Legal · DPA

Data Processing Agreement.

How CLEPTO.IN processes personal data on behalf of our clients.

At a glance
Effective Date:
December 27, 2025
Version:
1.0
Company:
CLEPTO.IO SERVICES PRIVATE LIMITED
CIN: U62013PN2025PTC248011
Pune, India (registered)
Indore, India

Table of Contents

  1. Definitions
  2. Scope and Applicability
  3. Data Controller and Processor Roles
  4. Processing Instructions
  5. Data Security and Protection
  6. Sub-Processors
  7. Data Subject Rights
  8. International Data Transfers
  9. Liability and Indemnification
  10. Term and Termination
  11. Contact Information

Definitions

In this Data Processing Agreement (DPA), the following terms have the meanings set out below:

  • Personal Data: Any information relating to an identified or identifiable natural person as defined in GDPR Article 4(1) and DPDP Act 2023.
  • Processing: Any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.
  • Controller: The natural or legal person that determines the purposes and means of Processing. Typically, you (the Client).
  • Processor: The natural or legal person that processes Personal Data on behalf of the Controller. In this case, Clepto.in.
  • Sub-Processor: Any natural or legal person engaged by the Processor to process Personal Data on behalf of the Controller.
  • Data Subject: The individual to whom Personal Data relates.
  • GDPR: General Data Protection Regulation (EU) 2016/679.
  • DPDP Act: Digital Personal Data Protection Act, 2023 (India).
  • Clepto.in Services: All automation, AI, and workflow services provided by Clepto.in under the Master Service Agreement.

Scope and Applicability

When This DPA Applies

This DPA applies to the extent that Clepto.in processes Personal Data on your behalf when providing Automation Services, including:

  • n8n workflow automation and data handling
  • Customer data processing in automated workflows
  • Email automation via n8n SMTP workflows
  • AI-powered data analysis and automation
  • API integrations involving Personal Data
  • Database storage and management on Hostinger VPS
  • Chat logs and interaction data from AI chatbots

Territorial Scope

This DPA complies with:

  • GDPR (for EU/EEA residents' data)
  • DPDP Act 2023 (for Indian residents' data)
  • Other applicable data protection laws by jurisdiction

Important: This DPA is incorporated into your Master Service Agreement with Clepto.in. In case of conflict, this DPA takes precedence regarding Personal Data processing.

Data Controller and Processor Roles

You Are the Data Controller

As our Client, you determine:

  • What Personal Data to process (scope)
  • Why you process it (purposes)
  • How long to retain it (retention period)
  • Who has access (data subjects)
  • Legal basis for processing (consent, contract, legitimate interest, etc.)

You are responsible for:

  • Obtaining lawful basis for processing (e.g., consent from data subjects)
  • Providing privacy notices to data subjects
  • Responding to data subject requests (access, deletion, etc.)
  • Conducting data protection impact assessments where required
  • Notifying regulators of data breaches

Clepto.in Is the Data Processor

Clepto.in processes Personal Data:

  • Only as instructed by you (the Controller)
  • For the specific purposes you define
  • For the duration you specify
  • Using the safeguards described in Section 5

Clepto.in is responsible for:

  • Processing data only per your written instructions
  • Implementing appropriate technical and organizational security measures
  • Managing sub-processors (with your authorization)
  • Assisting with data subject requests
  • Notifying you of data breaches without undue delay
  • Maintaining records of processing activities (as Processor)
  • Deleting or returning data upon termination

Clarity on Roles: You control what data and why. Clepto.in controls how to process it securely.

Processing Instructions

Scope of Processing

Processing ActivityDescriptionData Categories
Workflow Automationn8n-based automation of your business processesCustomer names, emails, phone numbers, identifiers
Email AutomationSending automated emails via n8n SMTP workflowsEmail addresses, subscriber preferences, message content
AI ProcessingProcessing data through OpenAI, Anthropic, Google, Mistral, Perplexity APIsChat messages, query text, user interactions
Data StorageStoring workflow and customer data on Hostinger VPSAll data processed in workflows (as configured by you)
Chat LogsLogging interactions with AI chatbots for improvementChat messages, timestamps, user identifiers

Purposes of Processing

Clepto.in processes Personal Data for:

  • Performing automation services as specified in your requests
  • Executing automated workflows you configure
  • Sending emails via your automation rules
  • Improving service quality and response accuracy
  • Maintaining workflow logs and audit trails
  • Complying with legal and regulatory obligations

Duration of Processing

  • During Contract: For the entire duration of your service with Clepto.in
  • After Termination: Data deleted within 60 days of contract termination
  • Exceptions: Legal holds, regulatory requirements, or your written request to retain data

Your Instructions

You provide Processing Instructions through:

  • Configuration of n8n workflows in your dashboard
  • Settings in your Clepto.in account
  • Written requests to contact@clepto.in
  • API calls or integrations you enable

You must ensure all instructions comply with applicable data protection laws and that you have legal authority to provide them.

