DPDP & GDPR - data processing
This page summarises the data-processing terms that apply when you use VaaniAPI to process personal data belonging to your own customers. A signed Data Processing Addendum in this form is available on request at hello@vaaniapi.com.
Last updated: 25 July 2026
Roles
For end-customer personal data in your workspace, you are the Data Fiduciary (DPDP Act, 2023) / Controller (GDPR) and VaaniAPI is the Data Processor. We process such data only on your documented instructions, which the service configuration and these terms constitute.
Scope of processing
- Subject matter: providing AI customer support on your behalf.
- Duration: for as long as your subscription is active, plus the 30-day export window.
- Categories of data subjects: your customers, prospects and staff who use the service.
- Categories of data: contact details, message content, and any personal data contained in documents you upload.
Our security measures
- Tenant isolation enforced at the database layer - every query is scoped to a single business.
- Encryption in transit (TLS 1.2+) and at rest; tokens and secrets encrypted with managed keys.
- Role-based access control with least-privilege internal access and audit logging.
- Segregated environments, dependency scanning and regular backups with tested restores.
Sub-processors
We engage sub-processors for hosting, email delivery, payments, AI inference and monitoring. Each is bound by written terms no less protective than these. We maintain a current list and give advance notice of additions affecting customer content, with a right to object.
Data-subject and principal requests
If a data principal contacts us directly, we refer them to you. We assist you in responding to access, correction, erasure and portability requests through dashboard export and deletion tooling, at no extra charge for reasonable volumes.
Breach notification
We notify you without undue delay and in any case within 72 hours of becoming aware of a personal-data breach affecting your data, with the facts known, the likely consequences and the measures taken. Where the DPDP Act requires it, we support your intimation to the Data Protection Board of India and to affected principals, and we report to CERT-In within the timelines its directions specify.
International transfers
Primary processing and storage is in India. Where a sub-processor operates outside India, transfers rely on Standard Contractual Clauses or an adequacy decision for GDPR purposes, and are limited to jurisdictions not restricted by the Central Government under section 16 of the DPDP Act.
AI model handling
Content sent to model providers for inference is not used by us or by them to train foundation models. Retrieval happens against your own tenant collection only, and every generated answer stores the source chunks it used so the reasoning stays auditable.
Deletion and return
On termination we make your data available for export for 30 days and delete it thereafter, including from backups within the backup rotation period, unless retention is required by law.