Data Processing Agreement
Last Updated: July 21, 2026
Effective Date: July 21, 2026
Effective Date: July 21, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement governing a Customer’s use of AlignHub, a product owned and operated by SpreadMe Digital Pvt. Ltd.. It applies when SpreadMe Digital Pvt. Ltd. processes Customer Personal Data on behalf of the Customer through AlignHub.
The Customer generally acts as the Data Controller or Data Fiduciary, and SpreadMe Digital Pvt. Ltd. generally acts as the Data Processor or processor. The terminology used depends on the Applicable Data Protection Law.
1. Scope, Application, and Precedence
This DPA applies to processing of Customer Personal Data in connection with the AlignHub Services, including supported credential, task, leave, payroll-administration, asset, collaboration, reporting, integration, support, implementation, and white-label functions.
This DPA becomes effective when the Customer accepts the Main Agreement, accepts this DPA, or begins using Services that involve our processing of Customer Personal Data, whichever occurs first.
If this DPA conflicts with the Main Agreement concerning the processing or protection of Customer Personal Data, this DPA controls. The Main Agreement controls on all other matters unless expressly stated otherwise.
2. Definitions
- "Applicable Data Protection Law" means any privacy, data-protection, or cybersecurity law applicable to the processing covered by this DPA, including applicable provisions of India's Digital Personal Data Protection Act, 2023 and implementing rules, the EU GDPR, the UK GDPR and Data Protection Act 2018, and applicable US state privacy laws.
- "Customer Personal Data" means Personal Data processed by us on behalf of the Customer through the Services.
- "Data Controller" or "Controller" means the party that determines the purposes and means of processing Personal Data.
- "Data Fiduciary" has the meaning given under applicable Indian data-protection law.
- "Data Principal" or "Data Subject" means the individual to whom Personal Data relates.
- "Data Processor" or "Processor" means a party that processes Personal Data on behalf of a Controller or Data Fiduciary.
- "Main Agreement" means the Terms of Service, Order, Professional Services Agreement, or other agreement governing the Customer's use of the Services.
- "Personal Data" means information relating to an identified or identifiable individual, or any equivalent definition under Applicable Data Protection Law.
- "Personal Data Breach" means a security breach resulting in accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.
- "Process" and "Processing" mean any operation performed on Personal Data, including collection, storage, access, use, transmission, organization, modification, retrieval, restriction, return, or deletion.
- "Services" means the AlignHub platform, website, modules, integrations, support, and related professional or white-label services under the Main Agreement.
- "Subprocessor" means a third party engaged by us to process Customer Personal Data in connection with the Services.
3. Roles and Responsibilities
3.1 Customer
The Customer determines the purposes and essential means of processing Customer Personal Data and is responsible for complying with Applicable Data Protection Law, including providing notices, establishing a lawful basis, obtaining required authorization, responding to individuals and authorities, and ensuring that its instructions are lawful.
3.2 SpreadMe Digital Pvt. Ltd.
We will process Customer Personal Data only on behalf of the Customer and in accordance with the Main Agreement, this DPA, the Customer’s configuration of the Services, and other documented instructions accepted by us, unless applicable law requires otherwise.
3.3 Customer authority
The Customer confirms that it has the right to disclose Customer Personal Data to us and to authorize processing under this DPA.
4. Processing Instructions
The Main Agreement, this DPA, the Customer’s use and configuration of the Services, and written instructions accepted by us constitute the Customer’s documented processing instructions.
If we reasonably believe an instruction violates Applicable Data Protection Law, we may suspend the affected processing and inform the Customer, unless law prohibits notice. We are not required to perform instructions that are technically infeasible, unlawful, or materially outside the agreed Services. Additional work may be subject to reasonable fees under an Order or change request.
5. Details of Processing
The subject matter, duration, nature, purpose, categories of individuals, and types of Personal Data are described in Annex A. The Customer controls the data entered into the Services and must use data-minimization principles.
AlignHub supports payroll calculation, payroll records, statutory-deduction fields, and payslip generation. We do not transfer salaries, execute payroll payments, or hold employee funds.
