NAVRITU DIGITAL
DATA PROCESSING AGREEMENT
Effective Date: August 22, 2026
This Data Processing Agreement (“DPA”) applies automatically whenever NavRitu Digital (“Processor,” “we,” “us”) processes personal data on behalf of a client (“Controller,” “you”) in the course of delivering services, and forms part of the Master Terms of Service governing that engagement. It reflects the requirements of Article 28 GDPR and analogous obligations under the DPDP Act and CCPA/CPRA (where we act as a “Service Provider”).
1. Subject Matter & Duration
This DPA applies for the duration of the underlying services engagement, and covers personal data we process on your documented instructions in the course of delivering the agreed services (e.g., managing ad campaigns, analytics, or a platform involving your end users' data).
2. Nature, Purpose & Categories of Data
The nature and purpose of processing, and the categories of personal data and data subjects involved, are as described in the applicable Statement of Work. In general, this may include your customers' or end users' identifiers, contact details, and usage/behavioral data, processed solely to deliver the agreed service.
3. Our Obligations as Processor
- Process personal data only on your documented instructions, including with regard to international transfers, unless required to do otherwise by law (in which case we will inform you, unless prohibited from doing so)
- Ensure that personnel authorized to process the data are subject to confidentiality obligations
- Implement appropriate technical and organizational security measures, consistent with our Incident Response & Breach Notification Policy
- Assist you, at your reasonable request, in responding to data subject rights requests and in meeting your own compliance obligations (e.g., data protection impact assessments)
- Notify you without undue delay, and in any event within 24 hours of becoming aware, of any personal data breach affecting data processed on your behalf
- At the end of the engagement, delete or return all personal data processed on your behalf, unless retention is required by law
- Make available to you the information reasonably necessary to demonstrate compliance with this DPA, and allow for audits on reasonable notice
4. Sub-Processors
We use a limited number of sub-processors to deliver our services, listed in our Approved Sub-Processor Registry. Before engaging any new sub-processor to process your personal data, we will seek your prior written consent. You may object to a proposed new sub-processor on reasonable data protection grounds, in which case we will work with you to find an alternative or adjust the affected part of the service.
5. International Transfers
Where processing under this DPA involves a transfer of personal data across borders, the safeguards described in our Cross-Border Data Transfer page apply, including Standard Contractual Clauses where required.
6. Liability
Liability arising under this DPA is subject to the Limitation of Liability provisions in our Master Terms of Service.
7. Precedence
If you require a separately negotiated, signed DPA (for example, incorporating your own Standard Contractual Clauses module or specific regulatory language), that signed document will govern in place of this default DPA to the extent of any conflict.
8. Contact Us
Questions about this DPA, or requests to negotiate a signed version: legal@navritu.digital.