Data Processing Addendum
Effective Date: 9 October 2026
Last Updated: 9 October 2026
Version: 2026-10-09
This Data Processing Addendum ("DPA") forms part of the Terms of Service (and of any master services agreement) between Aniket Raj, trading as MandateRoom ("we", "us", the "Processor") and the Customer (the "Customer"). It applies to the personal data in Customer Content that we process for the Customer ("Customer Personal Data"). It takes effect when the Customer accepts the Terms of Service, and a countersigned copy is available on request at hello@mandateroom.com. Words defined in the Terms of Service have the same meaning here.
1. Definitions
"Data Protection Laws" means the laws on the protection of personal data that apply to the processing, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and Data Protection Act 2018, the Swiss Federal Act on Data Protection ("FADP"), the privacy laws of the states of the United States, and India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). "Controller", "processor", "data subject", "personal data", "processing", "personal data breach" and "supervisory authority" have the meanings in the GDPR. "Sub-processor" means a processor that we engage to process Customer Personal Data. "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914. "UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0. "Restricted Transfer" means a transfer of Customer Personal Data that Data Protection Laws restrict unless a transfer mechanism applies.
2. Roles and scope
The Customer is the controller of Customer Personal Data, or, where it processes the data for its own client, a processor. We are its processor, or sub-processor. Annex 1 describes the processing. We process Customer Personal Data only to provide the Service to the Customer, on the Customer's documented instructions, which are the Terms of Service, this DPA, and the Customer's and its Authorised Users' use of the Service's features. The Customer may give further written instructions; if one goes beyond what the Service does, we may charge for it or decline. We will tell the Customer if we believe an instruction infringes Data Protection Laws. We process personal data about account holders and Authorised Users for our own purposes as a controller, as our Privacy Policy describes; this DPA does not apply to that processing.
3. The Customer's responsibilities
The Customer is responsible for having a lawful basis to put Customer Personal Data into the Service and to share it with its Authorised Users, for giving the notices and obtaining the consents the law requires, for the accuracy of the data, for minimising what it uploads, and for complying with the Acceptable Use Policy, which restricts the categories of data that may be uploaded.
4. Confidentiality of personnel
We ensure that the people who process Customer Personal Data on our behalf are bound by a duty of confidentiality. The Service is administered by its operator, who is bound by the confidentiality duties in the Terms of Service. Any person we engage in future will be bound in writing before they are given access.
5. Security
We implement the technical and organisational measures in Annex 2, taking into account the state of the art, the costs, the nature, scope and purposes of the processing and the risks to data subjects. We will not materially reduce those measures during a term the Customer has paid for. The Customer is responsible for the security of its own devices, networks and accounts and for the use of the Service's access controls.
6. Sub-processors
The Customer authorises us to engage the sub-processors on our sub-processors page. We will give at least 30 days' notice before a new or replacement sub-processor starts to process Customer Personal Data, by email to the Customer's account administrators and by updating that page. The Customer may object on reasonable data-protection grounds by writing to us within that period. We will then work with the Customer in good faith to find a solution. If we cannot, the Customer may end the affected Room's subscription and receive a pro-rata refund of the prepaid fees for its unexpired term. We impose on each sub-processor data-protection duties that are no less protective in substance than these, and we remain responsible to the Customer for each sub-processor's performance.
7. Assistance
Taking into account the nature of the processing, we will reasonably help the Customer to respond to requests from data subjects, and to meet its obligations on security, breach notification, data-protection impact assessments and prior consultation. If a data subject asks us directly about Customer Personal Data, we will refer them to the Customer and will not respond on the substance, unless the law requires us to. Help that goes beyond what the Service does as standard may be charged at our reasonable cost, which we will tell the Customer in advance.
8. Personal data breaches
If we confirm a personal data breach affecting Customer Personal Data, we will notify the Customer without undue delay and in any event within 72 hours after we confirm it, and will give the information we then have: the nature of the breach, the categories and approximate number of data subjects and records, the likely consequences, and the measures taken or proposed. We will give further information as we learn it. Our notice is not an admission of fault. The Customer decides whether and how to notify authorities and individuals, including under the notification laws of the United States (some of which, such as Ohio's, give the affected person notice within 45 days of discovery), of India and of other countries, and we will co-operate.
