This Data Processing Agreement ("DPA") supplements the Terms of Service between Azisly ("Processor") and the subscribing institution ("Customer", acting as Data Fiduciary / Controller). It sets out the terms on which Azisly processes personal data on Customer's behalf when providing the AzislyLab platform ("Service").
Where terms defined in the Digital Personal Data Protection Act, 2023 (India) ("DPDP Act") — including "Data Fiduciary", "Data Processor", "Personal Data", "Data Principal", and "Personal Data Breach" — are used in this DPA, they have the meanings given in that Act.
1. Roles
For personal data uploaded by Customer to the Service (including student rosters, notice recipients, and delivery records) Customer is the Data Fiduciary and Azisly is a Data Processor. Azisly will process such personal data solely on documented instructions from Customer, for the purposes of providing the Service in accordance with the Terms, and for no purpose unrelated to the services agreed with Customer. Azisly will not use such personal data for marketing or advertising of any kind, and will not process it for any purpose of its own.
2. Subject-matter and duration
- Subject-matter: provision of the AzislyLab Service.
- Duration: the subscription term plus the retention period set out below.
- Nature and purpose: storage, transmission, and processing of institutional data required to operate T&P workflows.
3. Categories of Data Principals and personal data
| Data Principal | Categories of personal data |
|---|---|
| Students | Name, email, roll number, department, batch, notice-delivery status; and an engagement score derived from the student's use of AzislyLab's affiliated career-coaching apps (MockMate AI, ResumeArchitect, DomainPrep, InterviewPrep), where the student has separately consented to that use with the relevant app. AzislyLab has no student account, login, or direct interaction with students — interview, CV, and video/audio data are held by the relevant coaching app, not by AzislyLab. |
| College administrators and department administrators | Name, email, role, authentication metadata, action logs. |
4. Processor obligations
Azisly will:
- process personal data only on Customer's documented instructions;
- ensure personnel authorised to process personal data are bound by confidentiality;
- maintain the technical and organisational security measures described in Section 6;
- restrict its own internal access to personal data on a least-privilege, role-based basis, as further described in Section 6;
- assist Customer in responding to Data Principal requests, taking into account the nature of the processing;
- assist Customer in meeting its own obligations regarding security, breach notification, and data-protection impact assessments;
- at Customer's election, delete or return personal data at the end of the engagement (see Section 8).
5. Sub-processors
Customer authorises Azisly to engage sub-processors to help provide the Service. Azisly will impose data-protection obligations on each sub-processor that are substantially similar to those in this DPA. Current sub-processors:
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database, object storage | Mumbai (ap-south-1), India |
| Amazon Simple Email Service (SES) | Transactional email delivery for notices | Mumbai (ap-south-1), India |
Azisly will notify Customer of any intended additions or replacements at least thirty (30) days in advance. Customer may object on reasonable data-protection grounds; if the parties cannot agree on a resolution, Customer may terminate the affected part of the Service without penalty.
6. Security measures
Azisly maintains the following measures:
- encryption in transit using TLS 1.2 or higher;
- encryption at rest for the primary database and object storage;
- tenant-level data isolation via a schema-per-institution architecture;
- bcrypt-hashed passwords and short-lived signed session tokens (JWT with refresh);
- role-based access control (superadmin / college_admin / dept_admin / tp_admin) enforced server-side;
- role-based, least-privilege access for Azisly personnel to Customer's personal data — including student roster data, notice-delivery records, and engagement scores — enforced through permission roles within Azisly's internal admin/ops systems, such that access is limited to the specific personnel and roles whose function requires it, with access reviewed at least annually;
- retention of system, processing, and security logs for a minimum of twelve (12) months, to support detection, investigation, and remediation of security incidents, as required under the DPDP Rules, 2025;
- automated daily database backups with periodic restore drills;
- application-level and infrastructure-level logging retained for incident investigation.
7. Personal Data Breach
Azisly will notify Customer without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Customer's personal data. The notification will include, to the extent then known: the nature of the breach, categories and approximate number of Data Principals affected, likely consequences, and measures taken or proposed. Azisly will cooperate reasonably with Customer's own notification obligations to the Data Protection Board of India and to Data Principals.
8. Return and deletion
On termination of the Service, and at Customer's written election, Azisly will either return Customer's personal data in a commonly used format or delete it. Unless a different election is made, Customer's personal data will be available for export for thirty (30) days after termination and then deleted from active, customer-facing systems within a further thirty (30) days, in keeping with the DPDP Act's requirement to erase personal data once the purpose for which it was collected is no longer being served. Processing logs and related records associated with that data continue to be retained in accordance with the retention period set out in Section 6, and are deleted once that period expires. Backups containing Customer's personal data are cycled out on their normal rotation schedule and are protected by the security measures in Section 6 until they expire.
9. Audit
Azisly will make available information reasonably necessary to demonstrate compliance with this DPA. On written request no more than once per year (or following a Personal Data Breach), Customer may request additional information or, at Customer's cost, an audit by a mutually agreed independent auditor under confidentiality.
10. International transfers
Customer's personal data is stored in India by default. Where any cross-border transfer is required to provide the Service, Azisly will ensure an appropriate legal basis under the DPDP Act and any other applicable law, and will disclose the destination and safeguards to Customer.
11. Miscellaneous
In the event of a conflict between this DPA and the Terms of Service, this DPA prevails with respect to the processing of personal data. This DPA is governed by the laws of India.
12. Contact
For questions relating to this DPA, for privacy inquiries, or to submit a signed counterpart for a specific institution, please write to contact@azislylab.ai. Azisly's designated Grievance Officer under the DPDP Act is Priyank Jain, reachable at contact@azislylab.ai, and is listed on the AzislyLab website in accordance with applicable law.