Back
Legal

Data Processing Agreement

Last updated: July 26, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Alphoris Technologies Pvt. Ltd. and the customer organisation. It applies automatically to every customer and does not need to be separately signed, though we will execute a counter-signed copy on request. It is drafted under the Digital Personal Data Protection Act, 2023 (“DPDP Act”).

1. Parties & Roles

For personal data that the Customer uploads to, or generates through, the Service:

  • The Customer is the Data Fiduciary and determines the purpose and means of processing.
  • Alphoris is the Data Processor and processes personal data only on the Customer's behalf.
  • The individuals whose personal data is processed — the Customer's contacts, callers and end customers — are Data Principals.

These terms carry the meanings given to them in the DPDP Act. Where this DPA is read alongside a GDPR-based framework, “Data Fiduciary” corresponds to “controller”, “Data Processor” to “processor”, and “Data Principal” to “data subject”.

Alphoris is a Data Fiduciary in its own right only for its customers' account and billing data, which is governed by the Privacy Policy rather than this DPA.

2. Scope & Instructions

Alphoris shall process personal data only on the Customer's documented instructions and solely to provide the contracted Services. The Terms of Service, this DPA, and the Customer's configuration of the platform (campaigns, prompts, knowledge bases, retention settings) together constitute the Customer's documented instructions. Alphoris will inform the Customer if, in its opinion, an instruction infringes applicable law, and may decline to act on it.

Alphoris will not sell personal data, use it for its own marketing, use it to build profiles of Data Principals, or use it to train artificial intelligence models. Alphoris uses AI providers on paid enterprise tiers under which the provider does not train on Customer data.

3. Nature & Purpose of Processing

Processing activities may include collection, recording, organisation, structuring, storage, retrieval, consultation, AI processing, voice transcription, summarisation, sentiment and data extraction, analytics, call recording, transmission, erasure and destruction — carried out for the purpose of delivering AI voice and messaging automation to the Customer.

Duration: for the term of the Customer's subscription, plus the retention periods in Section 13.

4. Categories of Data & Data Principals

Categories of personal data: names; telephone numbers; email addresses; voice recordings; call transcripts and AI-generated summaries; appointment and booking information; customer support interaction records; CRM records; and other business data uploaded by the Customer.

Categories of Data Principals: the Customer's customers, prospects, leads, callers, patients, applicants and other individuals contacted through or contacting the Service; and the Customer's own staff who use the platform.

The Service is not designed for, and the Customer must not upload, personal data of children under 18, financial account credentials, one-time passwords, or health data requiring heightened safeguards, unless separately agreed in writing.

5. Obligations of the Customer

As Data Fiduciary, the Customer shall:

  • Ensure all personal data provided to the Service was lawfully collected.
  • Give the notice required by Section 5 of the DPDP Act and obtain valid consent under Section 6, or establish another lawful ground under Section 7, before any Data Principal is contacted through the Service.
  • Maintain records of consent, and promptly remove contacts who have withdrawn consent or opted out.
  • Comply with TRAI / TCCCPR obligations, including DLT registration, header and template registration, NCPR scrubbing and calling-hour restrictions.
  • Respond to Data Principal requests, with Alphoris's assistance under Section 10.
  • Configure retention settings appropriate to its own legal obligations.

6. Obligations of Alphoris

As Data Processor, Alphoris shall:

  • Process personal data only as instructed by the Customer.
  • Implement and maintain the security safeguards described in Section 8, as required by Section 8(5) of the DPDP Act.
  • Restrict access to personnel who need it to deliver the Service, and bind them by written confidentiality obligations that survive their engagement.
  • Notify the Customer of personal data breaches in accordance with Section 9.
  • Assist the Customer in meeting its obligations to Data Principals and to the Data Protection Board, to the extent reasonably possible given the nature of processing.
  • Delete or return personal data in accordance with Section 13.
  • Make available the information reasonably necessary to demonstrate compliance with this DPA.

7. Sub-processors

The Customer grants Alphoris general authorisation to engage the sub-processors listed in Annex A. Alphoris shall:

  • Impose on each sub-processor, by written contract, data protection obligations no less protective than those in this DPA.
  • Remain fully liable to the Customer for the acts and omissions of its sub-processors.
  • Give the Customer at least 30 days' prior notice by email before adding or replacing a sub-processor.
  • Permit the Customer to object on reasonable data protection grounds within that notice period. If the objection cannot be resolved, the Customer may terminate the affected Services without penalty and receive a pro-rata refund of prepaid fees.

To receive sub-processor change notices, email privacy@alphoris.in.

