DATA PROTECTION ADDENDUM
Last Updated: August 2026
This Data Protection Addendum (“Addendum”) between Enthralltech Private Limited (“Enthralltech”) and the Customer (as defined in the Agreement) forms part of the Enthralltech Terms of Service or such other written or electronic agreement incorporating this Addendum, in each case governing Customer’s access to and use of the Services (the “Agreement”).
Customer enters into this Addendum on behalf of itself and any Affiliates authorized to use the Services under the Agreement and who have not entered into a separate contractual arrangement with Enthralltech. For the purposes of this Addendum only, and except where otherwise indicated, references to “Customer” shall include Customer and such Affiliates.
The Parties hereby agree that the terms and conditions set out below shall be added as an Addendum to the Agreement.
1. DEFINITIONS
In this Addendum, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:
“Affiliate” means an entity that owns or controls, is owned or controlled by, or is or under common control or ownership with either Customer or Enthralltech, as the context allows, where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract, or otherwise.
“Customer Personal Data” means any Personal Data provided by or made available by Customer to Enthralltech, or collected by Enthralltech on behalf of Customer, which is Processed by Enthralltech to perform the Services.
“Controller to Processor SCCs” means the standard contractual clauses for cross-border transfers adopted or approved by the European Commission, the UK Information Commissioner’s Office, the Swiss Federal Data Protection and Information Commissioner, or any successor or equivalent clauses adopted by an applicable data protection regulator relating to transfers of Personal Data to Third Countries.
“Data Protection Laws” means any local, state, national, or international law regarding the Processing of Personal Data applicable to Enthralltech in the jurisdictions in which the Services are provided to Customer, including, without limitation, applicable privacy, security, and data protection laws.
“EU Area” means the European Union, European Economic Area, United Kingdom, and Switzerland.
“EU Area Law” means:
- Regulation (EU) 2016/679 (“EU GDPR”), together with applicable legislation implementing, supplementing, or relating to the Processing of Personal Data;
- the UK GDPR and applicable UK data protection legislation;
- applicable Swiss data protection legislation;
- any other law relating to data protection, security, or privacy of individuals that applies in the EU Area; and
- any successor or amendment to the foregoing.
“Security Incident” means any breach of security that leads to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data being Processed by Enthralltech.
“Services” means the services supplied by Enthralltech to Customer or Customer’s Affiliates pursuant to the Agreement.
“Third Country” means a country that, where required by applicable Data Protection Laws, has not received an adequacy decision from an applicable authority relating to cross-border transfers of Personal Data.
The terms “Business,” “Business Purpose,” “commercial purpose,” “Contractor,” “Controller,” “Data Subject,” “Personal Data,” “Personal Data Breach,” “Process,” “Processor,” “Sell,” “Service Provider,” “Share,” “Subprocessor,” “Supervisory Authority,” and “Third Party” shall have the meanings assigned to them under applicable Data Protection Laws.
Capitalized terms not otherwise defined in this Addendum shall have the meanings ascribed to them in the Agreement.
2. SCOPE OF ADDENDUM
This Addendum applies to Enthralltech’s Processing of Customer Personal Data under the Agreement to the extent such Processing is subject to Data Protection Laws.
This Addendum is governed by the governing law of the Agreement unless otherwise required by applicable Data Protection Laws.
3. ROLES OF THE PARTIES
The Parties acknowledge and agree that, with regard to the Processing of Customer Personal Data and as more fully described in Annex 1:
- Customer acts as the Business or Controller; and
- Enthralltech acts as the Service Provider or Processor.
This Addendum shall apply solely to the Processing of Customer Personal Data by Enthralltech acting as a Processor, Subprocessor, or Third Party, as applicable.
Customer shall be solely responsible for ensuring timely communications to Customer’s Affiliates or relevant Controller(s) who receive the Services insofar as such communications may be required or useful under applicable Data Protection Laws.
Customer shall remain responsible for complying with Security Incident notification laws applicable to Customer and for fulfilling any obligations to notify governmental authorities, affected individuals, or other parties relating to Security Incidents.
