Data Processing Agreement
This Data Processing Agreement ('DPA') forms part of the commercial agreement between Pathari Trader Private Limited ('Pathari') and the Provider. It governs the processing of personal data by Pathari on behalf of the Provider in connection with India market access services.
1. Definitions
In this DPA:
'Personal Data' means any information relating to an identified or identifiable natural person, as defined under applicable data protection law including India's Digital Personal Data Protection Act 2023 (DPDP Act) and, where applicable, the EU General Data Protection Regulation (GDPR).
'Processing' means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
'Controller' means the party that determines the purposes and means of processing Personal Data. In most cases under this DPA, the Provider is the Controller.
'Processor' means the party that processes Personal Data on behalf of the Controller. In most cases under this DPA, Pathari is the Processor.
'Data Subject' means the individual whose Personal Data is being processed.
'Sub-processor' means any third party engaged by Pathari to process Personal Data on behalf of the Provider.
2. Scope and Nature of Processing
This DPA applies where Pathari processes Personal Data on behalf of the Provider in the course of delivering India market access services.
Categories of Personal Data processed may include: names, email addresses, job titles, company information, and commercial interaction records of the Provider's prospects, customers, and contacts in India.
Purpose of processing: business development, pipeline management, customer onboarding, support coordination, and renewal management within the agreed scope of services.
Duration: for the term of the commercial Agreement and as required for legal compliance thereafter.
3. Obligations of Pathari
As Processor, Pathari shall:
Process Personal Data only on documented instructions from the Provider, unless required to do so by applicable law.
Ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations.
Implement appropriate technical and organisational security measures to protect Personal Data.
Not engage sub-processors without prior written authorisation from the Provider, except as set out in this DPA.
Assist the Provider in responding to Data Subject requests and in meeting its compliance obligations under applicable law.
Delete or return all Personal Data to the Provider upon termination of the Agreement, unless retention is required by law.
4. Provider Obligations
As Controller, the Provider shall:
Ensure that Personal Data shared with Pathari has been collected lawfully and that Data Subjects have been informed of its use for India market development purposes.
Provide clear and documented instructions for the processing of Personal Data.
Notify Pathari promptly of any changes to applicable data protection law that affect the scope or nature of processing.
Ensure that all Personal Data provided to Pathari is accurate, relevant, and limited to what is necessary for the agreed purposes.
5. Sub-processors
Pathari may engage the following categories of sub-processors to deliver its services:
CRM and pipeline management platforms used to track commercial activities and customer interactions.
Email and communication tools used for correspondence with prospects and customers.
Cloud storage and productivity services used to manage documents and project records.
Analytics tools used to monitor service delivery and performance.
Pathari will notify the Provider of any intended changes to its sub-processors and allow reasonable time for the Provider to object. All sub-processors are bound by data protection obligations equivalent to those in this DPA.
6. International Data Transfers
Personal Data processed under this DPA may be transferred between India, Portugal, and other locations where Pathari or its sub-processors operate.
All international transfers of Personal Data will be conducted in accordance with applicable law, including through appropriate safeguards such as standard contractual clauses where required by EU or UK data protection law.
Where the Provider is subject to GDPR, Pathari will enter into EU Standard Contractual Clauses upon request.
7. Security Measures
Pathari implements the following technical and organisational measures to protect Personal Data:
Access controls limiting Personal Data access to authorised personnel only.
Encryption of Personal Data in transit using industry-standard protocols.
Regular review of security practices and access permissions.
Secure deletion of Personal Data when no longer required.
Pathari will review and update these measures as technology and threats evolve.
8. Data Breaches
In the event of a Personal Data breach affecting data processed under this DPA, Pathari shall:
Notify the Provider without undue delay and in any case within 72 hours of becoming aware of the breach.
Provide the Provider with sufficient information to meet its own notification obligations under applicable law.
Take immediate steps to contain the breach and prevent further unauthorised access or disclosure.
Cooperate fully with the Provider in investigating the breach and implementing remedial measures.
9. Data Subject Rights
Where a Data Subject exercises their rights under applicable law (including rights of access, rectification, erasure, restriction, or portability) in relation to Personal Data processed by Pathari on behalf of the Provider, Pathari shall:
Promptly forward the request to the Provider.
Provide reasonable assistance to the Provider in responding to the request within the required timeframe.
Not respond directly to Data Subjects on behalf of the Provider unless expressly authorised to do so.
10. Termination and Return of Data
Upon termination or expiry of the commercial Agreement, Pathari shall, at the Provider's choice:
Return all Personal Data to the Provider in a structured, commonly used format; or
Securely delete all Personal Data, and provide written confirmation of deletion.
Pathari may retain Personal Data beyond termination only where required by applicable law, and shall inform the Provider of any such retention.
11. Contact
For questions about this DPA or to exercise data protection rights, contact us at:
Pathari Trader Private Limited
Data Protection Contact
Email: privacy@pathari.com
Address: New Delhi, India
This DPA should be read alongside the Privacy Policy and Terms of Service published on this website.
© 2026 Pathari Trader Private Limited · India Market Access · New Delhi