Legal
Data Processing Agreement
Last updated: 1 May 2025
1. Parties
This Data Processing Agreement ("DPA") is between MetaHarbour Group Pvt. Ltd. ("Processor") and the institution ("Controller") that has signed up to use the ParikshAI platform.
2. Scope of Processing
The Processor processes personal data strictly as instructed by the Controller for the purpose of AI-assisted exam evaluation, including:
- Student roll numbers and answer scripts.
- Evaluator names and scoring activity.
- Question papers and rubrics uploaded by the Controller.
3. Legal Basis — DPDP Act 2023
Processing is carried out in compliance with India's Digital Personal Data Protection Act 2023. The Controller is the Data Fiduciary; the Processor acts as a Data Processor under the Controller's instructions. The Processor will not process personal data for any purpose other than providing the contracted service.
4. Data Residency
All personal data is stored and processed within India on AWS infrastructure in the Mumbai (ap-south-1) region. No personal data is transferred outside India without explicit written consent from the Controller.
5. Sub-Processors
The Processor uses the following sub-processors, all subject to equivalent data protection obligations:
- Amazon Web Services (AWS) — Cloud infrastructure & storage (India region)
- Anthropic / OpenAI / Google Gemini — AI evaluation models (data is not used for model training)
- Postmark — Transactional email delivery
6. Security Measures
- AES-256 encryption at rest; TLS 1.2+ in transit.
- Role-based access control with audit logging.
- Annual penetration testing.
- Incident response plan with 72-hour breach notification.
7. Retention & Deletion
Data is retained for 5 years from upload date unless the Controller requests earlier deletion. Upon contract termination, all personal data is deleted within 30 days. Anonymised aggregate statistics may be retained indefinitely.
8. Controller Rights
The Controller may audit the Processor's data handling practices with 14 days' written notice. The Processor will cooperate fully with any such audit.
9. Contact
For DPA-related queries:
MetaHarbour Group Pvt. Ltd.
Email: dpa@pariksha.tech