Skip to main content
Data Processing Agreement

Data protection commitments for our customers.

This DPA describes how Lenvy Technologies processes personal data on behalf of customers when providing its services, and the safeguards we apply.

Last updated 7/21/2026
01

Purpose and scope

This Data Processing Agreement ("DPA") forms part of the agreement between the customer ("Controller") and Lenvy Technologies ("Processor") whenever Lenvy Technologies processes personal data on the customer's behalf in the course of providing services. It applies in addition to our Terms & Conditions and Privacy Policy.

02

Roles of the parties

The customer is the data controller for personal data submitted to the services. Lenvy Technologies acts as the data processor and processes personal data only on documented instructions from the controller, as reflected in the underlying service agreement, SOW, or written request.

03

Details of processing

  • Subject matter: Provision of the agreed services.
  • Duration: For the term of the service agreement and any wind-down period.
  • Nature and purpose: Hosting, storage, processing, and operational support required to deliver the service.
  • Types of personal data: As determined by the controller (may include names, contact details, account credentials, usage data).
  • Data subjects: The controller's end users, employees, and contacts, as applicable.
04

Processor obligations

  • Process personal data only on the controller's documented instructions.
  • Ensure personnel authorized to process personal data are bound by confidentiality.
  • Implement appropriate technical and organizational measures to protect personal data.
  • Assist the controller in responding to data subject requests and regulatory obligations.
  • Notify the controller without undue delay after becoming aware of a personal data breach.
05

Security measures

We use encryption in transit, encryption at rest for supported stores, role-based access controls, least-privilege principles, audit logging, and continuous monitoring on our hosting infrastructure. Specific measures are aligned with industry best practice and are reviewed periodically.

06

Sub-processors

We use trusted sub-processors to deliver our services. The current list typically includes infrastructure, database, email, and analytics providers.

An up-to-date list is available on request from help@lenvytechnologies.in. We notify the controller of material changes and allow reasonable objection.

07

International transfers

Where personal data is transferred outside of the controller's jurisdiction, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or an equivalent recognised transfer mechanism.

08

Return and deletion of data

On termination or expiry of the services, and at the controller's choice, Lenvy Technologies will return or delete personal data within a reasonable period, unless retention is required by applicable law.

09

Requesting a signed DPA

To execute a signed copy of this DPA, email help@lenvytechnologies.in from your organization's domain with your company name, registered address, and the services covered. We typically return a countersigned copy within 3 business days.

Still need clarity?

We're happy to walk you through any part of this policy.

Contact us