Data Processing Agreement
Last reviewed 1 August 2026.
About this agreement
This Data Processing Agreement ("DPA") describes how BizBrainX, operated by Enerzyzone Vertex Innovations LLP, Pune, India ("BizBrainX," "we," "us"), processes personal data on your behalf when you use the platform. It forms part of, and should be read with, our Terms of Service and Privacy Policy. Where this DPA conflicts with the Terms on the subject of personal-data processing, this DPA governs.
Roles of the parties
For the leads, customers, and employee data you bring into BizBrainX, you (your business) are the Data Fiduciary (controller) and BizBrainX is your Data Processor, under the Digital Personal Data Protection Act, 2023. We process that data only to provide the service to you, on your instructions, and never for our own independent purposes.
For your own account data (name, email, phone, billing details), BizBrainX is the Data Fiduciary and our Privacy Policy governs that processing directly.
Scope, nature, and duration of processing
Subject matter & purpose: processing personal data as needed to operate the modules you activate (sales/CRM, marketing, finance, compliance, operations, HR, and related features).
Categories of data principals: your leads, customers, prospects, employees, and other contacts whose data you enter or connect.
Categories of personal data: contact and identity details, business and transaction records, communications, and other data you choose to store in the platform. You must not put special-category or unnecessary personal data into the platform without a lawful basis.
Duration: for as long as your account is active, subject to the return and deletion terms below.
Processing on your instructions
We process personal data only on your documented instructions — which include your use of the product's features and configuration — and as required by applicable law. If a legal requirement compels us to process beyond your instructions, we will inform you unless the law prohibits it.
Confidentiality
Personnel authorized to process your data are bound by confidentiality obligations and access data only on a need-to-know basis.
Security measures
We maintain appropriate technical and organizational measures, including: encryption in transit (HTTPS) and at rest; tenant isolation via row-level security on every table so your data is never visible to another organization; least-privilege, restricted and audited production access; and secrets held in a secure store, never in application code.
Sub-processors
You authorize us to engage the sub-processors below to help provide the service. Each receives only the data it needs for its specific function and is bound to data-protection obligations consistent with this DPA.
Clerk — Authentication and account sign-in only — never your business or customer data.
Supabase — Primary database hosting for your business data (Mumbai, India region).
Razorpay — Platform subscription payment processing only — never customer/lead-level payments.
Anthropic — AI processing (Claude models) for agent responses and drafting.
OpenRouter — AI routing for select lower-cost/classification tasks, using Zero Data Retention.
Meta — WhatsApp Cloud API messaging, where you have connected it.
Resend — Transactional email delivery.
Vercel — Application hosting and content delivery.
We keep this list current (it is also published on our Privacy Policy). If we add or replace a sub-processor, we will update this page; you may object on reasonable data-protection grounds by writing to us.
International transfers
Your business data is stored in India (Supabase, Mumbai region). Some processing necessarily crosses borders — for example AI requests to Anthropic and WhatsApp messages via Meta. We transfer personal data outside India only to countries not restricted by the Government of India for such transfers, and only under contractual terms that limit each provider to the agreed processing purpose, consistent with the DPDP Act, 2023.
Assistance to you
Taking into account the nature of processing, we will assist you, so far as reasonably possible, in: responding to data-principal requests (access, correction, erasure) — export and delete tools are available in your account; keeping data secure; notifying breaches; and any data-protection impact assessment you are required to carry out.
Personal data breach
If we become aware of a personal-data breach affecting data we process for you, we will notify you without undue delay and provide the information you reasonably need to meet your own notification obligations under the DPDP Act, 2023.
Return and deletion
On termination or account closure, you can export your data using the in-app export tools. After closure we delete or anonymize the personal data we process for you within 90 days, except where we are required to retain certain records longer to meet legal, tax, or dispute-resolution obligations; residual copies in backups are purged on our regular backup cycle.
Records and information
We will make available, on reasonable request, the information reasonably necessary to demonstrate compliance with this DPA. Any on-site audit is by prior written agreement, during business hours, subject to confidentiality, and without disrupting other customers or the security of the multi-tenant platform.
Requesting a signed DPA
If your organization requires a countersigned copy of this DPA, write to us at info@enerzyzone.com with your account and entity details, and we will arrange it.
Governing law
This DPA is governed by the laws of India, with courts in Pune, Maharashtra having jurisdiction.
Contact
Questions about this DPA or data processing: info@enerzyzone.com (Grievance Officer: Abhishek Potare — see our Grievance Redressal page).