4. DESCRIPTION AND PURPOSE OF PERSONAL DATA PROCESSING
In Annex 1 to this Addendum, the Parties have set out their understanding of the subject matter and details of the Processing of Customer Personal Data to be Processed by Enthralltech pursuant to this Addendum.
The Parties may make reasonable amendments to Annex 1 by mutual written agreement where reasonably necessary to reflect changes to the Services or requirements of applicable Data Protection Laws.
The purpose of Processing under this Addendum is the provision of the Services pursuant to the Agreement and applicable Order Forms.
5. DATA PROCESSING TERMS
5.1 Customer Obligations
Customer shall comply with all applicable Data Protection Laws in connection with the performance of this Addendum and the Processing of Customer Personal Data.
In connection with its access to and use of the Services, Customer shall Process Customer Personal Data within the Services and provide Enthralltech with instructions in accordance with applicable Data Protection Laws.
As between the Parties, Customer shall be solely responsible for compliance with applicable Data Protection Laws regarding the collection of and transfer to Enthralltech of Customer Personal Data.
Unless otherwise expressly agreed in writing, Customer shall not provide Enthralltech with data concerning an individual’s health, religion, or special categories of Personal Data as defined under applicable Data Protection Laws.
5.2 Enthralltech Obligations
Enthralltech shall comply with all applicable Data Protection Laws in the Processing of Customer Personal Data and shall:
5.2.1 Processing on Instructions
Process Customer Personal Data for the purposes of the Agreement and for the specific purposes set out in Annex 1 and otherwise solely on the documented instructions of Customer for purposes of providing the Services and performing its obligations under the Agreement.
The Agreement, this Addendum, and Customer’s use of the Services’ features and functionality constitute Customer’s written instructions to Enthralltech in relation to Processing Customer Personal Data.
5.2.2 Purpose Limitation
Enthralltech shall use, retain, disclose, or otherwise Process Customer Personal Data only on behalf of Customer and for the specific business purpose of providing the Services and in accordance with Customer’s instructions.
Enthralltech shall not Sell or Share Customer Personal Data, nor use, retain, disclose, or otherwise Process Customer Personal Data outside of its business relationship with Customer or for another purpose, including Enthralltech’s own commercial purpose, except as required or permitted by law.
Enthralltech shall promptly inform Customer if:
a. Enthralltech determines that it is no longer able to meet its obligations under applicable Data Protection Laws; or
b. in Enthralltech’s reasonable opinion, an instruction infringes applicable Data Protection Laws.
5.2.3 Permitted Processing
Enthralltech may Process Customer Personal Data solely to the extent necessary to:
a. perform the Services and its obligations under the Agreement;
b. operate, manage, test, maintain, support, and enhance the Services;
c. disclose aggregate statistics about the Services in a manner that prevents individual identification or re-identification of Customer Personal Data;
d. protect the Services and Customer Personal Data from security threats or other harmful activity;
e. comply with a valid court order or legally binding request from an authorized governmental authority;
f. comply with applicable legal obligations; or
g. perform any other activity expressly authorized by Customer.
5.2.4 Separation of Personal Data
Enthralltech shall not combine Customer Personal Data that it Processes on Customer’s behalf with Personal Data received from or on behalf of another person or persons, or collected from Enthralltech’s own interaction with individuals, except to the extent such combination is reasonably necessary to perform a permitted Business Purpose under the Agreement.
5.2.5 Confidentiality
Enthralltech shall implement and maintain measures designed to ensure that personnel authorized to Process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory or contractual obligation of confidentiality unless disclosure is required by law or professional regulations.
5.2.6 Technical and Organizational Measures
Enthralltech shall implement and maintain the technical and organizational measures described in the Agreement and Annex 2.
Taking into account the state of the art, costs of implementation, and the nature, scope, context, and purposes of Processing, Enthralltech shall maintain commercially reasonable measures designed to ensure a level of security appropriate to the risk of Processing Customer Personal Data.
