Skip to content
Connect by Vinpro

Legal

Data Processing Agreement (DPA)

Last updated: 5 June 2026

Working draft — pending legal review. This page provides structure only and is not yet a binding agreement or final policy. Vinpro Global Services Pvt Ltd is having it reviewed by counsel; do not rely on it until it is finalised.

This DPA forms part of the agreement between Vinpro Global Services Pvt Ltd(“Processor”) and the customer (“Controller”) and governs personal data we process on the customer's behalf when delivering EOR, HRMS, payroll and staffing services. It is intended to support DPDP, GDPR and equivalent obligations.

1. Roles & scope

The customer is the controller (or, for its own customers, processor); Vinpro Global Services Pvt Ltd is the processor (or sub-processor). We process personal data only on documented instructions.

2. Nature & purpose of processing

[To complete with counsel] Describe the processing operations, duration, and the purpose (payroll, HR, EOR administration).

3. Categories of data & data subjects

[To complete with counsel] List data categories (identity, contact, payroll/financial, statutory IDs) and data subjects (the customer's employees/contractors).

4. Confidentiality & security

Personnel are bound by confidentiality. We maintain the technical and organisational measures described on our Security page.

5. Sub-processors

The customer authorises the sub-processors listed on our Sub-processors page; we will give notice of changes and remain responsible for their performance.

6. International transfers

[To complete with counsel] Specify transfer safeguards (Standard Contractual Clauses, etc.) for cross-border processing between India, the US and elsewhere.

7. Data subject requests & breach notification

We assist the controller with data-subject requests and will notify the controller without undue delay after becoming aware of a personal-data breach.

[To complete with counsel] Set notification timelines and the assistance scope.

8. Audits

[To complete with counsel] Describe audit rights and how third-party certifications (SOC 2 / ISO 27001, once obtained) satisfy them.

9. Return & deletion

On termination, we return or delete personal data per the controller's instructions, subject to legal retention requirements.

10. Annexes

[To complete with counsel] Attach Annex I (processing details), Annex II (technical & organisational measures) and Annex III (sub-processors).

Contact

To request a signed DPA, email info@vinproconnect.com.