Skip to content
Nelogi.

Data Processing Agreement

Last updated: 30 September 2026

This Data Processing Agreement ("DPA") forms part of the Terms of Service between SydanticIQ Technologies LLP ("Processor", "Nelogi") and the customer organization ("Customer") and applies when Nelogi processes personal data on the Customer's behalf through the Service. It is designed to meet the requirements of the Digital Personal Data Protection Act, 2023 (India) and, where applicable, Article 28 of the GDPR. In case of conflict with the Terms, this DPA prevails for personal data processing.

1. Roles and scope

The Customer is the data fiduciary / controller and Nelogi is the data processor for Customer Data containing personal data. Nelogi processes it only to provide the Service.

2. Details of processing

  • Subject matter and duration: provision of the Service for the subscription term plus the deletion period in section 10.
  • Nature and purpose: hosting, storage, display, transmission (including notification emails), security monitoring, backup and support.
  • Categories of data subjects: the Customer's employees and contractors; the Customer's external collaborators, clients, vendors and guests whom the Customer invites.
  • Categories of personal data: names, business email addresses, job titles, organization and company affiliation, roles, work-item content, comments, approval decisions, sign-in and audit logs.
  • Special categories: none intended; the Customer shall not submit them unless agreed in writing.

3. Processor obligations

Nelogi shall: (a) process personal data only on the Customer's documented instructions, including these Terms and the Customer's configuration of the Service; (b) ensure personnel with access are bound by confidentiality; (c) implement the security measures in Annex 1; (d) assist the Customer, taking into account the nature of processing, in responding to data principal / data subject requests; (e) assist with security, breach notification and impact assessments where reasonably required; (f) inform the Customer if an instruction appears to infringe applicable law.

4. Sub-processors

The Customer authorises the sub-processors in Annex 2. Nelogi will impose data protection obligations on sub-processors no less protective than this DPA and remains responsible for their performance. Nelogi will give at least 30 days' notice of new sub-processors by updating this page and emailing organization owners; the Customer may object on reasonable data-protection grounds, and if unresolved may terminate the affected Service without penalty.

5. International transfers

Customer Data is hosted in the Asia Pacific region (Sydney, Australia). Transfers outside India or the EEA will be made only in compliance with applicable law, including any restrictions notified under the DPDP Act and, where the GDPR applies, appropriate safeguards such as the European Commission's Standard Contractual Clauses.

6. Personal data breaches

Nelogi will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting Customer Data, with the information reasonably available (nature of the breach, likely consequences, measures taken), and will cooperate so the Customer can meet its notification obligations to the Data Protection Board of India, supervisory authorities and affected individuals.

7. Data principal / data subject requests

If Nelogi receives a request relating to Customer Data, it will refer the requester to the Customer and will not respond directly except to confirm the referral, unless legally required. The Service allows organization owners to correct, export and delete personal data.

8. Audits

Nelogi will make available information reasonably necessary to demonstrate compliance with this DPA, including security documentation and third-party certifications of its hosting providers. On-site audits may be agreed in writing at the Customer's cost, with reasonable notice and confidentiality, no more than once a year unless required by a regulator or following a breach.

9. Confidentiality and personnel

Access to Customer Data is limited to personnel who need it to provide or support the Service, subject to confidentiality obligations and access logging.

10. Return and deletion

The organization owner can export Customer Data at any time (JSON and CSV). On termination, Nelogi will delete Customer Data from the live Service within 30 days after the 30-day export window, and backups will expire on their normal cycle (currently about 14 days), unless retention is required by law.

11. Liability

Liability under this DPA is subject to the limitations in the Terms, except where applicable law does not permit limitation.

12. Annex 1 – Technical and organisational measures

  • Tenant isolation: every customer organization is separated by database-level row-level security; access is granted only through project membership and role.
  • Access control: role-based permissions; external collaborators see only shared items in projects they are invited to; separation of duties for approvals (no self-approval).
  • Authentication: invitation-only accounts; two-step verification mandatory for owners and administrators and optionally for all members; 6-hour inactivity and 12-hour absolute session limits.
  • Logging: immutable, read-only audit logs of project activity, administrative actions and access events.
  • Encryption: data encrypted in transit (TLS) and at rest.
  • Resilience: daily database backups retained for about 14 days; independent periodic exports.
  • Application security: web application firewall, rate limiting, input validation, least-privilege server functions.
  • Data minimisation: documents are referenced by links and remain in the customer's repositories.
  • Organisational: confidentiality commitments, least-privilege administrative access, incident response procedure.

13. Annex 2 – Authorised sub-processors

Sub-processorPurposeLocation
Cloud application platform provider (SOC 2 Type 2 audited)Application hosting, database, file storage and transactional email deliveryAsia Pacific (Sydney, Australia)

The full list of named sub-processors is available to customers on request at privacy@nelogi.com. Updates to this list will be communicated as described in section 4.

Contact for DPA matters: privacy@nelogi.com