Data Processing Addendum
The terms on which Mithavo processes personal data on behalf of a customer, written for the procurement, IT and legal reviewers who have to sign off before a regulated manufacturer goes live. This page reproduces the standard addendum; a counter-signed copy is available on request.
- Processor
- Mithavo Technologies Pvt. Ltd.
- Controller
- The customer named in the order form
- Governing law
- DPDP Act, 2023 · India
- Breach notice
- Without undue delay, target 72 hours
01 · Roles
Who is what
This addendum forms part of the subscription agreement between Mithavo Technologies Pvt. Ltd. ("Processor") and the customer named in the order form ("Controller"). It applies whenever Mithavo processes personal data contained in Controller data.
The Controller determines the purposes and means of processing and is responsible for the lawfulness of the data it loads into its tenant, including having a lawful basis and providing notice to its own employees, contacts and vendors. Mithavo acts only as a processor for that data.
For data Mithavo determines the purpose of — website enquiries, marketing contacts, billing contacts — Mithavo is the fiduciary and the Privacy Policy applies instead.
02 · Scope
Subject matter, duration, nature and categories
| Element | Description |
|---|---|
| Subject matter | Provision of the Mithavo ERP, CRM, CMS and master-data platform |
| Duration | The term of the subscription, plus the deletion window in section 08 |
| Nature of processing | Storage, retrieval, structuring, display, transmission, backup, audit logging, deletion |
| Purpose | Delivering the contracted service and its support, security and availability |
| Categories of data subject | Controller's employees and users, customer contacts, vendor and supplier contacts, applicants |
| Categories of personal data | Identity and contact details, employment role and permissions, activity and approval records, and any personal data the Controller chooses to place in records, documents or free-text fields |
| Special / sensitive data | Not required by the service. If the Controller loads it, the Controller is responsible for its lawful basis and must tell Mithavo in advance so that additional controls can be agreed |
| Location | Hosted in India unless a different region is agreed in writing in the order form |
03 · Instructions
Processing on documented instructions
Mithavo processes Controller data only on the Controller's documented instructions, which comprise the subscription agreement, this addendum, the configuration the Controller applies in the product, and support requests the Controller raises. Mithavo will not use Controller data for its own purposes, will not sell it, and will not use it to train machine-learning models made available to other customers.
Personnel with access to Controller data are bound by confidentiality obligations and are granted access on a least-privilege, need-to-know basis. Administrative access to production is restricted and logged.
If Mithavo is required by law to process data beyond the Controller's instructions, it will inform the Controller before doing so unless the law prohibits that notice.
04 · Security
Technical and organisational measures
| Control area | Measure in place |
|---|---|
| Access control | Role-based permissions, per-tenant isolation, unique named accounts, administrative access restricted and logged |
| Authentication | Password hashing, email OTP verification on sensitive flows, session expiry and invalidation |
| Encryption | TLS for data in transit; encryption at rest for the managed database and object storage |
| Auditability | Immutable audit trail of record creation, change and approval events, exportable for inspection |
| Backup & recovery | Automated backups of the managed database with point-in-time recovery within the retention window |
| Change management | Version-controlled deployments, code review, environment separation between development and production |
| Monitoring | Application error and availability monitoring with alerting |
| Vendor management | Sub-processors engaged under written terms no less protective than this addendum |
05 · Sub-processors
Authorised sub-processors
The Controller grants general authorisation for Mithavo to engage sub-processors for the categories below. The current named list per category is provided on request and to customers on a signed DPA, and Mithavo gives at least 30 days' written notice before adding or replacing a sub-processor, during which the Controller may object on reasonable data-protection grounds.
| Category | Function | Data reached |
|---|---|---|
| Cloud hosting & database | Application hosting, managed PostgreSQL, object storage, backups | All Controller data |
| Transactional email | Verification, notification and system emails | Recipient name, email address, message content |
| Error & performance monitoring | Diagnostics for availability and defects | Technical metadata, user identifier, incidental data in stack traces |
| Support tooling | Ticketing and communication with Controller staff | Contact details and ticket content |
| Website analytics | Aggregated marketing-site measurement | Website visitors only — not tenant data |
Mithavo remains fully liable to the Controller for the performance of each sub-processor's obligations. To subscribe to sub-processor change notices, email privacy@mithavo.com.
