Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of the agreement between Logiqcube Consulting ("Processor") and you ("Controller") for use of the LogiqLead platform.
1. Definitions
- "Controller" means the entity that determines the purposes and means of processing personal data (you).
- "Processor" means the entity that processes personal data on behalf of the Controller (Logiqcube Consulting / LogiqLead).
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Data Subject" means the individual to whom the Personal Data relates.
- "Processing" means any operation performed on Personal Data (collection, storage, use, deletion, etc.).
- "Subprocessor" means a third-party service provider engaged by the Processor to process Personal Data.
2. Scope and Purpose
2.1 Scope
This DPA applies to Personal Data processed by LogiqLead on your behalf when you use the Service.
2.2 Purpose
LogiqLead processes Personal Data solely to provide the Service as described in the Terms of Service and on your documented instructions.
2.3 Duration
Processing continues for the duration of your Account, plus any legally required retention period.
3. Obligations of the Processor
3.1 Instructions
LogiqLead shall process Personal Data only on your documented instructions, unless required by applicable law. We will inform you if we are required by law to process data in a way that conflicts with your instructions.
3.2 Confidentiality
LogiqLead ensures that personnel authorized to process Personal Data:
- Are bound by appropriate confidentiality obligations
- Have received training on data protection relevant to their role
- Process Personal Data only as instructed
3.3 Security Measures
LogiqLead implements appropriate technical and organizational measures, including:
- Encryption of Personal Data in transit and at rest where supported by infrastructure
- Regular review and evaluation of security measures
- Incident response and breach notification procedures
- Access controls and authentication mechanisms
3.4 Subprocessors
LogiqLead shall not engage another Processor without your prior written consent, except as described in the Subprocessors list. When engaging Subprocessors, LogiqLead shall:
- Impose data protection obligations no less protective than this DPA
- Maintain a current list of Subprocessors
- Notify you of any intended changes at least 30 days in advance
3.5 Data Subject Rights
LogiqLead shall assist you in responding to Data Subject rights requests, including:
- Access requests
- Rectification requests
- Erasure requests
- Restriction of processing
- Data portability
- Objection to processing
3.6 Data Breach Notification
LogiqLead shall notify you without undue delay (and within 48 hours) after becoming aware of a Personal Data breach, providing:
- Description of the nature of the breach
- Categories and approximate number of Data Subjects affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
- Contact point for further information
3.7 Data Protection Impact Assessment
LogiqLead shall provide reasonable assistance with Data Protection Impact Assessments where required by applicable law.
3.8 Deletion and Return
Upon termination of the Service, LogiqLead shall, at your choice:
- Return all Personal Data in a commonly used, machine-readable format, or
- Delete all Personal Data within 30 days and provide written confirmation
4. Obligations of the Controller
You warrant that:
- You have a valid legal basis for processing Personal Data
- Your instructions to LogiqLead comply with applicable data protection laws
- You have obtained necessary consents from Data Subjects where required
- You will not use the Service to process special category data without explicit consent and appropriate safeguards
5. Technical and Organizational Measures
LogiqLead implements the following measures:
5.1 Organizational Measures
- Data protection policies and procedures
- Staff training on data protection
- Incident response plan
- Vendor management program
5.2 Technical Measures
- TLS encryption for data in transit
- Encryption at rest where supported by infrastructure
- Multi-factor authentication for administrative access
- Automated backup and recovery procedures
- Access logging and monitoring
Note: Logiqcube Consulting does not currently hold SOC 2, ISO 27001, HIPAA, or PCI-DSS certifications. We implement security measures appropriate for our scale and the nature of the data processed.
6. International Data Transfers
6.1 Transfer Mechanisms
Where Personal Data is transferred outside India or the European Economic Area, LogiqLead ensures protection through appropriate safeguards, which may include:
- Standard Contractual Clauses (SCCs)
- Adequacy decisions where available
- Your explicit consent where required
6.2 Locations
Personal Data may be processed in:
- India (primary operations)
7. Governing Law
This DPA is governed by the laws of India, specifically the laws of the State of Gujarat, without regard to conflict of law principles. The courts in Vadodara, Gujarat shall have exclusive jurisdiction.
8. Changes
We may update this DPA from time to time. Material changes will be notified at least 30 days in advance via email or through the Service.
Contact
For questions about this DPA, contact:
Logiqcube Consulting
Email: contact@logiqlead.com