Last updated: 25 August 2026
This Data Processing Addendum (“DPA”) is offered by OTOMEYT AI (INDIA) PRIVATE LIMITED (CIN: U74900KA2015FTC083041), trading as Otomeyt AI (“Otomeyt”, “Processor”), to each business customer (“Customer”, “Controller”) that uses Otomeyt products or services under a master agreement, order, or statement of work (the “Agreement”). It applies only where Otomeyt processes Customer Personal Data as a processor. Website visitor and marketing-lead data that Otomeyt controls is governed by the Privacy Policy, not this DPA.
If Customer and Otomeyt have signed a separate DPA, that signed document controls if it conflicts with this page. Otherwise this DPA is incorporated into the Agreement. Customer accepts it by executing the Agreement or by using the services after this page is made available.
“Customer Personal Data” means personal data that Customer (or its users) uploads to, or collects through, the services, or that Otomeyt processes on Customer’s documented instructions. Terms such as personal data, processing, controller, processor, and personal data breach have the meanings in the GDPR, India’s DPDP Act, 2023, and other laws applicable to the processing (“Data Protection Law”).
Customer is the controller (or a processor for its own customer). Otomeyt is the processor (or sub-processor). Otomeyt will process Customer Personal Data only to provide the services, to comply with law, and on Customer’s documented instructions. Customer is responsible for the lawfulness of its instructions and for providing notices and obtaining consents from candidates and other data subjects.
The Agreement, this DPA, Customer’s configuration of the services, and written instructions from Customer’s authorised users are Customer’s instructions. Otomeyt will inform Customer if, in its opinion, an instruction infringes Data Protection Law (unless the law prohibits that notice).
Otomeyt will ensure that persons authorised to process Customer Personal Data are bound by confidentiality and receive appropriate data-protection training. Access is limited on a need-to-know basis.
Otomeyt will implement technical and organisational measures appropriate to the risk, including encryption in transit, access control, logging, and an information security management system. Otomeyt maintains ISO 9001 and ISO 27001 compliance as described in the Privacy Policy. Customer is responsible for configuring available product security features (for example user roles) for its workspace.
Customer authorises Otomeyt to use subprocessors to deliver the services. Website subprocessors are listed in the Privacy Policy. Additional product subprocessors will be disclosed in the Agreement, an exhibit, or on written request to compliance@otomeyt.ai.
Otomeyt will impose data-protection terms on subprocessors that are no less protective than this DPA. Otomeyt remains responsible to Customer for subprocessors’ performance. Before appointing a new material subprocessor, Otomeyt will give Customer notice (including via this website or email). Customer may object on reasonable data-protection grounds within 14 days. If the parties cannot resolve the objection, Customer may terminate the affected services.
Customer Personal Data may be processed in India (including AWS ap-south-1) and in other countries where Otomeyt or its subprocessors operate. Where a transfer requires a safeguard under Data Protection Law, Otomeyt will use an appropriate mechanism (including standard contractual clauses or the subprocessor’s equivalent terms).
Taking into account the nature of the processing, Otomeyt will assist Customer by appropriate technical and organisational measures in responding to requests from data subjects. If Otomeyt receives a request that identifies Customer, it will forward the request without undue delay and will not respond as controller except to tell the individual to contact Customer.
Otomeyt will notify Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Personal Data, unless law prohibits the notice. The notice will include, where known, the nature of the breach, likely consequences, measures taken or proposed, and a contact point. Otomeyt will reasonably cooperate with Customer’s investigation and any required notifications to authorities or individuals. Customer remains responsible for determining whether and how to notify regulators and data subjects, unless law requires Otomeyt to notify them directly.
Otomeyt will provide reasonable information in its possession to help Customer carry out data-protection impact assessments and prior consultations with authorities, to the extent required by Data Protection Law and related to Otomeyt’s processing.
When the services end, or on Customer’s written request, Otomeyt will delete Customer Personal Data from live systems within 90 days, or return it in a reasonable commonly used format if Customer requests return before deletion, unless law requires storage or data is needed for a dispute. Backups expire on a rolling cycle of up to 90 days after live deletion. Anonymised or aggregated data that is no longer personal data may be retained.
On written request, no more than once per year (unless a confirmed breach or regulator requires otherwise), Otomeyt will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant ISO certificates and summaries of security measures. On-site audits, if still reasonably required after that information, are at Customer’s cost, during business hours, with 30 days’ notice, and limited to processing of Customer Personal Data.
Liability under this DPA is subject to the limitations in the Agreement. If there is a conflict about data protection, this DPA prevails over the Agreement. A signed DPA prevails over this page.
This DPA lasts for as long as Otomeyt processes Customer Personal Data under the Agreement. It is governed by the same law and courts as the Agreement. If the Agreement is silent, the laws of India apply and the courts at Bengaluru, Karnataka have exclusive jurisdiction.
OTOMEYT AI (INDIA) PRIVATE LIMITED
#22, 2nd Floor, SJR Cyber, Laskar Hosur Road, Adugodi, Bengaluru, Karnataka 560030, India
Email: compliance@otomeyt.ai