DATA PROCESSING AGREEMENT
Last Updated: August 23, 2026
BRedPixel Data Processing Agreement
This Data Processing Agreement (“DPA“) forms part of the agreement between:
BRedPixel (“BRedPixel“, “we“, “us“, or “Processor“)
and
The authorised business customer / service-centre operator (“Customer“, “you“, “Business Customer“, or “Data Fiduciary“).
BRedPixel and the Business Customer are individually referred to as a “Party” and collectively as the “Parties“.
This DPA applies where BRedPixel processes personal data on behalf of the Business Customer in connection with the BRedPixel Service.
This DPA is intended to govern the processing of personal data in accordance with applicable Indian data-protection law, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and applicable rules made thereunder.
Under the DPDP Act, a Data Processor processes personal data on behalf of a Data Fiduciary, and a Data Fiduciary may engage a Data Processor for processing in connection with offering goods or services only under a valid contract.
1. Purpose of this DPA
The purpose of this DPA is to establish the rights and responsibilities of the Parties regarding personal data processed by BRedPixel on behalf of the Business Customer.
This DPA covers:
- The categories of personal data processed;
- The purposes of processing;
- Processing instructions;
- Security measures;
- Confidentiality;
- Sub-processors;
- Data retention and deletion;
- Personal data breach cooperation;
- Data Principal requests;
- Termination;
- Return/deletion of personal data; and
- Other applicable data-protection responsibilities.
2. Relationship Between the Parties
For personal data covered by this DPA:
Business Customer = Data Fiduciary
BRedPixel = Data Processor
The Business Customer determines the purpose for which its customers’ personal data is processed through BRedPixel.
BRedPixel processes such personal data only for the purposes described in this DPA and according to the Business Customer’s documented instructions, subject to applicable law.
This DPA does not determine the legal status of BRedPixel for processing activities where BRedPixel independently determines the purpose and means of processing, such as its own account, subscription, licensing, security, and support data.
For such processing, BRedPixel may act as a Data Fiduciary under its Privacy Policy.
3. Data Principal
For the purposes of this DPA, the Data Principal is the individual whose personal data is uploaded, provided, retrieved, processed, printed, or otherwise handled through the Business Customer’s use of BRedPixel.
The Data Principal is generally the Business Customer’s customer/citizen and is separate from the Business Customer/agent.
4. Processing Flow
The Parties acknowledge that the intended customer-document processing flow is:
Citizen/Customer → QR Code or Secure Link → BRedPixel Upload Page → Firebase Temporary Storage → BRedPixel Windows Application → Requested Service → Deletion
The requested service may include:
- Document printing;
- Photograph processing;
- Document processing;
- Document verification; or
- Other functionality expressly provided through the Service.
5. Categories of Personal Data
Depending on the service requested, BRedPixel may process the following categories of personal data on behalf of the Business Customer:
5.1 Citizen/Customer Name
The name voluntarily provided by the Data Principal or Business Customer for the requested service.
5.2 Mobile Number
A mobile number may be provided where required for the requested service.
The mobile number is not required where the relevant service does not require it.
5.3 Photographs
Photographs uploaded for printing or other requested image-related services.
5.4 Documents
Documents uploaded by the Data Principal or Business Customer may include:
- Identity documents;
- Government-issued documents;
- Application forms;
- PDF documents;
- Photographs; and
- Other files required for the requested service.
The exact content of a document may contain additional personal information.
5.5 Technical Information
BRedPixel may process limited technical information necessary to operate the upload system, secure the Service, or maintain the relevant transaction.
This may include information such as:
- Upload timestamp;
- Technical identifiers;
- Security information; and
- Other minimum technical metadata required to operate and secure the Service.
BRedPixel will seek to minimise unnecessary collection.
6. Purpose of Processing
BRedPixel shall process the personal data covered by this DPA only for purposes instructed by the Business Customer and necessary to provide the requested Service.
Permitted purposes include:
- Receiving customer-uploaded documents;
- Temporarily storing uploaded documents;
- Making uploaded documents available to the authorised Business Customer;
- Printing documents;
- Processing photographs;
- Performing requested document-processing functions;
- Facilitating requested verification services;
- Maintaining security of the Service;
- Detecting and preventing misuse;
- Troubleshooting technical problems; and
- Performing other processing expressly authorised by the Business Customer and permitted by applicable law.
