Data Processing Agreement
Last updated 30 September 2026
Draft, under legal review. This agreement is not yet in force. Until it is, the Terms of Service and Privacy Policy govern how we handle your data.
1. Who this is between
This agreement is between the customer who holds a Bizkar CRM organization ("you") and [Registered company name], of [Registered office address] ("we"). It forms part of the Terms of Service and applies while we process personal data in your organization. For that data you are the data fiduciary under India's Digital Personal Data Protection Act 2023, and we are your data processor.
2. What we process
- Subject: providing Bizkar CRM to you.
- Duration: while your organization exists, and afterwards only as section 9 says.
- Nature and purpose: storing, organising, displaying, searching, exporting and deleting what your organization holds, sending the emails and webhooks you set up, and taking in leads from the forms and integrations you connect.
- People: your leads, contacts, customers' staff and your own members.
- Data: names, contact details, job titles, company details, notes, activities, deals, quotes, contracts, tickets, attachments and custom fields, as you or your integrations enter them.
3. Your instructions
We process your organization's data only to provide the service, as you use and configure it, and as the law requires. If we believe an instruction breaks the law, we will tell you.
4. Confidentiality
Only people who need it to run the service can reach your data, under a duty of confidentiality. Our support staff enter your organization only while you grant access, for the period you choose, and every session is recorded and reported to your owners.
5. Security
We keep the measures described on our security page in place for the whole term, including encryption in transit, access controls within your organization, separation between organizations, malware scanning of uploads, and monitoring.
6. Sub-processors
You authorise the sub-processors on our sub-processors page. We bind each by contract to protect your data at least as this agreement does, and we remain responsible for them. We tell your organization owners by email at least 30 days before a new sub-processor starts processing your data; if you object on reasonable grounds and we can't resolve it, you may close your organization.
7. Where data is kept
Your organization's data is stored with DigitalOcean in Singapore. We transfer personal data out of India only to countries the law permits.
8. Helping you
Bizkar CRM lets you find, correct, export and erase a person's data yourself. Where you need more to answer a person's request, or a request from the Data Protection Board, we help within a reasonable time.
9. Breaches
If a personal data breach affects your organization's data, we tell your organization owners without undue delay, and within 48 hours of becoming aware of it: what happened, which data and people it affects, its likely consequences, and what we have done and will do. We keep you informed as we learn more, so that you can meet your own duties to the Data Protection Board and the people affected.
10. When the organization ends
You can export your organization's data at any time. When you close your organization, its data is deleted at the end of the closure period shown when you close it, and is gone from our backups within 30 days after that. Records you empty from the recycle bin, and people you erase, are deleted the same way.
11. Showing we comply
On request, we give you the information you reasonably need to show that we meet this agreement, including a description of our security measures.
12. General
Liability under this agreement is as the Terms of Service set it. If this agreement and the Terms conflict about personal data, this agreement wins. It is governed by the laws of India.
Questions: privacy@bizkar.in.