Data Processing Agreement
The terms under which RefundSensor processes Personal Data on the Customer’s behalf in connection with the Service.
Last updated · June 2026
Data Processing Agreement (DPA)
Product: RefundSensor (refundsensor.com)
Operated by: Vasundhara Infotech LLP
Effective date: 1 June 2026
Last updated: 1 June 2026
This Data Processing Agreement ("DPA") forms part of and is incorporated into the Terms of Use (the "Agreement") between Vasundhara Infotech LLP ("RefundSensor", "Processor") and the customer that has accepted the Agreement ("Customer", "Controller"). Each a "party" and together the "parties".
This DPA governs RefundSensor's processing of Personal Data on the Customer's behalf in connection with the Service. Where the Customer's end users' personal data is processed through the Service, the Customer acts as the Controller / Data Fiduciary and RefundSensor acts as the Processor / Data Processor.
If there is a conflict between this DPA and the Agreement on data-protection matters, this DPA prevails.
1. Definitions
"Data Protection Laws" means all applicable laws relating to the processing of Personal Data, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR, the California Consumer Privacy Act as amended ("CCPA/CPRA"), and India's Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025 ("DPDP"), each as applicable.
"Personal Data", "Controller", "Processor", "Data Subject", "Processing", and "Personal Data Breach" have the meanings given in the GDPR; under DPDP, "Controller" corresponds to "Data Fiduciary", "Processor" to "Data Processor", and "Data Subject" to "Data Principal".
"Customer Personal Data" means Personal Data that RefundSensor processes on the Customer's behalf under the Agreement, as described in Annex 1.
"Sub-processor" means any third party engaged by RefundSensor to process Customer Personal Data.
2. Roles and scope
2.1 The parties acknowledge that, with respect to Customer Personal Data, the Customer is the Controller and RefundSensor is the Processor.
2.2 RefundSensor will process Customer Personal Data only for the purposes of providing the Service and as described in Annex 1, and otherwise in accordance with the Customer's documented instructions, including those given through the Service's configuration and settings.
2.3 The Customer is responsible for ensuring it has a lawful basis and all necessary consents and notices to provide Customer Personal Data and to instruct RefundSensor to process it.
3. Processor obligations
RefundSensor shall:
3.1 Instructions. Process Customer Personal Data only on the Customer's documented instructions, including regarding international transfers, unless required by law (in which case RefundSensor will inform the Customer, unless legally prohibited).
3.2 Confidentiality. Ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations.
3.3 Security. Implement and maintain appropriate technical and organisational measures as set out in Annex 2, taking into account the state of the art, costs, and the nature, scope, context, and purposes of processing, and the risk to Data Subjects. This includes the protections applied to platform credentials such as Apple .p8 keys (encryption at rest and in transit, restricted access, and no exposure to third parties).
3.4 Sub-processors. Engage Sub-processors only in accordance with Section 4.
3.5 Assistance with Data Subject requests. Taking into account the nature of the processing, assist the Customer by appropriate measures, insofar as possible, to respond to requests from Data Subjects exercising their rights under Data Protection Laws.
3.6 Assistance with compliance. Assist the Customer in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation, taking into account the information available to RefundSensor.
3.7 Breach notification. Notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and provide reasonably available information to help the Customer meet its own notification obligations (including under GDPR Articles 33–34 and the DPDP Rules, 2025).
3.8 Deletion or return. At the Customer's choice, delete or return all Customer Personal Data at the end of the provision of the Service, and delete existing copies unless retention is required by law. This includes deleting or rendering unusable any platform credentials, including .p8 keys, upon disconnection or termination.
3.9 Records and audits. Make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency limits, and not unreasonably disrupting RefundSensor's operations.
4. Sub-processors
4.1 The Customer provides general authorisation for RefundSensor to engage Sub-processors. The current Sub-processors are listed in Annex 3 (and/or at [refundsensor.com]).
4.2 RefundSensor will impose data-protection obligations on each Sub-processor that are substantially similar to those in this DPA, and remains responsible for each Sub-processor's performance.
4.3 RefundSensor will give the Customer reasonable notice of any intended addition or replacement of a Sub-processor, giving the Customer the opportunity to object on reasonable data-protection grounds. If the parties cannot resolve a reasonable objection, the Customer may terminate the affected part of the Service.
5. International transfers
5.1 RefundSensor may transfer Customer Personal Data internationally to provide the Service, subject to appropriate safeguards under Data Protection Laws.
5.2 Where transfers from the EEA/UK occur, the parties agree that the applicable Standard Contractual Clauses (and the UK Addendum, where relevant) are incorporated by reference and apply, with RefundSensor (or its relevant entity) acting as data importer.
5.3 For Customer Personal Data subject to DPDP, transfers outside India are permitted except to jurisdictions restricted by the Government of India, and RefundSensor will comply with any such restrictions notified from time to time.
6. CCPA / CPRA (where applicable)
Where RefundSensor processes Personal Information subject to the CCPA/CPRA as a "service provider", RefundSensor will not: (a) sell or share such information; (b) retain, use, or disclose it for any purpose other than performing the Service or as permitted by the CCPA; or (c) combine it with information from other sources except as permitted by the CCPA. RefundSensor certifies that it understands and will comply with these restrictions.
7. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
8. Term and termination
This DPA takes effect on the Effective Date and continues for as long as RefundSensor processes Customer Personal Data under the Agreement. Sections that by their nature should survive (including Sections 3.8 and 7) survive termination.
9. General
This DPA is governed by the same governing law and dispute-resolution provisions as the Agreement (the laws of India; courts and arbitration seated at Surat, Gujarat), except to the extent Data Protection Laws require otherwise.
Annex 1 — Description of Processing
Item
Details
Subject matter
Provision of the RefundSensor Service (refund-request tracking and automated reply) to the Customer.
Duration
For the term of the Agreement and any period required to return or delete data thereafter.
Nature and purpose
Collecting, storing, organising, retrieving, using, and transmitting Personal Data to operate the Service, including connecting to the Customer's platform accounts, retrieving subscription/transaction/refund data, and sending automated replies configured by the Customer.
Types of Personal Data
Customer account contacts (name, email, role); platform credentials provided by the Customer (e.g., Apple .p8 key, Key ID, Issuer ID); and end-user / refund-requester data retrieved from connected platforms (which may include identifiers, purchase and transaction details, refund reasons, and related communications).
Categories of Data Subjects
The Customer's authorised users and the Customer's end users / app customers who submit or are associated with refund requests.
Sensitive data
The Service is not intended to process special categories of data. The Customer should not submit such data unless agreed in writing.
Annex 2 — Technical and Organisational Security Measures
RefundSensor maintains measures including, as applicable:
Encryption of platform credentials (including .p8 keys) and sensitive data at rest and in transit.
Access control — least-privilege access, authentication, and restriction of credential access to authorised systems and personnel only.
Network and application security — firewalls, secure configuration, and protection against common vulnerabilities.
Logging and monitoring of access and activity for security and troubleshooting.
Confidentiality obligations for personnel.
Sub-processor management with contractual data-protection terms.
Backup and resilience measures appropriate to the Service.
Incident response procedures for detecting, investigating, and notifying breaches.
Secure deletion of credentials and data on disconnection or termination.
Annex 3 — List of Sub-processors
Sub-processor
Purpose
Location
Razorpay
Payment processing and subscription billing
India
AWS
Hosting and storage of application data
India
How to execute this DPA
This DPA is incorporated into and accepted as part of the Terms of Use. No separate signature is required for it to apply. If your organisation requires a signed copy, contact [email protected].

