Legal
Data Processing Agreement
DPA for Qrynto customers
Last updated: 2026-04-24
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between Qrynto Innovations Private Limited (“Processor” or “Company”) and the Brand Client (“Controller” or “Client”) and governs the processing of personal data by the Processor on behalf of the Controller in connection with the Qrynto platform (“Platform”).
This DPA is entered into to ensure compliance with applicable data protection laws, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 and its associated rules, and, where applicable, the General Data Protection Regulation (“GDPR”) (Regulation (EU) 2016/679).
1. DEFINITIONS
In this DPA, the following terms shall have the meanings ascribed below, in addition to those defined in the Terms of Service:
“Personal Data” means any data about an individual who is identifiable by or in relation to such data, as defined under the DPDP Act, or any information relating to an identified or identifiable natural person as defined under the GDPR.
“Processing” means any operation performed on Personal Data, including collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.
“Data Breach” means any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
“Sub-processor” means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
2. SCOPE AND ROLES
2.1 Roles
For the purposes of this DPA, the Client acts as the Data Fiduciary (under DPDP Act) or Controller (under GDPR), and the Company acts as the Data Processor. The Client determines the purposes and means of processing Personal Data; the Company processes Personal Data only on the documented instructions of the Client.
2.2 Scope of Processing
The Processor shall process Personal Data solely for the purpose of providing the Platform Services, including:
Generating, activating, and managing QR codes linked to the Client’s products.
Processing and storing Consumer scan data (geolocation, device information, timestamps) for authentication and analytics.
Providing dashboards, reports, and verification logs to the Client.
Processing supply chain tracking data entered by authorised Supply Chain Partners.
Maintaining system logs for security and performance monitoring.
3. OBLIGATIONS OF THE PROCESSOR
The Processor shall:
Process Personal Data only on the documented instructions of the Controller, unless required by law.
Ensure that all personnel authorised to process Personal Data are bound by confidentiality obligations.
Implement appropriate technical and organisational measures to ensure the security of Personal Data, including encryption, access controls, and regular security assessments.
Assist the Controller in responding to Data Principal/Data Subject requests, including requests for access, correction, and erasure.
Notify the Controller of any Data Breach without undue delay, and in any event within seventy-two (72) hours of becoming aware of such breach.
Delete or return all Personal Data to the Controller upon termination of the agreement, and delete existing copies unless retention is required by law.
Make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for audits.
4. SUB-PROCESSORS
4.1 Authorisation
The Controller provides general authorisation for the Processor to engage Sub-processors for the provision of Platform Services. The Processor shall maintain a current list of Sub-processors, which shall be made available to the Controller upon request.
4.2 Obligations
The Processor shall: (a) enter into a written agreement with each Sub-processor imposing data protection obligations no less protective than those in this DPA; (b) remain fully liable to the Controller for the acts and omissions of its Sub-processors; and (c) notify the Controller in writing at least thirty (30) days before engaging a new Sub-processor or replacing an existing one.
4.3 Objection
The Controller may object to the appointment of a new Sub-processor within fifteen (15) days of receiving notice. If the objection is reasonable and the parties cannot reach a resolution, the Controller may terminate the affected services without penalty.
5. INTERNATIONAL DATA TRANSFERS
Where Personal Data is transferred to a country outside India or the European Economic Area that does not provide an adequate level of data protection, the Processor shall ensure that appropriate safeguards are in place, including:
Standard Contractual Clauses (SCCs) as approved by the European Commission.
Compliance with any transfer mechanisms recognised under the DPDP Act and rules issued thereunder.
Binding corporate rules, where applicable.
6. DATA BREACH NOTIFICATION
6.1 Notification
In the event of a Data Breach, the Processor shall notify the Controller in writing within seventy-two (72) hours of becoming aware of the breach. The notification shall include: (a) the nature of the breach, including the categories and approximate number of Data Principals/Data Subjects affected; (b) the likely consequences of the breach; (c) the measures taken or proposed to mitigate the breach; and (d) the contact details of the Processor’s data protection point of contact.
6.2 Cooperation
The Processor shall cooperate fully with the Controller in investigating and remediating the breach and in meeting any notification obligations to supervisory authorities or affected individuals as required by law.
7. AUDITS AND COMPLIANCE
The Controller shall have the right to conduct audits, directly or through a qualified third party, to verify the Processor’s compliance with this DPA. Audits shall be conducted with reasonable prior notice (not less than thirty (30) days), during normal business hours, and in a manner that minimises disruption to the Processor’s operations. The Controller shall bear the costs of such audits unless the audit reveals a material breach by the Processor.
8. DURATION AND TERMINATION
This DPA shall remain in effect for the duration of the Processor’s processing of Personal Data on behalf of the Controller. Upon termination of the underlying service agreement, the Processor shall, at the Controller’s election, return or securely delete all Personal Data within thirty (30) days, and certify such deletion in writing. The obligations of confidentiality and security survive termination.
9. LIABILITY
The liability of each party under this DPA is subject to the limitations set forth in the Terms of Service. Nothing in this DPA excludes or limits liability for breaches that cannot be limited under applicable data protection law.
10. GOVERNING LAW
This DPA shall be governed by the laws of India. Where Personal Data of EEA residents is processed, the relevant provisions of GDPR shall apply. Disputes arising under this DPA shall be resolved in accordance with the dispute resolution provisions of the Terms of Service.