§ IIILegalLast updated April 2026

Data Processing Addendum (DPDP)

This Addendum is entered into between your firm (the Data Fiduciary) and ORIS (the Data Processor) and forms part of the iVee Terms. It reflects the Digital Personal Data Protection Act, 2025 and accompanying Rules.

Roles

  • The firm is the Data Fiduciary for stakeholder, employee, and end-client personal data.
  • ORIS is the Data Processor acting solely on the firm’s documented instructions.
  • Sub-processors are listed in the customer dashboard and require prior written objection rights.

Technical & organisational measures

  • Namespace isolation enforced at the API guard layer — no cross-tenant reads.
  • AES-256-GCM encryption for OAuth tokens and secrets at rest; TLS 1.2+ in transit.
  • Signed, append-only audit log of every autonomous action, written before execution.
  • Role-based access; admin actions require re-authentication.
  • Retention workers enforce per-data-type TTLs; cascade delete on data principal request.

Breach notification

We notify the firm without undue delay (target: 48 hours) of any personal data breach, with the information needed for the firm to meet its own notification obligations to the Data Protection Board.

Cross-border transfers

Primary processing is in India. Any transfer outside India is made only to jurisdictions permitted under the DPDP Rules and listed in the customer dashboard.

Audit rights

The firm may audit compliance with this Addendum on reasonable notice, either directly or via an independent auditor bound by confidentiality.

Questions? Contact privacy@ivee.dev.