Data Processing Addendum
Version 1.0 · Effective 25 August 2026
This Addendum forms part of the Terms of Service between you (the "Controller" or "Data Fiduciary") and Dream Blend Solutions Private Limited (the "Processor"). It applies whenever we process personal data on your behalf.
It is designed to satisfy Article 28 of the GDPR and the corresponding obligations under the Digital Personal Data Protection Act, 2023.
1. Subject matter and duration
We process personal data only to provide the Service, for the duration of your subscription plus the 30-day retention window that follows termination.
2. Nature and purpose of processing
| Operation | Purpose |
|---|---|
| Retrieval and storage | Synchronising mail from your connected mailboxes |
| Encryption and decryption | Protecting data at rest and displaying it to authorised users |
| Indexing | Allowing search across your own mail |
| Transmission | Sending mail you compose |
| Deletion | Honouring your retention and erasure instructions |
3. Categories of data and data subjects
Data subjects: your employees and authorised users; the senders and recipients corresponding with your mailboxes.
Categories: names, email addresses, phone numbers, message content, attachments, and any other personal data your correspondents choose to include in an email.
Because email is free-form, we cannot control what categories appear in message bodies. You remain responsible for ensuring you have a lawful basis for the personal data present in the mailboxes you connect.
4. Our obligations
- Process personal data only on your documented instructions, unless required otherwise by law, in which case we will inform you unless prohibited.
- Ensure everyone authorised to process the data is bound by confidentiality.
- Implement the technical and organisational measures set out in section 6.
- Not engage a sub-processor without the authorisation described in section 7.
- Assist you in responding to data subject requests, given the nature of the processing.
- Assist you with data protection impact assessments and prior consultation.
- Delete or return personal data at the end of the engagement, as you elect.
- Make available the information needed to demonstrate compliance and allow audits under section 9.
5. Your obligations
- Ensure you have a lawful basis for the personal data you place in the Service.
- Provide any notices and obtain any consents required from your data subjects.
- Configure permissions so that users can only access what they need.
- Respond to data subject requests directed at you as Controller.
6. Security measures
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS 1.2 or above, HSTS enforced |
| Encryption at rest | AES-256-GCM on message content, subjects, addresses and credentials |
| Key management | Encryption key separate from the application key; rotation supported |
| Access control | Role-based, default-deny, permissions grantable at any hierarchy level |
| Authentication | Argon2id password hashing; multiple two-factor methods; optional IP restrictions |
| Tenant isolation | Enforced at the database query layer, not in application code |
| Logging | Hash-chained, tamper-evident audit trail |
| Monitoring | Automated detection of bulk export, mass read and anomalous sign-in |
| Resilience | Daily encrypted backups with a 90-day rolling retention |
7. Sub-processors
You give general authorisation for the sub-processors listed in our Privacy Policy. We will:
- give at least 30 days' notice before adding or replacing one;
- impose data protection obligations on it no less protective than these;
- remain fully liable to you for its performance.
If you reasonably object to a new sub-processor, you may terminate the affected part of the Service without penalty.
8. Data subject requests
If a data subject contacts us directly about data we process on your behalf, we will not respond substantively but will forward the request to you within 5 business days. We provide export and deletion tools within the Service so that you can respond yourself, and will assist further on request.
9. Audits
On reasonable written notice and no more than once per year, you may audit our compliance with this Addendum, either by reviewing documentation we provide or by engaging an independent auditor bound by confidentiality. Audits must not unreasonably disrupt the Service. Where a current third-party report exists, we may provide it in satisfaction of an audit request.
10. Breach notification
We will notify you without undue delay and in any event within 72 hours of becoming aware of a personal data breach affecting your data, and provide the nature of the breach, categories and approximate numbers affected, likely consequences and remedial measures.
11. International transfers
Personal data is stored in India. Mail content is never transferred outside India. Where a payment sub-processor operates internationally, transfers are covered by Standard Contractual Clauses.
12. Deletion and return
On termination you may export your data at any point during the 30-day window. After it, data is deleted from live systems, and from backups within a further 90 days, unless retention is required by law.
13. Liability and precedence
Liability under this Addendum is subject to the limitations in the Terms of Service. Where this Addendum conflicts with the Terms in respect of data protection, this Addendum prevails.
14. Signing a countersigned copy
If your procurement process requires an executed DPA, email info@dreambspl.com and we will provide one for signature.
15. Contact
Dream Blend Solutions Private LimitedSamastipur
Samastipur, Bihar 848101
India
Email: info@dreambspl.com
Phone: +91 7280008555