This agreement forms part of the OCTYN Terms & Conditions and applies whenever your organisation uses OCTYN to process personal data.
01 Parties and scope
This Data Processing Agreement ("DPA") is between the organisation that subscribes to OCTYN ("you", the Data Fiduciary) and Zenithyn Technologies Private Limited ("we", the Data Processor), which operates OCTYN.
It covers personal data that you, your staff and your users enter into or upload to OCTYN, and that we process to provide the service. It does not cover personal data we collect for our own purposes — for example, to run your subscription or our website — which the Privacy Policy covers, and for which we are the Data Fiduciary.
By accepting the DPA when you sign up or set up your organisation, you agree to it on behalf of your organisation.
02 Definitions
"Personal data", "processing", "Data Fiduciary", "Data Processor", "Data Principal", "personal data breach" and "Board" have the meanings given in the Digital Personal Data Protection Act 2023 ("DPDP Act") and the rules made under it. "Customer data" means the personal data described in section 4.
03 Roles
You decide why and how customer data is processed: which staff, customers and vehicles you record, what you keep, and who in your organisation may see it. We process customer data only on your documented instructions, which are the Terms, this DPA and your use of OCTYN's features.
You are responsible for having a lawful basis for the personal data you put into OCTYN, and for giving your staff and customers any notice the DPDP Act requires. If we believe an instruction breaks the law, we will tell you and may decline it.
04 What we process
| Item | Detail |
|---|---|
| Data Principals | Your owners, managers, cashiers and accountants who use OCTYN; your staff and attendants; your credit customers and their drivers; your suppliers' contact people |
| Personal data | Names, phone numbers and email addresses; staff wages, attendance, advances, bonuses and bank details; staff documents you upload; shift PINs (stored hashed); credit-customer contacts, vehicle numbers and balances; invoices and statements that carry these |
| Purpose | Running your station on OCTYN: shifts, cash, credit, purchases, retail, payroll, accounts, compliance and reports, including reading uploaded purchase invoices automatically |
| Duration | For the life of your subscription, then as set out in section 11 |
OCTYN is not designed for children's data or for special categories of data beyond what payroll requires. Please do not upload anything else.
05 Our obligations
- Instructions only — we use customer data only to provide and support OCTYN for you, never for advertising and never to sell.
- Confidentiality — everyone at Zenithyn with access to customer data is bound by confidentiality, and access is limited to those who need it.
- Security — we apply the measures in section 8.
- Sub-processors — we engage them only as set out in section 6.
- Assistance — we help you respond to Data Principals and meet your DPDP duties, as set out in section 10.
06 Sub-processors
You authorise us to use the following sub-processors. We require each of them to protect customer data at least as well as this DPA does.
| Sub-processor | What it does for OCTYN | Where it processes |
|---|---|---|
| Supabase | Database, sign-in and file storage for all customer data | India (Mumbai, ap-south-1) |
| Cloudflare | Hosting of the OCTYN app, invoice upload storage and processing queues, bot protection on sign-in, and reading the purchase-invoice PDFs you upload (Workers AI, open-source Llama model) | Cloudflare's global network |
| Anthropic | Fallback only: reads an uploaded purchase invoice that the primary reader could not read reliably | United States |
| Resend | Sends the emails OCTYN sends: sign-in links, invitations, reminders and statements | United States |
| Razorpay | Subscription payments (your billing contact's details, not your station's data) | India |
We will give you at least 30 days' notice, by email and on this page, before adding or replacing a sub-processor. If you object on reasonable data-protection grounds, we will discuss it with you in good faith; if we cannot resolve it, you may stop using the affected feature or cancel your subscription; refunds follow our Refund Policy.
07 Transfers outside India
OCTYN's database, where your records live, is in India. Some customer data is processed outside India, as the table in section 6 shows: purchase-invoice files you upload are held and read on Cloudflare's network; an invoice the primary reader cannot read reliably may be sent to Anthropic in the United States; and email is sent through a United States provider. We do not transfer customer data to any country the Central Government has restricted under section 16 of the DPDP Act.
08 Security
- Every organisation's data is separated by row-level security in the database, so one organisation cannot read another's records.
- Within your organisation, what each person can see and change follows their role (owner, manager, cashier, accountant), enforced on the server as well as in the app.
- Traffic is encrypted in transit (TLS); our infrastructure providers encrypt data at rest.
- Two-factor sign-in is available to every user.
- Financial actions — postings, reversals, overrides, reopens — are recorded in an audit log.
- Shift PINs are stored only as hashes; staff bank details are stored encrypted.
Our wider measures are described in section 8 of the Privacy Policy.
09 Personal data breaches
If we become aware of a personal data breach affecting customer data, we will tell you without undue delay and in any case within 72 hours, with what we know about its nature, the data and Data Principals affected, its likely consequences and the steps we are taking. We will update you as we learn more and help you with any notice you must give the Board or Data Principals.
10 Helping you meet your duties
OCTYN lets you view, correct, export and delete the records you keep. Where a Data Principal contacts us directly about customer data, we will pass the request to you and will not answer it ourselves unless you ask us to. On request we will give you reasonable help with your own obligations, including information for any assessment you carry out.
11 Return and deletion
While your subscription is active you can export your data at any time (CSV, Excel, PDF and the CA pack), and before termination you can ask us for a full export at [email protected]. After termination we delete customer data, except where the law requires us to keep it — for example, tax and GST records — in which case we keep only what is required, for as long as it is required, and then delete it. Retention periods are listed in section 7 of the Privacy Policy.
12 Information and audits
On reasonable written request, and not more than once a year unless a breach or a regulator requires it, we will give you the information you need to confirm we are meeting this DPA. Where our sub-processors publish independent certifications, we will point you to them.
13 Term, precedence and law
This DPA lasts as long as we process customer data for you. If it conflicts with the Terms on how personal data is processed, this DPA prevails. The limitations of liability in the Terms apply to it. It is governed by the laws of India, and the dispute-resolution and jurisdiction clauses of the Terms apply to it.
14 Contact
- Email — [email protected] (subject "DPA")
- Grievance Officer — as named in the Privacy Policy