This Data Processing Agreement ("DPA") forms part of the Authyo Terms of Service at https://authyo.io/terms-service/ (the "Agreement"). It is between Konceptwise Digital Media Pvt. Ltd., a company incorporated in India with its registered office at 601A, B & 602, 6th Floor, Shlok Infinity, Chandlodiya, Ahmedabad 382481, Gujarat, which provides the Authyo services ("Authyo", "we", "us"), and the customer that has accepted the Agreement ("Customer", "you").
You accept this DPA when you accept the Agreement, including by ticking the acceptance box in the Authyo dashboard. No signature is needed. If you need a countersigned copy for your records, email info@authyo.io.
1. Definitions
Capitalised terms that are not defined in this DPA have the meaning given in the Agreement.
- "Data Protection Laws" means all laws on privacy and personal data that apply to the processing under the Agreement, including, where they apply: the EU General Data Protection Regulation 2016/679 ("GDPR"); the UK GDPR and the UK Data Protection Act 2018; the Swiss Federal Act on Data Protection ("FADP"); US State Privacy Laws; and India's Digital Personal Data Protection Act, 2023 (from the dates its provisions take effect).
- "US State Privacy Laws" means the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA"), and the comprehensive privacy laws of other US states, to the extent they apply.
- "Customer Personal Data" means personal data that Authyo processes on behalf of Customer in providing the Services, including End User data and the service records described in Section 2.3.
- "End User" means an individual whose personal data Customer submits to, or collects through, the Services. Examples: a person who receives a one-time passcode (OTP) or signs in to Customer's application, a person whose Windows login is protected by RDP Guard, and a person who approves such logins.
- "Services" means the Authyo services described in the Agreement, including the OTP and authentication APIs and SDKs, messaging by SMS, WhatsApp, voice call and email, passkeys, RDP Guard, and Authyo's integrations (such as the Authyo Shopify app).
- "Sub-processor" means a third party engaged by Authyo to process Customer Personal Data.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
- "SCCs" means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0, in force from 21 March 2022), or any version that replaces it.
- "controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR. Equivalent terms in other Data Protection Laws (such as "business" and "service provider" under the CCPA, or "Data Fiduciary" and "Data Processor" under India's Digital Personal Data Protection Act) are read accordingly.
2. Roles and scope
2.1 Customer Personal Data. For Customer Personal Data, Customer is the controller (or a processor acting for its own customers) and Authyo is Customer's processor (or sub-processor).
2.2 Account Data. Authyo is a separate controller of Account Data: information about Customer and its authorised users, such as names, email addresses, phone numbers, billing and tax details, and login records. Authyo handles Account Data as described in its Privacy Policy at https://authyo.io/privacy-policy/, and the rest of this DPA does not apply to it.
2.3 Service records about End Users. Technical records created when the Services are used, such as message delivery status, timestamps, destination country and network, and End Users' IP addresses, are Customer Personal Data, and this DPA applies to them. Customer instructs Authyo to use them only to: provide, bill and secure the Services; detect and prevent fraud and abuse (for example, SMS traffic pumping); keep a list of phone numbers and email addresses that cannot receive messages (for example, addresses that bounce), used only to avoid sending to them; meet legal obligations; and produce statistics that do not identify any End User or Customer. Authyo will never sell Customer Personal Data or use it to market to End Users.
2.4 Details of processing. The subject matter, duration, nature and purpose of the processing, and the types of personal data and categories of data subjects, are set out in Annex 1.
3. Customer's responsibilities
Customer is responsible for:
- having a lawful basis for the processing and giving End Users all information required by Data Protection Laws, including that a service provider located in India processes their data;
- obtaining any consent required to send messages to End Users; sending OTP, verification and transactional messages only to End Users who requested them; and sending marketing messages only with valid consent and a working opt-out;
- complying with the telecom and messaging rules that apply to its traffic, including TRAI DLT registration of sender headers and templates for messages to Indian numbers; for US and Canadian numbers, the toll-free messaging rules and use limits in the Terms of Service; and the policies of messaging platforms such as WhatsApp;
- not submitting special categories of personal data (such as health data) in message content, and obtaining any parental consent required for End Users who are children; and
- making sure its instructions to Authyo comply with Data Protection Laws.
