HomeDPA
Legal

Data processing
agreement.

For customers who need it — especially under GDPR and India's DPDP Act — this is the standard DPA we incorporate into subscriptions. It defines who controls what, and what we must do with personal data. Last updated: October 2026.

1 · Roles & scope

You (the subscribing organization) are the data controller for your staff's and customers' personal data. Visaler is the data processor — we process personal data only on your documented instructions, which these Terms, your subscription and your use of the product constitute.

Scope: all personal data your organization and its users put into the service — staff accounts, field activity, GPS tracks, attached media and business records.

2 · What we may do with the data

  • Provide the service — store, index, display and sync the data your organization enters.
  • Secure it — apply the controls listed on our Security & Trust page (tenant isolation, encryption in transit and at rest, least-privilege roles).
  • Support you — troubleshoot incidents and assist with your data-rights requests (access, correction, deletion, export).

We never sell your data, never use it for advertising, and never process it for our own purposes beyond running the service.

3 · Sub-processors

The third parties that may touch personal data are listed on our Sub-processors page — hosting, object storage, email and SMS delivery. We keep the list current and will tell your admin contacts before adding a new category of sub-processor, so you can object.

4 · Data subject rights & consent

The product itself carries the machinery: users can export their personal data, withdraw a consent, and request account deletion from inside the app or web admin. Where a request needs your decision (for example, deleting a field employee's account), it routes to your managers and admins — not to us.

For requests that reach us directly (e.g., website visitors), we respond within 30 days and hand the request to you where the data is yours to control.

5 · Security incidents

If we discover a breach affecting your personal data we notify your organization admin without undue delay, share what we know (scope, affected data, containment steps), and cooperate with your obligations — including India's Data Protection Board notification under the DPDP Act and GDPR Article 33 timelines.

6 · Audits, retention & deletion

Once a year, or after a security incident, you may ask us in writing to demonstrate compliance — we answer with our current security documentation and, where reasonable, a targeted review.

While the subscription runs, data is retained for the life of the subscription. On termination: we export or delete your data at your direction, then remove production copies within 30 days and backups within 90 days.

7 · International transfers

Deployments run in the cloud region we provision for your organization. Where personal data crosses borders, transfers rely on the sub-processors' standard contractual clauses or certified safeguards. Tell us if your compliance requires a specific region.

This DPA is incorporated into every Visaler subscription that asks for it — request a signed copy at sales@visaler.com.