Data Processing Addendum
How Urjadata Solar Renewable Energy Private Limited processes personal data on your behalf, as your processor.
Last updated:
1. Scope and roles
This Data Processing Addendum ("DPA") forms part of the Terms of Service and applies where we process personal data on your behalf.
- You are the data fiduciary / controller of the project data you put into your workspace — including personal data about your staff, contractors, landowners, or counterparties.
- We are the data processor for that data: we process it only to provide the Service, on your documented instructions.
- For your own account and billing data we are the controller — see the Privacy Policy.
2. Processing details
| Subject matter | Providing UrjaOps Platform to you |
|---|---|
| Duration | For as long as your account is active, plus any retention period in §8 |
| Nature and purpose | Hosting, storage, display, backup, transmission, and AI-assisted drafting at your request |
| Types of personal data | Whatever you choose to enter — typically names, roles, contact details, and identifiers in project records and documents |
| Categories of data subject | Your staff and invited users; and individuals named in your project data |
You control what enters the Service. Please do not upload special-category or sensitive personal data you do not need.
3. Our obligations
- Process personal data only on your instructions (using the Service is your instruction), unless the law requires otherwise.
- Keep it confidential and ensure people with access are bound by confidentiality.
- Apply the security measures in §5.
- Never sell your data, and never use it to train AI models.
- Help you meet data-subject requests and your own security/breach obligations, so far as we reasonably can.
- Delete or return the data at the end, per §8.
4. Your obligations
- Have a lawful basis for the personal data you upload, and give any notices your own users/data subjects are owed.
- Keep your credentials secure and manage who you invite into your workspace.
- Only enter data you are entitled to process — see the Acceptable Use Policy.
5. Security measures
- Encryption of data in transit.
- Authentication, and row-level tenancy isolation enforced at the database so one workspace cannot read another's data.
- Access to production data restricted to those who need it.
- Guards on destructive writes, with snapshots taken before records are removed.
- Automated tests that assert cross-organisation access is denied.
6. Sub-processors
You authorise us to use sub-processors to provide the Service. Each is bound by terms no less protective than this DPA. The categories we use are:
| Category | Purpose |
|---|---|
| Cloud hosting & database | Running the application and storing your workspace |
| Application hosting / CDN | Serving the web application |
| Email delivery | Deadline reminders and transactional email |
| AI provider | Generating the drafts you request |
| Payment gateway | Taking payment (card data goes to them, never to us) |
We will give reasonable notice before adding or replacing a sub-processor. If you have a reasonable objection on data-protection grounds, tell us and we will work with you or you may stop using the affected feature. For the current named list, email support@urjaops.com.
7. International transfers
Some sub-processors operate outside India. Where personal data is transferred, we rely on contractual protections with the provider and transfer only what the Service needs.
8. Return and deletion
- You can export your workspace at any time from within the Service.
- On written request, or on account closure, we delete or anonymise your personal data — currently a manual process; there is no self-service erasure yet.
- We may keep what the law requires us to keep (for example billing records), and backups age out on their normal cycle.
9. Personal data breach
If we become aware of a personal data breach affecting your data, we will notify you without undue delay with what we know, and support your own notifications to the Data Protection Board of India and to affected individuals. We do not make those notifications on your behalf unless separately agreed.
10. Audit
On reasonable written request, and no more than once a year (unless required by a regulator or after a breach), we will provide information reasonably necessary to demonstrate compliance with this DPA.
11. Governing law
This DPA is governed by the laws of India and the courts at Deori, Sagar, Madhya Pradesh, consistent with the Terms of Service. If you need a countersigned copy, email support@urjaops.com.