BRedPixel shall not intentionally use customer-uploaded personal data for:
- Advertising;
- Selling personal data;
- Unrelated commercial profiling;
- AI model training; or
- Unrelated commercial purposes.
7. Business Customer Instructions
The Business Customer shall provide lawful and appropriate instructions concerning the processing of personal data.
BRedPixel shall process personal data according to such instructions unless:
- The processing is required by applicable law;
- The instruction is unlawful;
- The instruction creates a material security risk; or
- Processing is necessary to protect the security or integrity of the Service.
If BRedPixel reasonably believes that an instruction violates applicable data-protection law, BRedPixel may notify the Business Customer and take appropriate steps to address the issue.
8. Lawful Collection and Customer Notice
The Business Customer is responsible for ensuring that it has the appropriate lawful basis, consent, authorisation, or other permission required for processing the Data Principal’s personal data.
The Business Customer shall ensure that the Data Principal receives any notice required by applicable law.
Where consent is the applicable legal basis, the Business Customer shall ensure that appropriate consent is obtained.
The intended BRedPixel customer-upload flow may display a notice such as:
Your information will be processed for the service requested from this service centre. The information you provide may include your name, mobile number, photograph, or documents. Your information will be temporarily processed through BRedPixel for the requested service and will be deleted from BRedPixel’s temporary cloud storage within 24 hours, subject to applicable legal or security requirements.
☐ I agree to the processing of my information for this service.
The actual notice and consent mechanism may be updated by BRedPixel or the Business Customer to comply with applicable law.
The consent mechanism should not be used to authorise processing that is prohibited by law.
9. Data Minimisation
The Business Customer shall seek to provide only personal data reasonably necessary for the requested service.
BRedPixel shall not intentionally require unnecessary personal data for a service where such information is not reasonably necessary.
The Parties shall cooperate in maintaining appropriate data minimisation practices.
10. Temporary Storage
Customer-uploaded documents are temporarily stored using BRedPixel’s cloud infrastructure, including Google Firebase.
The intended retention period is:
Up to twenty-four (24) hours from upload.
BRedPixel will use reasonable technical measures to protect the documents during this temporary processing period.
BRedPixel does not intentionally maintain a permanent archive of customer-uploaded documents.
11. Deletion of Customer Documents
BRedPixel shall configure its Service to automatically delete customer-uploaded documents from BRedPixel-controlled temporary cloud storage within the stated 24-hour period, subject to applicable technical, security, or legal requirements.
Where deletion is required under applicable law or the Business Customer’s lawful instructions, BRedPixel shall take reasonable steps to delete the relevant personal data from BRedPixel-controlled systems.
The Business Customer acknowledges that:
- Third-party systems may have their own retention policies;
- Government portals may independently retain information;
- External verification providers may have separate retention requirements; and
- Local information stored on the Business Customer’s computer is not necessarily controlled by BRedPixel.
12. Local Processing and Local Data
The Parties acknowledge that many BRedPixel features operate locally on the Business Customer’s computer.
Examples may include:
- Local photo processing;
- Image compression;
- Text-to-PDF;
- Local document processing;
- Local photographs;
- Local customer records;
- Printing history; and
- Other locally stored business information.
BRedPixel does not treat such locally stored information as BRedPixel-controlled cloud data merely because the BRedPixel software operates on the Business Customer’s computer.
The Business Customer is responsible for securing and managing locally stored information under its control.
Where BRedPixel provides a technical facility for deleting locally stored BRedPixel application data, the Business Customer may use that facility according to the applicable instructions.
13. Security Measures
BRedPixel shall implement reasonable technical and organisational measures appropriate to the nature of the personal data processed.
Depending on the applicable system, security measures may include:
- HTTPS/TLS encrypted transmission;
- Encryption during storage;
- Firebase security controls;
- Authentication;
- Access controls;
- Restricted administrative access;
- Device authentication/licensing;
- Security monitoring;
- Access logging where applicable;
- Secure credentials and permissions; and
- Measures designed to detect and prevent unauthorised access.
The Parties acknowledge that no internet-connected system can guarantee absolute security.