4. Authyo's obligations as processor
4.1 Instructions. Authyo processes Customer Personal Data only on Customer's documented instructions, including with regard to transfers to other countries, unless EU or EU Member State law (or, for the UK GDPR, UK law) to which Authyo is subject requires otherwise. In that case Authyo will tell Customer about that legal requirement before processing, unless that law prohibits this on important grounds of public interest. Requests and requirements under other laws, including Indian law, are handled under Section 5.6 and Clauses 14 and 15 of the SCCs. The Agreement, this DPA, and Customer's use and configuration of the Services are Customer's complete instructions. Authyo will tell Customer immediately if, in its opinion, an instruction breaches Data Protection Laws.
4.2 Confidentiality. Authyo ensures that the people it authorises to process Customer Personal Data are bound by confidentiality obligations and access the data only as needed to provide the Services.
4.3 Security. Authyo implements the technical and organisational measures described in Annex 2. Authyo may update these measures over time, provided the overall level of protection is not reduced.
4.4 Requests from End Users. Taking into account the nature of the processing, Authyo helps Customer respond to requests from End Users to exercise their rights under Data Protection Laws. If Authyo receives such a request directly, it will forward it to Customer without undue delay and will not respond itself, except to direct the End User to Customer.
4.5 Other assistance. Taking into account the nature of the processing and the information available to it, Authyo provides reasonable assistance with Customer's data protection impact assessments, prior consultations with supervisory authorities, and security obligations under Data Protection Laws.
4.6 Personal Data Breaches. Authyo notifies Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, the measures taken or proposed, and a contact point. Authyo will provide further information as it becomes available and will take reasonable steps to contain and remedy the breach. A notice under this section is not an admission of fault or liability.
4.7 Deletion and return. During the term of the Agreement, Customer can export the reports available in the Authyo dashboard and can ask Authyo to delete specific Customer Personal Data by emailing info@authyo.io. When the Agreement ends, Customer may choose, by emailing info@authyo.io within 30 days, to have Authyo return Customer Personal Data as an export in a common format (such as CSV). Within 90 days after the Agreement ends, Authyo deletes all Customer Personal Data, including copies, and confirms the deletion in writing on request. Backup copies are deleted in their normal cycle. If a law requires Authyo to keep some data (for example, the CERT-In Directions require certain logs to be kept for 180 days), Authyo keeps only that data, only for as long as that law requires, protects it under this DPA and uses it for no other purpose.
4.8 Information and audits. Authyo makes available the information reasonably necessary to demonstrate its compliance with this DPA, including documentation of its security measures. Once in any 12-month period, or more often if a supervisory authority requires it, after a Personal Data Breach, or if there are indications that Authyo is not complying with this DPA, Customer may audit Authyo's compliance with this DPA, itself or through an independent auditor bound by confidentiality. Audits may include inspections of Authyo's premises. Customer must give at least 30 days' written notice (or less if a supervisory authority requires it), carry out the audit during business hours without disrupting Authyo's operations, and bear its own costs. Authyo may first offer written answers, documents or third-party reports; if Customer reasonably considers them insufficient, the audit goes ahead.
4.9 Notice if unable to comply. Authyo will tell Customer if it determines that it can no longer meet its obligations under Data Protection Laws or this DPA.
5. Data location and international transfers
5.1 Where data is stored. Authyo stores Customer Personal Data in India. Its application servers run on Microsoft Azure (Central India region) and its database servers are hosted by E2E Networks in Delhi. The Authyo Shopify app is hosted by DigitalOcean and MongoDB Atlas in India (Bangalore). Sub-processors may process Customer Personal Data in the countries listed at https://authyo.io/subprocessors/. Customer authorises these transfers, subject to this Section 5.
5.2 Transfers from the EEA. Where the GDPR applies to Customer's transfer of Customer Personal Data to Authyo, the SCCs are incorporated into this DPA as follows:
- Module Two (controller to processor) applies where Customer is a controller, and Module Three (processor to processor) applies where Customer is a processor;
- the optional docking clause in Clause 7 applies;
- in Clause 9, Option 2 (general written authorisation) applies, with the notice period set out in Section 6.3;
- the optional wording in Clause 11 does not apply;
- in Clause 13, the competent supervisory authority is the one identified in Annex 1, Part C;
- in Clause 17, Option 1 applies and the governing law is the law of the Netherlands;
- in Clause 18, the courts of Amsterdam, the Netherlands, are chosen; and
- Annexes I, II and III of the SCCs are completed with the information in Annexes 1, 2 and 3 of this DPA.
