Data Processing Addendum

Last updated: June 2026

This is a draft template, not legal advice. Have it reviewed by qualified counsel before you rely on it.

This addendum describes how KlaritiQ processes personal data on behalf of customers using KlaritiQ, in line with India's Digital Personal Data Protection Act, 2023 (DPDP). Enterprise customers can request a signed copy.

Roles

For data you submit about your organisation and people, you act as the Data Fiduciary and KlaritiQ acts as a Data Processor, processing data only on your documented instructions to provide KlaritiQ.

Scope of processing

We process assessment inputs, contact details, and usage data solely to deliver the assessment, score, benchmark, and roadmap, and to support and improve the service.

Security

We apply reasonable security safeguards including row-level security, access controls, and encryption in transit. We notify you without undue delay of any personal-data breach affecting your data.

Sub-processors

We use a limited set of sub-processors (e.g. cloud hosting and database providers) under contractual safeguards. A current list is available on request.

Data localisation & retention

We honour applicable Indian data-localisation requirements (including RBI rules where relevant) and retain data only as long as needed or as instructed by you, deleting or returning it on termination.

Data principal rights

We assist you in responding to access, correction, and erasure requests from data principals as required under DPDP.

Request a signed DPA

Email klaritiq@gmail.com to request a signed Data Processing Addendum.