9. Return and deletion
On the Customer's instruction, and in any event at the end of the Customer's subscription, we return or delete Customer Personal Data as our Data Return, Retention, Deletion and Legal Hold Policy sets out, and on request we confirm in writing that we have done so. We may keep what the law requires us to keep and the evidentiary records that policy describes, on which the personal identifiers can be made permanently unreadable, and we keep the Customer Personal Data they contain confidential and protected under this DPA for as long as we keep it. We will not delete data that a legal hold covers.
10. Audits and information
On reasonable request, no more than once a year, we will give the Customer the information needed to show that we comply with this DPA, including a completed security questionnaire. We do not currently hold a third-party audit report such as a SOC 2 or ISO 27001 report, and we will say so in our answers. An on-site audit is not included, but we will allow one if a competent regulator requires it, on reasonable notice, during business hours, subject to confidentiality, at the Customer's cost, and without access to other customers' data.
11. International transfers
Customer Personal Data is stored mainly in the United States and is accessed from India by the person who administers the Service. Where the Customer is established in the European Economic Area, the United Kingdom or Switzerland, or the processing is otherwise subject to the GDPR, the UK GDPR or the FADP, the transfer to us in India is a Restricted Transfer, and the following apply.
EU SCCs. The SCCs are incorporated into this DPA, with the Customer as "data exporter" and us as "data importer". Module Two (controller to processor) applies where the Customer is a controller; Module Three (processor to processor) applies where the Customer is a processor for its own client. The options are: Clause 7 (docking clause) applies; Clause 9(a), option 2 (general written authorisation), with the notice period in section 6; the optional wording in Clause 11(a) does not apply; Clause 13: the competent supervisory authority is the one in Annex 1; Clause 17, option 1: the law of Ireland; Clause 18(b): the courts of Ireland. Annex 1 and Annex 2, with the sub-processors page, are Annexes I, II and III of the SCCs.
UK Addendum. For a Restricted Transfer under the UK GDPR, the UK Addendum is incorporated: the parties and the details are those in this DPA and Annex 1; the Addendum is attached to the SCCs as incorporated above; and in Table 4, the importer may end the Addendum as the Addendum allows.
Switzerland. For a Restricted Transfer under the FADP, the SCCs apply with these changes: references to the GDPR mean the FADP; the competent supervisory authority is the Federal Data Protection and Information Commissioner; the courts of Switzerland may be used by data subjects who habitually reside there; and "Member State" is not to be read to stop data subjects in Switzerland from enforcing their rights.
Other transfers. Where we send Customer Personal Data to a sub-processor outside India, we do so under a transfer mechanism that Data Protection Laws accept, such as the EU-US Data Privacy Framework where the sub-processor is certified, or standard contractual clauses. If a transfer stops needing a mechanism, for example because of an adequacy decision, the clauses stop applying to it.
Government access. If we receive a request from an authority for Customer Personal Data, we will handle it as our legal-requests policy and the Terms of Service describe: we will review its validity, redirect the authority to the Customer where lawful, tell the Customer before disclosing unless the law forbids it, challenge a request we reasonably believe is overbroad, and disclose only what is required. We do not claim that we cannot access stored content: the Service's operator can technically do so, and does so only for the purposes in section 7 of the Terms of Service. On request we will give the Customer the information it reasonably needs for its own assessment of the transfer, including our understanding of the laws of India and of the United States on government access.
12. US state privacy laws
To the extent that US state privacy laws apply, we act as the Customer's service provider or processor and we: process Customer Personal Data only for the business purposes in the Terms of Service and this DPA; do not sell or share it as those laws define those words; do not retain, use or disclose it outside our direct business relationship with the Customer or for any purpose other than those business purposes; do not combine it with personal data from other sources except as the law allows; comply with those laws and give the level of privacy protection they require; tell the Customer if we can no longer meet our obligations; allow the Customer to take reasonable steps to stop and remedy unauthorised use; and confirm that we understand these restrictions.