Such measures shall include, where appropriate:
a. pseudonymization and encryption of Customer Personal Data;
b. measures designed to ensure ongoing confidentiality, integrity, availability, and resilience of Processing systems and services;
c. measures designed to restore availability and access to Customer Personal Data in a timely manner following a physical or technical incident; and
d. regular testing, assessment, and evaluation of the effectiveness of technical and organizational measures.
6. SUBPROCESSORS
Customer generally authorizes Enthralltech to engage and appoint Subprocessors and specifically authorizes the Subprocessors listed in Annex 3.
Enthralltech shall:
6.1 Notice
Notify Customer at least thirty (30) calendar days in advance of any intended material changes or additions to its Subprocessors listed in Annex 3 by providing notice to Customer.
6.2 Contractual Obligations
Include data protection obligations in its contract with each Subprocessor that are materially consistent with the obligations set out in this Addendum.
6.3 Responsibility
Remain responsible to Customer for the performance of each Subprocessor with respect to its Processing of Customer Personal Data, subject to the terms and limitations of the Agreement.
6.4 Objection
Customer shall have thirty (30) days from the date of notice to inform Enthralltech in writing of any reasonable objection on material data protection grounds to the use of such Subprocessor.
The Parties shall then, for a period of no more than thirty (30) days from the date of Customer’s objection, work together in good faith to attempt to identify a commercially reasonable solution that avoids the use of the objected-to Subprocessor.
Where no such solution can be found, either Party may, notwithstanding anything to the contrary in the Agreement, terminate the affected Services upon written notice to the other Party, without damages, penalty, or indemnification solely as a result of such termination, but without prejudice to fees incurred by Customer before termination.
7. LEGALLY BINDING DISCLOSURES
To the extent legally permissible, Enthralltech shall promptly notify Customer in the event of any legally binding request for disclosure of Customer Personal Data received by Enthralltech.
Such requests may include requests arising from:
- court orders;
- subpoenas;
- governmental authorities;
- law enforcement agencies; or
- other legally authorized bodies.
Where a request is not legally binding, Enthralltech shall, where legally permissible, reject or challenge the request and notify Customer.
Enthralltech shall disclose only the Customer Personal Data legally required and shall maintain reasonable records of legally binding disclosure requests relating to Customer Personal Data.
8. DATA SUBJECT REQUESTS AND REGULATORY COMMUNICATIONS
To the extent legally permissible, Enthralltech shall promptly notify Customer of:
a. any communication from a Data Subject regarding Processing of Customer Personal Data; and
b. any communication from a Supervisory Authority concerning an obligation under applicable Data Protection Laws relating to Customer Personal Data.
Enthralltech shall not respond to such requests unless expressly authorized by Customer or otherwise required by applicable Data Protection Laws.
Taking into account the nature of the Processing, Enthralltech shall reasonably assist Customer, Customer Affiliates, or relevant Controllers through appropriate technical and organizational measures insofar as reasonably possible to fulfill obligations concerning Data Subject rights.
Such assistance may include assistance concerning:
- access;
- correction;
- deletion;
- restriction;
- objection;
- portability;
- withdrawal of consent; and
- other rights available under applicable Data Protection Laws.
Where permitted by the Agreement, Customer shall reimburse Enthralltech for reasonable additional time and out-of-pocket expenses incurred in providing assistance beyond the standard functionality of the Services.
9. PERSONAL DATA BREACHES
Upon becoming aware of a Personal Data Breach involving Customer Personal Data, Enthralltech shall notify Customer without undue delay.
The notification shall include, to the extent reasonably available:
a. the nature of the Personal Data Breach;
b. the categories of Customer Personal Data affected;
c. the approximate number or categories of affected Data Subjects;
d. the likely consequences of the Personal Data Breach;
e. measures taken or proposed to address the Personal Data Breach; and
f. other information reasonably required by Customer to comply with applicable data breach reporting obligations.
Enthralltech shall take reasonable measures and actions necessary to remedy or mitigate the effects of the Security Incident and shall keep Customer reasonably informed of material developments.
Customer acknowledges that Enthralltech’s notification of a Security Incident does not constitute an acknowledgement by Enthralltech of fault or liability.
