How we process your end customers' personal data on your behalf, and who else touches it.
This Data Processing Agreement ("DPA") forms part of the Terms of Service between smritix AI LLP("Processor", "we") and the customer entity operating a LeapCrew AI workspace ("Controller", "you") wherever you process personal data of your own end customers (e.g. WhatsApp contacts, order and appointment records) through the platform.
It reflects Indian data protection law, including the Digital Personal Data Protection Act, 2023, and is written to be recognisable against internationally common DPA structures (GDPR Art. 28-style) for customers who need one for their own compliance file.
For data you upload or generate through your workspace about your own end customers, you are the Controller and smritix AI LLP is the Processor, acting only on your documented instructions as expressed through your use of the platform's features.
For account and billing data about you and your team (workspace admin details, invoices), smritix AI LLP is the Controller — this is covered by our Privacy Policy, not this DPA.
We process end-customer data solely to provide the platform's core functions: WhatsApp/Voice/SMS message delivery, shared team inbox, chatbot and automation execution, campaign broadcasting, order and appointment record-keeping, and analytics reporting shown inside your own workspace.
Categories typically include: contact identifiers (name, phone number), conversation content and message metadata, order/booking references, and any custom fields you configure. We do not sell this data, and do not use it to train models for any customer other than you.
Processing continues for the life of your subscription. On cancellation, data is retained in a read-only state so you can export it, then deleted per the retention schedule in our Privacy Policy, unless a longer period is required by law (e.g. financial records).
We use the following sub-processors to operate the platform. Each is bound by its own data protection terms with us, and only receives the minimum data needed for its function.
| Sub-processor | Purpose | Location |
|---|---|---|
| Meta Platforms, Inc. | WhatsApp Business Cloud API — message delivery | USA / Global |
| Railway Corp. | PostgreSQL database hosting & application infrastructure | USA |
| Razorpay Software Pvt. Ltd. | Subscription payment processing | India |
| Uploadthing, Inc. | Customer-uploaded file & media storage | USA |
| Cloudflare, Inc. | Bot protection (Turnstile) & network security | USA / Global |
| Google LLC | Font delivery, and Analytics (only if you opt in — see Cookie Policy) | USA / Global |
We'll update this list and notify workspace admins by email before adding a new sub-processor that materially changes how your data is handled.
Consistent with our published Securitypractices: AES-256-GCM encryption for secrets and sensitive fields at rest, TLS 1.2+ enforced on all connections, HMAC-SHA256 signed webhooks, bcrypt-hashed API keys, and logical multi-tenant isolation at the database layer so no workspace can query another's data.
Our primary database is hosted with Railway in the USA; the Meta WhatsApp Cloud API, Cloudflare, and Uploadthing likewise operate global/US infrastructure. Where personal data of Indian data principals is transferred outside India, we rely on contractual safeguards with each sub-processor consistent with applicable Indian data protection requirements.
We'll assist you in responding to your end customers' access, correction, or deletion requests concerning data held in your workspace, and in notifying you promptly of any confirmed security incident affecting your data so you can meet your own notification obligations.
This page is our standard DPA and applies automatically to every workspace. If your organisation requires a countersigned PDF for its own vendor-compliance records, email hello@leapcrew.inwith your workspace name and we'll send one for signature.