DATA PROCESSING AGREEMENT (DPA)

Effective Date: ___________________

This Data Processing Agreement ("DPA") is entered into between:

Campus Marg Innovative Tech Services LLP, operating as CMI BPO Services ("Processor", "Service Provider", "CMITS", "we", "our", or "us"),

and

Client Name: __________________________________________ ("Controller", "Client", or "Customer").

This DPA forms part of and is incorporated into the Master Service Agreement (MSA), Service Agreement, Statement of Work (SOW), Purchase Order, or other commercial agreement ("Principal Agreement") between the parties.

1. Purpose

The purpose of this Agreement is to establish the obligations and responsibilities of each party regarding the processing of personal data in connection with the services provided by CMI BPO Services.

2. Definitions

For the purposes of this Agreement:

Controller means the party that determines the purposes and means of processing personal data.

Processor means Campus Marg Innovative Tech Services LLP, acting on behalf of the Controller.

Personal Data means any information relating to an identified or identifiable natural person.

Processing includes collecting, recording, storing, organizing, modifying, transmitting, using, disclosing, deleting, or otherwise handling personal data.

Data Subject means the individual to whom the personal data relates.

3. Scope of Processing

The Processor may process personal data solely for the purpose of providing services agreed under the Principal Agreement, including:

  • Customer Support

  • Contact Center Operations

  • Technical Support

  • Recruitment Process Outsourcing (RPO)

  • HR Support

  • Back Office Processing

  • Data Entry

  • Helpdesk Services

  • Lead Management

  • Email Support

  • Chat Support

  • Voice Support

  • Other agreed outsourcing services

4. Categories of Personal Data

Depending on the project, processing may include:

  • Full Name

  • Email Address

  • Mobile Number

  • Postal Address

  • Company Information

  • Employee Information

  • Customer Information

  • Candidate Information

  • Employment Details

  • Educational Records

  • Communication Records

  • Transaction Information

  • Customer Service Records

  • Support Tickets

  • Voice Recordings (where applicable)

  • Chat Transcripts

  • Email Communications

  • Any additional information provided by the Controller for the agreed services

5. Categories of Data Subjects

Personal data may relate to:

  • Customers

  • Employees

  • Candidates

  • Vendors

  • Business Partners

  • Website Users

  • Students

  • Prospective Customers

  • Contractors

  • Other individuals identified by the Controller

6. Processor Obligations

The Processor shall:

  • Process personal data only on documented instructions from the Controller.

  • Process data solely for the agreed business purposes.

  • Maintain confidentiality of all personal data.

  • Ensure personnel handling personal data are subject to confidentiality obligations.

  • Implement reasonable technical and organizational security measures.

  • Notify the Controller of any known personal data breach without undue delay after becoming aware of it.

  • Assist the Controller, where reasonably requested, in responding to data subject rights requests.

  • Cooperate with the Controller regarding compliance obligations, where applicable.

7. Controller Obligations

The Controller shall:

  • Ensure it has a lawful basis for processing and sharing personal data.

  • Provide lawful instructions to the Processor.

  • Inform data subjects as required by applicable law.

  • Obtain any necessary consents where applicable.

  • Ensure that data supplied to the Processor is accurate and relevant.

8. Confidentiality

The Processor shall treat all personal data and confidential information as strictly confidential and shall not disclose such information except:

  • As instructed by the Controller.

  • As required by applicable law.

  • To authorized personnel or approved subprocessors who are bound by appropriate confidentiality obligations.

9. Security Measures

The Processor will maintain commercially reasonable administrative, technical, and organizational measures to protect personal data, including, where appropriate:

  • Access controls based on business need.

  • User authentication procedures.

  • Password-protected systems.

  • Endpoint protection and anti-malware controls.

  • Secure storage of data.

  • Backup and recovery procedures.

  • Employee security awareness training.

  • Physical security for office facilities.

  • Logging and monitoring where appropriate.

The specific security measures may vary based on the nature of the services and contractual requirements.

10. Subprocessors

The Processor may engage third-party service providers (subprocessors) where necessary to deliver the agreed services.

The Processor will take reasonable steps to ensure that any approved subprocessors are contractually bound to protect personal data in a manner consistent with this Agreement.

Where required by the Principal Agreement, the Processor will notify the Controller of material changes to subprocessors.

11. International Transfers

Where personal data is transferred outside the jurisdiction in which it was collected, the parties will take reasonable steps to ensure that such transfers comply with applicable legal requirements and are subject to appropriate safeguards where required.

12. Data Subject Rights

Where applicable and reasonably requested by the Controller, the Processor shall assist in responding to requests relating to:

  • Access

  • Correction

  • Deletion

  • Restriction of processing

  • Objection to processing

  • Data portability (where legally applicable)

The Controller remains responsible for responding to data subject requests unless otherwise agreed.

13. Data Breach Notification

If the Processor becomes aware of a confirmed personal data breach affecting Controller data, the Processor shall notify the Controller without undue delay after becoming aware of the breach.

The notification will include, where reasonably available:

  • Nature of the incident

  • Categories of affected data

  • Likely impact

  • Steps taken or proposed to mitigate the effects

The Processor does not guarantee uninterrupted service or absolute security, as no security system is entirely immune from risk.

14. Data Retention and Deletion

The Processor shall retain personal data only for as long as necessary to perform the agreed services, comply with applicable legal obligations, resolve disputes, or enforce contractual rights.

Upon termination of the Principal Agreement, and subject to legal or contractual retention requirements, the Processor will, upon written request, return or securely delete Controller personal data within a commercially reasonable period.

15. Audits

Where expressly agreed in writing, and subject to reasonable notice, confidentiality obligations, and operational requirements, the Controller may request information reasonably necessary to demonstrate the Processor's compliance with this DPA.

Any audit shall be conducted during normal business hours in a manner that minimizes disruption to the Processor's operations.

16. Liability

Each party shall remain responsible for its own acts and omissions.

The Processor's liability under this DPA shall be subject to the limitations of liability set out in the Principal Agreement, except where such limitations are prohibited by applicable law.

17. Term and Termination

This DPA becomes effective on the Effective Date and remains in force for the duration of the Principal Agreement or as long as the Processor processes personal data on behalf of the Controller.

Termination of the Principal Agreement shall not affect obligations relating to confidentiality, data protection, or retention where those obligations are intended to survive termination.

18. Governing Law

This Data Processing Agreement shall be governed by the laws of India, unless otherwise agreed in writing in the Principal Agreement.

Any disputes arising under this DPA shall be subject to the jurisdiction specified in the Principal Agreement.

19. Contact Information

Campus Marg Innovative Tech Services LLP
(Operating as CMI BPO Services)

Email: privacy@cmibpo.com

Phone: +91 9700880567

Website: www.cmibpo.com

20. Entire Agreement

This DPA forms part of the Principal Agreement. In the event of any inconsistency between this DPA and the Principal Agreement concerning the processing of personal data, the provisions of this DPA shall prevail to the extent of that inconsistency, unless the Principal Agreement expressly provides otherwise.

21. Signatures

For Campus Marg Innovative Tech Services LLP

Authorized Signatory: ___________________________

Name: _________________________________________

Designation: ___________________________________

Signature: _____________________________________

Date: __________________________________________

For Client

Company Name: _________________________________

Authorized Signatory: ___________________________

Name: _________________________________________

Designation: ___________________________________

Signature: _____________________________________

Date: __________________________________________