Data Processing Addendum

Version 1.0 · Effective 25 August 2026

This Addendum forms part of the Terms of Service between you (the "Controller" or "Data Fiduciary") and Dream Blend Solutions Private Limited (the "Processor"). It applies whenever we process personal data on your behalf.

It is designed to satisfy Article 28 of the GDPR and the corresponding obligations under the Digital Personal Data Protection Act, 2023.

1. Subject matter and duration

We process personal data only to provide the Service, for the duration of your subscription plus the 30-day retention window that follows termination.

2. Nature and purpose of processing

OperationPurpose
Retrieval and storageSynchronising mail from your connected mailboxes
Encryption and decryptionProtecting data at rest and displaying it to authorised users
IndexingAllowing search across your own mail
TransmissionSending mail you compose
DeletionHonouring your retention and erasure instructions

3. Categories of data and data subjects

Data subjects: your employees and authorised users; the senders and recipients corresponding with your mailboxes.

Categories: names, email addresses, phone numbers, message content, attachments, and any other personal data your correspondents choose to include in an email.

Because email is free-form, we cannot control what categories appear in message bodies. You remain responsible for ensuring you have a lawful basis for the personal data present in the mailboxes you connect.

4. Our obligations

  • Process personal data only on your documented instructions, unless required otherwise by law, in which case we will inform you unless prohibited.
  • Ensure everyone authorised to process the data is bound by confidentiality.
  • Implement the technical and organisational measures set out in section 6.
  • Not engage a sub-processor without the authorisation described in section 7.
  • Assist you in responding to data subject requests, given the nature of the processing.
  • Assist you with data protection impact assessments and prior consultation.
  • Delete or return personal data at the end of the engagement, as you elect.
  • Make available the information needed to demonstrate compliance and allow audits under section 9.

5. Your obligations

  • Ensure you have a lawful basis for the personal data you place in the Service.
  • Provide any notices and obtain any consents required from your data subjects.
  • Configure permissions so that users can only access what they need.
  • Respond to data subject requests directed at you as Controller.

6. Security measures

MeasureImplementation
Encryption in transitTLS 1.2 or above, HSTS enforced
Encryption at restAES-256-GCM on message content, subjects, addresses and credentials
Key managementEncryption key separate from the application key; rotation supported
Access controlRole-based, default-deny, permissions grantable at any hierarchy level
AuthenticationArgon2id password hashing; multiple two-factor methods; optional IP restrictions
Tenant isolationEnforced at the database query layer, not in application code
LoggingHash-chained, tamper-evident audit trail
MonitoringAutomated detection of bulk export, mass read and anomalous sign-in
ResilienceDaily encrypted backups with a 90-day rolling retention

7. Sub-processors

You give general authorisation for the sub-processors listed in our Privacy Policy. We will:

  • give at least 30 days' notice before adding or replacing one;
  • impose data protection obligations on it no less protective than these;
  • remain fully liable to you for its performance.

If you reasonably object to a new sub-processor, you may terminate the affected part of the Service without penalty.

8. Data subject requests

If a data subject contacts us directly about data we process on your behalf, we will not respond substantively but will forward the request to you within 5 business days. We provide export and deletion tools within the Service so that you can respond yourself, and will assist further on request.

9. Audits

On reasonable written notice and no more than once per year, you may audit our compliance with this Addendum, either by reviewing documentation we provide or by engaging an independent auditor bound by confidentiality. Audits must not unreasonably disrupt the Service. Where a current third-party report exists, we may provide it in satisfaction of an audit request.

10. Breach notification

We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your data, and provide the nature of the breach, categories and approximate numbers affected, likely consequences and remedial measures.

11. International transfers

Personal data is stored in India. Mail content is never transferred outside India. Where a payment sub-processor operates internationally, transfers are covered by Standard Contractual Clauses.

12. Deletion and return

On termination you may export your data at any point during the 30-day window. After it, data is deleted from live systems, and from backups within a further 90 days, unless retention is required by law.

13. Liability and precedence

Liability under this Addendum is subject to the limitations in the Terms of Service. Where this Addendum conflicts with the Terms in respect of data protection, this Addendum prevails.

14. Signing a countersigned copy

If your procurement process requires an executed DPA, email info@dreambspl.com and we will provide one for signature.

15. Contact

Dream Blend Solutions Private Limited
Samastipur
Samastipur, Bihar 848101
India

Email: info@dreambspl.com
Phone: +91 7280008555