LEGAL
Data Processing Addendum
Last updated: June 2026 · Supplements our Terms
1. Roles
For personal data you ("Customer") submit to the platform — questionnaire answers, connector discovery output, uploaded artefacts, and any generated documents — Customer is the Data Fiduciary (Controller) under the Digital Personal Data Protection Act, 2023, and CompliSense-AI is the Data Processor, processing that data solely to provide the platform to Customer. This DPA governs that processing and forms part of, and is incorporated into, our Terms of Service.
2. Processing Only on Instruction
We process Customer Personal Data only on Customer's documented instructions — which include operating the platform's ordinary features (scoring readiness, rendering documents, running a connector Customer has configured, storing what Customer approves) — and for no other purpose, except where required by applicable law, in which case we will inform Customer of that legal requirement first, unless the law prohibits it.
3. Security Safeguards
We implement technical and organisational measures mirroring the baseline the DPDP Rules, 2025 (Rule 6) set for a Data Fiduciary's own processing, so that a Customer relying on us can point to the same standard we hold ourselves to:
- Encryption of personal data in transit and at rest.
- Role-based access control and least-privilege access to Customer Personal Data.
- Logging and monitoring sufficient to detect, investigate, and respond to a breach.
- Log retention sufficient to support breach investigation and evidence.
- Backup and restore procedures for continuity of Customer's data.
- Contractual security terms flowed down to every Sub-processor (Section 5).
4. Personnel and Confidentiality
Anyone we permit to process Customer Personal Data is bound by confidentiality obligations and access is limited to what their role requires.
5. Sub-processors
We currently use the following categories of Sub-processor. Each is bound to data-protection terms at least as protective as this DPA, and we remain responsible for their performance.
| Sub-processor | Purpose | What it sees |
|---|---|---|
| Anthropic (Claude API) | AI-assisted drafting of documents you explicitly consent to send | The cited rule and confirmed facts only — never raw artefacts or personal-data values |
| Render | Application hosting | Data in transit and at rest for the hosted app |
| MongoDB Atlas | Database hosting | Stored account, questionnaire and document data |
We will give Customer reasonable advance notice before adding or replacing a Sub-processor that processes Customer Personal Data, so Customer may object on reasonable data-protection grounds.
What Anthropic retains
We do not claim "zero retention" as a blanket statement — the accurate terms are more specific than that. By default: Anthropic does not train on our commercial API inputs or outputs, and inputs/outputs are retained for 30 days and then automatically deleted. Zero Data Retention (ZDR) is available to eligible commercial customers only under a separately signed agreement — it is not a toggle we can flip ourselves — and, even then, covers only certain endpoints (Messages, Token Counting); it does not cover Batch, the Files API, Managed Agents, or the Console/Workbench. Even under a signed ZDR agreement, User Safety classifier results are still retained to enforce Anthropic's Usage Policy, so the accurate description of that state is "zero retention except safety-classifier metadata" — never an unqualified zero retention. Certain models ("Covered Models") require 30-day retention and are never ZDR-eligible regardless of endpoint; we pin any AI feature that is meant to run under ZDR to a model and endpoint that actually qualifies.
The document-assessment agent (an AI feature that reads a Customer's existing compliance documents) runs every document through a local redaction pass before any text reaches Anthropic or any other model provider — emails, phone numbers, government IDs, card numbers and names are masked first, entirely on our infrastructure, with no network call. Enterprise customers may instead route this feature to a self-hosted model so nothing leaves their own network at all. This feature ships gated behind a preview flag and is not enabled for any Customer until we have re-verified the provider's retention terms and, if relevant, a signed ZDR agreement is in place.
6. Breach Notification
If we become aware of a personal-data breach affecting Customer Personal Data, we will notify Customer without undue delay, providing the information reasonably available to us so Customer can meet its own notification duties under DPDP section 8(6) and Rule 7 — the nature of the breach, the data and people affected so far as known, and the steps we have taken and are taking.
7. Assistance
Taking into account the nature of the processing, we will reasonably assist Customer in responding to Data Principal rights requests and in meeting Customer's own security, breach-notification, and impact-assessment obligations, to the extent this platform holds the relevant data.
8. Deletion or Return on Termination
On termination of the Agreement, and at Customer's written request, we will delete or return Customer Personal Data within a reasonable period, except to the extent retention is required by applicable law — in which case we continue to protect it under this DPA for as long as we hold it.
9. Audit
On reasonable written notice, and no more than once per year absent a security incident, we will make available the information reasonably necessary to demonstrate compliance with this DPA, which may take the form of a summary report rather than an on-site audit.
Questions about this DPA?
Contact us at support@complisenseai.com and we'll respond within 48 hours.