06 · Incidents
Personal data breach notification
On becoming aware of a personal data breach affecting Controller data, Mithavo will notify the Controller's designated security contact without undue delay and, as a target, within 72 hours. The notice will describe the nature of the breach, the categories and approximate volume of data and data subjects affected so far as known, the likely consequences, and the measures taken or proposed.
Where full information is not available at the time of the first notice, Mithavo will provide it in phases as the investigation progresses, and will cooperate with the Controller's obligations to notify the Data Protection Board of India and affected data subjects. Mithavo will not make a public statement identifying the Controller without prior consultation, except where legally compelled.
Security contact: security@mithavo.com.
07 · Assistance
Data subject requests, audit and information rights
Data subject requests. The product gives the Controller the ability to access, correct, export and delete records directly. Where a request cannot be fulfilled through the product, Mithavo will provide reasonable assistance. If a data subject contacts Mithavo directly about Controller data, Mithavo will not respond substantively and will redirect the request to the Controller.
Information and audit. Mithavo will make available the information reasonably necessary to demonstrate compliance with this addendum, including responses to a security questionnaire and a description of controls. On not less than 30 days' notice, and no more than once in any 12-month period unless required by a regulator or following a breach, the Controller may conduct an audit at its own cost, subject to confidentiality, during business hours, and in a manner that does not compromise other customers' data.
Impact assessments. Mithavo will provide reasonable assistance with any data protection impact assessment or prior consultation the Controller is required to carry out, taking into account the nature of processing and the information available to Mithavo.
08 · Exit
Return and deletion on termination
On termination or expiry of the subscription, the Controller may export its data through the product or request an export from Mithavo, in a structured, machine-readable format, for 30 days after the effective termination date.
After that window, Mithavo will delete Controller data from production systems within 30 days, and from backups on the ordinary backup rotation cycle thereafter. Mithavo may retain data where required by law, in which case it remains subject to this addendum's confidentiality and security obligations and is not processed for any other purpose. Written confirmation of deletion is provided on request.
09 · Shared responsibility
Who is responsible for what
| Area | Mithavo | Customer |
|---|---|---|
| Platform security | Infrastructure, application code, encryption, backups, monitoring | — |
| User accounts | Authentication mechanism, session handling, role framework | Who is invited, which role they get, timely deactivation of leavers |
| Data content | Storage and integrity of what is submitted | Lawful basis, accuracy, minimisation, notice to its own data subjects |
| Retention | Honouring configured and contracted retention | Defining the retention policy that suits its regulatory obligations |
| Incident response | Detection, containment and notification of platform breaches | Notifying its regulator and data subjects; reporting suspected misuse to Mithavo |
| Regulatory validation | Providing audit trail, records and export capability | Its own GxP validation, SOPs and qualification of the system in its environment |
Effective date: 1 January 2026. This page is maintained by Mithavo and reproduces our standard processing terms for review. It is not legal advice, and the executed agreement between the parties prevails in the event of conflict.
10 · Contact
Privacy contact and request handling
Use the route that matches the matter. Contractual notices under this addendum are valid only when sent to the addresses below.
Privacy Office
DPA questions, data subject requests routed by a controller, deletion and export instructions.
Security & incidents
Suspected breaches, vulnerability reports, penetration-test and questionnaire requests.
Grievance Officer
Unresolved responses under the DPDP Act, 2023, before approaching the Data Protection Board of India.
Signed copies
Counter-signature, customer paper review and sub-processor change notices.
How a request is handled
- Intake and classification — we confirm within 7 working days whether the data is held by Mithavo as a fiduciary or inside a customer tenant where we act only as a processor.
- Routing — tenant-data requests are forwarded to the controlling customer's administrator; we do not act unilaterally on tenant data, and we tell the requester who the controller is.
- Assistance — for controller-instructed requests we provide search, export, correction and deletion support within the timelines in section 07.
- Execution and evidence — the action is performed, logged in the audit trail, and confirmed in writing with a reference number.
- Escalation — unresolved matters go to the Grievance Officer, then to the Data Protection Board of India.
Need this counter-signed?
Send us your paper or use ours — we will turn a DPA review around with your legal team in a single call.