Data processing addendum
How we handle the personal data in your records, as your processor.
This addendum (“DPA”) forms part of our terms of service between you, the customer (“you”), and Amit Singh Rawat, trading as The Openn Group (“we”). It applies whenever we process personal data contained in the records you keep in Openn Invoice (“customer personal data”). It is accepted with the terms, so you do not need to sign anything. If you need a countersigned copy, write to hello@theopenngroup.com.
Words such as controller, processor, personal data breach and supervisory authority have the meaning given in the EU General Data Protection Regulation (GDPR).
1. Roles
For customer personal data, you are the controller and we are your processor. Under India’s Digital Personal Data Protection Act, 2023, you are the Data Fiduciary and we are your Data Processor. If you are yourself a processor for someone else, we are your sub-processor, and you confirm that your controller has authorised this DPA.
For your own account and billing data, we are the controller, as our privacy policy explains. This DPA does not cover that data.
2. Your instructions
We process customer personal data only on your documented instructions. Those instructions are these terms, this DPA and what you do in the app. We do not process it for any other purpose, and never sell it or use it for our own marketing. If the law requires us to process it otherwise, we tell you first unless the law forbids that. If we believe an instruction breaks data protection law, we tell you.
3. Confidentiality
Only people who need access to run or support the service can reach customer personal data, and each is bound to keep it confidential. Today that is Amit Singh Rawat alone.
4. Security
We apply the technical and organisational measures in Annex II, and keep them at least as strong as they are today.
5. Sub-processors
- You authorise us to use the sub-processors listed on our sub-processors page.
- We give the owner of every account at least 15 days’ notice by email before adding or replacing a sub-processor that will process customer personal data.
- You may object on reasonable data protection grounds by writing to hello@theopenngroup.com within that period. We will try to find a solution. If we cannot, you may end your subscription before the change applies, and we refund the unused part of the period you paid for.
- Each sub-processor is bound by written terms that protect the data at least as well as this DPA. We remain responsible to you for their work.
6. Helping with people’s requests
The app lets you find, correct, export and delete customer personal data yourself. If someone contacts us about data in your records, we pass the request to you and do not answer it ourselves unless you ask us to. We give you any further reasonable help you need to answer it.
7. Helping with your obligations
We give you the information reasonably available to us to help with data protection impact assessments, consultations with a supervisory authority, and your own security obligations.
8. Personal data breaches
We tell you without undue delay, and in any case within 48 hours of becoming aware, of a personal data breach affecting customer personal data. We tell you what happened, the kinds and approximate number of people and records affected, the likely consequences, what we have done or will do about it, and who to contact. If we do not know everything at once, we tell you in stages. We help you meet your own duty to notify an authority or the people affected.
9. Deletion and return
You can export customer personal data as CSV at any time, including after your plan ends. When you delete your account, we delete customer personal data from the live service at once and from our backups within 30 days, unless the law requires us to keep it. On request, we confirm the deletion in writing.
10. Audits
We make available the information needed to show that we meet this DPA. We answer a reasonable written security questionnaire once a year, or more often after a breach or when an authority asks. If that is not enough, you or an independent auditor bound by confidentiality may inspect our processing on site, with at least 30 days’ notice, during business hours, at your cost, and no more than once a year unless a breach or an authority requires it.
11. International transfers
EU and EEA. Where customer personal data is transferred from the EEA to us in India, or onward to a country without an adequacy decision, the Standard Contractual Clauses adopted by the European Commission in Decision (EU) 2021/914 apply and are incorporated into this DPA by reference: Module 2 (controller to processor) where you are a controller, and Module 3 (processor to processor) where you are a processor. You are the data exporter and we are the data importer. Clause 7 (docking) applies. Under Clause 9, option 2 (general written authorisation) applies with the notice period in section 5. The optional wording in Clause 11 does not apply. Under Clause 13, the competent supervisory authority is the one that is competent for you. Under Clauses 17 and 18, the clauses are governed by the law of Ireland and disputes go to the courts of Ireland. Annexes I and II of this DPA complete the clauses’ annexes, and our sub-processors page completes Annex III.
United Kingdom. For transfers from the UK, the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the Information Commissioner (version B1.0) applies and is incorporated by reference. Its tables are filled in with the parties and details in Annex I, the clauses selected above, and Annex II. Either party may end it as its section 19 allows.
Switzerland. For transfers from Switzerland, the same clauses apply with these changes: the Federal Data Protection and Information Commissioner is the competent authority, references to the GDPR include the Swiss Federal Act on Data Protection, and people in Switzerland may bring claims where they usually live.
If there is a conflict between these clauses and the rest of this DPA or our terms, the clauses prevail.
12. India
This DPA is the contract under section 8(2) of the Digital Personal Data Protection Act, 2023 by which you engage us as your Data Processor. You remain responsible for giving notice, having a lawful ground, and handling the rights of the people in your records. We process customer personal data only on your behalf, protect it with reasonable security safeguards, tell you of a breach as set out in section 8 so you can inform the Data Protection Board of India and the people affected, and erase it as set out in section 9.
13. United States
Where US state privacy laws apply, such as the California Consumer Privacy Act, we act as your service provider or processor. We do not sell or share customer personal data, do not keep, use or disclose it outside our direct business relationship with you or for any purpose other than providing the service, and do not combine it with data from other sources except as those laws allow. We tell you if we can no longer meet these duties.
14. Order and liability
For data protection matters, this DPA prevails over the rest of our terms. The limits of liability in our terms apply to this DPA as far as the law allows. They do not limit the rights of people under the Standard Contractual Clauses.
Annex I: details of the processing
- Data exporter (controller)
- You, the customer that holds the Openn Invoice account, as named in your account’s business details. Contact: the account owner’s email.
- Data importer (processor)
- Amit Singh Rawat, sole proprietor trading as The Openn Group, B-2908, Nikoo Homes 4, Bhartiya City, Thanisandra, Bengaluru 560064, Karnataka, India. Contact: Amit Singh Rawat, hello@theopenngroup.com.
- People whose data is processed
- Your customers and their contact people, your suppliers or payers named in bank statements, and the members of your team.
- Kinds of personal data
- Names, business names, email addresses, phone numbers, postal addresses, tax registration numbers, bank or UPI details printed on documents, invoice, quotation, credit note and payment details, payment proof files, and bank statement lines.
- Sensitive data
- None is intended. Do not upload health, biometric or other special category data.
- How often
- Continuously, for as long as you use the service.
- Nature and purpose
- Storing, organising, displaying and backing up your records, producing documents and reports, sharing documents through the links you create, and sending account emails, only to provide the service to you.
- How long
- For as long as your account exists, then deleted as set out in section 9.
Sub-processors and the countries where they process data are listed on our sub-processors page. The competent supervisory authority is the one that is competent for you.
Annex II: security measures
- All connections use HTTPS, with HTTP Strict Transport Security.
- Passwords are hashed with scrypt and a unique salt. Two-step sign-in with an emailed code is available.
- Sessions use secure, http-only cookies; only a hash of each session token is stored.
- Every database query is scoped to the business it belongs to, so one business cannot read another’s records.
- Sign-in, code and other sensitive actions are rate limited.
- Payment proof files are stored outside the public web folder and shown only to signed-in members of the business.
- Shared document links use long random tokens and are hidden from search engines.
- The database and uploaded files are backed up every night, and backups are kept for 30 days.
- Only Amit Singh Rawat can reach the production servers and database. Sensitive account changes are written to an audit log.
Our security page describes these measures in more detail.