5.3 Transfers from the UK. Where the UK GDPR applies, the UK Addendum is incorporated into this DPA and amends the SCCs as follows: Table 1 is completed with the parties' details in Annex 1; in Table 2, the "Addendum EU SCCs" are the SCCs as incorporated under Section 5.2; Table 3 is completed with the information in Annexes 1, 2 and 3; and in Table 4, neither party may end the UK Addendum under its Section 19.
5.4 Transfers from Switzerland. Where the FADP applies, the SCCs apply as set out in Section 5.2 with these changes: references to the GDPR are read as references to the FADP; the competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner (FDPIC); and the term "Member State" in Clause 18(c) does not prevent data subjects in Switzerland from bringing claims in their place of habitual residence.
5.5 Order of precedence. If the SCCs or the UK Addendum conflict with this DPA or the Agreement, the SCCs or the UK Addendum prevail.
5.6 Requests from public authorities. If Authyo receives a legally binding request from a public authority for Customer Personal Data, Authyo will, unless the law prohibits it: notify Customer promptly; review the lawfulness of the request and challenge it where there are reasonable grounds to do so; and disclose only the minimum information required. Authyo is subject to Indian law, including the CERT-In Directions of 28 April 2022, which require service providers to keep certain system logs for 180 days and to provide them to CERT-In on request.
5.7 Transfer assessments. On request to info@authyo.io, Authyo will give Customer reasonable information to help it assess transfers to India, including a summary transfer impact assessment.
6. Sub-processors
6.1 Authorisation. Customer gives Authyo general authorisation to engage Sub-processors. The current list is at https://authyo.io/subprocessors/ and forms Annex 3.
6.2 Sub-processor contracts. Authyo engages each Sub-processor under a written contract that imposes, in substance, the same data protection obligations as this DPA and, where the SCCs apply, the obligations required by Clause 9(b) of the SCCs, including third-party beneficiary rights for data subjects. Authyo remains fully liable to Customer for each Sub-processor's performance of its obligations.
6.3 Changes. Authyo will email Customer, at the account owner's email address, at least 30 days before a new Sub-processor starts processing Customer Personal Data, and will update the Sub-processor page at the same time. The notice names the Sub-processor, what it will do and where it will process the data. Sending Customer's traffic to a Sub-processor that is already listed (for example, switching messaging routes when one fails) is not a change, unless Authyo has agreed under Section 6.4 not to use that Sub-processor for Customer.
6.4 Objections. Customer may object to a new Sub-processor on reasonable data protection grounds by emailing info@authyo.io within 15 days of the notice. While the objection is being discussed, Authyo will not use that Sub-processor for Customer Personal Data. If the parties cannot agree on a solution within 30 days, Customer may end the Agreement or stop using the affected Services, and Authyo will refund any unused prepaid balance that relates to them.
6.5 Telecom carriers. Mobile network operators and telecom carriers that deliver messages to End Users' devices (for example, the recipient's mobile operator) are not Sub-processors. They carry communications as providers of public telecommunications services. Aggregators and platforms that Authyo contracts with to route or deliver messages are Sub-processors and are listed on the Sub-processor page.
7. US State Privacy Laws
7.1 Role and business purposes. To the extent US State Privacy Laws apply, Customer is the "business" or "controller" and Authyo is Customer's "service provider" or "processor". Customer discloses Customer Personal Data to Authyo only for these limited and specified business purposes, and Authyo processes it only for them (the "Business Purposes"):
- sending one-time passcodes, verification messages and notifications by SMS, WhatsApp, voice call and email, and checking the codes entered;
- passkey, magic-link and social sign-in authentication;
- RDP Guard login protection and approvals;
- delivery reports, logs and support; and
- protecting Customer's traffic and the Services against security incidents, fraud and abuse.
