loader1

Data Processing Agreement (DPA)

Effective Date: April 18, 2026

Last Updated: April 18, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions and/or any commercial agreement between HRMS4U and the customer using the Services.

Platform: HRMS4U
Operated by: DesignzIndia
Country: India
Jurisdiction: Chandigarh

This DPA governs the processing of personal data by HRMS4U on behalf of its customers.

1. Purpose of this Agreement

Customers may upload, store, manage, or process employee and business data through HRMS4U.

Where such information includes personal data, this DPA sets out:

  • Responsibilities of each party
  • Data protection obligations
  • Security measures
  • Confidentiality requirements
  • Data deletion procedures
  • Use of subprocessors
  • Cross-border processing safeguards

2. Definitions

For purposes of this DPA:

“Controller”

The organization or customer that determines the purpose and means of processing personal data.

“Processor”

DesignzIndia / HRMS4u, which processes personal data on behalf of the Controller.

“Personal Data”

Any information relating to an identified or identifiable individual.

“Processing”

Any operation performed on personal data including collection, storage, use, access, transmission, deletion, organization, or disclosure.

“Data Subject”

An individual whose personal data is processed, including employees, applicants, contractors, or users.

“Applicable Data Protection Law”

Any privacy or data protection law applicable to the parties, including Indian laws and other relevant laws depending on customer location.

3. Roles of the Parties

For customer data processed through HRMS4U:

  • The Customer acts as the Data Controller
  • HRMS4U / DesignzIndia acts as the Data Processor

The Customer remains responsible for ensuring lawful collection and use of personal data.

4. Scope of Processing

HRMS4U may process personal data solely for the purpose of delivering SaaS services requested by the Customer.

This may include modules such as:

  • Employee Management
  • Core HR
  • Attendance
  • Leave Management
  • Payroll
  • Recruitment
  • Project Management
  • Finance
  • Performance Management
  • Document Storage
  • Internal Communications
  • Reporting and Analytics

5. Categories of Personal Data

Depending on customer usage, data processed may include:

Employee Information

  • Full name
  • Email address
  • Phone number
  • Address entered by customer
  • Employee ID
  • Department
  • Job title
  • Reporting manager
  • Joining date

Attendance & Leave Data

  • Check-in/check-out records
  • Attendance logs
  • Leave balances
  • Leave history

Payroll Data

  • Salary details
  • Bonuses
  • Deductions
  • Tax fields
  • Payslip information
  • Bank details entered by customer

Recruitment Data

  • Candidate profiles
  • CVs / resumes
  • Interview notes

Documents

  • Identity documents uploaded by customer
  • Contracts
  • Letters
  • HR documents

6. Nature of Processing

Processing activities may include:

  • Hosting
  • Storage
  • Access by authorized users
  • Backup creation
  • Retrieval
  • Reporting
  • Search and filtering
  • Export/import functions
  • Support troubleshooting
  • Deletion upon instruction or termination

7. Customer Responsibilities

The Customer agrees that it shall:

  • Have a lawful basis to collect personal data
  • Inform employees/users about use of HRMS4U
  • Obtain required consent where necessary
  • Ensure uploaded data is accurate
  • Use the service in compliance with applicable laws
  • Respond to data subject requests unless assistance is required

The Customer is solely responsible for HR, payroll, labor, tax, and employment compliance obligations.

8. Processor Obligations

HRMS4U shall:

  • Process personal data only on documented customer instructions
  • Use data only to provide contracted services
  • Maintain confidentiality
  • Implement reasonable technical and organizational safeguards
  • Notify customer of confirmed personal data incidents where legally required
  • Delete or return data as described in this DPA

9. Confidentiality

All personnel authorized to access customer data shall be subject to confidentiality obligations or equivalent professional duties.

Access shall be limited to persons who need access for:

  • Service delivery
  • Maintenance
  • Technical support
  • Security operations

10. Security Measures

HRMS4U implements commercially reasonable safeguards, which may include:

  • Hosting on DigitalOcean or equivalent infrastructure
  • Data encryption in transit and/or at rest where applicable
  • Password protections
  • Role-based access controls
  • Secure backups
  • Monitoring systems
  • Firewall/network protections
  • Routine maintenance

No method of transmission or storage can guarantee absolute security.

11. Data Backups

Daily backups may be maintained for business continuity and disaster recovery purposes.

Backup copies may remain in secure retention cycles for limited periods even after deletion requests.

12. Sub processors

HRMS4U may engage trusted sub processors to support service delivery, including providers for:

  • Cloud hosting
  • Email delivery
  • Monitoring
  • Backup systems
  • Payment processing
  • Customer support tools

We remain responsible for ensuring subprocessors are subject to appropriate obligations.

13. International Data Transfers

Where sub processors or infrastructure involve access outside India, HRMS4U shall use commercially reasonable safeguards appropriate to the transfer.

14. Assistance with Data Subject Requests

Where feasible and reasonable, HRMS4U may assist the Customer in responding to requests involving:

  • Access requests
  • Correction requests
  • Deletion requests
  • Restriction requests
  • Portability requests

Such assistance may depend on technical feasibility and subscription scope.

15. Security Incidents

If HRMS4u becomes aware of a confirmed personal data breach affecting customer data, we will notify the Customer within a commercially reasonable time where required by law.

Notification may include:

  • Nature of incident
  • Affected systems/data (if known)
  • Steps taken
  • Recommended mitigation actions

16. Audit & Information Requests

Upon reasonable written request, HRMS4U may provide information regarding security practices sufficient to demonstrate compliance with this DPA, subject to:

  • Protection of confidential information
  • Security restrictions
  • Operational feasibility

Formal audits may require separate agreement.

17. Data Retention & Deletion

Upon cancellation or termination:

  • Customer data may remain accessible for up to 30 days
  • Thereafter, production data may be deleted
  • Backup archives may persist temporarily in rotation systems

Customers should export needed data before termination.

18. Return of Data

Where technically feasible and included in the service plan, customers may export available data using:

  • Standard export tools
  • Reports
  • CSV / downloadable records

Custom migration services may be separately chargeable.

19. Liability

Liability under this DPA shall be subject to the liability limitations set out in the main Terms & Conditions, unless otherwise required by law.

20. Governing Law

This DPA shall be governed by the laws of India.

Any disputes shall be subject to courts located in Chandigarh.

21. Order of Precedence

If there is a conflict between this DPA and the Terms & Conditions regarding personal data processing, this DPA shall prevail only to that extent.

22. Changes to this DPA

We may update this DPA from time to time to reflect legal, technical, or operational changes.

Updated versions become effective upon publication or written notice.

23. Contact Information

HRMS4U
Operated by DesignzIndia
India
For privacy or data processing requests:
Email: [email protected]