CONTROLLER-PROCESSOR DATA ACCORDv1.0Effective: March 2026

JOY PeopleHR — Data Processing Agreement (DPA)

Legally binding Controller-to-Processor agreement defining JOY's technical, organizational, and security responsibilities when processing customer employee and workforce data.

Legal & Compliance Hub

Key Governance Highlights (Enterprise Overview)

✓
Clear separation of Customer as Data Controller / Fiduciary and JOY as Data Processor
✓
Mandatory encryption in transit (TLS 1.3) and at rest (AES-256) across all data clusters
✓
Sub-processor governance with strict confidentiality and security pass-through terms
✓
Security incident notification protocols and statutory compliance cooperation
✓
Assistance with Data Subject / Data Principal access and deletion requests
§ 01

1. Purpose

The purpose of this DPA is to establish the responsibilities of JOY and the Customer regarding personal data processed through JOY PeopleHR.

The parties intend to operate the Service in accordance with applicable data-protection and privacy requirements.

The DPA is designed to support compliance with applicable Indian data-protection requirements, including the Digital Personal Data Protection Act, 2023 and applicable rules and regulations as they come into force. The Act and Rules have a staged commencement framework, and the parties will comply with provisions applicable to their activities as they become effective.

§ 02

2. Definitions

For this DPA:

"Customer Data" means information submitted, generated, uploaded or otherwise processed through JOY PeopleHR on behalf of the Customer.

"Personal Data" means information relating to an identified or identifiable individual.

"Data Principal" means an individual to whom personal data relates, where that terminology applies under applicable law.

"Data Fiduciary" has the meaning given under applicable Indian data-protection law.

"Data Processor" has the meaning given under applicable Indian data-protection law.

"Processing" includes collection, storage, organization, retrieval, use, transmission, sharing, modification, deletion and other handling of personal data.

§ 03

3. Roles of the Parties

For employee and workforce information submitted by the Customer:

the Customer generally determines the purposes and means for which employee information is processed;

JOY processes such information to provide JOY PeopleHR;

the Customer is responsible for ensuring lawful collection and use of employee information;

JOY acts as a service provider/data processor to the extent it processes such information on the Customer's instructions.

JOY may independently act as a Data Fiduciary for information it requires for its own purposes, including:

Customer account administration;

billing;

payment records;

security;

fraud prevention;

legal compliance;

service communications;

business administration.

§ 04

4. Customer Responsibilities

The Customer shall:

ensure that it has appropriate authority to provide personal information to JOY;

determine appropriate purposes for employee-data processing;

provide required privacy notices;

obtain consent where required;

maintain accurate information;

establish appropriate employee access rights;

comply with employment and privacy laws;

respond to employee/data-subject requests where applicable;

ensure that employee data is not unlawfully uploaded;

ensure that sensitive HR operations are lawfully configured.

§ 05

5. Instructions to JOY

JOY shall process Customer Data primarily for:

providing JOY PeopleHR;

hosting and storing Customer Data;

employee and HR management;

attendance;

payroll;

leave;

employee documentation;

notifications;

security;

technical support;

service maintenance;

backup and recovery;

product improvement as permitted under this DPA;

complying with Customer instructions.

JOY shall not intentionally use Customer employee data for unrelated commercial purposes.

§ 06

6. Categories of Personal Data

Depending on the Customer's use of JOY PeopleHR, data may include:

identity information;

contact information;

employment information;

salary and payroll information;

bank details;

tax information;

attendance records;

shift information;

leave information;

GPS/location information associated with attendance;

biometric or face-attendance information;

identity/KYC documents;

employee photographs;

emergency-contact information;

employee-generated requests;

performance/task information;

technical identifiers;

device information;

authentication information.

§ 07

7. Categories of Data Principals

Data Principals may include:

employees;

prospective employees;

former employees;

contractors;

trainees;

interns;

authorized representatives;

other individuals whose information is lawfully entered by the Customer.

