Data Protection Agreement

This Data Protection Agreement ("Agreement") between Affinsys AI Pvt. Ltd. ("Affinsys") and the Customer (as defined in the Agreement) forms part of the Affinsys AI Pvt Ltd-. Terms of Service or such other written or electronic agreement incorporating this agreement, in each case governing Customer’s access to and use of the Services (the "Agreement"). This agreement was last updated in December, 2025.

1. Definitions

2. Subject Matter and Duration

The Processor will process Personal Data solely for providing services related to Affinsys AI solutions and associated support. The duration of processing shall align with the service contract between the parties.

3. Description of Processing Activities for Customer Personal Data

The following describes the specific processing activities performed by Affinsys AI Pvt. Ltd. (the Processor) when providing AI, automation, and conversational banking solutions to the Controller:

3.1 Collection

Affinsys processes customer personal data only when supplied by the Controller through:

3.2 Storage

Affinsys stores customer data only within secure, access-controlled environments, including:

3.3 Processing & Analysis

Affinsys processes customer data to deliver the following services:

Affinsys does not use customer personal data for model training unless explicitly authorised by the Controller.

3.4 Transmission & Sharing

Affinsys may transmit customer personal data:

3.5 Access

Affinsys personnel access customer data only for:

3.6 Retention

Affinsys retains customer personal data only for:

3.7 Deletion & Return

Upon termination or written instruction from the Controller:

3A. Nature and Purpose of Processing

The Processor may process Personal Data for the following purposes:

4. Types of Personal Data and Data Subjects

Personal Data categories may include:

Data subjects may include:

5. Obligations of the Processor

The Processor agrees to:

6. Security Measures

The Processor shall maintain measures including but not limited to:

7. Personal Data Breach

In the event of a Personal Data Breach, the Processor shall notify the Controller without undue delay, providing all necessary information for the Controller to meet its GDPR obligations.

8. Rights of Data Subjects

The Processor shall assist the Controller in responding to requests from data subjects, including:

9. Return or Deletion of Data

Upon termination of services, all Personal Data shall be deleted or returned to the Controller, unless legal obligations require retention.

10. Audit Rights

The Controller may conduct audits or inspections of the Processor’s facilities and processes with reasonable notice. The Processor will cooperate fully.

11. Indemnity

11.1 Indemnity by the Controller The Controller shall indemnify, defend, and hold harmless Affinsys AI Pvt. Ltd. ("Processor") from and against any claims, actions, liabilities, penalties, fines, losses, or expenses (including reasonable legal fees) arising out of or relating to: a) the Controller’s breach of its obligations under this DPA or under applicable data protection laws, including GDPR; b) the Controller’s instructions that result in unlawful processing of Personal Data; c) the Controller’s provision of inaccurate, unlawful, or non-compliant Personal Data; or d) any failure by the Controller to obtain necessary consents or authorisations from data subjects.

11.2. Indemnity by the Processor The Processor shall indemnify and hold harmless the Controller from and against claims, damages, or liabilities arising solely from the Processor’s failure to comply with its obligations under this DPA, including failure to implement appropriate technical and organisational security measures as required under GDPR Article 32.

11.3. Exclusions Neither party shall be liable to the extent that any claim arises due to the other party’s negligence, misconduct, or failure to comply with its own obligations under this DPA or applicable law.

11.4. Limitation of Liability Unless otherwise agreed in the main Service Agreement, the indemnity obligations under this clause shall be subject to the liability limitations defined in the governing Master Service Agreement between the parties.

12. Liability

Each party’s liability is subject to the limitations of the main service agreement unless otherwise required by law.

13. Governing Law

This Agreement shall be governed by and construed in accordance with the laws applicable to the main service agreement.

This Data Processing Agreement forms an integral part of all service agreements, order forms, and statements of work entered into with Affinsys AI Pvt. Ltd. By executing a service agreement or by using Affinsys services, the Controller agrees to be bound by the terms of this DPA.

For any questions regarding this DPA, please contact the DPO: hello@affinsys.com

Affinsys AI Pvt. Ltd, Bangalore, India