6. Confidentiality and Personnel
We will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations and receive access only where reasonably necessary to perform their duties.
We will provide appropriate privacy and security awareness to relevant personnel and will take reasonable steps to ensure compliance with this DPA.
7. Security Measures
We will maintain reasonable technical and organizational measures appropriate to the nature of Customer Personal Data and the risks of processing. Current categories of measures are described in Annex B.
AlignHub includes end-to-end encryption for supported data and communications, together with additional controls that may include encryption in transit and at rest, role-based access, authentication controls, audit logging, monitoring, backups, secure development practices, vulnerability management, and incident response.
The Customer is responsible for configuring its Workspace, limiting administrative privileges, protecting credentials and devices, reviewing user access, managing integrations, and promptly removing access that is no longer required.
8. Subprocessors
8.1 General authorization
The Customer gives general authorization for us to appoint Subprocessors where reasonably necessary to provide the Services.
8.2 Contractual protection
We will require each Subprocessor that processes Customer Personal Data to be bound by written data-protection and confidentiality obligations appropriate to the services it performs. We remain responsible for our Subprocessors to the extent required by Applicable Data Protection Law and the Main Agreement.
8.3 Changes and objections
We will make current Subprocessor information available through our website, the Services, or on written request. Where required by Applicable Data Protection Law, we will provide reasonable advance notice of a material new Subprocessor. The Customer may object on reasonable data-protection grounds within the notice period.
The parties will work in good faith to address a valid objection. If no reasonable solution is available, the Customer may discontinue the affected portion of the Services in accordance with the Main Agreement.
9. Data Principal and Data Subject Requests
If we receive a request directly from an individual concerning Customer Personal Data, we will direct the individual to the Customer unless we are legally required to respond.
Taking into account the nature of processing and the functionality available in the Services, we will provide reasonable assistance to the Customer with valid requests for access, correction, completion, updating, erasure, restriction, objection, portability, consent withdrawal, nomination, or grievance redressal, where applicable.
The Customer remains responsible for verifying requests, deciding how to respond, and meeting applicable deadlines.
10. Regulatory and Assessment Assistance
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance with data-protection impact assessments, consultations, regulatory inquiries, and other compliance obligations that relate to our processing under this DPA.
Assistance beyond standard product functionality and compliance information may be subject to reasonable fees where permitted by law and agreed in advance.
11. Personal Data Breach
We will notify the Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.
To the extent reasonably available, the notice will describe the nature of the breach, affected categories of individuals and data, likely consequences, measures taken or proposed, and a contact for follow-up. Information may be provided in stages as the investigation progresses.
Our notice does not constitute an admission of fault or liability. The Customer is responsible for notifications to individuals, authorities, or other parties, except where Applicable Data Protection Law directly requires us to notify them.
12. International Transfers
AlignHub is operated from India. Customer Personal Data may be processed in India and in other countries where approved Subprocessors or customer-selected integrations operate.
Where Applicable Data Protection Law restricts an international transfer, the parties will use an appropriate legal mechanism and supplementary safeguards where required. This may include the European Commission Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, or another valid transfer mechanism.
If a specific transfer instrument requires party details, processing descriptions, security measures, or signatures beyond this public DPA, the parties will complete the required addendum or transfer documentation.
13. Audits and Compliance Information
Upon reasonable written request, we will provide information reasonably necessary to demonstrate compliance with this DPA, such as relevant policies, questionnaires, summaries, or independent reports that are available and appropriate to share.
If such information is not reasonably sufficient, the Customer may request an audit no more than once in any 12-month period, unless a Personal Data Breach or regulator requires an additional audit. Audits must be conducted during normal business hours, on reasonable notice, without disrupting operations, and subject to confidentiality and security requirements.
The Customer bears its audit costs and will reimburse reasonable assistance beyond standard compliance materials, unless an audit identifies our material breach of this DPA.
14. Return and Deletion
During the service term, the Customer may use available features to access, export, correct, or delete Customer Personal Data, subject to permissions and module capabilities.