Data Security and Protection

Technical Safeguards

Encryption in Transit

  • All data transmission: TLS 1.2/1.3 HTTPS enforced
  • Between your browser and Clepto.in: End-to-end encryption
  • Between Clepto.in and AI providers: Encrypted connections
  • Between n8n workflows and APIs: TLS/SSL secured

Encryption at Rest

  • Database storage: Hostinger VPS with PostgreSQL encrypted storage
  • Password protection: Industry-standard hashing (bcrypt)
  • Access controls: Role-based database access
  • Backups: Encrypted by Hostinger infrastructure

Authentication & Access Control

  • Session management: Secure session tokens
  • Password requirements: Strong minimum standards enforced
  • Failed attempts: Rate-limiting on login failures
  • Admin access: Limited to authorized personnel only
  • Access logs: Maintained for security audits

Organizational Safeguards

  • Personnel training: Staff trained on data protection
  • Access restrictions: Need-to-know basis only
  • Confidentiality agreements: All staff bound by confidentiality
  • Regular audits: Access logs reviewed periodically
  • Incident response: Procedures in place for data breaches

Infrastructure Details

  • Hosting & Infrastructure: Hostinger VPS (Europe-based, GDPR compliant)
  • Database: PostgreSQL on Hostinger managed infrastructure
  • Backups: Regular encrypted backups by Hostinger
  • Monitoring: 24/7 uptime monitoring
  • Updates: Regular security patches applied

Data Breach Notification

If a data breach occurs, Clepto.in will:

  • Notify you within 24 hours of discovery
  • Provide details: nature, scope, likely consequences
  • Provide contact: Designated data protection officer (contact@clepto.in)
  • Provide remedial actions: Steps being taken to mitigate harm
  • Preserve evidence: For investigation and compliance

You are responsible for notifying affected data subjects and regulators (as required by law, typically within 72 hours).

Sub-Processors

Authorized Sub-Processors

You authorize Clepto.in to engage the following sub-processors:

Sub-ProcessorLocationFunctionDPA Status
HostingerEuropeHosting, database, backupsDPA in place
n8n (Open-Source)Self-hosted on HostingerWorkflow automation platformOpen-source (no DPA needed)
OpenAIUSAAI model processingDPA signed
AnthropicUSAAI model processing (Claude)DPA signed
GoogleUSAAI model processing (Gemini)DPA signed
MistralEuropeAI model processingDPA signed
PerplexityUSAResearch & retrievalIn progress (Q1 2026)

Perplexity Status: DPA with Perplexity is being finalized. We recommend using Perplexity only for non-sensitive queries until DPA is confirmed. We will notify you when it's completed.

Changes to Sub-Processors

If Clepto.in engages a new sub-processor, we will:

  • Notify you at least 30 days in advance
  • Provide details about the new sub-processor and processing
  • Allow you to object (within 14 days)
  • Provide alternative solutions if you object
  • Inform you of any remediation measures

Data Subject Rights

Your Obligations as Controller

You must provide data subjects with information about processing, including:

  • Identity of the controller and processor
  • Purposes of processing
  • Legal basis for processing
  • Recipients of data (including Clepto.in as processor)
  • Retention period
  • Data subject rights
  • Contact for privacy inquiries

Data Subject Rights Support

  • Access: Request a copy of their Personal Data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion (right to be forgotten)
  • Restriction: Limit how data is processed
  • Portability: Receive data in machine-readable format
  • Objection: Object to certain types of processing
  • Not to be subject to automated decision-making: For decisions with legal effects

Clepto.in's Support

When you receive a data subject request, Clepto.in will:

  • Assist you in responding to requests
  • Provide access to data stored in your account within 10 business days
  • Delete data upon your instruction within 30 days
  • Correct data upon your request without delay
  • Restrict processing of specific data upon your instruction
  • Provide data in CSV/JSON format for portability requests

International Data Transfers

Data Location

  • Primary: Hostinger VPS in Europe (GDPR-compliant jurisdiction)
  • AI Processing: May be transferred to USA-based AI providers (OpenAI, Anthropic, Google) with appropriate safeguards
  • EU providers: Mistral (Europe-based, no transfer needed)

Transfer Mechanisms for USA Processors

  • Standard Contractual Clauses (SCCs) with all USA sub-processors
  • Data Processing Agreements incorporating GDPR-compliant terms
  • Supplementary safeguards to mitigate data access risks
  • EU-to-US data transfer agreements where available

Your Obligations

  • Ensuring lawful basis for international transfers
  • Informing data subjects about transfers and safeguards
  • Complying with any supplementary transfer requirements in your jurisdiction

Liability and Indemnification

Limitation of Liability

Each party's total liability under this DPA is limited to the fees paid in the 12 months preceding the claim (or €500,000, whichever is greater), except for:

  • Data breaches caused by the Processor's gross negligence or willful misconduct
  • Violations of data subject rights
  • Infringement of applicable data protection laws

Indemnification

Clepto.in will indemnify you against claims arising from:

  • Clepto.in's breach of this DPA
  • Data breaches caused by Clepto.in's security failures
  • Unauthorized disclosure of Personal Data by Clepto.in personnel

Term and Termination

Duration

This DPA remains in effect for the duration of your service agreement with Clepto.in, plus any applicable data retention period.

Termination Effects

  • Days 1-30: Your account marked for deletion; you can request data export
  • Days 31-60: Personal data permanently deleted from database
  • Days 61+: Only legal/audit logs retained (if required by law)

Data Return or Deletion

You can request return of all your data or immediate deletion of your account and data. Email contact@clepto.in with "Data Return/Deletion Request".

Contact Information

Email: contact@clepto.in

Company: CLEPTO.IO SERVICES PRIVATE LIMITED
CIN: U62013PN2025PTC248011
Registered Address: Pune, India  Additional Office: Indore, India

End of Data Processing Agreement