Security Incidents do not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, including unsuccessful login attempts, pings, port scans, denial-of-service attempts, or other unsuccessful network attacks.
10. ASSISTANCE WITH DATA PROTECTION OBLIGATIONS
To the extent required by applicable Data Protection Laws, Enthralltech shall provide reasonable assistance to Customer, Customer Affiliates, or relevant Controllers concerning obligations relating to:
- security of Processing;
- Personal Data Breaches;
- Data Protection Impact Assessments;
- prior consultation with Supervisory Authorities;
- security assessments;
- regulatory investigations; and
- other applicable data protection compliance obligations.
Where permitted by the Agreement, Customer shall reimburse Enthralltech for reasonable additional time and out-of-pocket expenses incurred in connection with assistance that is beyond the standard functionality of the Services.
11. RETURN AND DELETION
Upon termination or expiry of the Agreement, Enthralltech shall cease Processing Customer Personal Data.
At Customer’s option, Enthralltech shall either:
a. return Customer Personal Data to Customer; or
b. delete Customer Personal Data,
unless and solely to the extent and for such period as applicable law requires Enthralltech to retain some or all of the Customer Personal Data.
Any Customer Personal Data retained pursuant to applicable law shall remain subject to the confidentiality obligations contained in the Agreement and this Addendum.
12. RECORDS OF PROCESSING
Enthralltech shall maintain necessary records reasonably required to demonstrate compliance with its obligations concerning the Processing of Customer Personal Data carried out on behalf of Customer.
13. AUDITS AND COMPLIANCE
Enthralltech shall make available to Customer all information reasonably necessary to demonstrate compliance with this Addendum and shall allow for and contribute to audits, including inspections, by Customer or an independent third-party auditor mandated by Customer.
Customer shall:
a. provide reasonable prior notice of an intended audit;
b. conduct audits during Enthralltech’s normal business hours;
c. take reasonable measures to prevent unnecessary disruption to Enthralltech’s operations; and
d. comply with reasonable confidentiality and security requirements.
As a first instance, Customer may request relevant cybersecurity questionnaires, compliance assessments, security documentation, certifications, audit reports, or similar documentation available to Enthralltech.
Where such information is insufficient to demonstrate compliance, Customer may request a reasonable inspection of relevant Processing operations.
Where permitted under the Agreement, Customer shall reimburse Enthralltech for reasonable time and out-of-pocket expenses incurred in connection with extraordinary audits or assessments.
14. WARRANTIES
The Parties warrant that they and their personnel, contractors, and Subprocessors shall comply with their respective obligations under applicable Data Protection Laws for the duration of the Agreement.
15. RESTRICTED TRANSFERS
The Parties agree that when the transfer of Customer Personal Data from Customer or its Affiliates, as exporter, to Enthralltech, as importer, constitutes a Restricted Transfer and EU Area Law applies, the transfer shall be subject to an appropriate Controller-to-Processor transfer mechanism.
Where applicable, the EU Standard Contractual Clauses shall be incorporated into and form part of this Addendum.
15.1 EU GDPR
For Customer Personal Data protected by the EU GDPR and Processed by Enthralltech on behalf of and under the instructions of Customer, the applicable EU SCC Controller-to-Processor module shall apply.
The applicable SCC annexes shall be completed using the information contained in Annex 1 and Annex 2 of this Addendum.
15.2 Switzerland
For Customer Personal Data protected by Swiss data protection law, the EU SCCs, where used, shall be interpreted and adapted as necessary to comply with applicable Swiss data protection requirements.
References to EU institutions, Member States, EU law, or EU supervisory authorities shall be interpreted as references to their applicable Swiss equivalents where required.
15.3 United Kingdom
For Customer Personal Data protected by the UK GDPR, the EU SCCs, where applicable, shall be supplemented by the UK International Data Transfer Addendum or another lawful UK transfer mechanism.
16. INTERNATIONAL TRANSFERS
Enthralltech shall not participate in Restricted Transfers of Customer Personal Data unless such transfer is made in compliance with applicable Data Protection Laws and pursuant to an appropriate lawful transfer mechanism.