7.2 Restrictions. Authyo will not:
- sell or share Customer Personal Data (as "sell" and "share" are defined in the CCPA) or use it for targeted advertising;
- retain, use or disclose it for any purpose, including any commercial purpose, other than the Business Purposes, except as US State Privacy Laws expressly permit service providers and processors to do;
- retain, use or disclose it outside the direct business relationship between Customer and Authyo; or
- combine it with personal information that Authyo receives from or on behalf of anyone else, or collects from its own interactions with the consumer, except as those laws permit.
7.3 Compliance. Authyo will comply with the obligations that apply to it under US State Privacy Laws and will give Customer Personal Data the same level of privacy protection that the CCPA requires of businesses, including the security measures in Annex 2. Authyo will notify Customer if it determines that it can no longer meet these obligations.
7.4 Customer's rights. Customer may take reasonable and appropriate steps to ensure that Authyo uses Customer Personal Data consistently with Customer's obligations under US State Privacy Laws, including the information and audit rights in Section 4.8. On notice, including after a notice under Section 7.3, Customer may take reasonable and appropriate steps to stop and remediate unauthorised use, including instructing Authyo to stop the processing concerned.
7.5 Consumer requests. Customer will inform Authyo of any consumer request under US State Privacy Laws that Authyo must comply with, and give Authyo the information it needs to comply. Authyo will help as described in Section 4.4. When Customer instructs Authyo to delete, Authyo will also tell its Sub-processors to delete, unless an exception in those laws applies.
7.6 Assessments and audits. Authyo will give Customer the information reasonably necessary for Customer's data protection assessments, risk assessments and cybersecurity audits under US State Privacy Laws, and will not misrepresent any fact relevant to them.
7.7 Sub-processors. Authyo notifies Customer of each Sub-processor under Section 6.3, gives Customer the opportunity to object under Section 6.4, and binds each Sub-processor by written contract to the restrictions and obligations in this Section 7.
7.8 Other processor terms. Annex 1 (nature and purpose, types of data and duration) and Sections 4.1, 4.2, 4.4 to 4.8 and 6 also apply as the processor terms that US State Privacy Laws require.
7.9 Certification. Authyo certifies that it understands the restrictions in this Section 7 and will comply with them.
8. India
Where India's Digital Personal Data Protection Act, 2023 applies to Customer Personal Data, Authyo acts as Customer's Data Processor and processes the data only under the Agreement and this DPA. Authyo maintains the safeguards in Annex 2, notifies Personal Data Breaches under Section 4.6 so that Customer can meet its own notification duties, and erases Customer Personal Data on Customer's instruction, subject to any retention that the law requires.
9. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. Those limitations do not apply to a party's liability to data subjects under the SCCs or the UK Addendum. They do not reduce a party's liability to the other party under Clause 12 of the SCCs below the fees Customer paid in the 12 months before the claim, and they do not limit any liability that cannot be limited by law.
10. General
10.1 Term. This DPA applies for as long as Authyo processes Customer Personal Data.
10.2 Precedence. For data protection matters, this DPA prevails over the rest of the Agreement, subject to Section 5.5.
10.3 Changes. Authyo may update this DPA to reflect changes in law, regulator guidance or the Services. Authyo will give at least 30 days' notice of updates by email or in the dashboard. Updates will not materially reduce the protection of Customer Personal Data unless the law requires it. For material changes, Authyo may ask Customer to accept the updated DPA in the dashboard. Authyo will not change the SCCs, the UK Addendum or the options chosen in Sections 5.2 to 5.4, except to adopt a new version issued by the European Commission, the UK Information Commissioner or the FDPIC.
10.4 Governing law. This DPA is governed by the law that governs the Agreement, except that the SCCs and the UK Addendum are governed by the law stated in them.
