Data Processing Agreement (DPA)
Last Updated: November 22, 2025
This Data Processing Agreement ("DPA") forms part of the Master Terms of Service ("Agreement") between SYT Solutions Private Limited ("Processor" or "Brivo") and the user or entity utilizing the Services ("Controller" or "Customer").
By using the Services, the Customer accepts this DPA.
1. Definitions
- "Applicable Data Protection Law" means the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023 (DPDP Act), and any other applicable privacy laws governing the processing of Personal Data in the jurisdiction where the Services are provided.
- "Customer Personal Data" means any Personal Data provided by the Customer to the Processor for the purpose of using the Services (e.g., candidate names, PAN numbers, Aadhaar details).
- "Data Fiduciary" (or "Controller") determines the purpose and means of processing the data.
- "Data Processor" processes data on behalf of the Data Fiduciary.
2. Scope and Purpose
2.1 Roles of Parties The Parties acknowledge and agree that with regard to the Processing of Customer Personal Data, the Customer is the Data Fiduciary (Controller) and SYT Solutions is the Data Processor.
2.2 Purpose of Processing Brivo shall process Customer Personal Data solely for the purpose of providing the Services described in the Master Terms of Service (e.g., background verification, KYC, due diligence) and in accordance with the Customer’s documented instructions.
3. Processor Obligations
3.1 Confidentiality Brivo ensures that all personnel (employees, contractors, agents) authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
3.2 Security Measures Brivo shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including but not limited to:
- Encryption of data in transit (TLS) and at rest (AES).
- Role-based access controls (RBAC).
- Regular vulnerability assessments and penetration testing.
- Physical security of data centers (via top-tier cloud providers).
3.3 Sub-processors The Customer grants Brivo a general authorization to engage third-party Sub-processors to support the delivery of Services (e.g., cloud hosting providers like AWS/Google Cloud, database providers, or verification authorities like NSDL/UIDAI gateways).
- Brivo remains fully liable to the Customer for the performance of any Sub-processor’s obligations.
- Brivo shall ensure Sub-processors are bound by data protection obligations compatible with this DPA.
3.4 Assistance Brivo shall, taking into account the nature of the processing, assist the Customer by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Customer’s obligation to respond to requests for exercising the Data Subject’s rights (e.g., right to access, rectification, or erasure).
4. Customer Obligations
4.1 Lawful Basis and Consent The Customer represents and warrants that:
- It has a lawful basis for processing the Personal Data (e.g., legitimate interest or employment contract).
- It has obtained all necessary explicit consents from the Data Subjects (Candidates/Entities) prior to sharing their data with Brivo for verification purposes.
- It is responsible for the accuracy, quality, and legality of the Customer Personal Data and the means by which it acquired the data.
5. Data Breach Notification
5.1 Notification In the event of a Personal Data Breach affecting Customer Personal Data, Brivo shall notify the Customer without undue delay (and in any event within 72 hours) after becoming aware of the breach.
5.2 Content of Notification The notification shall describe, to the extent known:
- The nature of the breach.
- The categories and approximate number of data subjects concerned.
- The likely consequences of the breach.
- Measures taken or proposed to be taken to mitigate the breach.
6. Audit Rights
Upon reasonable written request (not more than once per year), Brivo shall make available to the Customer all information necessary to demonstrate compliance with this DPA. Brivo may satisfy this requirement by providing a summary of its latest security audit report or ISO/SOC certifications.
7. International Transfers
Brivo primarily stores and processes data within India. If Brivo transfers Customer Personal Data to a jurisdiction outside India, it shall ensure that such transfer complies with Applicable Data Protection Laws and that appropriate safeguards are in place.
8. Term and Termination
8.1 Return or Deletion Upon termination of the Services, at the Customer’s choice, Brivo shall delete or return all Customer Personal Data, unless applicable law requires storage of the Personal Data (e.g., for audit trails required by financial regulations).
8.2 Survival The confidentiality and security obligations within this DPA shall survive the termination of the Agreement for as long as Brivo retains any Customer Personal Data.
9. Governing Law
This DPA shall be governed by and construed in accordance with the laws of India. Any disputes arising out of this DPA shall be subject to the jurisdiction of the courts in Gurgaon, Haryana.
Let's discuss your verification and compliance needs
Our offices
- Gurugram
Sector 62, Gurugram
Haryana, 122098