What We DoAgentic AIProductsCustomersTechnologyAboutResourcesContact

Data Protection Agreement

This Data Protection Agreement ("Agreement") between Affinsys AI Pvt. Ltd. ("Affinsys") and the Customer (as defined in the Agreement) forms part of the Affinsys AI Pvt Ltd-. Terms of Service or such other written or electronic agreement incorporating this agreement, in each case governing Customer’s access to and use of the Services (the "Agreement"). This agreement was last updated in December, 2025.

1. Definitions

  • "Personal Data": Any information relating to an identified or identifiable natural person.
  • "Processing": Any operation performed on Personal Data, whether automated or not.
  • "Controller": The entity determining the purposes and means of processing Personal Data.
  • "Processor": The entity processing Personal Data on behalf of the Controller.
  • "Sub-processor": Any third party engaged by the Processor to process Personal Data.

2. Subject Matter and Duration

The Processor will process Personal Data solely for providing services related to Affinsys AI solutions and associated support. The duration of processing shall align with the service contract between the parties.

3. Description of Processing Activities for Customer Personal Data

The following describes the specific processing activities performed by Affinsys AI Pvt. Ltd. (the Processor) when providing AI, automation, and conversational banking solutions to the Controller:

3.1 Collection

Affinsys processes customer personal data only when supplied by the Controller through:

  • API integrations from the Controller’s systems (e.g., banking systems, CRM, support systems).
  • Secure file transfers or data connectors.
  • Inputs provided by end-users interacting through chatbots, WhatsApp banking, or digital channels configured by the Controller.

3.2 Storage

Affinsys stores customer data only within secure, access-controlled environments, including:

  • Encrypted databases used for workflow automation, conversational AI, or intelligent routing.
  • Logs limited to service performance, debugging, and security monitoring.
  • Temporary cache used strictly for processing and cleared regularly.

3.3 Processing & Analysis

Affinsys processes customer data to deliver the following services:

  • Conversational AI responses and workflow automation.
  • Intent classification, entity extraction, and context-based reasoning.
  • Customer request routing for banking operations.
  • Execution of API calls to third-party or internal systems, strictly as instructed by the Controller.
  • Generating insights or automated actions required for functional outputs.

Affinsys does not use customer personal data for model training unless explicitly authorised by the Controller.

3.4 Transmission & Sharing

Affinsys may transmit customer personal data:

  • Between internal system components required for service operation.
  • To authorised Sub-processors (e.g., cloud infrastructure providers), only as listed and approved by the Controller. Affinsys never shares customer data with unauthorised third parties.

3.5 Access

Affinsys personnel access customer data only for:

  • Technical support or troubleshooting.
  • Performance monitoring.
  • Issue resolution and service reliability. Access is strictly role-based and logged.

3.6 Retention

Affinsys retains customer personal data only for:

  • The duration required to provide contracted services.
  • The period mandated by the Controller’s data retention policy. Operational logs are retained only for security and diagnostic purposes, based on retention limits agreed with the Controller.

3.7 Deletion & Return

Upon termination or written instruction from the Controller:

  • All stored customer personal data will be securely deleted.
  • Data backups will be purged as per standard secure deletion timelines.
  • A deletion certificate can be provided upon request.

3A. Nature and Purpose of Processing

The Processor may process Personal Data for the following purposes:

  • Providing AI, automation, and integration services.
  • Maintaining system performance and support.
  • Enhancing features or functionality as authorised by the Controller.

4. Types of Personal Data and Data Subjects

Personal Data categories may include:

  • Identification data (name, email, phone).
  • Customer interaction data.
  • Account or usage-related metadata.

Data subjects may include:

  • Customers of the Controller.
  • Employees or authorised users.

5. Obligations of the Processor

The Processor agrees to:

  • Process Personal Data only on documented instructions from the Controller.
  • Ensure confidentiality and train personnel accordingly.
  • Implement appropriate technical and organisational security measures.
  • Not engage Sub-processors without prior written authorisation from the Controller.
  • Assist the Controller with data subject rights requests.
  • Support the Controller in complying with GDPR obligations, including security, breach notification, and DPIAs.
  • Delete or return Personal Data upon termination of services, unless retention is required by law.
  • Allow audits and inspections initiated by the Controller, with reasonable notice.

6. Security Measures

The Processor shall maintain measures including but not limited to:

  • Encryption of data in transit and at rest.
  • Access control and authentication protocols.
  • Regular security assessments.
  • Incident response procedures.

7. Personal Data Breach

In the event of a Personal Data Breach, the Processor shall notify the Controller without undue delay, providing all necessary information for the Controller to meet its GDPR obligations.

8. Rights of Data Subjects

The Processor shall assist the Controller in responding to requests from data subjects, including:

  • Access
  • Rectification
  • Erasure
  • Restriction
  • Objection
  • Data portability

9. Return or Deletion of Data

Upon termination of services, all Personal Data shall be deleted or returned to the Controller, unless legal obligations require retention.

10. Audit Rights

The Controller may conduct audits or inspections of the Processor’s facilities and processes with reasonable notice. The Processor will cooperate fully.

11. Indemnity

11.1 Indemnity by the Controller The Controller shall indemnify, defend, and hold harmless Affinsys AI Pvt. Ltd. ("Processor") from and against any claims, actions, liabilities, penalties, fines, losses, or expenses (including reasonable legal fees) arising out of or relating to: a) the Controller’s breach of its obligations under this DPA or under applicable data protection laws, including GDPR; b) the Controller’s instructions that result in unlawful processing of Personal Data; c) the Controller’s provision of inaccurate, unlawful, or non-compliant Personal Data; or d) any failure by the Controller to obtain necessary consents or authorisations from data subjects.

11.2. Indemnity by the Processor The Processor shall indemnify and hold harmless the Controller from and against claims, damages, or liabilities arising solely from the Processor’s failure to comply with its obligations under this DPA, including failure to implement appropriate technical and organisational security measures as required under GDPR Article 32.

11.3. Exclusions Neither party shall be liable to the extent that any claim arises due to the other party’s negligence, misconduct, or failure to comply with its own obligations under this DPA or applicable law.

11.4. Limitation of Liability Unless otherwise agreed in the main Service Agreement, the indemnity obligations under this clause shall be subject to the liability limitations defined in the governing Master Service Agreement between the parties.

12. Liability

Each party’s liability is subject to the limitations of the main service agreement unless otherwise required by law.

13. Governing Law

This Agreement shall be governed by and construed in accordance with the laws applicable to the main service agreement.

This Data Processing Agreement forms an integral part of all service agreements, order forms, and statements of work entered into with Affinsys AI Pvt. Ltd. By executing a service agreement or by using Affinsys services, the Controller agrees to be bound by the terms of this DPA.

For any questions regarding this DPA, please contact the DPO: hello@affinsys.com

Affinsys AI Pvt. Ltd, Bangalore, India