Data Processing Agreement
Last updated: 3 July 2026
DPDP Act 2023 data-processing terms between your organisation and PeopleOS
This Data Processing Agreement (“DPA”) forms part of the Terms of Service between the subscribing organisation (the “Client”) and Oris Intelligence Pvt. Ltd. (“PeopleOS”) and governs the processing of personal data of the Client’s employees and contractors on the PeopleOS platform.
1. Roles under the DPDP Act, 2023
The Client is the Data Fiduciary for the personal data of its employees (the Data Principals). PeopleOS processes that data strictly on the Client’s documented instructions as a Data Processor under a valid contract, as contemplated by Section 8(2) of the DPDP Act, 2023.
2. Scope and purpose of processing
PeopleOS processes employee master data, statutory identifiers (PAN, UAN), salary and bank details, attendance records, and related HR documents solely to deliver the contracted services: payroll computation, statutory compliance (PF, ESI, PT, TDS, LWF), HR operations, and reporting. PeopleOS does not use Client personal data for advertising and does not sell it.
3. Security measures
- Encryption in transit (TLS 1.2+) and at rest; field-level encryption for bank and PAN data
- Aadhaar numbers are never stored in the application database — only tokens issued by a separate, HSM-backed Aadhaar Data Vault
- Tenant isolation via PostgreSQL Row-Level Security
- Role-based access control, 2FA, and session management for all user access
- Immutable, hash-chained audit trail for every payroll and data-change event
- PII is redacted before any content is sent to AI/LLM providers
4. Data residency
All Client personal data is stored and processed on infrastructure located in India. No employee personal data is transferred outside Indian jurisdiction.
5. Sub-processors
PeopleOS engages sub-processors only where needed to deliver the service (cloud infrastructure, payment processing, transactional email, error monitoring). Each is bound by contractual obligations no less protective than this DPA. A current list is available on request at support@meetpeopleos.com; Clients are notified of material changes in advance.
6. Personal data breach
PeopleOS will notify the Client without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting the Client’s data, and will provide the information reasonably required for the Client to meet its own notification obligations to the Data Protection Board of India and affected Data Principals.
7. Data Principal rights
PeopleOS provides in-product tooling (data export, correction workflows, erasure requests) to help the Client honour Data Principals’ rights of access, correction, and erasure. Requests received directly from employees are redirected to the Client as Data Fiduciary.
8. Return and deletion of data
On termination of the subscription, the Client may export all data in standard formats (CSV/Excel) for 90 days. Thereafter, personal data is deleted from production systems, with backup copies aging out on the rolling backup schedule, except where retention is required by Indian law (e.g., statutory payroll registers).
9. Contact
Questions about this DPA, sub-processors, or a signed countersigned copy for enterprise procurement: support@meetpeopleos.com.