10.5 Contacts.
- Privacy questions and notices under this DPA: Nishant Meghnathi, Founder, info@authyo.io
Annex 1: Details of processing
A. Parties
| Data exporter | Customer, as identified in its Authyo account (name, address and contact email). Role: controller (or processor). Activities: use of the Services. Signature and date: given by accepting the Agreement and this DPA electronically. |
|---|---|
| Data importer | Konceptwise Digital Media Pvt. Ltd. (Authyo), 601A, B & 602, 6th Floor, Shlok Infinity, Chandlodiya, Ahmedabad 382481, Gujarat, India. Contact person: Nishant Meghnathi, Founder, info@authyo.io. Role: processor (or sub-processor). Activities: providing the Services. Signature and date: given by making this DPA available and providing the Services. |
B. Description of processing
| Subject matter | Providing the Services to Customer under the Agreement. |
|---|---|
| Duration | For the term of the Agreement and until deletion under Section 4.7. |
| Categories of data subjects | End Users of Customer's websites, apps and services who receive OTPs or other messages, or sign in through Authyo; Customer's staff and other people whose Windows logins are protected by RDP Guard, and the people who approve those logins; customers of Shopify merchants that use the Authyo Shopify app; and any other individuals whose data Customer submits. |
| Categories of personal data | Phone numbers and email addresses; one-time passcodes, magic links and verification results; message content and templates; delivery status and timestamps; IP addresses, approximate location derived from IP addresses, and device and browser information; passkey public keys and credential IDs (biometric data stays on the user's device and is never sent to Authyo); backup codes; profile data from social sign-in providers (such as name, email address and profile ID) where Customer enables social sign-in; for RDP Guard: Windows usernames, server names, IP addresses, login events and audit logs, and approvers' names, phone numbers and email addresses; and any other data Customer includes in messages. |
| Special categories of data | None intended (see Section 3(d)). |
| Frequency of transfer | Continuous, while Customer uses the Services. |
| Nature of processing | Collection, storage, sending and receiving of messages, verification, logging, reporting, support and deletion. |
| Purpose | Providing the Services under the Agreement, including sending and verifying OTPs and notifications, authentication and passkeys, RDP Guard login protection, protecting Customer's traffic against fraud and abuse, reporting and support, and the uses of service records listed in Section 2.3. |
| Retention | For the term of the Agreement, then as set out in Section 4.7. Message delivery logs are kept for 12 months unless Customer asks for earlier deletion, subject to any retention the law requires. |
| Transfers to Sub-processors | Same subject matter, nature and duration as above, for the purposes listed on the Sub-processor page. |
C. Competent supervisory authority
If Customer is established in the EEA: the supervisory authority of the Member State where Customer is established. If not, but Customer has appointed a GDPR Article 27 representative: the supervisory authority of the Member State where that representative is established. Otherwise: the Dutch Autoriteit Persoonsgegevens. For transfers under the UK Addendum: the UK Information Commissioner. For transfers under the FADP: the FDPIC.
Annex 2: Technical and organisational security measures
- Encryption in transit. Data sent between users or customers and Authyo's web app and APIs is encrypted with TLS (HTTPS, with HSTS enabled).
- Encryption at rest. Files in Microsoft Azure Storage are encrypted at rest by the platform.
- Access control. Administrative access is limited to authorised staff through role-based permissions for each admin page, granted on a need-to-know basis. Admin sign-in requires a password and, on any device not already approved, a one-time passcode.
- Account security. Customer accounts use passwordless sign-in (one-time passcodes, passkeys or trusted sign-in providers) with new-device sign-in alerts. Session cookies are HttpOnly and SameSite.
- OTP security. One-time passcodes expire after a short time. Sending is rate-limited and monitored by automated abuse and fraud controls.
- Logging and monitoring. Application and security events are logged.
- Personnel. Staff with access to personal data are bound by confidentiality obligations.
- Incident response. Incidents are reported to CERT-In within 6 hours and to customers within the time in Section 4.6.
- Sub-processors. Bound by written data protection terms (Section 6).
- Physical security. Servers are hosted in data centres operated by Microsoft Azure and E2E Networks, which provide physical access controls, monitoring and environmental protections.
- Data minimisation and deletion. The Services are designed to collect only the data needed to deliver messages and verify users. Data is deleted as described in Section 4.7.
Annex 3: Sub-processors
The current list of Sub-processors, with their purpose and location, is published at https://authyo.io/subprocessors/ and forms part of this DPA. Each Sub-processor's registered address and contact details are available on request at info@authyo.io.
Authyo is provided by Konceptwise Digital Media Pvt. Ltd., which also runs the SMS IDEA, EmailIdea and Jalpi platforms. Authyo uses these systems, which are operated by the same company and covered by this DPA, for SMS delivery to Indian numbers, email delivery and WhatsApp pricing. They are not third-party Sub-processors.