13. India
To the extent that the DPDP Act applies to our processing for the Customer, we process Customer Personal Data only on the Customer's instructions, maintain reasonable security safeguards, tell the Customer of a breach as section 8 provides, erase or return the data as section 9 provides, and co-operate with the Data Protection Board of India.
14. Covered persons
We are an individual resident in India and are not owned or controlled by a "covered person" or a "country of concern" as defined in 28 C.F.R. Part 202. We will not give any covered person, or any person located in a country of concern, access to Customer Personal Data, and we require the same of our sub-processors.
15. Liability
Each party's liability under this DPA is subject to the limits and exclusions in the Terms of Service, except that nothing in this DPA limits liability to data subjects that the SCCs or the law do not allow to be limited.
16. Term and order of precedence
This DPA lasts as long as we process Customer Personal Data, and the sections that need to survive do so. If there is a conflict, the SCCs and the UK Addendum prevail over this DPA, and this DPA prevails over the Terms of Service, in each case about the processing of Customer Personal Data.
Annex 1: Description of the processing
- Data exporter (Customer): the organisation named on the Customer's invoice or Order Form, and its contact for data protection is the account administrator it registered with us.
- Data importer (Processor): Aniket Raj, trading as MandateRoom, Delhi NCR, India. Contact: hello@mandateroom.com.
- Subject matter and nature: hosting, storing, rendering, securing and delivering the documents and content that the Customer and its Authorised Users upload to a Room, and recording activity in it.
- Purpose: providing the Service as the Terms of Service describe.
- Duration: the Customer's subscription, plus the period in the Data Return, Retention, Deletion and Legal Hold Policy.
- Frequency of transfer: continuous, while the Room is in use.
- Categories of data subjects: the Customer's and the target business's directors, officers, shareholders, employees and contractors, customers, suppliers and advisers, and the Authorised Users.
- Categories of personal data: whatever the Customer chooses to upload. Typically identity and contact details, employment and remuneration records, financial and commercial records, and correspondence. The Acceptable Use Policy restricts sensitive categories, such as health data, and the Customer must not upload them without our prior written agreement.
- Retention: as the Data Return, Retention, Deletion and Legal Hold Policy sets out.
- Sub-processors: the list on our sub-processors page.
- Competent supervisory authority (SCC Clause 13): the authority of the Member State where the Customer, or its representative in the European Union, is established, or, if there is none, the authority of the Member State where most of the affected data subjects are located.
Annex 2: Technical and organisational measures
These are the measures in place when this DPA takes effect. Our Terms of Service state what we do not have, and that statement applies to this Annex.
- Access control and tenant isolation. Access is enforced by the database for each Room and not only by application code. Each access decision resolves to a named reason, and access can be withdrawn at once. Permissions can be set by folder and by document and by disclosure stage.
- Authentication. Second factors are an authenticator app or a passkey; we do not offer SMS codes. Sessions end after a period of inactivity. A Room can restrict access by IP address.
- Dual control. Turning off watermarking, turning off multi-factor authentication or clearing an IP allow-list needs a second administrator's approval.
- Encryption. TLS protects data in transit. Data at rest is encrypted as provided by our storage and database providers.
- Logging and evidence. Security-relevant actions are recorded in an append-only, hash-chained audit ledger that is sealed daily.
- Watermarking. Every download, and every view beyond the first (teaser) disclosure stage, is watermarked to the individual viewer.
- Data minimisation and erasure. Personal identifiers in evidentiary records can be made permanently unreadable by destroying an encryption key, as the retention policy describes.
- Testing. Access controls are tested with automated suites, including tests that one Room's users cannot reach another's data.
- Separation of duties for staff. The platform's staff roles cannot read customer documents through the Service. The operator can technically access stored data and does so only for the purposes in the Terms of Service.
- Incident handling. We investigate suspected incidents, contain them, notify as section 8 provides and record the incident.