The DPDP framework requires reasonable security safeguards, and the 2025 Rules address measures such as encryption, access control, monitoring, logs and processor security arrangements.
14. Confidentiality
BRedPixel shall ensure that persons authorised to process personal data under its control are subject to appropriate confidentiality obligations.
Personal data processed under this DPA shall not be intentionally disclosed to unauthorised persons.
The Business Customer shall also ensure that its employees, agents, operators, and authorised personnel maintain appropriate confidentiality regarding customer information.
15. Access Control
BRedPixel shall use reasonable access controls to limit access to personal data.
The Business Customer shall:
- Restrict access to authorised personnel;
- Protect account credentials;
- Prevent unauthorised access to the registered computer;
- Avoid sharing BRedPixel accounts;
- Protect customer documents; and
- Notify BRedPixel of suspected unauthorised access.
The Business Customer remains responsible for access to customer data that occurs through its own employees, agents, devices, credentials, or local systems.
16. Sub-Processors and Third-Party Service Providers
BRedPixel may use third-party service providers to provide infrastructure or functionality required for the Service.
Depending on the Service, these may include:
- Google Firebase;
- Cloud infrastructure providers;
- Payment service providers where relevant;
- Verification/API providers;
- DigiLocker or authorised government/API services; and
- Other service providers reasonably required to provide the Service.
Where BRedPixel engages a third party to process personal data on BRedPixel’s behalf, BRedPixel shall use appropriate contractual and security arrangements consistent with applicable law.
Third-party government services or APIs that independently determine their own processing are not necessarily BRedPixel sub-processors merely because BRedPixel provides an integration or access mechanism.
17. Government and Verification Services
Where the Business Customer uses BRedPixel to access or facilitate a government or verification service, the Business Customer is responsible for using that service in accordance with the applicable:
- Terms;
- API rules;
- Consent requirements;
- Authentication requirements;
- Government requirements; and
- Applicable law.
BRedPixel does not authorise the Business Customer to bypass government authentication, OTP, consent, access controls, API restrictions, or security mechanisms.
18. Personal Data Breach
If BRedPixel becomes aware of a personal data breach affecting personal data processed under this DPA, BRedPixel shall take reasonable steps to:
- Contain the incident;
- Investigate the incident;
- Assess the affected information;
- Mitigate potential harm;
- Secure affected systems;
- Preserve relevant incident information; and
- Cooperate with the Business Customer regarding applicable legal obligations.
Where required, BRedPixel shall notify the Business Customer without undue delay after becoming aware of the relevant breach.
The Business Customer shall reasonably cooperate with BRedPixel in investigating and responding to a breach.
The Data Fiduciary remains responsible for its statutory notification obligations under applicable law, while BRedPixel shall provide reasonable cooperation and information required for such response.
The DPDP Act requires the Data Fiduciary to notify the Board and affected Data Principals in the prescribed manner in the event of a personal data breach. The notified Rules provide specific breach-notification requirements, including prompt communication to affected Data Principals and information to the Board.
19. Data Principal Requests
Where a Data Principal requests access, correction, updating, erasure, withdrawal of consent, or other applicable rights from the Business Customer, the Business Customer shall handle the request as the relevant Data Fiduciary.
Where the request requires BRedPixel to assist, the Business Customer may request reasonable assistance from BRedPixel.
BRedPixel shall take reasonable steps to assist the Business Customer with requests relating to personal data under BRedPixel’s control, subject to:
- Applicable law;
- Technical feasibility;
- Security requirements; and
- Verification of the request.
The Business Customer shall not request BRedPixel to delete data where retention is required by law.
20. Correction and Data Accuracy
The Business Customer is responsible for the accuracy and completeness of information supplied by it for processing.
Where personal data is used by the Business Customer to make a decision affecting a Data Principal or is disclosed to another Data Fiduciary, the Business Customer shall take reasonable steps to ensure that the relevant information is complete, accurate, and consistent as required by applicable law.
21. Children’s Personal Data
If the Business Customer uses BRedPixel to process personal data of a person under 18 years of age, the Business Customer shall comply with applicable requirements relating to children’s personal data.
The Business Customer shall obtain any required consent or authorisation and shall provide any required notice.
The Business Customer shall not use BRedPixel to process children’s personal data for unlawful or unrelated purposes.
