Data Processing Agreement
Last updated: 2026-07-25
This Data Processing Agreement ("DPA") forms part of the Agreement between AEYEON Technologies Private Limited ("AEYEON", "Processor", "we") and the customer ("Customer", "Controller", "you") for the use of Klar. It reflects the parties' obligations under applicable data-protection laws, including the EU GDPR, UK GDPR, California CCPA/CPRA and India's Digital Personal Data Protection Act, 2023 (the "DPDP Act").
Enterprise customers requiring a counter-signed copy or Standard Contractual Clauses may request one at legal@aeye-on.com.
1. Roles of the parties
For Customer Data processed through Klar, the Customer is the Controller and AEYEON is the Processor, acting on the Customer's documented instructions. AEYEON is the Controller only for limited account and billing data described in our Privacy Policy.
2. Subject matter of processing
| Subject matter | Provision of the Klar analytics service |
| Duration | For the term of the Agreement plus applicable retention periods |
| Nature & purpose | Ingesting, storing, querying, cleaning, analysing, explaining and alerting on Customer Data to produce dashboards, insights and reports |
| Types of data | Business/operational data the Customer connects — e.g. sales, orders, payments, advertising, analytics, spreadsheet and database records, which may include limited personal data (e.g. customer names, emails) |
| Categories of data subjects | The Customer's own customers, users and contacts contained in the connected sources |
3. Processor obligations
AEYEON shall:
- Process Customer Data only on the Customer's documented instructions, including for international transfers, unless required by law;
- Ensure personnel authorised to process Customer Data are bound by confidentiality;
- Implement the technical and organisational security measures in Section 6;
- Not use Customer Data to train any AI/ML model;
- Assist the Customer, taking into account the nature of processing, in responding to data-subject requests (Section 11) and in meeting its security, breach-notification and impact-assessment obligations;
- On termination, delete or return Customer Data per Section 7.
4. Controller obligations
The Customer shall ensure it has a lawful basis and all necessary consents/notices to connect its data sources to Klar, and that its instructions comply with applicable law.
5. Sub-processors
The Customer authorises AEYEON to engage the sub-processors listed at /sub-processors. AEYEON imposes data-protection obligations on each sub-processor no less protective than this DPA, and remains liable for their performance. AEYEON gives at least 14 days' notice of any intended addition or replacement, during which the Customer may object on reasonable grounds.
6. Security measures
AEYEON maintains appropriate technical and organisational measures, including:
- Encryption in transit (TLS 1.2+) and at rest (AWS RDS / object-storage encryption);
- Credentials stored in AWS Secrets Manager with KMS-wrapped envelope encryption — never in application databases;
- Least-privilege, read-only database connections where supported;
- Tenant isolation via PostgreSQL Row-Level Security enforced by a least-privilege runtime role;
- Audit logging of data-source access and administrative actions;
- Automated database backups (7-day retention) and infrastructure monitoring;
- A documented incident-response process.
7. Retention & deletion
Connected-source data and OAuth tokens are deleted on source disconnection or account deletion. Following termination, AEYEON deletes or returns remaining Customer Data within a reasonable period (and no later than 90 days), except where retention is required by law. Backups are cycled out within the 7-day backup window.
8. Audits
AEYEON will make available information reasonably necessary to demonstrate compliance with this DPA. Where AEYEON holds third-party audit reports (e.g. SOC 2, once available), it may provide these to satisfy audit requests.
9. Personal data breach
AEYEON will notify the Customer without undue delay, and within 72 hours of becoming aware of a personal-data breach affecting Customer Data, and will provide information reasonably available to assist the Customer's own notification obligations.
10. International transfers
Customer Data is hosted primarily in AWS ap-south-1 (Mumbai). Where personal data is transferred across borders, AEYEON relies on appropriate safeguards such as Standard Contractual Clauses. An EU-region hosting option is available to Enterprise customers on request.
11. Data-subject requests
AEYEON will, taking into account the nature of processing, assist the Customer by appropriate technical and organisational measures in fulfilling data-subject requests (access, rectification, erasure, restriction, portability, objection). The Customer can exercise most such actions directly in-product or via privacy@aeye-on.com.
12. Liability & term
This DPA is subject to the liability provisions of the Agreement. It takes effect when the Customer begins using Klar and continues for as long as AEYEON processes Customer Data.
13. Contact
| Purpose | |
|---|---|
| Legal / DPA | legal@aeye-on.com |
| Privacy / data-subject requests | privacy@aeye-on.com |
| Security | security@aeye-on.com |
This DPA is provided for transparency. It does not constitute legal advice; specific commitments for regulated or enterprise use should be confirmed in a signed agreement.