Skip to main content

LEGAL

Data Processing Agreement

This Data Processing Agreement (DPA) forms part of the agreement between MindPolar Pvt Ltd ("processor", "MindPolar") and a customer organization ("controller") for the processing of personal data about the controller's people through the MindPolar platform.

Document status

Version 1.0.0Last updated August 23, 2026Not yet in effect

This document is a draft prepared to describe MindPolar's systems accurately. It is not legal advice, and it requires review by qualified legal counsel before it governs any account, transaction, or data processing.

1

Subject matter, duration, and purpose

Subject matterProcessing of personal data the controller enters into MindPolar's people-directory and organization-structure features.
DurationFor as long as the controller's organization has an active MindPolar account, plus the deletion/retention windows described in §7.
Nature and purposeStorage, display, and organization of employee-directory records so the controller can model its people, departments, teams, locations, positions, and reporting structure.
Categories of data subjectsThe controller's employees, contractors, and other individuals the controller chooses to add to its directory.
Categories of personal data
CategoryFields
IdentityDisplay name, given name, family name, employee number, work email
EmploymentEmployment status, start date, end date
StructureDepartment, team, work location, job position, reporting line

2

MindPolar's obligations as processor

  • Process personal data only on the controller's documented instructions, including with regard to transfers, unless required to do otherwise by law.
  • Ensure persons authorized to process the data are subject to confidentiality.
  • Implement appropriate technical and organizational security measures (Art. 32) — see §6.
  • Not engage a sub-processor without the controller's general authorization, and inform the controller of any intended change, giving the controller an opportunity to object (§4).
  • Assist the controller, insofar as reasonably possible, in responding to data-subject rights requests concerning the controller's employee-directory data.
  • Assist the controller with its own Art. 32–36 obligations (security, breach notification, impact assessments), taking into account the information available to MindPolar as processor.
  • At the controller's choice, delete or return all personal data at the end of the provision of services, and delete existing copies unless retention is required by law (see §7's retention statement).
  • Make available to the controller information necessary to demonstrate compliance with this article, and allow for and contribute to audits, including inspections, conducted by the controller or an auditor mandated by the controller.

3

The controller's obligations

  • Have a lawful basis to provide MindPolar with the personal data described in §1, and to instruct MindPolar to process it as described.
  • Provide any notice its own employees or other data subjects are legally owed about this processing — MindPolar's Privacy Policy covers MindPolar's own role as processor, but does not substitute for the controller's own notice to its people.
  • Ensure the accuracy of the data it enters, and correct it using the product's own administrative tools where possible.

4

Sub-processors

The controller authorizes MindPolar's general use of the sub-processors below to provide the service. MindPolar will inform the controller before adding a new sub-processor, giving the controller a reasonable opportunity to object on reasonable data-protection grounds.

Sub-processorRoleRegion
Amazon Web Services, Inc.Cloud infrastructure: compute, database, object storage, cache, CDN, and transactional email delivery.ap-south-1 (Mumbai, India)

AWS is the only sub-processor MindPolar uses today. No analytics, advertising, error-tracking, customer-support, or session-replay third party is integrated into the product. If that changes, this list is updated before the new vendor goes live — not after.

5

International transfers

RegionProviderWhat's processed there
ap-south-1 — Mumbai, IndiaAmazon Web ServicesAll personal data MindPolar processes today. The platform runs from this single region; there is no second region and no data stored outside it as part of normal operation.
GAP — NOT YET BUILT

No cross-border transfer safeguard is in place yet

India does not currently hold an EU adequacy decision. If the controller is established in, or the data subjects described in §1 are located in, the EU/EEA or UK, this processing constitutes a restricted transfer that requires Standard Contractual Clauses and a Transfer Impact Assessment before it may lawfully proceed — neither has been executed as of this document's version. This is the prerequisite to onboarding an EU customer, not a formality to complete afterward, and this section is updated the moment either is in place.

6

Security measures and audit rights

  • Encryption in transit (TLS) and at rest.
  • Database-enforced tenant isolation (Postgres Row-Level Security, forced on every organization-scoped table).
  • Least-privilege AWS IAM roles; no long-lived access keys used by the application.
  • Session-level controls: an account holder can view and revoke sessions signed in on other devices from their own account settings at any time.

MindPolar will make available information reasonably necessary to demonstrate compliance with this DPA, and will contribute to audits reasonably requested by the controller, subject to reasonable confidentiality, frequency, and cost terms to be agreed at execution.

7

Retention and deletion

When an organization is deleted, MindPolar provides a 90-day reversible window before its records are purged; deleted rows can persist in disaster-recovery backups for up to 7 days afterward.

GAP — NOT YET BUILT

No retention-expiry mechanism exists for former-employee records

A person marked as a former employee is retained indefinitely as a terminal record (department, position, employment dates, reporting position) for the organization's own audit history; there is no automatic expiry today. A controller with its own retention-limitation obligation toward its former employees should account for this when deciding what it enters into MindPolar and for how long, until this changes.

8

Liability and execution

[TO BE SUPPLIED BY OWNER / COUNSEL — liability allocation, indemnities, and the mechanics of execution (signature block, effective date tied to the underlying services agreement). Not derived from the codebase, and deliberately not invented here.]

Version history

  1. v1.0.0Pending — not yet published

    Initial draft, pending legal review.