Data Processing Agreement.
How CLEPTO.IN processes personal data on behalf of our clients.
December 27, 2025
1.0
contact@clepto.in
CLEPTO.IO SERVICES PRIVATE LIMITED
CIN: U62013PN2025PTC248011
Pune, India (registered)
Indore, India
Table of Contents
- Definitions
- Scope and Applicability
- Data Controller and Processor Roles
- Processing Instructions
- Data Security and Protection
- Sub-Processors
- Data Subject Rights
- International Data Transfers
- Liability and Indemnification
- Term and Termination
- Contact Information
Definitions
In this Data Processing Agreement (DPA), the following terms have the meanings set out below:
- Personal Data: Any information relating to an identified or identifiable natural person as defined in GDPR Article 4(1) and DPDP Act 2023.
- Processing: Any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, erasure, or destruction.
- Controller: The natural or legal person that determines the purposes and means of Processing. Typically, you (the Client).
- Processor: The natural or legal person that processes Personal Data on behalf of the Controller. In this case, Clepto.in.
- Sub-Processor: Any natural or legal person engaged by the Processor to process Personal Data on behalf of the Controller.
- Data Subject: The individual to whom Personal Data relates.
- GDPR: General Data Protection Regulation (EU) 2016/679.
- DPDP Act: Digital Personal Data Protection Act, 2023 (India).
- Clepto.in Services: All automation, AI, and workflow services provided by Clepto.in under the Master Service Agreement.
Scope and Applicability
When This DPA Applies
This DPA applies to the extent that Clepto.in processes Personal Data on your behalf when providing Automation Services, including:
- n8n workflow automation and data handling
- Customer data processing in automated workflows
- Email automation via n8n SMTP workflows
- AI-powered data analysis and automation
- API integrations involving Personal Data
- Database storage and management on Hostinger VPS
- Chat logs and interaction data from AI chatbots
Territorial Scope
This DPA complies with:
- GDPR (for EU/EEA residents' data)
- DPDP Act 2023 (for Indian residents' data)
- Other applicable data protection laws by jurisdiction
Important: This DPA is incorporated into your Master Service Agreement with Clepto.in. In case of conflict, this DPA takes precedence regarding Personal Data processing.
Data Controller and Processor Roles
You Are the Data Controller
As our Client, you determine:
- What Personal Data to process (scope)
- Why you process it (purposes)
- How long to retain it (retention period)
- Who has access (data subjects)
- Legal basis for processing (consent, contract, legitimate interest, etc.)
You are responsible for:
- Obtaining lawful basis for processing (e.g., consent from data subjects)
- Providing privacy notices to data subjects
- Responding to data subject requests (access, deletion, etc.)
- Conducting data protection impact assessments where required
- Notifying regulators of data breaches
Clepto.in Is the Data Processor
Clepto.in processes Personal Data:
- Only as instructed by you (the Controller)
- For the specific purposes you define
- For the duration you specify
- Using the safeguards described in Section 5
Clepto.in is responsible for:
- Processing data only per your written instructions
- Implementing appropriate technical and organizational security measures
- Managing sub-processors (with your authorization)
- Assisting with data subject requests
- Notifying you of data breaches without undue delay
- Maintaining records of processing activities (as Processor)
- Deleting or returning data upon termination
Clarity on Roles: You control what data and why. Clepto.in controls how to process it securely.
Processing Instructions
Scope of Processing
| Processing Activity | Description | Data Categories |
|---|---|---|
| Workflow Automation | n8n-based automation of your business processes | Customer names, emails, phone numbers, identifiers |
| Email Automation | Sending automated emails via n8n SMTP workflows | Email addresses, subscriber preferences, message content |
| AI Processing | Processing data through OpenAI, Anthropic, Google, Mistral, Perplexity APIs | Chat messages, query text, user interactions |
| Data Storage | Storing workflow and customer data on Hostinger VPS | All data processed in workflows (as configured by you) |
| Chat Logs | Logging interactions with AI chatbots for improvement | Chat messages, timestamps, user identifiers |
Purposes of Processing
Clepto.in processes Personal Data for:
- Performing automation services as specified in your requests
- Executing automated workflows you configure
- Sending emails via your automation rules
- Improving service quality and response accuracy
- Maintaining workflow logs and audit trails
- Complying with legal and regulatory obligations
Duration of Processing
- During Contract: For the entire duration of your service with Clepto.in
- After Termination: Data deleted within 60 days of contract termination
- Exceptions: Legal holds, regulatory requirements, or your written request to retain data
Your Instructions
You provide Processing Instructions through:
- Configuration of n8n workflows in your dashboard
- Settings in your Clepto.in account
- Written requests to contact@clepto.in
- API calls or integrations you enable
You must ensure all instructions comply with applicable data protection laws and that you have legal authority to provide them.
