Legal

Data Processing Agreement

Last updated: August 2026 · Effective from: August 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between the Tenant ("Data Fiduciary" / "Controller") and Rupenet Technologies Private Limited ("Data Processor" / "Processor") for the processing of personal data through the Rupenet Legal platform, in compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) and applicable Indian data protection regulations.

1. Scope & Applicability

  • This DPA applies to all personal data processed by Rupenet on behalf of the Tenant through the platform
  • The Tenant is the Data Fiduciary and determines the purposes and means of processing
  • Rupenet is the Data Processor and processes personal data only on the Tenant's documented instructions
  • This DPA supplements and is incorporated into the Terms of Service

2. Data Processing Details

Subject matterProvision of legal practice management, AI research, document management, billing and related platform services
DurationFor the duration of the subscription agreement plus the data retention period
Nature & purposeStorage, retrieval, display, search, analysis, AI processing and transmission of Tenant data for platform functionality
Categories of data subjectsTenant employees/users, Tenant's clients, opposing parties, witnesses, contacts, service providers
Types of personal dataNames, contact details, identity documents, professional information, case/matter details, financial data, communications

3. Processor Obligations

Rupenet shall:

  • Process personal data only on the Tenant's documented instructions, unless required by law
  • Ensure that persons authorised to process personal data are bound by confidentiality obligations
  • Implement appropriate technical and organisational security measures (see Section 5)
  • Not engage sub-processors without prior specific or general written authorisation of the Tenant
  • Assist the Tenant in responding to data subject rights requests under DPDPA
  • Assist the Tenant in ensuring compliance with security, breach notification and impact assessment obligations
  • Delete or return all personal data at the end of the engagement, at the Tenant's choice
  • Make available all information necessary to demonstrate compliance and allow audits

4. Sub-Processors

  • Rupenet maintains a documented sub-processor register available to Tenants upon request
  • New sub-processors will be notified to the Tenant at least 30 days before engagement
  • The Tenant may object to a new sub-processor within 14 days of notification
  • Each sub-processor is bound by data protection obligations no less protective than this DPA
  • Rupenet remains liable for the acts and omissions of its sub-processors

Current Sub-Processor Categories

CategoryPurposeLocation
Cloud InfrastructureHosting, storage, computeIndia (primary)
AI Model ProviderAI inference (with PII redaction)As disclosed
Payment ProcessorPayment collection & payoutsIndia
Communication ProviderEmail, SMS, WhatsApp deliveryIndia
eSign ProviderDigital signature executionIndia

5. Security Measures

Rupenet implements the following technical and organisational measures:

Technical Measures

  • Encryption: TLS 1.3 in transit, AES-256 at rest; tenant-specific encryption keys for enterprise
  • Multi-tenant isolation at database, application and network layers
  • Role-based access control (RBAC) with attribute-based access control (ABAC)
  • Multi-factor authentication and SSO/SAML/OIDC support
  • Ethical walls and conflict-of-interest barriers
  • Immutable audit logging for all data access, exports and administrative actions
  • Automated vulnerability scanning (SAST/DAST/SCA) in CI/CD pipeline
  • CERT-In empanelled VAPT before production and after material changes
  • PII and privilege redaction before external AI model calls
  • Prompt-injection protection for AI document processing

Organisational Measures

  • Information security policies and procedures
  • Employee background checks and confidentiality agreements
  • Regular security awareness training
  • Incident response plan and team
  • Business continuity and disaster recovery plans (RPO: 1 hour, RTO: 4 hours)
  • Periodic access certification and review
  • Secure software development lifecycle (SSDLC)

6. Data Breach Notification

  • Rupenet shall notify the Tenant of any confirmed personal data breach without undue delay and within 72 hours of becoming aware
  • Notification shall include: nature of the breach, categories and approximate number of data subjects affected, likely consequences, and measures taken or proposed
  • Rupenet shall cooperate with the Tenant in investigating and remediating the breach
  • Rupenet shall assist the Tenant in meeting its notification obligations under DPDPA and to CERT-In as required

7. AI-Specific Data Processing

AI Data Protection Commitments

  • Tenant data is never used to train AI foundation models
  • PII is redacted before transmission to external AI model providers
  • Privileged and confidential information is classified and protected before AI processing
  • All AI interactions are logged with source, model version, prompt and reviewer information
  • AI model providers are contractually bound to not retain or train on input data

8. Data Return & Deletion

  • Upon termination, the Tenant may export all Client Data in standard formats within 90 days
  • After the export period, Rupenet shall delete all Client Data using defensible deletion procedures
  • Rupenet may retain data required by law (tax records, audit logs) for the legally mandated period
  • Deletion certification will be provided to the Tenant upon request

9. Audit Rights

  • The Tenant may audit Rupenet's compliance with this DPA with 30 days' prior written notice
  • Audits shall be conducted during business hours and shall not unreasonably interfere with operations
  • Rupenet shall make available relevant documentation, certifications (ISO 27001, SOC 2) and VAPT reports
  • The Tenant may engage a mutually agreed independent third-party auditor
  • Audit costs are borne by the Tenant unless the audit reveals material non-compliance by Rupenet

10. Liability & Indemnification

Liability under this DPA is subject to the limitations set out in the Terms of Service. Each party shall be liable for damages caused by its breach of this DPA. Rupenet shall indemnify the Tenant against claims arising from Rupenet's failure to comply with its obligations under this DPA.

11. Governing Law

This DPA is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, and rules made thereunder. Disputes shall be resolved as set out in the Terms of Service.

Contact

Data Protection Officer

Rupenet Technologies Private Limited

Noida, Uttar Pradesh, India

Email: dpo@rupenet.com

Enterprise customers may request a signed copy of this DPA with custom annexures.