After termination of the Main Agreement, we will delete or return Customer Personal Data in accordance with the Customer’s documented request, the Main Agreement, and applicable retention requirements. Data may remain in encrypted or access-restricted backups until overwritten through the normal backup cycle, provided it is not used for another purpose.
We may retain information where required by law or reasonably necessary to establish, exercise, or defend legal claims, provided it remains protected and is processed only for that purpose.
15. Liability
Each party is responsible for its compliance with Applicable Data Protection Law and for losses caused by its breach of this DPA.
Liability arising under this DPA is subject to the exclusions and limitations in the Main Agreement, except to the extent such limitation is prohibited by Applicable Data Protection Law.
16. Term and Termination
This DPA remains effective while we process Customer Personal Data under the Main Agreement. It ends after the Main Agreement has terminated and Customer Personal Data has been returned or deleted as required.
Confidentiality, security, deletion, audit, liability, international-transfer, and governing-law obligations survive for as long as we retain Customer Personal Data.
17. Governing Law and Disputes
This DPA is governed by the governing-law and dispute-resolution provisions of the Main Agreement. If the Main Agreement does not contain such provisions, this DPA is governed by the laws of India and the courts at Gandhinagar, Gujarat, India will have jurisdiction, subject to any mandatory rights under Applicable Data Protection Law.
18. Privacy Contact
Product:
AlignHub
Legal Entity:
SpreadMe Digital Pvt. Ltd.
Grievance Officer / Privacy Contact:
Jigar Patel
Email:
Telephone:
Address:
Capitol Icon, 604, GIFT City Road, Sargasan, Gandhinagar, Gujarat 382419, India
Website:
Annex A - Processing Details
Item
Description
Subject matter
Processing Customer Personal Data to provide, support, secure, configure, and maintain the AlignHub Services.
Duration
For the term of the Main Agreement and the period reasonably required to return or delete Customer Personal Data, subject to legal retention and backup cycles.
Nature and purpose
Hosting, organizing, retrieving, displaying, transmitting, securing, backing up, supporting, and deleting Customer Personal Data; enabling task, credential, leave, payroll-administration, asset, collaboration, reporting, integration, implementation, and white-label functions.
Processing frequency
Continuous or as initiated by the Customer and Authorized Users during use of the Services.
Categories of individuals
Customer employees, contractors, administrators, Authorized Users, project participants, clients, suppliers, business contacts, and other individuals whose information is submitted by the Customer.
Types of Personal Data
Names; business or personal contact details; account identifiers; job titles; roles; departments; employment and leave records; compensation, tax, deduction, and payroll-administration data; bank details entered by the Customer; task and project activity; credential identifiers and encrypted secrets; device and asset records; messages; comments; files; support records; technical and usage data; and other data selected by the Customer.
Special or sensitive data
Only where the Customer chooses to submit it and has lawful authority. This may include payroll, financial, tax, employment, authentication, or credential information. Customers must not submit prohibited card authentication data such as CVV codes.
Retention
As configured or instructed by the Customer, stated in the Main Agreement, required by law, or necessary for security, backup, dispute, and legal-claim purposes.
Annex B - Technical and Organizational Measures
- End-to-end encryption for supported data and communications;
- Encryption in transit and, where supported, encryption at rest;
- Role-based access controls, permission management, and separation of administrative privileges;
- Authentication controls and secure handling of account credentials;
- Encrypted handling and access controls for supported Credential Vault content;
- Logging and monitoring of relevant security, access, and credential-use events;
- Secure development, change management, code review, and vulnerability-management practices;
- Backups, recovery procedures, service-resilience measures, and restricted backup access;
- Incident detection, investigation, containment, response, and notification procedures;
- Confidentiality obligations and security awareness for authorized personnel;
- Vendor and Subprocessor review appropriate to the services provided; and
- Periodic review of access, security measures, and risks.
Specific measures may vary by module, service configuration, customer environment, and technical feasibility. We may update measures provided that the overall level of protection is not materially reduced.
Annex C - Subprocessor Information
A current list of material Subprocessors and the services they perform will be made available through the AlignHub website, the Services, or upon written request to info@spreadme.digital. The list may change in accordance with Section 8 of this DPA.