Legal
Data Processing Agreement.
These are the terms we accept when we process personal data on your behalf. They are published rather than held behind a sales conversation, because needing to email for a DPA adds a week to procurement for no reason.
Version 1.0 · Effective 7 August 2026
This page reproduces our standard terms so you can review them before we talk. It forms part of a signed agreement when incorporated by reference into a services contract — it is not itself a contract until then. We will sign your DPA instead if you prefer, and we will sign the ICO’s International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum where a transfer safeguard is required.
1Roles and scope
You are the controller. Flutterfrog Software Solutions is the processor. These terms apply to any personal data we process on your behalf while providing services to you, and they sit alongside the main services agreement rather than replacing it.
Where the Digital Personal Data Protection Act 2023 applies, you are the Data Fiduciary and we are a Data Processor acting under your instructions.
2What we process, and why
Subject matter: provision of the software development, operation and document-automation services described in the services agreement.
Duration: the term of the services agreement, plus the deletion period in clause 9.
Nature and purpose: hosting, storage, retrieval, structuring, generation of documents from your own records, and support.
Categories of data subject and personal data: as set out in the order form or statement of work. We do not require special-category data and you should not send it to us without agreeing that in writing first.
3We act only on your instructions
We process personal data only on your documented instructions, including on transfers, unless we are required to do otherwise by law — in which case we will tell you before processing, unless that law forbids it on important grounds of public interest. (Article 28(3)(a).)
We will tell you if, in our opinion, an instruction infringes data protection law. We will not use your personal data for our own purposes, and we will not use it to train general-purpose models.
4Confidentiality
Everyone we authorise to process your personal data is bound by a written confidentiality obligation that survives the end of their engagement with us. Access is granted by name and to the minimum necessary. (Article 28(3)(b).)
5Security
We implement appropriate technical and organisational measures, taking account of the state of the art, cost, and the risk to individuals. (Article 28(3)(c), Article 32.) These include encryption in transit and at rest, single-tenant isolation of client environments, role-scoped access, and separation of production from development.
The measures in force are described on our security page, which also states plainly what we do not have — we are not SOC 2 or ISO 27001 certified, and we do not claim to be.
6Sub-processors
You give general authorisation for us to engage sub-processors. Our current list, with each party’s purpose and location, is published on the security page. (Article 28(2), 28(3)(d).)
We will give you 30 days’ written notice before adding or replacing a sub-processor. You may object on reasonable data-protection grounds within that period; if we cannot resolve your objection, you may terminate the affected services without penalty.
We impose the same obligations on every sub-processor by contract, and we remain fully liable to you for their performance.
7Helping you meet your own obligations
We will assist you, by appropriate technical and organisational measures and so far as is possible, in responding to requests to exercise data-subject rights. (Article 28(3)(e).) If a request reaches us directly we will not respond to it ourselves; we will pass it to you without undue delay.
We will assist you with security, breach notification, data protection impact assessments and prior consultation, taking account of the nature of processing and the information available to us. (Article 28(3)(f), Articles 32–36.)
8Breach notification
We will notify you without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting your data, with what we know at the time: the nature of the breach, the categories and approximate number of records, the likely consequences, and the measures taken. A fuller written account follows once the position is established.
As an Indian body corporate we are separately subject to the CERT-In Directions of 28 April 2022, which require certain incidents to be reported to CERT-In within six hours.
9Return and deletion
At the end of the services, and at your choice, we will return your personal data or delete it, and delete existing copies unless law requires us to keep them. (Article 28(3)(g).)
Unless you tell us otherwise, we delete within 30 days of termination, and confirm deletion in writing. Backups age out on their normal cycle, which does not exceed 90 days.
Where we hold your knowledge as plain-text files, you already have a copy and there is nothing to export.
10Audit and information
We will make available all information necessary to demonstrate compliance with these terms, and allow for and contribute to audits, including inspections, conducted by you or an auditor you appoint. (Article 28(3)(h).)
In practice: we return a completed security questionnaire within one working day, and we will accommodate one audit per year on 30 days’ notice, at your cost, subject to reasonable confidentiality terms and without disruption to other clients.
11International transfers
We deploy client environments in the region you nominate. Where personal data is transferred to, or accessed from, a country without an adequacy decision — including India, which currently holds neither a UK nor an EU adequacy decision — an Article 46 safeguard applies.
We will enter into the ICO’s International Data Transfer Agreement, or the EU Standard Contractual Clauses together with the UK Addendum, and complete a transfer risk assessment with you.
12Changes to these terms
We may update this document to reflect changes in law or in how we operate. Where a change materially reduces your protections we will give you 30 days’ notice. Version and effective date are stated at the top, and superseded versions are available on request.
13Contact
Flutterfrog Software Solutions — LLP, GSTIN 33AAGFF7006F1ZU
No. 53C4, Kamarajar Nagar, Kattaiyanvilai, Nagercoil, Kanyakumari, Tamil Nadu 629003
gokul@theflutterfrog.com
Send us your own DPA, your security questionnaire, or a request to sign the IDTA or SCCs and we will come back within one working day.