How we process personal data for our business customers
Applicability: This Data Processing Agreement ("DPA") applies to business customers who use Bluetick services and where Bluetick processes personal data on behalf of the customer. Individual consumers should refer to our Privacy Policy.
This Data Processing Agreement ("DPA") forms part of the Master Service Agreement or Terms of Service ("Agreement") between Bluetick Network LLP ("Data Processor," "Bluetick," "we," "us") and the customer ("Data Controller," "Customer," "you") using our services.
This DPA governs the processing of Personal Data by Bluetick when providing digital business card and networking services to the Customer.
Processing will continue for the duration of the Agreement and until all Personal Data is deleted or returned in accordance with this DPA.
As Data Controller, you are responsible for:
We will process Personal Data only on your documented instructions, unless required by law to do otherwise.
We ensure that persons authorized to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality.
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk.
We will not engage another processor without your prior written authorization. We maintain a list of authorized sub-processors.
We assist you in responding to Data Subject requests and ensuring compliance with obligations under data protection laws.
Upon termination, we will delete or return all Personal Data at your choice, unless legal requirements mandate retention.
We make available all information necessary to demonstrate compliance and allow for audits by you or an auditor mandated by you.
Bluetick implements the following technical and organizational security measures:
We use the following sub-processors to provide our services:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database and authentication | USA (Mumbai region) |
| Cloudinary Ltd. | Media storage and processing | USA/EU |
| Razorpay Software Pvt. Ltd. | Payment processing | India |
| Google LLC (Firebase) | Analytics and notifications | USA |
| Digital Ocean, Inc. | Web hosting | USA (BLR region) |
| Vercel Inc. | Edge hosting | Global CDN |
You may subscribe to sub-processor updates by emailing [email protected]. We will notify you of any new sub-processors at least 30 days before engagement.
Where Personal Data is transferred outside of India, the EEA, UK, or Switzerland, we ensure appropriate safeguards through:
Bluetick will assist you in responding to Data Subject requests, including:
We will promptly notify you if we receive a request from a Data Subject regarding their Personal Data, unless prohibited by law.
In the event of a Personal Data breach, Bluetick will:
10.1 Bluetick maintains industry-standard certifications and undergoes regular security assessments.
10.2 Upon reasonable request and subject to confidentiality obligations, we will provide audit reports, certifications, and attestations demonstrating compliance.
10.3 You may conduct an audit (or appoint a third-party auditor) with 30 days written notice, at your expense, during normal business hours, and subject to reasonable confidentiality requirements.
This DPA remains in effect for the duration of the Agreement between you and Bluetick.
Upon termination, we will, at your election, return or delete all Personal Data within 30 days, unless retention is required by applicable law.
Obligations that by their nature should survive termination (including confidentiality and data protection) will remain in effect.
For DPA-related inquiries, execution of this agreement, or to request a signed copy:
Bluetick Network LLP
138 Atlanta Mall, Motavaracha
Surat - 394101
India
Email: [email protected]
DPA Requests: [email protected]
Phone: +91 94286 32907
To execute this DPA, contact us at [email protected] with your company details. A countersigned copy will be provided within 5 business days.