BRedPixel shall process such data only for the permitted service and according to the applicable instructions.
22. Processing of Sensitive or Government Documents
The Business Customer acknowledges that uploaded documents may contain highly sensitive or important personal information.
The Business Customer shall:
- Upload only documents required for the requested service;
- Avoid unnecessary copies;
- Prevent unauthorised access;
- Use documents only for authorised purposes;
- Follow applicable government requirements; and
- Follow any specific legal or contractual restrictions applicable to the relevant document or service.
BRedPixel does not represent that processing a particular government document is legally permitted merely because the Service technically supports document upload.
The Business Customer remains responsible for ensuring that its particular use of a government document or verification service is legally authorised.
23. International Processing
BRedPixel may use infrastructure or service providers that process information outside India.
Where applicable, the Parties shall comply with restrictions or requirements relating to processing personal data outside India under applicable Indian law.
The DPDP Act contains specific provisions concerning processing of digital personal data outside India.
24. Audit and Compliance Cooperation
The Business Customer may request reasonable information from BRedPixel necessary to demonstrate compliance with the processing obligations applicable to BRedPixel under this DPA.
BRedPixel may provide relevant information concerning:
- Security controls;
- Processing practices;
- Data retention;
- Deletion procedures;
- Sub-processors; and
- Data breach response.
Any audit or assessment shall:
- Be reasonable in scope;
- Respect BRedPixel’s security;
- Protect confidential information;
- Not unreasonably disrupt the Service; and
- Be subject to reasonable notice.
BRedPixel is not required to disclose confidential information, security credentials, source code, or information that would create a material security risk.
25. Assistance with Compliance
Taking into account the nature of processing and information reasonably available to BRedPixel, BRedPixel shall provide reasonable assistance to the Business Customer regarding:
- Personal data security;
- Data breach response;
- Deletion of BRedPixel-controlled data;
- Data Principal requests; and
- Other applicable processor obligations.
The Business Customer remains responsible for determining the lawful purpose and legal basis for its processing activities.
26. Prohibited Instructions
The Business Customer shall not instruct BRedPixel to:
- Process personal data for unlawful purposes;
- Circumvent government authentication;
- Bypass security controls;
- Access data without authorisation;
- Process data beyond the agreed purpose without lawful authority;
- Retain customer data beyond the applicable retention requirement without lawful basis; or
- Violate applicable law.
BRedPixel may refuse or suspend an instruction that it reasonably believes would violate applicable law or create a significant security risk.
27. Return and Deletion Upon Termination
Upon termination of the Business Customer’s BRedPixel subscription or the applicable processing relationship:
- BRedPixel shall cease processing customer personal data except where continued processing is required by law or necessary for legitimate security, dispute, or legal purposes;
- Customer-uploaded temporary documents shall remain subject to the applicable deletion process;
- BRedPixel shall delete eligible personal data from BRedPixel-controlled systems in accordance with applicable retention requirements; and
- The Business Customer shall remain responsible for deleting personal data stored locally on its own devices.
The Parties acknowledge that BRedPixel does not control data independently retained by government portals, third-party providers, or the Business Customer’s own local systems.
28. Data Retention
The primary retention period for customer-uploaded documents processed through the BRedPixel upload system is:
Up to 24 hours from upload.
Other data processed by BRedPixel may have different retention periods where necessary for:
- Account management;
- Subscription management;
- Security;
- Fraud prevention;
- Customer support;
- Legal obligations;
- Tax/accounting requirements; or
- Dispute resolution.
The Business Customer acknowledges that the 24-hour deletion commitment applies specifically to customer-uploaded documents in BRedPixel-controlled temporary cloud storage and does not automatically apply to local data or independent third-party systems.
29. Confidential Business Information
The Parties shall maintain confidentiality of non-public business, technical, operational, and security information received from the other Party.
Confidential information shall not be disclosed except:
- To authorised personnel;
- To authorised service providers;
- Where necessary to provide the Service;
- Where required by law; or
- With appropriate authorisation.
30. Relationship with BRedPixel Privacy Policy
The BRedPixel Privacy Policy applies to BRedPixel’s processing activities.
This DPA applies specifically to processing performed by BRedPixel on behalf of the Business Customer.
