Data Processing Addendum
Who we are
Kartivo is operated by two affiliated entities. Which one you contract with, and which law applies, depends on the currency you are billed in.
|
Customers billed in INR Webliska Technologies (Proprietorship) GSTIN: 06ATYPG3011E1ZX SCF 65, Sector 9, 1st Floor, Near Axis Bank Faridabad, Haryana 121006, India Email: Contact@webliska.com |
Customers billed in USD Webliska Technologies, Inc. 130 Descanso Drive, UNIT 160 San Jose, CA 95134, United States Phone: +1 (669) 201-6082 Email: Contact@webliska.com |
Last updated: 8 August 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between you ("Controller") and the Kartivo entity that contracts with you ("Processor"). It applies where you use Kartivo to process personal data of your own customers or contacts.
1. Roles
For data about your customers that you put into or generate on the platform, you are the Controller and we are the Processor. For data about you as our own customer — your account, billing and support records — we are the Controller, and our Privacy Policy applies.
2. Scope and instructions
We process personal data only on your documented instructions, which are given by your configuration and use of the platform, and as required by applicable law. If we believe an instruction breaches data-protection law, we will tell you.
3. Details of processing
- Subject matter: provision of the Kartivo platform.
- Duration: for the term of your subscription, plus the deletion period in section 8.
- Nature and purpose: hosting, storage, transmission, checkout and payment orchestration, delivery of digital products and courses, communications, and reporting.
- Types of personal data: name, email address, phone number, billing address, tax identifiers, order and transaction records, IP address, device and usage data, and any other data you choose to collect.
- Categories of data subject: your customers, leads, members and other contacts.
4. Confidentiality
Personnel authorised to process personal data are bound by confidentiality obligations and are granted access on a least-privilege basis.
5. Security
We implement appropriate technical and organisational measures, including encryption in transit (TLS), hashed credential storage, access control and authentication, segregation of environments, logging and monitoring, and backup and recovery procedures.
6. Sub-processors
You give general authorisation for us to engage sub-processors. Current categories, and representative providers:
- Payment processing — PhonePe, PayU, Cashfree, Razorpay, Paytm, Stripe, PayPal.
- Cloud hosting and storage — infrastructure and object-storage providers.
- Content delivery and video — CDN and video streaming providers.
- Email and messaging delivery — transactional email and messaging providers.
- Analytics and error monitoring.
We impose data-protection obligations on each sub-processor no less protective than this DPA, and remain liable for their performance. We will give notice of an intended change of sub-processor, and you may object on reasonable data-protection grounds.
7. Assistance
Taking into account the nature of processing, we will provide reasonable assistance with data-subject requests, data-protection impact assessments and consultations with supervisory authorities. Where a data subject contacts us directly about your data, we will refer them to you.
8. Deletion and return
On termination, you may export your data for a reasonable period. After that we will delete or anonymise personal data processed on your behalf, except where retention is required by law. Backups are purged on their normal cycle.
9. Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf, with the information reasonably available to us to help you meet your own notification obligations.
10. Audits
On reasonable written notice, and no more than once in any twelve-month period unless required by a supervisory authority, we will make available information necessary to demonstrate compliance with this DPA and will contribute to audits conducted by you or an independent auditor, subject to confidentiality and to not compromising the security of other customers.
11. International transfers
We operate in India and the United States. Where personal data protected by the GDPR or UK GDPR is transferred outside its origin, the transfer is made under an appropriate safeguard, including the European Commission's Standard Contractual Clauses, which are incorporated into this DPA by reference where they apply.
12. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service.
13. Conflict
Where this DPA conflicts with the Terms of Service in respect of the processing of personal data, this DPA prevails.
Note. This DPA is a contractual document. If you require a signed DPA, a specific set of Standard Contractual Clauses, or terms tailored to your regulator, write to Contact@webliska.com and we will arrange it.
Grievance Officer (India)
In accordance with the Information Technology Act, 2000 and the rules made thereunder, and the Digital Personal Data Protection Act, 2023, the contact details of our Grievance Officer are set out below.
Grievance Officer
Webliska Technologies
SCF 65, Sector 9, 1st Floor, Near Axis Bank, Faridabad, Haryana 121006, India
Email: Contact@webliska.com
We acknowledge complaints within 48 hours and aim to resolve them within 30 days of receipt. Please include your account email and a description of the issue so we can identify your records.