Data Processing Agreement
The processor terms under the DPDP Act 2023: the customer as Data Fiduciary, ZeniaPex as Data Processor, security measures, breach notice and the sub-processor list.
Contents
This Data Processing Agreement ("DPA") forms part of the Terms of Service between ZeniaPex Private Limited ("Processor", "we") and the Customer ("Fiduciary", "you"). It governs the personal data of your employees, workers, candidates, clients and other individuals ("Data Principals") that you process using ZeniaHR ("Customer Personal Data"). Terms have the meaning given in the Digital Personal Data Protection Act 2023 ("DPDP Act").
1. Roles
You are the Data Fiduciary and we are the Data Processor for Customer Personal Data. We process it only on your documented instructions, which are these Agreements, your configuration of the Service, and your use of its features.
2. Processing details
| Item | Description |
|---|---|
| Subject matter | Providing the ZeniaHR HR, attendance, payroll, compliance and document service |
| Duration | The subscription term plus the deletion period in the Data Retention and Deletion Policy |
| Nature and purpose | Hosting, storing, computing, transmitting, backing up and displaying data to run the HR and payroll processes you configure |
| Data Principals | Your employees, contract workers, candidates, contacts at your clients and vendors, and your admin users |
| Categories of data | Identity and contact; employment and salary; attendance and location (when enabled); bank, PAN, Aadhaar, UAN, ESIC and similar identifiers; documents and photos; leave and performance; device tokens |
3. Your obligations
3.1 Give Data Principals the notice the DPDP Act requires and obtain consent, or rely on another lawful ground (including employment purposes under s.7(i)), before putting their data into the Service.
3.2 Ensure your instructions and use are lawful, that data is accurate and limited to what you need, and that you keep statutory records yourself.
3.3 Respond to Data Principals' requests and grievances; we assist as set out in section 6.
3.4 Configure access rights and security settings appropriately and keep credentials secure.
4. Our obligations
4.1 Process only on your instructions, and tell you if an instruction appears unlawful.
4.2 Keep Customer Personal Data confidential; allow access only to staff who need it and are bound by confidentiality.
4.3 Implement the technical and organizational measures in section 5.
4.4 Not sell Customer Personal Data, share it for advertising, or use it for our own purposes, except as aggregated, non-identifying service statistics.
4.5 Process in India; not transfer data outside India without your prior written consent and the safeguards the law requires.
4.6 Delete or return Customer Personal Data at the end of the relationship under the Data Retention and Deletion Policy, and confirm deletion in writing.
5. Security measures
Encryption in transit (TLS 1.2 or higher) and at rest; role-based access with logging; separate customer workspaces; multi-factor authentication for our staff; secure software development and vulnerability management; daily backups in AWS Mumbai with restore testing; network firewalls and intrusion detection; staff background checks and confidentiality undertakings; an incident response plan; periodic third-party security assessment. We may improve these measures over time and will not lower the overall level of protection.
6. Assistance
We help you respond to Data Principal requests (access, correction, erasure, withdrawal) through the Service's export, edit and delete tools, and with reasonable additional help at our standard rates for unusual requests. We help with your assessments and with the Data Protection Board where our processing is involved.
7. Personal data breach
If we become aware of a personal data breach affecting Customer Personal Data, we notify your admin contacts without undue delay and within 48 hours, with what we know: the nature of the breach, the data and Data Principals affected, the likely consequences, and the measures taken. You remain responsible for notifying the Data Protection Board and Data Principals as the DPDP Act requires; we give you the information you need to do so.
8. Sub-processors
You authorize the sub-processors below. We post changes at zeniahr.com/legal/dpa/ and email your admins at least 30 days before adding one; you may object on reasonable data-protection grounds, and if we cannot resolve the objection you may terminate the affected service.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting, storage, backups | Mumbai, India |
| Google Firebase Cloud Messaging | Push notifications to the employee app (device tokens and notification content only) | Google infrastructure |
| Zoho Corporation | Email delivery, support desk, CRM, sign-in | India data centre |
| Payment gateway (Cashfree or Razorpay, as shown at checkout) | Subscription payments | India |
| SMS and OTP provider, as configured | OTP and SMS notifications | India |
| India Post PIN code API | PIN code to city and state lookup (PIN code only) | India |
9. Audits and information
On request, no more than once a year or after a breach, we provide information to demonstrate compliance with this DPA, including summaries of security assessments, and allow an audit by you or an independent auditor bound by confidentiality, at your cost, on 30 days' notice, without disrupting other customers.
10. Liability and term
Liability under this DPA is subject to the limitation of liability in the Terms of Service. This DPA lasts as long as we process Customer Personal Data.
11. Contact
Data protection queries: sales@zeniahr.com. The Grievance Officer is named in the Privacy Policy.
Version history
| Version | Effective date | Change | Link |
|---|---|---|---|
| v1.0 | 29 September 2026 | First release | /legal/dpa/v1.0/ |
Every version stays online at its own address and is never edited after publication. A customer who accepted an earlier version is linked to that exact text.