1. Purpose & Scope
This Data Processing Addendum ("DPA") supplements our Terms of Use, Privacy Policy, and underlying Service Agreements. It applies to the processing of personal data provided by clients, agency partners, and business users ("Data Fiduciary" or "Client") to Enlargenet ("Data Processor" or "Company") in connection with digital marketing, lead generation, software development, web hosting, CRM integration, and white-label agency fulfillment services.
This DPA is established to ensure full compliance with the statutory mandates of India's Digital Personal Data Protection Act (DPDP Act, 2023) and applicable Information Technology laws.
2. Roles & Statutory Responsibilities
Client as Data Fiduciary: The Client determines the purpose and means of processing personal data collected from its end-users, leads, or customers. The Client warrants that all personal data transferred or made accessible to Enlargenet has been collected with valid, explicit, and informed consent under Section 6 of the DPDP Act 2023.
Enlargenet as Data Processor: Enlargenet processes personal data solely on behalf of, and in accordance with, the documented instructions provided by the Client, except where processing is mandated by Indian law or judicial orders.
3. Categories of Data & Purpose of Processing
Enlargenet processes personal data strictly necessary to fulfill agreed operational and white-label service scope:
Categories of Data Principals: End-client leads, website visitors, event registrants, job applicants, customer lists, and business contacts provided by the Client.
Types of Personal Data: Names, phone numbers, email addresses, job titles, IP addresses, geographical location data, custom form entries, and ad account engagement metrics.
Processing Operations: Data intake, storage, conversion tracking (CAPI), CRM synchronization, ad targeting, lead routing, technical web application hosting, and analytics aggregation.
4. Processor Obligations & Compliance Controls
In accordance with the DPDP Act 2023, Enlargenet agrees to:
- Instructional Compliance: Process personal data exclusively for the purposes specified in the primary Service Agreement, SOW, or written instructions issued by the Client.
- Confidentiality: Ensure that all personnel, software engineers, media buyers, and operators authorized to process personal data are bound by strict non-disclosure obligations.
- Technical & Organizational Security: Implement reasonable security safeguards—including SSL encryption, secure API webhooks, restricted database access, and routine system monitoring—to prevent unauthorized access, alteration, disclosure, or destruction of personal data.
- Sub-Processor Governance: Engage third-party infrastructure and software sub-processors (e.g., AWS, Google Cloud, Meta API, web hosting servers) only under contracts that impose equivalent data protection obligations.
- Assistance with Data Principal Rights: Assist the Client, via appropriate technical and organizational measures, in fulfilling obligations to respond to requests from Data Principals exercising rights under the DPDP Act 2023 (such as rights to access, correction, or erasure).
5. Personal Data Breach Management & Notification
In the event of a confirmed personal data breach affecting the Client's data processed by Enlargenet:
Notification SLA: Enlargenet shall notify the Client in writing without undue delay, and no later than twenty-four (24) hours after becoming aware of the confirmed breach.
Breach Details: The notification will provide available details regarding the nature of the breach, affected data categories, estimated number of impacted Data Principals, and immediate mitigation measures undertaken.
Regulatory Reporting: Enlargenet will assist the Client in fulfilling any statutory reporting obligations required by the Data Protection Board of India or relevant authorities.
6. Data Retention, Erasure & Return
Retention Limitation: Personal data is retained only for as long as necessary to fulfill the specific operational purpose or as required by applicable Indian tax, auditing, and legal retention laws.
Deletion upon Termination: Upon completion of services or termination of the business agreement, Enlargenet shall, at the Client's written election, securely return or permanently delete/anonymize all personal data from active servers within thirty (30) business days, excluding archival backups maintained for statutory compliance.
7. Contact & Grievance Information
For any inquiries, data processing audits, or data breach notices related to this Data Processing Addendum, please contact our designated Grievance Officer:
Grievance Officer: Vineet Baveja (Founder & Sole Proprietor)
Entity Name: Enlargenet
Registered Address: 301-C, 3rd Floor, Supermart 2, DLF Phase 4, Gurugram, Haryana, India
Official Email: vineet@conceptualise.in
Official Phone: +91 9990158777