Legal

Data Processing Addendum

Effective date: [EFFECTIVE_DATE]

Template — requires legal review. This page is a structural starting point, not finished legal advice. It must be reviewed by an India-qualified lawyer (and, for any market you operate in outside India, a lawyer qualified there) before it's relied on in production.

1. Roles

Where a business client's own end-customer data is processed through RuvexTech, the customer acts as data controller and RuvexTech acts as data processor, to the extent applicable law recognizes those roles.

2. Subject matter and duration

This Addendum applies for as long as RuvexTech processes personal data on the customer's behalf under the underlying service agreement.

3. Nature and purpose of processing

Processing is carried out to provide the AI chatbot, booking, and related workspace features described in the service agreement.

4. Types of data

Customer contact details, conversation content, appointment data, and related technical metadata, as described in our Privacy Policy.

5. Categories of data subjects

The customer's own end-customers, leads, and staff users of the workspace.

6. Customer instructions

We process personal data only on the customer's documented instructions, as configured through the platform or agreed in writing.

7. Confidentiality

Personnel authorized to process personal data are subject to confidentiality obligations.

8. Security

We aim to apply appropriate technical and organizational measures as described on our Security page.

9. Subprocessors

We use subprocessors for hosting, messaging, and related infrastructure. [SUBPROCESSOR_LIST_PLACEHOLDER — to be maintained and referenced here.]

10. International transfers

[INTERNATIONAL_TRANSFER_TERMS_PLACEHOLDER — to be finalized with counsel per applicable law.]

11. Assistance with data subject rights

We'll provide reasonable assistance to help the customer respond to data subject requests concerning data we process on their behalf.

12. Breach notification

We'll notify the customer without undue delay upon becoming aware of a personal data breach affecting their data. [BREACH_NOTIFICATION_TIMEFRAME_PLACEHOLDER.]

13. Deletion or return of data

Upon termination, we'll delete or return customer data as instructed, subject to any legal retention obligations.

14. Audit and inspection

[AUDIT_RIGHTS_PLACEHOLDER — scope and process for customer audit rights to be finalized with counsel.]

15. Annex — processing details

[ANNEX_PLACEHOLDER — a completed annex describing specific data categories, subjects, and subprocessors per customer/market should be attached to the signed service agreement.]

16. Legal review note

This Addendum is a business-to-business template and must be reviewed by qualified legal counsel before being relied on in a customer agreement.

Questions about this policy? Contact us at [PRIVACY_EMAIL].

Choose which categories of cookies you're okay with. You can change this at any time from the footer.

Necessary

Required for the site to function — cannot be turned off.

Preference

Remembers choices like cookie settings across visits.

Analytics

Helps us understand how the site is used, in aggregate.

Marketing

Used to measure and improve marketing campaigns.