in advance and putting an appropriate safeguard in place.
7. Audit
On reasonable written notice, not more than once a year, we will answer a reasonable security questionnaire and provide the evidence available to us. Where you require an on-site audit, we will agree scope and timing in advance, and it will be at your cost.
7a. Security measures in detail
The technical and organisational measures we apply are set out on our security page and form part of this addendum: per-organisation isolation enforced at the query and tested automatically before each release; role-based access control checked server-side on every route; encryption of credentials and integration secrets at rest, and TLS in transit; append-only audit logging; encrypted backups with tested restores; two-factor authentication and logging on production access; and support access to a customer account only with a recorded reason, a time limit and an email to the account owner.
We will not weaken these during the term. If we change them, it will be to strengthen them, and the page will say what changed.
7b. Return and deletion
You can export your data yourself at any time, in any account state, at no charge. On termination we keep it for 90 days so you can retrieve it, warn you by email before the end of that window, and then delete it permanently from live systems. Backup copies age out on their normal retention schedule and are not restored to fulfil a request.
7c. Personnel
Access to production data is limited to named people whose role requires it, is protected by two-factor authentication, and is logged. Everyone with access is bound by confidentiality obligations that survive the end of their engagement.
8. Signing it
Write to security@supportcentral.in with your legal entity name and address. We will return a signed copy for countersignature by email, which both of us accept as valid execution.
Something here unclear or unfair? Tell us at support@supportcentral.in. We would rather fix the wording than argue about it later. See also Terms, Privacy and Grievance redressal.