8. Security Measures

  • AES-256 encryption of personal data at rest; TLS 1.3 in transit.
  • Tenant isolation: each customer's data is scoped to its organisation and access is enforced at the query layer.
  • Role-based access control and multi-factor authentication for all internal and administrative access.
  • Audit logging of access to and modification of personal data.
  • Automated, irreversible deletion of call recordings 90 days after the call.
  • Regular security assessment and penetration testing.
  • Secrets management, least-privilege infrastructure credentials, and prompt patching of known vulnerabilities.

Alphoris may update these measures provided the overall level of security is not reduced.

9. Personal Data Breach

On becoming aware of a personal data breach affecting Customer personal data, Alphoris shall:

  • Notify the Customer without undue delay, and in any event within 24 hours of becoming aware.
  • Provide the nature of the breach, categories and approximate number of Data Principals and records affected, likely consequences, and measures taken or proposed.
  • Assist the Customer in notifying the Data Protection Board of India and affected Data Principals within the timelines the DPDP Act requires.
  • Take reasonable steps to mitigate and remediate, and document the breach and the response.

Notification is not an admission of fault or liability. Alphoris will not delay notice in order to complete its investigation.

10. Data Principal Requests

The platform provides self-service tools allowing the Customer to access, export, correct and delete personal data, which the Customer should use in the first instance. Where a Data Principal contacts Alphoris directly, Alphoris will not respond substantively but will forward the request to the Customer without undue delay and assist the Customer in responding within the statutory period. Alphoris will provide reasonable assistance with data protection impact assessments and consultations with the Data Protection Board where the nature of processing requires it.

11. Cross-Border Processing

Personal data is stored at rest in India. Certain processing — principally speech recognition and language processing by the AI provider, and transactional email delivery — occurs on infrastructure outside India, as identified in Annex A. Section 16 of the DPDP Act permits such transfers except to countries restricted by the Central Government; Alphoris does not transfer personal data to any restricted country and will cease any transfer that becomes restricted. All transfers are covered by written data protection terms with the receiving processor.

12. Audit & Assurance

On written request, and no more than once per year (or following a personal data breach affecting the Customer), Alphoris will provide a written response to a reasonable security questionnaire and copies of any current third-party assessment reports. Where that is insufficient to satisfy a mandatory audit obligation, the Customer may conduct an audit on 30 days' notice, during business hours, subject to confidentiality, at the Customer's cost, and in a manner that does not disrupt the Service or compromise other customers' data.

13. Retention, Return & Deletion

  • Call recordings are automatically and permanently deleted 90 days after the call, by an automated daily process.
  • Transcripts, summaries and analytics are retained for the life of the account unless the Customer deletes them earlier.
  • On termination, the Customer may export its data for 30 days. Alphoris will then delete all personal data within a further 60 days, including from backups on their normal rotation cycle.
  • Alphoris may retain personal data where required by applicable law, for the period so required, and will continue to protect it under this DPA for as long as it is retained.

14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions in Section 13 of the Terms of Service, including the carve-outs stated there. Nothing in this DPA limits liability that cannot be limited under applicable law, or either party's direct liability to a Data Principal or to the Data Protection Board under the DPDP Act.

15. Term & Order of Precedence

This DPA takes effect when the Customer accepts the Terms of Service and continues while Alphoris processes personal data on the Customer's behalf. In the event of conflict between this DPA, the Terms of Service and the Privacy Policy, this DPA prevails in respect of the processing of personal data on the Customer's behalf. This DPA is governed by the laws of India and subject to the dispute resolution provisions of the Terms of Service.

Annex A — Sub-processors

Current as of the “last updated” date above. Changes are notified 30 days in advance under Section 7.

Sub-processorPurposeLocation
Amazon Web Services India Pvt. Ltd.Cloud hosting, application servers, data storageIndia (ap-south-1, Mumbai)
Exotel Techcom Pvt. Ltd.Voice call origination, termination and SIP connectivityIndia
MongoDB Inc. (Atlas)Managed database hosting for account, call and campaign dataIndia (Mumbai region)
Google LLC (Gemini API)Speech recognition, conversational AI, summarisation, data extractionOutside India
Razorpay Software Pvt. Ltd.Payment processing and invoicingIndia
Resend, Inc.Transactional email deliveryOutside India
Meta Platforms, Inc. (WhatsApp Business Platform)WhatsApp messaging, where enabled by the CustomerOutside India

Note: this Annex must be kept accurate. Verify each entry against the infrastructure actually in use before publication, and update it whenever a provider or region changes.

Contact

Questions about this DPA, requests for a counter-signed copy, or sub-processor notifications:
Email: privacy@alphoris.in
Grievance Officer: grievance@alphoris.in
Address: Alphoris Technologies Pvt. Ltd., Bangalore, Karnataka, India