Customer should assess international transfers on a case-by-case basis where required to monitor changes in local laws, data practices, and transfer risks.
Where appropriate, the Parties shall implement additional safeguards, including:
- encryption;
- access restrictions; and
- other supplementary technical and organizational measures.
17. TRANSFER MECHANISM
Where a Party is located outside the EEA or another jurisdiction recognized as providing an adequate level of protection and receives Personal Data:
a. that Party shall act as the data importer;
b. the other Party shall act as the data exporter; and
c. the relevant lawful Transfer Mechanism shall apply.
A Transfer Mechanism may include:
- Standard Contractual Clauses approved by the European Commission;
- the UK International Data Transfer Agreement;
- the UK International Data Transfer Addendum;
- an adequacy decision; or
- another lawful mechanism recognized under applicable Data Protection Laws.
18. ADDITIONAL TRANSFER SAFEGUARDS
If the applicable Transfer Mechanism is insufficient to safeguard transferred Personal Data, the data importer shall implement reasonable supplementary measures necessary to ensure that the Personal Data receives protection required under applicable Data Protection Laws.
Where the data importer receives a request from a public authority to access Personal Data, the importer shall, where legally permitted:
a. challenge the request where reasonable legal grounds exist;
b. promptly notify the data exporter;
c. disclose only the minimum amount of Personal Data legally required; and
d. maintain a record of the disclosure.
19. PRIVACY BY DESIGN AND DEFAULT
The Parties acknowledge that this Addendum addresses, where applicable:
- Privacy by Design and Default;
- security of Processing;
- notification of Personal Data Breaches;
- notification and cooperation with relevant Supervisory Authorities;
- Data Protection Impact Assessments;
- prior consultation with Supervisory Authorities; and
- reasonable assistance by Enthralltech in fulfilling applicable data protection obligations.
Enthralltech shall maintain reasonable privacy and security practices appropriate to the Services and applicable Data Protection Laws.
20. DATA PROTECTION CONTACT
For requests concerning Customer Personal Data or the exercise of applicable Data Subject rights, requests may be submitted to:
Company:
Enthralltech
Data Protection Officer / Privacy Contact:
Vaibhav Satpute
Email:
vaibhav.satpute@enthral.ai
21. TEMPORARY FILES
Enthralltech shall maintain reasonable controls concerning temporary files created during Processing.
Where the Services do not generate temporary files during Processing, Enthralltech may state:
“No temporary files are generated during processing.”
22. PRECEDENCE
The provisions of this Addendum are supplemental to the provisions of the Agreement.
In the event of an inconsistency, the following order of precedence shall apply:
a. applicable Standard Contractual Clauses or other mandatory Cross-Border Transfer Mechanisms;
b. this Addendum; and
c. the Agreement.
In the event that any provision of this Addendum or the Agreement contradicts mandatory provisions of applicable Controller-to-Processor SCCs, the applicable SCCs shall control.
23. INDEMNITY
To the extent permissible by applicable law and subject to the liability and indemnification provisions of the Agreement, each Party shall be responsible for losses, damages, liabilities, penalties, costs, and expenses arising from its own breach of this Addendum or its obligations under applicable Data Protection Laws.
Nothing in this Addendum shall exclude or limit liability to the extent prohibited by applicable law.
24. SEVERABILITY
The Parties agree that if any section or subsection of this Addendum is held by any court or competent authority to be unlawful, invalid, or unenforceable, such provision shall be modified to the minimum extent necessary to make it enforceable, and the remaining provisions shall continue in full force and effect.
ANNEX 1 — DESCRIPTION OF PROCESSING ACTIVITIES FOR CUSTOMER PERSONAL DATA
This Annex includes details of the Processing of Customer Personal Data by Enthralltech in connection with the Services.
1. LIST OF PARTIES
DATA EXPORTER
Name:
Customer, as defined in the Agreement.
Address:
As set forth in the relevant Order Form.
Contact Person’s Name, Position and Contact Details:
As set forth in the relevant Order Form.
Activities relevant to the data transferred:
Recipient of the Services provided by Enthralltech in accordance with the Agreement.
