Data Processing Agreement (DPA)
This page explains how the IvaFlow Data Processing Agreement works for business customers of Designiva. The DPA is an addendum to the Terms of Service that governs how we process personal data on behalf of your organisation when you use the Service. Questions or execution requests: ivaflow@designiva.in or +91 78428 74377.
1. When the DPA applies
Businesses that use IvaFlow to manage their own customer data act as the controller of that data, and Designiva acts as a processor for it. Where applicable privacy law requires a processing agreement between controller and processor, the DPA provides that framework. It applies per organisation: the agreement is between Designiva and the legal entity that holds the IvaFlow account.
2. What the DPA covers
The DPA documents, among other things:
- The subject matter, duration and purpose of processing on your instructions.
- Confidentiality commitments for personnel permitted to process your data.
- The security measures applied to protect your data.
- Our obligations to assist you with data subject requests and with the security of processing.
- Return or deletion of your data when the agreement ends, consistent with the Privacy Policy and the data-deletion controls available in the platform.
- How changes to the Service, applicable law and required disclosures are managed over time.
3. Service providers
To operate, secure, maintain and deliver the Service, IvaFlow relies on third-party service providers and infrastructure providers under their own confidentiality and data-handling commitments. Where a customer contract, a DPA or applicable privacy law requires a specific provider to be identified for your organisation, that identification is made in the executed DPA document itself rather than on this page, so the disclosure you receive is accurate and specific to your agreement.
4. How to request execution
Any organisation owner can request a DPA for their organisation by emailing ivaflow@designiva.in from the account owner's address with your organisation name. We will provide the current DPA template for review, and once both parties agree, it is executed and countersigned for your records.
Execution status is visible to the organisation owner at any time in Settings → Legal & Agreements, where the DPA row shows Status: Not executed until the agreement has been signed by both parties. Once executed, the row shows the execution date and reference, and — where a countersigned copy is on file — a Signed copy button the organisation owner can use to download your organisation's own executed DPA at any time. Signed copies are held privately and are not accessible to anyone outside your organisation.
5. Records of acceptance and processing
Your acceptance of the Terms of Service and acknowledgement of the Privacy Policy are recorded as read-only audit evidence (document versions, timestamp and acceptance context) and shown to your organisation owner in Settings → Legal & Agreements. These records are maintained by the platform, cannot be edited by users, and are preserved so that your organisation always has proof of which document versions applied to it at any point in time.
6. Changes
When an updated DPA template or an updated legal document version is published, affected organisation owners are asked to review and accept it explicitly before continuing to use the Service — existing agreements and acceptance records are never silently modified. The version and effective date at the top of this page identify the current template.