Legal

Data Processing Agreement (DPA)

Effective date: 1 April 2026 · Version 1.0

This Data Processing Agreement (“DPA”) is entered into between EPCdoc (a product of Twor India, “Processor”) and the customer organisation that has accepted EPCdoc’s Terms of Service (“Controller”). This DPA governs the processing of personal data by EPCdoc on behalf of the Controller in connection with the EPCdoc platform.

1. Definitions

“Personal Data” means any information relating to an identified or identifiable natural person, as defined under applicable data protection law including the Information Technology (Amendment) Act 2008 and rules thereunder.

“Processing” means any operation performed on Personal Data, including storage, retrieval, use, disclosure, and deletion.

“Customer Data” means all data, including Personal Data, uploaded by the Controller or their authorised users to the EPCdoc platform.

2. Scope of processing

EPCdoc processes Personal Data solely as instructed by the Controller and only to the extent necessary to provide the EPCdoc platform services. The categories of Personal Data processed include user names, work email addresses, professional roles, IP addresses, and usage logs.

3. Controller obligations

  • The Controller confirms it has a lawful basis for processing Personal Data under applicable law.
  • The Controller is responsible for the accuracy and lawfulness of Personal Data submitted to EPCdoc.
  • The Controller must notify EPCdoc promptly of any instructions that would cause EPCdoc to violate applicable data protection law.

4. Processor obligations

  • EPCdoc will process Personal Data only on documented instructions from the Controller.
  • EPCdoc will ensure persons authorised to process Personal Data are bound by confidentiality.
  • EPCdoc will implement appropriate technical and organisational security measures.
  • EPCdoc will not engage sub-processors without prior written authorisation from the Controller, except for sub-processors already disclosed.
  • EPCdoc will assist the Controller in responding to data subject access requests.
  • EPCdoc will notify the Controller without undue delay upon becoming aware of a Personal Data breach.
  • EPCdoc will delete or return all Personal Data upon termination of the service agreement.

5. Sub-processors

EPCdoc uses the following categories of sub-processors to deliver its services: cloud infrastructure providers (for hosting and storage), AI model providers (for AI Hub features, with data processed in accordance with their data processing terms), and email delivery providers (for SMTP notifications). A current list of sub-processors is available upon written request to cs@epcdoc.com.

6. Data transfers

Customer Data is stored in India-region S3-compatible cloud storage by default. Where data is processed outside India for AI Hub features, EPCdoc ensures appropriate contractual protections are in place with the relevant sub-processor.

7. Security

EPCdoc maintains the following security measures: TLS 1.2+ encryption in transit, AES-256 encryption at rest, per-tenant database schema isolation, JWT authentication with short-lived tokens, bcrypt password hashing, and immutable audit logs.

8. Term and termination

This DPA remains in effect for the duration of the EPCdoc subscription. Upon termination, EPCdoc will retain Customer Data for 30 days to allow export, after which it will be securely deleted from all systems.

9. Contact

For DPA enquiries, data subject requests, or security concerns: cs@epcdoc.com

EPCdoc (a product of Twor India) · VIOS Towers, 4th Floor, Off Eastern Express Highway, Sewri-Chembur Road, New Cuffe Parade, Mumbai 400037, Maharashtra, India.

© 2026 EPCdoc (a product of Twor India)
Terms of ServicePrivacy Policy
💬 Ask me about EPCdoc