Data Security and Protection
Technical Safeguards
Encryption in Transit
- All data transmission: TLS 1.2/1.3 HTTPS enforced
- Between your browser and Clepto.in: End-to-end encryption
- Between Clepto.in and AI providers: Encrypted connections
- Between n8n workflows and APIs: TLS/SSL secured
Encryption at Rest
- Database storage: Hostinger VPS with PostgreSQL encrypted storage
- Password protection: Industry-standard hashing (bcrypt)
- Access controls: Role-based database access
- Backups: Encrypted by Hostinger infrastructure
Authentication & Access Control
- Session management: Secure session tokens
- Password requirements: Strong minimum standards enforced
- Failed attempts: Rate-limiting on login failures
- Admin access: Limited to authorized personnel only
- Access logs: Maintained for security audits
Organizational Safeguards
- Personnel training: Staff trained on data protection
- Access restrictions: Need-to-know basis only
- Confidentiality agreements: All staff bound by confidentiality
- Regular audits: Access logs reviewed periodically
- Incident response: Procedures in place for data breaches
Infrastructure Details
- Hosting & Infrastructure: Hostinger VPS (Europe-based, GDPR compliant)
- Database: PostgreSQL on Hostinger managed infrastructure
- Backups: Regular encrypted backups by Hostinger
- Monitoring: 24/7 uptime monitoring
- Updates: Regular security patches applied
Data Breach Notification
If a data breach occurs, Clepto.in will:
- Notify you within 24 hours of discovery
- Provide details: nature, scope, likely consequences
- Provide contact: Designated data protection officer (contact@clepto.in)
- Provide remedial actions: Steps being taken to mitigate harm
- Preserve evidence: For investigation and compliance
You are responsible for notifying affected data subjects and regulators (as required by law, typically within 72 hours).
Sub-Processors
Authorized Sub-Processors
You authorize Clepto.in to engage the following sub-processors:
| Sub-Processor | Location | Function | DPA Status |
|---|---|---|---|
| Hostinger | Europe | Hosting, database, backups | DPA in place |
| n8n (Open-Source) | Self-hosted on Hostinger | Workflow automation platform | Open-source (no DPA needed) |
| OpenAI | USA | AI model processing | DPA signed |
| Anthropic | USA | AI model processing (Claude) | DPA signed |
| USA | AI model processing (Gemini) | DPA signed | |
| Mistral | Europe | AI model processing | DPA signed |
| Perplexity | USA | Research & retrieval | In progress (Q1 2026) |
Perplexity Status: DPA with Perplexity is being finalized. We recommend using Perplexity only for non-sensitive queries until DPA is confirmed. We will notify you when it's completed.
Changes to Sub-Processors
If Clepto.in engages a new sub-processor, we will:
- Notify you at least 30 days in advance
- Provide details about the new sub-processor and processing
- Allow you to object (within 14 days)
- Provide alternative solutions if you object
- Inform you of any remediation measures
Data Subject Rights
Your Obligations as Controller
You must provide data subjects with information about processing, including:
- Identity of the controller and processor
- Purposes of processing
- Legal basis for processing
- Recipients of data (including Clepto.in as processor)
- Retention period
- Data subject rights
- Contact for privacy inquiries
Data Subject Rights Support
- Access: Request a copy of their Personal Data
- Rectification: Correct inaccurate or incomplete data
- Erasure: Request deletion (right to be forgotten)
- Restriction: Limit how data is processed
- Portability: Receive data in machine-readable format
- Objection: Object to certain types of processing
- Not to be subject to automated decision-making: For decisions with legal effects
Clepto.in's Support
When you receive a data subject request, Clepto.in will:
- Assist you in responding to requests
- Provide access to data stored in your account within 10 business days
- Delete data upon your instruction within 30 days
- Correct data upon your request without delay
- Restrict processing of specific data upon your instruction
- Provide data in CSV/JSON format for portability requests
International Data Transfers
Data Location
- Primary: Hostinger VPS in Europe (GDPR-compliant jurisdiction)
- AI Processing: May be transferred to USA-based AI providers (OpenAI, Anthropic, Google) with appropriate safeguards
- EU providers: Mistral (Europe-based, no transfer needed)
Transfer Mechanisms for USA Processors
- Standard Contractual Clauses (SCCs) with all USA sub-processors
- Data Processing Agreements incorporating GDPR-compliant terms
- Supplementary safeguards to mitigate data access risks
- EU-to-US data transfer agreements where available
Your Obligations
- Ensuring lawful basis for international transfers
- Informing data subjects about transfers and safeguards
- Complying with any supplementary transfer requirements in your jurisdiction
Liability and Indemnification
Limitation of Liability
Each party's total liability under this DPA is limited to the fees paid in the 12 months preceding the claim (or €500,000, whichever is greater), except for:
- Data breaches caused by the Processor's gross negligence or willful misconduct
- Violations of data subject rights
- Infringement of applicable data protection laws
Indemnification
Clepto.in will indemnify you against claims arising from:
- Clepto.in's breach of this DPA
- Data breaches caused by Clepto.in's security failures
- Unauthorized disclosure of Personal Data by Clepto.in personnel
Term and Termination
Duration
This DPA remains in effect for the duration of your service agreement with Clepto.in, plus any applicable data retention period.
Termination Effects
- Days 1-30: Your account marked for deletion; you can request data export
- Days 31-60: Personal data permanently deleted from database
- Days 61+: Only legal/audit logs retained (if required by law)
Data Return or Deletion
You can request return of all your data or immediate deletion of your account and data. Email contact@clepto.in with "Data Return/Deletion Request".
Contact Information
Email: contact@clepto.in
Company: CLEPTO.IO SERVICES PRIVATE LIMITED
CIN: U62013PN2025PTC248011
Registered Address: Pune, India Additional Office: Indore, India