Data Processing Agreement (DPA)
Effective Date: April 18, 2026
Last Updated: April 18, 2026
This Data Processing Agreement (“DPA”) forms part of the Terms & Conditions and/or any commercial agreement between HRMS4U and the customer using the Services.
Platform: HRMS4U
Operated by: DesignzIndia
Country: India
Jurisdiction: Chandigarh
This DPA governs the processing of personal data by HRMS4U on behalf of its customers.
1. Purpose of this Agreement
Customers may upload, store, manage, or process employee and business data through HRMS4U.
Where such information includes personal data, this DPA sets out:
- Responsibilities of each party
- Data protection obligations
- Security measures
- Confidentiality requirements
- Data deletion procedures
- Use of subprocessors
- Cross-border processing safeguards
2. Definitions
For purposes of this DPA:
“Controller”
The organization or customer that determines the purpose and means of processing personal data.
“Processor”
DesignzIndia / HRMS4u, which processes personal data on behalf of the Controller.
“Personal Data”
Any information relating to an identified or identifiable individual.
“Processing”
Any operation performed on personal data including collection, storage, use, access, transmission, deletion, organization, or disclosure.
“Data Subject”
An individual whose personal data is processed, including employees, applicants, contractors, or users.
“Applicable Data Protection Law”
Any privacy or data protection law applicable to the parties, including Indian laws and other relevant laws depending on customer location.
3. Roles of the Parties
For customer data processed through HRMS4U:
- The Customer acts as the Data Controller
- HRMS4U / DesignzIndia acts as the Data Processor
The Customer remains responsible for ensuring lawful collection and use of personal data.
4. Scope of Processing
HRMS4U may process personal data solely for the purpose of delivering SaaS services requested by the Customer.
This may include modules such as:
- Employee Management
- Core HR
- Attendance
- Leave Management
- Payroll
- Recruitment
- Project Management
- Finance
- Performance Management
- Document Storage
- Internal Communications
- Reporting and Analytics
5. Categories of Personal Data
Depending on customer usage, data processed may include:
Employee Information
- Full name
- Email address
- Phone number
- Address entered by customer
- Employee ID
- Department
- Job title
- Reporting manager
- Joining date
Attendance & Leave Data
- Check-in/check-out records
- Attendance logs
- Leave balances
- Leave history
Payroll Data
- Salary details
- Bonuses
- Deductions
- Tax fields
- Payslip information
- Bank details entered by customer
Recruitment Data
- Candidate profiles
- CVs / resumes
- Interview notes
Documents
- Identity documents uploaded by customer
- Contracts
- Letters
- HR documents
6. Nature of Processing
Processing activities may include:
- Hosting
- Storage
- Access by authorized users
- Backup creation
- Retrieval
- Reporting
- Search and filtering
- Export/import functions
- Support troubleshooting
- Deletion upon instruction or termination
7. Customer Responsibilities
The Customer agrees that it shall:
- Have a lawful basis to collect personal data
- Inform employees/users about use of HRMS4U
- Obtain required consent where necessary
- Ensure uploaded data is accurate
- Use the service in compliance with applicable laws
- Respond to data subject requests unless assistance is required
The Customer is solely responsible for HR, payroll, labor, tax, and employment compliance obligations.
8. Processor Obligations
HRMS4U shall:
- Process personal data only on documented customer instructions
- Use data only to provide contracted services
- Maintain confidentiality
- Implement reasonable technical and organizational safeguards
- Notify customer of confirmed personal data incidents where legally required
- Delete or return data as described in this DPA
9. Confidentiality
All personnel authorized to access customer data shall be subject to confidentiality obligations or equivalent professional duties.
Access shall be limited to persons who need access for:
- Service delivery
- Maintenance
- Technical support
- Security operations
10. Security Measures
HRMS4U implements commercially reasonable safeguards, which may include:
- Hosting on DigitalOcean or equivalent infrastructure
- Data encryption in transit and/or at rest where applicable
- Password protections
- Role-based access controls
- Secure backups
- Monitoring systems
- Firewall/network protections
- Routine maintenance
No method of transmission or storage can guarantee absolute security.
11. Data Backups
Daily backups may be maintained for business continuity and disaster recovery purposes.
Backup copies may remain in secure retention cycles for limited periods even after deletion requests.
12. Sub processors
HRMS4U may engage trusted sub processors to support service delivery, including providers for:
- Cloud hosting
- Email delivery
- Monitoring
- Backup systems
- Payment processing
- Customer support tools
We remain responsible for ensuring subprocessors are subject to appropriate obligations.
13. International Data Transfers
Where sub processors or infrastructure involve access outside India, HRMS4U shall use commercially reasonable safeguards appropriate to the transfer.
14. Assistance with Data Subject Requests
Where feasible and reasonable, HRMS4U may assist the Customer in responding to requests involving:
- Access requests
- Correction requests
- Deletion requests
- Restriction requests
- Portability requests
Such assistance may depend on technical feasibility and subscription scope.
15. Security Incidents
If HRMS4u becomes aware of a confirmed personal data breach affecting customer data, we will notify the Customer within a commercially reasonable time where required by law.
Notification may include:
- Nature of incident
- Affected systems/data (if known)
- Steps taken
- Recommended mitigation actions
16. Audit & Information Requests
Upon reasonable written request, HRMS4U may provide information regarding security practices sufficient to demonstrate compliance with this DPA, subject to:
- Protection of confidential information
- Security restrictions
- Operational feasibility
Formal audits may require separate agreement.
17. Data Retention & Deletion
Upon cancellation or termination:
- Customer data may remain accessible for up to 30 days
- Thereafter, production data may be deleted
- Backup archives may persist temporarily in rotation systems
Customers should export needed data before termination.
18. Return of Data
Where technically feasible and included in the service plan, customers may export available data using:
- Standard export tools
- Reports
- CSV / downloadable records
Custom migration services may be separately chargeable.
19. Liability
Liability under this DPA shall be subject to the liability limitations set out in the main Terms & Conditions, unless otherwise required by law.
20. Governing Law
This DPA shall be governed by the laws of India.
Any disputes shall be subject to courts located in Chandigarh.
21. Order of Precedence
If there is a conflict between this DPA and the Terms & Conditions regarding personal data processing, this DPA shall prevail only to that extent.
22. Changes to this DPA
We may update this DPA from time to time to reflect legal, technical, or operational changes.
Updated versions become effective upon publication or written notice.
23. Contact Information
HRMS4U
Operated by DesignzIndia
India
For privacy or data processing requests:
Email: [email protected]