Data & Security
Gappeo is committed to protecting your data with enterprise-grade security. Our Data Processing Agreement outlines exactly how we collect, process, and secure your information.
Overview
This Data Processing Agreement ("DPA") forms part of the Master Subscription Agreement or Terms of Service between Uprise Labs Pvt. Ltd. ("Gappeo" or "Processor") and the entity purchasing or using the Services ("Customer" or "Controller").
Gappeo is committed to processing your data securely, transparently, and in full compliance with applicable data protection laws including GDPR, CCPA, and the Digital Personal Data Protection Act, 2023 (India).
1. Key Definitions
2. Scope & Roles
This DPA applies where Gappeo processes Personal Data on behalf of the Customer as a Processor to provide the Services described in the Agreement.
The Customer acts as a Data Controller and Gappeo acts as a Data Processor.
3. Processing of Personal Data
- Instructions: Gappeo shall process Personal Data only on documented instructions from the Customer, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by applicable law.
- Purpose: The subject matter, duration, nature, and purpose of the processing are described in Annex I.
- AI & Biometric Data: The Customer acknowledges that the Services utilize Artificial Intelligence to analyze candidate voice (Telephonic Screening) and visual/tonal data (Video Interviews). The Customer is responsible for ensuring it has a valid legal basis (such as explicit consent) for the collection and processing of such data, including biometric information where applicable.
4. Gappeo's Obligations
- Confidentiality: Gappeo shall ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Security: Gappeo shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, as outlined in Annex II.
- Data Subject Rights: Gappeo shall assist the Customer by appropriate technical and organizational measures for the fulfillment of the Customer's obligation to respond to requests for exercising Data Subject rights.
- Impact Assessments: Gappeo shall provide reasonable assistance for any data protection impact assessments and prior consultations with supervising authorities, specifically regarding the use of AI-driven automated decision-making.
5. Sub-processors
The Customer provides a general authorization for Gappeo to engage Sub-processors to process Personal Data for the purpose of providing, securing, and supporting the Services. Gappeo shall maintain a list of its Authorized Sub-processors and shall inform the Customer of any intended changes.
The Customer may object to a new Sub-processor on reasonable grounds relating to data protection by providing written notice to Gappeo within ten (10) business days of receiving notice of the change.
Gappeo shall impose data protection terms on any Sub-processor it appoints that require the Sub-processor to protect Personal Data to the same standard required of Gappeo under this DPA.
6. Personal Data Breach Notification
Gappeo shall notify the Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach involving Personal Data processed under this DPA.
Such notification shall include: a description of the nature of the breach; the likely consequences; and the measures taken or proposed to address the breach.
Gappeo shall provide reasonable further information and cooperation to support the Customer's obligations to notify supervisory authorities, regulators, and/or affected Data Subjects under applicable Data Protection Laws.
Unless required by applicable law, Gappeo's notification of a Personal Data Breach shall not be construed as an admission of fault or liability.
7. International Data Transfers
Gappeo may process Personal Data in India or any other country where Gappeo or its Sub-processors maintain facilities.
Where required by applicable Data Protection Laws, Gappeo shall ensure that international transfers are implemented with appropriate safeguards and transfer mechanisms, including: Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EEA; the UK International Data Transfer Agreement (IDTA) for transfers from the UK; and the Swiss Federal Data Protection Act recognized transfer mechanisms.
Where the Customer is subject to the Digital Personal Data Protection Act, 2023 (India) and cross-border transfer restrictions apply, the parties shall ensure transfers occur only in accordance with applicable Indian law.
8. Audits & Compliance
Gappeo shall make available to the Customer all information necessary to demonstrate compliance with the obligations laid down in this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or another auditor mandated by the Customer, no more than once per year.
9. Data Deletion & Return
Upon termination of the Agreement, Gappeo shall, at the choice of the Customer, delete or return all Personal Data to the Customer and delete existing copies unless applicable law requires storage of the Personal Data.
10. Liability
Each party's liability taken together in the aggregate arising out of or related to this DPA shall be subject to the exclusions and limitations of liability set forth in the Agreement.
11. Governing Law
This DPA shall be governed by the laws of India. The courts at Bangalore, Karnataka, India shall have exclusive jurisdiction over any dispute arising out of or in connection with this DPA.
Annex I: Details of Processing
Annex II: Technical & Organizational Security Measures
Restricted access to Personal Data based on the principle of least privilege, including role-based access controls and periodic access reviews.
Encryption of Personal Data at rest and in transit (SSL/TLS or equivalent industry-standard cryptography).
Regular backups and disaster recovery protocols, including monitoring for unauthorized changes and restoration testing.
Use of Tier-1 cloud infrastructure providers (e.g., AWS/Azure/GCP) with industry-standard certifications (ISO 27001, SOC 2 or equivalent).
Security logging for key systems and administrative actions, with alerting for suspicious activity.
Regular patching and vulnerability scanning; security testing processes appropriate to the nature of the Services.
Documented incident response procedures and escalation paths for security events and Personal Data Breaches.
Measures to maintain availability and recoverability appropriate to the risk (e.g., redundancy, backups, and disaster recovery planning).
Background checks where permitted by law; security awareness training; confidentiality obligations for personnel with access to Personal Data.
Logical controls supporting retention and deletion consistent with Customer instructions and the Agreement.
Regular auditing and evaluation of AI models to minimize algorithmic bias and improve data quality and accuracy; governance controls around model changes.
Security measures implemented at data centers by infrastructure providers, including controlled access and environmental safeguards.
Questions about data & security?
Reach out to our team for any DPA inquiries, security documentation, or compliance questions.
info@gappeo.ai →