Skip to content

Data Processing Addendum

How we process your customers’ personal data, in writing

Last updated: 19 July 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between Sumvaik Management Consulting Private Limited (“Sumvaik”, operator of Shally) and the customer accepting the Terms of Service (“Customer”). This DPA applies to all customers; for a countersigned execution copy, contact hello@shally.io.

1. Roles of the Parties

For personal data that the Customer and its users upload into Shally about their own leads, clients, contacts, creators, team members and projects (“Customer Content”), the Customer is the controller (Data Fiduciary under India’s DPDP Act) and Sumvaik is the processor, acting only on the Customer’s documented instructions. This mirrors Section 2 of our Privacy Policy. For data about the Customer itself (account, billing, usage), Sumvaik is the controller / Data Fiduciary and this DPA does not apply.

2. Processing Instructions

Sumvaik will process Customer Content only (a) to provide, secure and support the service, (b) as configured by the Customer through the platform, and (c) as otherwise instructed in writing by the Customer, unless processing is required by applicable law — in which case Sumvaik will inform the Customer before processing, unless the law prohibits it. Sumvaik will inform the Customer if, in its opinion, an instruction infringes applicable data protection law.

3. Confidentiality

Sumvaik ensures that persons authorised to process Customer Content are bound by contractual or statutory confidentiality obligations, and access Customer Content only to the extent needed to provide and support the service.

4. Security Measures

Sumvaik implements appropriate technical and organisational measures, including encryption in transit (TLS) and at rest, logical workspace/tenant isolation, role-based access control, audit logging of sensitive actions, backups, and defined incident-response processes. The current measures are described on our Security page. Formal third-party certifications (e.g. SOC 2, ISO 27001) are on our roadmap and are not yet certified; we do not represent otherwise.

5. Sub-Processors

The Customer provides general authorisation for Sumvaik to engage the sub-processors listed at /sub-processors, which is the canonical, current list. Sumvaik will update that page before a new sub-processor begins processing Customer Content. If the Customer reasonably objects to a new sub-processor on data-protection grounds and no resolution is found, the Customer may terminate the affected service and receive a pro-rata refund of prepaid fees for the unused period. Sumvaik remains responsible for its sub-processors’ performance under this DPA.

6. Assistance to the Customer

Taking into account the nature of the processing, Sumvaik will assist the Customer with reasonable technical and organisational measures to respond to data-subject / Data Principal requests (access, correction, erasure, portability, objection), and with the Customer’s obligations regarding security, breach notification and data protection impact assessments, insofar as the information is available to Sumvaik.

7. Personal Data Breach

Sumvaik will notify the Customer without undue delay, and in any event within 72 hours, of becoming aware of a personal data breach affecting Customer Content, and will provide information reasonably required for the Customer to meet its own notification obligations, including to supervisory authorities and, under the DPDP Act, to the Data Protection Board of India and affected Data Principals.

8. International Transfers

Customer Content is primarily hosted in India (AWS Mumbai, ap-south-1). Where processing by a sub-processor involves a transfer of personal data that is restricted under the GDPR, UK GDPR or other applicable law, the parties incorporate the European Commission’s Standard Contractual Clauses (Module 2: controller-to-processor, or Module 3: processor-to-processor, as applicable), or another valid transfer mechanism, into this DPA by reference. Transfer mechanisms per sub-processor are shown at /sub-processors.

9. India DPDP Act Provisions

Where the Customer is a Data Fiduciary under the Digital Personal Data Protection Act, 2023, Sumvaik acts as its Data Processor under a valid contract as required by the DPDP Act. Sumvaik will (a) process Customer Content only for the purposes of providing the service, (b) implement reasonable security safeguards to prevent personal data breach, (c) notify the Customer of any personal data breach as set out in Section 7, and (d) delete or return Customer Content as set out in Section 10. The Customer remains responsible for obtaining consents from, and providing notices to, its Data Principals.

10. Deletion and Return on Termination

During the term, the Customer can export Customer Content from the platform. On termination of the agreement, Sumvaik will, at the Customer’s choice, return and/or delete Customer Content. Customer Content and associated personal data are deleted or irreversibly anonymised within 90 days of account termination (typically sooner), except where retention is required by applicable law (e.g. financial records under Indian tax law), in which case the data remains protected under this DPA until deleted.

11. Audit and Information

Sumvaik will make available information reasonably necessary to demonstrate compliance with this DPA, and will respond to reasonable written security questionnaires from the Customer no more than once per year, unless a personal data breach has occurred.

12. Liability and Order of Precedence

Liability under this DPA is subject to the limitations of liability in the Terms of Service. If there is a conflict between this DPA and the Terms of Service regarding the processing of Customer Content, this DPA prevails to the extent of the conflict.

13. Contact

Questions, execution copies and data-protection notices: hello@shally.io · Grievance Officer, Sumvaik Management Consulting Private Limited, C-41 Basement, Nangal Dewat, Vasant Kunj, New Delhi 110070, India.

This page is provided for transparency and convenience and is not legal advice for the Customer’s own compliance obligations.