image

Data Processing Agreement

This Data Processing Agreement (“DPA”) constitutes a legally enforceable arrangement between Neuroturing, designated as the “Data Processor,” and the party agreeing to these terms, identified as the “Data Controller.” This document governs the manner in which Personal Data is collected, used, and safeguarded in connection with digital financial transaction services.

Roles of the Parties

Controller Role:The Controller is responsible for defining the purpose, scope, and lawful grounds for Processing Personal Data and must ensure full compliance with all Applicable Data Protection Laws.

Processor Role:The Processor shall Process Personal Data only upon explicit instructions from the Controller and strictly within the limits necessary to deliver approved transaction-related services.

Scope of Processing

Processing of Personal Data by the Processor shall be limited to the following purposes:

  • Execution and completion of transaction-related operations
  • Customer verification and prevention of fraudulent activities
  • Authentication of users, including two-factor authentication (2FA)
  • Financial reporting, transaction tracking, and reconciliation
  • Compliance with RBI, NPCI, and applicable regulatory and network requirements

Security Measures

The Processor commits to maintaining appropriate administrative, physical, and technical safeguards, including:

  • Implementation of industry-recognized security frameworks
  • Encryption of Personal Data during storage and transmission
  • Controlled access systems utilizing multi-factor authentication
  • Secure handling and protection of cryptographic materials
  • Routine system testing, vulnerability scanning, and penetration reviews

All Processor personnel with access to Personal Data shall be subject to confidentiality obligations and ongoing data security training.

Data Subject Rights

The Processor shall support the Controller in addressing Data Subject requests in accordance with Applicable Laws, including but not limited to:

  • Requests for access to Personal Data
  • Requests for correction or updates
  • Requests for erasure of Personal Data
  • Requests for data portability
  • Requests to restrict, object to, or limit Processing

Subprocessors

Engagement of any Subprocessor by the Processor shall require prior written approval from the Controller.
All authorized Subprocessors must be contractually bound to data protection standards that are at least equivalent to those outlined in this DPA.

Data Breach Notification

The Processor shall inform the Controller within 24 hours of detecting or becoming aware of any Personal Data Breach.
Such notification shall include:

  • Details regarding the nature and impact of the breach
  • Categories and approximate number of affected Data Subjects
  • Mitigation steps taken to control the incident
  • Preventive actions planned to avoid future occurrences

Audit & Compliance

The Controller may conduct compliance assessments of the Processor upon reasonable prior notice. The Processor shall provide access to relevant records, internal procedures, and compliance documentation to support such audits.

Data Retention & Deletion

Personal Data shall be stored only for the duration required to fulfill transaction processing needs and statutory compliance obligations, including those mandated by RBI.
Upon cessation of services, Personal Data shall be securely deleted or returned, unless legal retention requirements apply.

Legal & Regulatory Changes

The Processor shall notify the Controller without undue delay if any change in applicable laws or regulations affects its ability to Process Personal Data in compliance with this Agreement.

Liability & Indemnification

Each Party shall be accountable for damages resulting from its own violations of this Agreement. The Processor shall indemnify the Controller against losses, penalties, or claims arising from data protection non-compliance.

Governing Law & Dispute Resolution

This Agreement shall be governed by and construed in accordance with the laws of India. All disputes shall be subject to the exclusive jurisdiction of Indian courts.

Amendments

Any revisions or amendments to this Agreement shall be valid only if documented in writing and mutually agreed upon by both Parties.

Acknowledgment and Acceptance

By accepting this Agreement, both Parties acknowledge their understanding of and consent to all provisions contained within this Data Processing Agreement.