Skip to content

Data processing addendum

When we build or run software for you, we may handle personal data that belongs to you: your customers, your staff, your users. This addendum sets out how we treat it. It forms part of our agreement with you whenever we process personal data on your behalf, and where your signed agreement says something different, the signed agreement wins. Effective October 4, 2026.

Who is who

You are the controller of the personal data in your systems: you decide why and how it is used. iTechnoSol Inc. ("iTechnoSol", "we") is your processor: we handle that data only to deliver the work you engaged us for. The terms here follow article 28 of the GDPR and the UK GDPR, and we apply them to clients everywhere, including under India’s Digital Personal Data Protection Act, 2023.

What we process, and why

We process personal data only as needed to build, test, migrate, support and maintain the software in our agreement. The statement of work describes the systems, the kinds of data (for example names, contact details and account data of your users) and the people it concerns. We keep the data for as long as the work lasts, unless the agreement says otherwise.

Only on your instructions

We act only on your documented instructions, which are the agreement, the statement of work and what you ask of us in writing during the project. We do not use your data for any purpose of our own, never sell it, and never use it to train AI models. If we believe an instruction breaks data protection law, we tell you.

Our people

Only the people working on your project can reach your data, under the confidentiality terms of the NDA we sign with you before any work starts, and their access ends when they leave the project.

Security

We protect your data with measures suited to the risk, as described on our Security page. In short:

  • We work inside your access policies (single sign-on, VPN) with only the access each person needs, and every action is logged and documented for your IT and compliance teams.
  • Where your policy requires it, data stays in your own cloud account.
  • AI services we use on your project are business-grade, with model training switched off; regulated work can run on open models inside your infrastructure.
  • Code is reviewed before it ships.

Subprocessors

We do not hand your personal data to another company to process unless you agree in advance. Where a project relies on a service (for example a cloud host or an email provider), we name it in the statement of work, prefer accounts you own, and bind any subprocessor we engage to terms that protect the data at least as well as these. We stay responsible to you for their work.

International transfers

Our team works from India. Where GDPR or UK GDPR data is reached from India, or moved to any other country without an adequacy decision, we rely on the European Commission’s standard contractual clauses (with the UK addendum where UK data is involved), which we will sign with you on request.

Helping you meet your duties

We help you answer requests from the people whose data it is (to see, correct, delete or move their data), carry out data protection impact assessments, and consult regulators, to the extent our work makes that possible. Requests that reach us directly are passed to you, not answered by us.

Incidents

If we become aware of a breach affecting your personal data, we tell you without undue delay, with what we know about what happened, the data and people involved, and what we are doing about it, and we keep you updated so you can meet your own deadlines to tell regulators and the people affected.

At the end of the work

When the work ends, we return your personal data or delete it, as you choose, and delete any copies we hold, unless a law requires us to keep them. On request, we confirm the deletion in writing.

Records and audits

We make available the information you need to show these terms are kept, and allow audits by you or an auditor you appoint, on reasonable notice, during business hours and under a duty of confidentiality.

Liability and order of terms

Each party’s liability under this addendum is governed by the limits in our main agreement. If this addendum conflicts with the standard contractual clauses, the clauses win; if it conflicts with the rest of our agreement on data protection, this addendum wins, unless the signed agreement says otherwise.

Signing and contact

To sign a copy of this addendum, or your own data processing agreement, with your contract, email info@itechnosol.com. We reply within 4 business hours.