Where the Business Customer’s own privacy notice applies to its processing activities, the Business Customer remains responsible for maintaining that notice.
Where there is a conflict:
- Mandatory applicable law shall prevail;
- This DPA shall govern the specific processor relationship; and
- The BRedPixel Privacy Policy shall govern BRedPixel’s independent Data Fiduciary processing.
31. Security Incident Cooperation
Each Party shall reasonably cooperate with the other in relation to security incidents affecting personal data processed under this DPA.
The Business Customer shall promptly provide BRedPixel with relevant information where the incident involves BRedPixel systems or services.
BRedPixel shall provide reasonable information concerning incidents affecting BRedPixel-controlled systems.
Neither Party shall make misleading or unauthorised public statements concerning the other Party’s security incident without prior coordination, except where disclosure is required by law.
32. Term and Termination
This DPA becomes effective when the Business Customer accepts the applicable BRedPixel Terms and DPA or otherwise enters into a contractual relationship incorporating this DPA.
The DPA remains effective for as long as BRedPixel processes personal data on behalf of the Business Customer.
The obligations concerning:
- Confidentiality;
- Security;
- Data deletion;
- Data breach cooperation;
- Applicable legal requirements; and
- Other provisions that by their nature should survive
shall survive termination to the extent applicable.
33. No Transfer of Ownership
The Business Customer retains its rights and interests in personal data it provides for processing.
BRedPixel does not obtain ownership of the Business Customer’s customer personal data merely by processing it as a Data Processor.
BRedPixel receives only the rights reasonably necessary to provide the agreed Service and perform the processing described in this DPA.
34. Compliance with Applicable Law
Each Party shall comply with laws applicable to its respective activities under this DPA.
This DPA is intended to operate consistently with applicable Indian law, including, where applicable:
- Digital Personal Data Protection Act, 2023;
- Digital Personal Data Protection Rules, 2025;
- Information Technology Act, 2000;
- Applicable rules and regulations;
- Applicable government portal requirements;
- Applicable API terms; and
- Other applicable Indian laws.
This DPA does not grant either Party permission to perform an activity that is otherwise prohibited by law.
35. Liability
Each Party remains responsible for its own acts and omissions under applicable law.
Nothing in this DPA:
- Excludes a liability that cannot legally be excluded;
- Removes statutory obligations;
- Authorises unlawful processing; or
- Transfers a statutory obligation that cannot legally be transferred.
Any contractual limitation of liability between the Parties shall be governed by the applicable BRedPixel Terms and Conditions or other written agreement, subject to mandatory law.
36. Changes to this DPA
BRedPixel may update this DPA where reasonably necessary due to:
- Changes in applicable law;
- Changes in the Service;
- Changes in security requirements;
- Changes in data-processing practices; or
- Changes in third-party infrastructure.
Where a material change substantially affects the Business Customer’s processing obligations, BRedPixel will provide reasonable notice where required.
37. Governing Law
This DPA shall be governed by the laws of India.
Subject to any mandatory statutory jurisdiction, disputes relating to this DPA shall be subject to the jurisdiction of competent courts in India.
Nothing in this DPA prevents either Party from approaching a statutory authority or exercising a mandatory legal right or remedy.
38. Entire Data Processing Arrangement
This DPA, together with the applicable BRedPixel Terms and Conditions, Privacy Policy, and any other written agreement expressly incorporated into the processing relationship, constitutes the agreement between the Parties concerning the processing of personal data under the Service.
If a separate signed DPA exists between the Parties, that signed DPA shall prevail over this standard DPA to the extent of any conflict.
39. Acceptance
The Business Customer may accept this DPA electronically through the BRedPixel software, website, account-registration process, subscription process, or another method provided by BRedPixel.
By accepting this DPA, the Business Customer confirms that:
- It is authorised to enter into the agreement;
- It will use BRedPixel only for lawful purposes;
- It will provide appropriate instructions to BRedPixel;
- It will obtain required customer consent or other lawful authorisation;
- It will protect customer personal data under its control; and
- It will comply with applicable data-protection and other laws.
40. Contact
For questions concerning this DPA or personal-data processing:
BRedPixel
Privacy & Data Protection Contact
Email: office@bredpixel.online