Data Processing Addendum Overview

Project-specific data-processing terms

Last updated:

Status: This page is a public overview of the subjects addressed when Meru Software Private Limited and a client require data-processing terms. It is not a standalone, self-executing agreement and does not automatically become part of a client engagement.

A binding data processing addendum ("DPA") applies only when its terms are incorporated into a written client agreement or otherwise accepted in writing by Meru Software Private Limited and the client.

1. When a DPA Applies

A project-specific DPA may be appropriate when Meru Software processes personal data on a client's documented instructions while delivering agreed services. The parties' roles depend on the facts of the processing and are recorded in the executed agreement; they are not determined by this webpage alone.

Personal information that Meru Software handles for its own website, enquiries, recruitment, billing or business administration is addressed in the Privacy Policy, not this overview.

2. Processing Details

For an engagement requiring a DPA, the executed document or its processing schedule should identify:

3. Processor Commitments

Where Meru Software acts as a processor, the executed DPA should address commitments appropriate to the applicable law and engagement, including:

4. Security Schedule

The controls appropriate to covered processing depend on the data, system, risks and services. The executed agreement or security schedule should record the applicable measures, which may include encryption in transit, access controls, logging, backups, patching, vulnerability management, incident handling and continuity arrangements.

5. Subprocessors

The executed DPA should identify the authorisation method for subprocessors, the applicable notice or objection process, and the requirement for relevant written data-protection obligations. Approved subprocessors and processing locations must be documented for the engagement rather than assumed from this webpage.

6. International Transfers

If covered personal data is transferred across borders, the parties should document the processing locations and any transfer mechanism required by applicable law. References to contractual clauses or other safeguards apply only when the relevant instrument has actually been completed for the transfer.

7. Security Incidents and Assistance

Notification contacts, timing, investigation support, remediation responsibilities and cooperation with data-subject or regulator requests should be specified in the executed DPA or service agreement.

8. Governing Terms

The governing law, jurisdiction, liability provisions, order of precedence and duration are those stated in the written agreement into which the DPA is incorporated.

9. Request Data-Processing Terms

To discuss data-processing terms for a proposed or active engagement, email info@merusoftware.com. Please identify the relevant project and avoid sending personal data that is not necessary for the request.