Data Processing Agreement (DPA)
Version 1.0 · Effective 29 June 2026. This DPA forms part of the agreement between you (“Controller”) and AVI Verifide India Private Limited (“Processor”, “MIKA”) and governs MIKA’s processing of personal data on your behalf — chiefly the leads and end-user data you collect through MIKA. It does not apply to data for which MIKA is the controller (your account data); that’s covered by our Privacy Policy.
1. Scope & roles
You are the Controller and MIKA is the Processor for the personal data you submit or collect through the Service. MIKA processes it only on your documented instructions (including via your use of the Service), unless law requires otherwise.
2. Subject matter, duration, nature & purpose
Subject matter & duration: processing for the term of your use of MIKA. Nature & purpose: hosting your site, capturing and storing leads, generating content you request, and the related features you enable.
3. Categories of data & data subjects
- Data subjects — your leads, site visitors, and contacts.
- Categories — name, email, phone, message content, and other details those individuals submit; usage/technical data.
- Special-category data — not requested by MIKA; you should not submit it unless you have a lawful basis and have configured the relevant safeguards.
4. Processor obligations
- Process personal data only on your instructions and for the purposes above.
- Ensure personnel are bound by confidentiality.
- Implement appropriate technical and organizational security measures (see Privacy Policy §14 — tenant isolation, encryption at rest for connected-account tokens, minimization, no PII in logs/AI prompts).
5. Subprocessors
You authorize MIKA to engage the subprocessors listed on our subprocessors page, under terms protecting the data to the standard of this DPA. We give notice before adding a subprocessor, and you may object on reasonable data-protection grounds.
6. Assistance with data-subject requests
MIKA provides tools and reasonable assistance to help you respond to data-subject requests (access, deletion, correction, export) and to your data-protection obligations (impact assessments, consultations), taking into account the nature of processing.
7. Personal-data breach notification
MIKA will notify you without undue delay (and within 72 hours where required) after becoming aware of a personal-data breach affecting your data, with the information you reasonably need to meet your own notification duties.
8. Deletion or return on termination
On termination, and on your request, MIKA deletes or returns the personal data it processes for you, except where law requires retention. Deleting a project hard-deletes its leads, brand voice, audits, imports, and connected-account tokens.
9. Audits & information
MIKA makes available the information reasonably necessary to demonstrate compliance with this DPA and allows for and contributes to audits — on reasonable prior written notice, no more than once a year (unless a regulator requires it or following a breach), during business hours, subject to confidentiality, and at the requesting party’s cost.
10. International transfers
Your data is primarily processed in India (Mumbai); some subprocessors process data in the United States. Where MIKA transfers your data across borders on your behalf, it does so under contractual data-protection terms, and under Standard Contractual Clauses where EU/UK personal data is involved.
11. Liability & order of precedence
In case of conflict between this DPA and the Terms of Service on the processing of personal data, this DPA controls. Liability is subject to the limitations in the Terms. Where the EU/UK GDPR applies, the EU Standard Contractual Clauses (controller-to-processor module) and, for the UK, the UK International Data Transfer Addendum, are incorporated by reference and prevail over conflicting terms.