Data Processing Agreement
Technomate IT-Solution Private Limited · Effective 2026-09-26
1. Scope of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the ASTRA IT operations service under the Terms of Service |
| Duration | The term of the Customer’s subscription, plus the deletion period in section 9 |
| Nature and purpose | Device inventory and telemetry collection, AI-assisted diagnosis, approved remediation, consented remote support, reporting, notifications and audit logging |
| Data principals | The Customer’s employees, contractors and other people who use enrolled devices or the ASTRA portal |
| Personal data | Names, work email addresses, signed-in Windows usernames and security IDs, device hostnames, support conversation text, approval and audit records, and the live screen content of a remote support session while it is open (not stored) |
| Sensitive data | None is intended. The agent does not read documents, email, browsing history or keystrokes |
2. Instructions
Technomate processes personal data only on the Customer’s documented instructions. The Terms of Service, this agreement, and the Customer’s configuration of ASTRA (including enabled approval tiers and remote support) are those instructions. If Technomate believes an instruction breaks the law, it will say so and may decline to follow it. Technomate will not use the Customer’s personal data for its own purposes, sell it, or use it to train AI models.
3. Customer responsibilities
The Customer is responsible for having a lawful basis for the processing, for giving its personnel the notice the law requires, and for the accuracy of the instructions it gives — including who may approve remediation and request remote support sessions.
4. Confidentiality
Technomate ensures that everyone it authorises to process the personal data is bound by a duty of confidentiality, and that access is limited to those who need it to provide or support the service.
5. Security
Technomate maintains at least the following measures:
- Encryption in transit (TLS) for all traffic between agent, portal and backend.
- Encryption at rest for the database and for stored third-party credentials.
- Logical separation of every organisation’s data, enforced on every request.
- Role-based access control, short-lived access tokens, and rotating refresh tokens with reuse detection.
- Per-device agent credentials; remediation limited to a fixed allowlist enforced by both server and agent; signed agent updates.
- Remote support only with the device user’s live consent, not recorded, with file transfer and command-line access disabled.
- Audit logging of every change and every command sent to a device.
- Automatic deletion of raw telemetry after 7 days.
6. Sub-processors
The Customer authorises Technomate to use the sub-processors listed on the sub-processors page. Technomate binds each one to data-protection obligations no less protective than this agreement and remains responsible for their performance. Technomate will update that page at least 30 days before a new sub-processor starts processing Customer personal data, and will email account administrators who have asked for notice. The Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, the Customer may terminate the affected service and receive a refund of prepaid fees for the unused period.
7. Assistance
Taking into account the nature of the processing, Technomate will help the Customer respond to requests from data principals exercising their rights, and with any data-protection impact assessment or consultation with a regulator that concerns the service. A request Technomate receives directly about Customer data is passed to the Customer, not answered by Technomate.
8. Personal data breaches
Technomate will notify the Customer without undue delay, and in any case within 72 hours, after becoming aware of a breach affecting Customer personal data. The notice will describe what happened, the data and people likely affected, the likely consequences, and the steps taken or proposed. Technomate will keep the Customer updated as it learns more and cooperate with the Customer’s own notifications to the Data Protection Board of India and affected individuals.
9. Deletion and return
On termination the Customer may export its data for 30 days. Technomate then deletes Customer personal data from its live systems, and backup copies expire within a further 30 days, unless the law requires Technomate to keep a record for longer — in which case it is kept only for that purpose.
10. Transfers outside India
Customer data is hosted in Singapore, and some sub-processors operate in other countries, as listed on the sub-processors page. Technomate transfers personal data only to countries not restricted by the Government of India under the Digital Personal Data Protection Act, 2023. Where the Customer is subject to the EU or UK GDPR, the parties will, on request, enter into the applicable Standard Contractual Clauses, which will take precedence over this agreement to the extent they conflict.
11. Audits
Technomate will make available the information reasonably needed to demonstrate compliance with this agreement, including completed security questionnaires and summaries of independent security testing. Where that is not sufficient, the Customer may, once a year and with 30 days’ notice, audit Technomate’s compliance, at its own cost, during business hours, and subject to confidentiality.
12. Liability and precedence
Liability under this agreement is subject to the limits in the Terms of Service. If this agreement conflicts with the Terms of Service on the processing of personal data, this agreement prevails.
13. Contact
Privacy questions: privacy@technomateai.com
Grievance Officer: Adeel Ahamad, grievance@technomateai.com
Technomate IT-Solution Private Limited, Ayodhya Ganj, Dadri, Gautam Budh Nagar, Uttar Pradesh 203207, India