Data Processing Agreement
How Naaradh processes personal data on a merchant’s behalf (DPDP Act 2023; GDPR Art. 28 where applicable).
Last updated 2026-09-12
Draft — pending review by counsel. It describes how the product works today; binding terms follow legal review.
Scope and instructions
Naaradh processes customer phone numbers, names, order details, recordings and transcripts only to place and answer calls the merchant has configured, to record outcomes and to bill. The merchant’s configuration is its documented instruction.
Security measures
- Numbers hashed for lookups and encrypted at rest; decryption only by the dialling component.
- Tenant isolation enforced by database row-level security.
- Recordings encrypted with customer-managed keys; access by signed, short-lived links, every access logged and visible to the merchant.
- Every inbound webhook and engine request verified by signature before processing.
Sub-processors
Listed on the sub-processors page with at least 30 days’ notice of changes.
Breaches, deletion, audits
Breach notification timelines, audit rights and deletion on termination: to be finalised with counsel. Data residency: see the Privacy Policy (database hosted in Singapore; recordings in Mumbai).