Signature and Date:
Signature and date are set out in the Agreement.
Role:
Controller / Business.
DATA IMPORTER
Name:
Enthralltech
Legal Entity Name:
Enthralltech Private Limited
Address:
The 5th Avenue Office No:D-4, 3rd Floor, Balkrishna Sakharam Dhole Patil Rd, Pune, Maharashtra 411001
Contact Person’s Name, Position and Contact Details:
Dhruv Inamdar, CTO, dhruv@enthral.ai
Activities relevant to the data transferred:
Provision of the Services to Customer in accordance with the Agreement.
Signature and Date:
Signature and date are set out in the Agreement.
Role:
Processor / Service Provider.
2. COMPETENT SUPERVISORY AUTHORITY
The competent Supervisory Authority shall be identified in accordance with the applicable Data Protection Laws and, where applicable, Clause 13 of the EU SCCs.
3. PROCESSING INFORMATION
Categories of Data Subjects Whose Personal Data Is Transferred
Depending on the Services, categories of Data Subjects may include:
- Customer’s authorized users of the Services;
- Customer employees;
- Customer contractors;
- Customer representatives;
- Customer customers;
- Customer vendors and suppliers; and
- other individuals whose Personal Data is submitted by Customer or its authorized users.
Categories of Personal Data Transferred
Personal Data may include, depending on the Services:
- names;
- email addresses;
- telephone numbers;
- business contact information;
- job title;
- company information;
- user identifiers;
- account information;
- IP addresses;
- device information;
- browser information;
- authentication information;
- usage information;
- support information;
- information contained in files or documents submitted by Customer; and
- other Personal Data provided by Customer or its authorized users.
Sensitive Personal Data Transferred
Unless expressly agreed otherwise:
None intentionally.
Customer shall not intentionally provide special categories of Personal Data or sensitive Personal Data unless the Parties have expressly agreed to such Processing.
Frequency of Transfer
Continuous, where necessary for the provision of the Services.
Nature of Processing
The Processing may include:
- collecting;
- recording;
- organizing;
- storing;
- accessing;
- retrieving;
- transmitting;
- using;
- analyzing;
- supporting;
- troubleshooting;
- securing;
- backing up;
- deleting; and
- otherwise Processing Customer Personal Data as necessary to provide the Services.
Purpose of Data Transfer and Further Processing
The purpose of the transfer is to facilitate the performance of the Services described in the Agreement and applicable Order Forms.
Enthralltech may Process Customer Personal Data to:
- provide the Services;
- operate and maintain the Services;
- provide customer support;
- troubleshoot technical issues;
- maintain security;
- prevent unauthorized activity;
- perform backups;
- maintain service availability;
- improve the Services;
- comply with applicable law; and
- perform other activities authorized under the Agreement.
Period for Which Personal Data Will Be Retained
The period for which Customer Personal Data will be retained is determined by the Agreement, this Addendum, applicable Order Forms, Customer instructions, and applicable Data Protection Laws.
4. SUBPROCESSOR TRANSFERS
The subject matter, nature, purpose, and duration of Processing by Subprocessors shall be as described in the Agreement, this Addendum, and applicable Order Forms.
Subprocessors shall Process Customer Personal Data only to the extent necessary to provide the services for which they have been engaged.
ANNEX 2 — TECHNICAL AND ORGANIZATIONAL SECURITY MEASURES
Enthralltech shall maintain technical and organizational security measures appropriate to the nature, scope, context, and purposes of Processing and the risks to the rights and freedoms of natural persons.
Security Management System
Organization
Enthralltech shall designate appropriate personnel whose responsibilities include development, implementation, and ongoing maintenance of its information security and privacy program.
Policies
Enthralltech shall maintain information security and privacy policies appropriate to its business and Services.
Such policies shall be reviewed periodically and updated where reasonably necessary.
Assessments
Enthralltech shall conduct reasonable security and risk assessments of systems containing Customer Personal Data.
