Data processing addendum
Last updated: 10 October 2026
This addendum is part of the agreement between Hadoopt Technologies Private Limited, India ("Hadoopt", "we", "the processor") and the organisation that subscribes to a SmartMy product ("the customer"). It sets out how we process personal data on the customer's behalf under the Digital Personal Data Protection Act, 2023 and the rules made under it ("DPDP law"). Where it differs from the rest of the agreement on personal data, this addendum applies.
1. Roles
- The customer is the Data Fiduciary for the personal data it, its users and the people it serves put into the service ("customer personal data"). It decides why and how that data is processed.
- Hadoopt is the customer's Data Processor for customer personal data. We process it only to provide the service and only on the customer's documented instructions. The customer agreement, the settings the customer chooses in the product and the requests its administrators make are those instructions.
- For the data we collect for ourselves (our websites, sign-up, billing, the account directory that lets apps find a workspace, and our own support records), Hadoopt is the Data Fiduciary, as our privacy notice explains.
2. What we process
| People | The customer's staff and users; and, depending on the products used, students and their parents or guardians, applicants and alumni, residents and their household and domestic help, hostel and PG residents and guests, visitors and their hosts, event participants and members, people who book the customer's facilities, recruiters, customers of a canteen, shop or garage, drivers and riders, complainants and the people complaints are about. |
| Data | As listed by product in section 3 of our privacy notice: identity and contact details, records of the customer's activity with each person (attendance, fees, bookings, entries and exits, orders, tickets), photos and documents the customer uploads, and, where the customer turns the feature on, face templates and vehicle locations. |
| Special care | Data of children; face templates (biometric); identity numbers, bank and salary data; health notes (diet, allergies, medical notes kept by a school or hostel); grievance reports. |
| Purpose | Running the products the customer subscribes to, keeping them secure, fixing faults, and the support the customer asks for. |
| Duration | The term of the agreement, then deletion as in section 10. |
3. Our commitments
We will:
- process customer personal data only on the customer's instructions, and tell the customer if we believe an instruction breaks DPDP law;
- not sell it, not use it for advertising, profiling or our own purposes, and not use it to train AI models, ours or anyone else's;
- keep each customer's data in its own database, apart from every other customer's;
- make sure everyone at Hadoopt who can reach customer personal data is bound to confidentiality, and give access only to those who need it;
- look at a customer's data only when the customer asks for help with a specific request, only for that request, and log every such access (who, when, which request); the customer can ask for that log;
- keep the security measures in section 6;
- help the customer answer requests from the people its data is about (access, correction, erasure, nomination, grievance) through the tools in the product, and assist where a request cannot be answered with them;
- tell the customer of a personal data breach as in section 7;
- delete customer personal data at the end as in section 10.
4. The customer's commitments
The customer will:
- give each person the notice DPDP law requires and have a lawful basis (consent or a legitimate use) for everything it records, including the purpose-wise consent the product asks for before enrolling a face;
- take verifiable consent from a parent or lawful guardian before processing data of a child (anyone under 18), except where DPDP law exempts it, and not use the service to track or monitor children's behaviour beyond what that law allows an educational institution, hostel or transport service;
- set up roles so that each user sees only what that user needs;
- turn on only the optional features (AI, face recognition, location sharing, messaging channels) it has a basis for;
- answer the requests of its own people, and publish its own grievance contact.
5. Sub-processors
The customer authorises us to use the service providers listed in section 9 of our privacy notice, each for the purpose listed there and each bound by a written contract with protections no weaker than this addendum. Some of them are used only when the customer turns on the feature that needs them (for example WhatsApp, SMS, a payment gateway, single sign-on, AI or face recognition). We will publish any new sub-processor on that page at least 30 days before it starts processing customer personal data; a customer that objects on reasonable grounds may end the affected product without penalty before the change takes effect. We remain responsible for our sub-processors.
6. Security
- Encryption in transit (HTTPS/TLS) for every website, portal, app and service connection.
- Encryption at rest of server disks, databases, file storage and backups.
- One database per customer; access by role inside it; administrator actions and sign-ins logged.
- Face templates: no user, of the customer or of Hadoopt, can read them through the product; only the server process uses them. On devices they are kept in encrypted storage and wiped after 7 days without a sync, on sign-out and when the device is blocked.
- Passwords stored only as salted hashes; optional single sign-on and two-step sign-in.
- Regular backups, kept encrypted, with restore tests.
- Patching of servers and dependencies; least-privilege access for our staff, with strong authentication.
7. Personal data breaches
We will tell the customer without undue delay, and in any case within 24 hours of becoming aware of a breach affecting its personal data, with what we know: what happened, the data and people likely affected, what we have done and what we recommend. We will update the customer as we learn more and give the help it needs to inform the Data Protection Board of India and the people affected within the time DPDP law sets. Informing the Board and the people is the customer's duty as Data Fiduciary, unless we agree that we do it on its behalf.
8. Where data is stored
Customer personal data may be stored and processed in India or in other countries where we or our sub-processors operate, but never in a country to which the Government of India has restricted transfers under section 16 of the DPDP Act. The same safeguards apply everywhere. We will tell the customer before its data is moved to another country.
9. Audits and information
We will give the customer the information it reasonably needs to show that this addendum is followed: answers to security questionnaires once a year, the support-access log, and our sub-processor list. Any on-site audit is by agreement, with reasonable notice, at the customer's cost, and subject to confidentiality.
10. End of the service and deletion
- While a subscription is active, the customer can export its records with the export functions in each product.
- When a product is given up, it is locked and its data kept for 30 days in case the customer takes it again; then, or earlier on "Delete now", that product's data and files are deleted. Data the customer's other products use is kept.
- When the agreement ends, or a bill stays unpaid 30 days after access was blocked, the customer's whole database and files are deleted.
- Deleted data drops out of our backups as they expire, within 35 days. We keep nothing after that, except invoices and records the law requires us to keep, which hold no customer personal data beyond the billing contact.
11. Contact
Questions about this addendum, and breach notices: Grievance Officer, Hadoopt Technologies Private Limited, [email protected].