aikram by ClickZain
aikram by ClickZain
Home Platform & Features Solutions by Industry Pricing User Guide About Us Contact Sign In to Dashboard Book an Appointment Talk to Sales
Home/Legal/Data Processing Addendum

Data Processing Addendum

Last updated: 19 August 2026 · Applies to Aikram, a product of ClickZain Digital Solutions

This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Controller") and ClickZain Digital Solutions ("Processor") and applies whenever we process personal data on your behalf through Aikram.

1. Roles of the parties

You are the Controller. You decide whose data is uploaded, what messages are sent, on what basis, and for how long it is kept.

We are the Processor. We process that data only on your documented instructions, which are given through your use of the platform and any written instruction you send us.

We are an independent Controller only for our own account and billing data, which is covered by our Privacy Policy.

2. Scope of processing

ItemDetails
Subject matterProvision of the Aikram messaging and automation platform
DurationFor the term of your subscription, plus the retention period after termination
Nature and purposeStorage, transmission, analysis and automated processing of customer communications
Categories of dataContact identifiers, message content, delivery metadata, custom fields you define, and any files you upload
Categories of data subjectsYour customers, leads, patients, students, attendees or other contacts

Sensitive data. The platform is not designed for special categories of personal data — health records, financial account credentials, biometric or government identity data. If your use case requires processing such data, contact us first so we can agree appropriate additional safeguards in writing.

3. Our obligations

We will:

  • Process personal data only on your documented instructions.
  • Ensure our personnel who access the data are bound by confidentiality.
  • Implement and maintain appropriate technical and organisational security measures.
  • Assist you, so far as reasonably possible, in responding to data subject requests.
  • Assist you with data protection impact assessments and consultations with authorities where required.
  • Delete or return personal data on termination, subject to legal retention obligations.
  • Make available the information reasonably necessary to demonstrate compliance with this DPA.

4. Your obligations

You will:

  • Ensure you have a valid lawful basis and documented consent for every contact you upload.
  • Provide the privacy notices your own customers are entitled to receive.
  • Not upload special categories of personal data without a prior written agreement with us.
  • Respond to your own data subjects' requests — we assist, but the obligation is yours.
  • Configure retention, access and permission settings appropriately for your risk profile.

5. Sub-processors

You authorise us to engage sub-processors to deliver the service. These include cloud hosting providers, messaging platform providers, payment gateways and communication infrastructure providers.

  • Every sub-processor is bound by written obligations no less protective than this DPA.
  • We remain fully liable to you for their performance.
  • We will give you reasonable notice before adding a new sub-processor that materially changes how your data is processed, and you may object on reasonable data protection grounds.

A current list is available on request.

6. Security measures

  • Encryption of data in transit using TLS, and encryption of stored data at rest.
  • Role-based access control with least-privilege defaults.
  • Two-factor authentication available on all accounts.
  • Network segregation and firewalling of production systems.
  • Audit logging of administrative access.
  • Encrypted, regularly tested backups.
  • Documented incident response procedures.
  • Background-appropriate confidentiality undertakings from personnel.

7. Personal data breach

If we become aware of a personal data breach affecting data we process for you, we will:

  1. Notify you without undue delay, and in any case within 72 hours of becoming aware.
  2. Describe the nature of the breach, the categories and approximate volume of data affected, and the likely consequences.
  3. Describe the measures taken or proposed to address it and mitigate harm.
  4. Cooperate with you and provide reasonable assistance with any regulatory notification you must make.

8. International transfers

Where personal data is transferred outside India, we ensure an appropriate transfer mechanism is in place with each recipient, together with contractual confidentiality and security commitments.

9. Audit

On reasonable written notice, not more than once in any 12-month period, you may request information demonstrating our compliance with this DPA. Where an on-site audit is genuinely necessary, the parties will agree scope, timing and cost in advance, and it must not compromise the confidentiality or security of other customers' data.

10. Deletion and return

On termination, you may export your data through the dashboard for 30 days. After that, we delete personal data in accordance with the retention schedule in our Privacy Policy, except where retention is required by law.

Contact

If anything on this page is unclear, or you wish to exercise a right described here, write to us:

ClickZain Digital Solutions
Email: clickzaindigitalsolutions@gmail.com
Product: Aikram · Contact page

A note on this document. This policy has been prepared as a working template for ClickZain Digital Solutions. Before you publish it, please have it reviewed by a qualified lawyer in your jurisdiction and update the company address, registration details and any figures to match your actual business. It is not legal advice.