Data Processing Agreement (DPA)
Last updated: July 20, 2026 — Version 1.0 · Forms part of the Terms of Service.
This Data Processing Agreement ("DPA") governs our processing of end-customer personal data that we process on your behalf when providing the Service. In this DPA, you are the "Controller" and Zero Headache is the "Processor." This DPA is intended to satisfy the requirements of GDPR Article 28 and Section 8(2) of India's Digital Personal Data Protection Act 2023 and the DPDP Rules 2025. Alap Putatunda is designated as our Grievance Officer.
1. Scope & roles
We process end-customer personal data only to provide the Service and only on your documented instructions (your account configuration, qualification rules, and these terms).
2. Subject matter & details
- Subject matter: capture, qualification, booking, and CRM-sync of inbound leads.
- Duration: the term of the Service.
- Nature/purpose: answering, qualifying, scheduling, recording/transcribing communications, and syncing records to your systems.
- Data types: identifiers (name, phone, email), communication content (calls, messages, transcripts), appointment and lead-source data.
- Data subjects: your prospective and existing customers.
3. Our obligations
We will:
- (a) process only on your instructions;
- (b) not use your end-customer personal data, call audio, or transcripts to train, improve, or fine-tune any AI model, ours or our sub-processors', without your explicit written authorization;
- (c) ensure personnel are bound by confidentiality;
- (d) implement appropriate technical and organizational security measures;
- (e) assist you with data-subject requests and with security, breach, and impact-assessment obligations (a Data Protection Impact Assessment has been conducted and is available to clients on reasonable request);
- (f) notify you of a personal-data breach without undue delay (and in any event within 72 hours of becoming aware, consistent with GDPR Article 33, and "as soon as possible" under the DPDP Rules); and
- (g) on termination, you may request return of your end-customer data in a standard format (CSV or JSON) within 30 days, after which we delete all copies except where retention is legally required (e.g., tax records or DPDP log-retention of 1 year).
4. Sub-processors
You authorize us to engage the sub-processors listed in our Sub-processor List. We bind each to data-protection obligations no less protective than this DPA and remain responsible for their performance. We will notify you of new sub-processors at least 30 days before they begin processing. You may object on reasonable grounds related to data-protection. If we cannot resolve your objection, you may terminate the affected service without penalty.
5. International transfers
Where data is transferred across borders, we rely on lawful transfer mechanisms, including the EU Standard Contractual Clauses, Module 2 (controller-to-processor) or Module 3 (processor-to-processor) as applicable, as implemented by Commission Implementing Decision 2021/914. We will conduct and provide a Transfer Impact Assessment for transfers to India upon reasonable request.
6. Audits
We will make available information reasonably necessary to demonstrate compliance and allow audits (including via third-party reports) subject to confidentiality and reasonable notice.
7. Liability
Each party's liability under this DPA is subject to the limitations in the Terms of Service.
Controller Signature:
This DPA is accepted electronically when you sign up for the Service and forms part of the Terms of Service. A countersigned copy is available on request.
Processor:
Alap Putatunda, from Zero Headache