Risk Treatment
Enthralltech shall maintain reasonable processes for:
- penetration testing, where appropriate;
- vulnerability management;
- patch management;
- security monitoring;
- risk assessment; and
- remediation of identified security issues.
Vendor Management
Enthralltech shall maintain a reasonable vendor management program for third parties that Process Customer Personal Data.
Incident Management
Enthralltech shall maintain security incident management procedures, including procedures for:
- incident identification;
- escalation;
- containment;
- investigation;
- remediation;
- root-cause analysis; and
- corrective action.
Personnel Security
Personnel authorized to access Customer Personal Data shall be required to act consistently with Enthralltech’s confidentiality, privacy, security, and professional standards.
Personnel shall be subject to confidentiality obligations.
Where appropriate and legally permissible, Enthralltech may conduct reasonable background checks for personnel with access to Customer Personal Data.
Personnel shall receive appropriate privacy and information security training.
Personnel shall not Process Customer Personal Data without appropriate authorization.
Access Controls
Access Management
Enthralltech shall maintain a formal access management process designed to control:
- access requests;
- approvals;
- provisioning;
- modification;
- periodic review; and
- removal of access.
Access shall be limited to authorized personnel with a legitimate need to access Customer Personal Data.
Privilege Management
Enthralltech shall use reasonable least-privilege and need-to-know principles.
Where technically supported, access controls may include:
- unique user IDs;
- strong passwords;
- multi-factor authentication;
- single sign-on;
- role-based access;
- monitored access lists; and
- access logging.
Access rights shall be reviewed periodically.
Data Center and Network Security
Data Centers / Cloud Infrastructure
Cloud / Data Center Provider:
Microsoft Azure
Primary Processing Region:
India Jio West
Enthralltech shall maintain reasonable infrastructure security controls appropriate to the Services.
Resiliency
Where applicable, Enthralltech shall maintain redundancy, backup, and recovery mechanisms designed to support service availability and resilience.
Server Security
Production systems shall be configured and maintained using reasonable security practices appropriate to the operating environment.
Disaster Recovery
Where applicable, Enthralltech shall maintain disaster recovery procedures designed to protect against accidental destruction, loss, or unavailability of Customer Personal Data.
Security Logs
Where appropriate, system logging shall be enabled to support security monitoring, investigations, audits, and detection of actual or attempted attacks.
Vulnerability Management
Enthralltech shall perform reasonable vulnerability assessments or scans of relevant infrastructure.
Identified vulnerabilities shall be prioritized and remediated based on risk.
Networks and Transmission
Customer Personal Data transmitted over public networks shall use appropriate security protocols.
Enthralltech shall maintain reasonable network security controls designed to protect production environments from unauthorized access and external attacks.
Incident Response
Enthralltech shall maintain incident response procedures and security incident escalation processes.
Security personnel or other designated personnel shall respond to suspected or known Security Incidents, take reasonable steps to mitigate harmful effects, and document material incidents and their outcomes.
Encryption Technologies
Where technically applicable:
- HTTPS/TLS or equivalent encryption shall be used for Customer Personal Data in transit; and
- appropriate encryption technologies shall be used to protect Customer Personal Data at rest.
Data Storage, Isolation, Authentication, and Destruction
Where the Services operate in a multi-tenant environment, Enthralltech shall implement reasonable logical controls designed to isolate Customer Personal Data from other customers.
Authentication mechanisms shall be implemented to support appropriate security of access to the Services.
Enthralltech shall maintain reasonable procedures for secure disposal of Customer Personal Data when such data is no longer required, subject to applicable legal retention requirements.
ANNEX 3 — SUBPROCESSORS
The following Subprocessors are authorized to Process Customer Personal Data in connection with the Services:
| Subprocessor | Service / Purpose | Processing Location |
|---|---|---|
| Microsoft Azure, India | Cloud hosting / infrastructure | Jio West |
| Microsoft Azure, India | Database / storage | Jio West |
| Twilio SendGrid, Global | Email / communications | (US) or EU |
| Enthralltech | Customer support | Pune Maharashtra, India |
Enthralltech may add or replace Subprocessors in accordance with Section 6 of this Addendum.