§ 08

8. Processing Activities

JOY may perform:

collection through Customer-controlled workflows;

storage;

organization;

retrieval;

synchronization;

display;

notification;

calculation;

document processing;

reporting;

backup;

deletion;

security monitoring;

technical support.

§ 09

9. Special Processing Categories

The Customer acknowledges that JOY PeopleHR may support processing of information that may require heightened care under applicable law or organizational policy, including:

government identification information;

payroll and bank information;

location information;

biometric attendance information;

face-related attendance information.

The Customer is responsible for determining the appropriate legal basis, notice, authorization and configuration for such processing.

§ 10

10. Security Measures

JOY shall maintain reasonable technical and organizational security measures appropriate to the nature of the Service.

Measures may include:

tenant isolation;

role-based access control;

authentication;

access permissions;

secure storage mechanisms;

signed-access mechanisms;

logging;

monitoring;

backups;

infrastructure security;

controlled administrative access;

vulnerability management;

security incident procedures.

JOY may improve or change specific security technologies where the overall security objective remains reasonably maintained.

§ 11

11. Confidentiality

JOY shall ensure that personnel authorized to access Customer Data are subject to appropriate confidentiality obligations.

Access shall be limited to personnel who require access for legitimate service, security, support or operational purposes.

§ 12

12. Customer Data Access by JOY

JOY does not ordinarily access employee records for its own business purposes.

Where technically or operationally necessary, authorized JOY personnel may access limited information for:

customer support;

troubleshooting;

security investigation;

service maintenance;

legal compliance;

incident response.

Such access should be limited to what is reasonably necessary.

§ 13

13. Subprocessors and Service Providers

JOY may use third-party service providers to provide the Service.

These may include providers for:

cloud hosting;

payment processing;

SMS;

email;

WhatsApp;

push notifications;

maps;

analytics;

authentication;

security;

infrastructure.

JOY shall take reasonable steps to ensure that service providers handling Customer Data are subject to appropriate confidentiality, security and data-processing obligations.

§ 14

14. Current Hosting and Infrastructure

JOY PeopleHR is currently undergoing infrastructure testing and development using Supabase infrastructure, including the Mumbai region.

JOY intends to migrate its infrastructure to Amazon Web Services in the future.

Infrastructure and service-provider changes may be made as the Service develops.

JOY shall take reasonable steps to maintain appropriate data-protection and security measures during infrastructure migrations.

§ 15

15. International Processing

JOY's current service model is intended primarily for India.

JOY does not currently intend to transfer Customer Data internationally as part of the standard operating model.

If international processing or hosting is introduced, JOY shall assess applicable legal requirements and implement appropriate contractual, technical and organizational safeguards.

§ 16

16. Data Subject / Data Principal Requests

Where an individual requests access, correction, deletion, withdrawal of consent or another applicable right relating to Customer-controlled employee information, the Customer shall ordinarily be responsible for handling the request.

JOY shall provide reasonable assistance where technically and legally appropriate.

JOY may redirect an employee to the Customer where the Customer is responsible for the relevant processing decision.

§ 17

17. Security Incidents

JOY shall maintain reasonable procedures for identifying and responding to security incidents.

If JOY becomes aware of a confirmed or reasonably suspected personal-data breach involving Customer Data, JOY shall:

investigate the incident;

take reasonable steps to contain it;

mitigate potential harm;

preserve relevant evidence;

cooperate with the Customer as reasonably necessary;

provide information reasonably required for the Customer's applicable legal obligations.

Where legally required, appropriate notifications shall be made to the relevant authorities or affected individuals.

§ 18

18. Data Retention and Deletion

JOY shall retain Customer Data for as long as reasonably required to provide the Service.

Following cancellation or termination:

Customer access is terminated;

the Customer receives a 15-day period to obtain or request available data;

eligible Customer Data may then be permanently deleted.

JOY may retain limited information where required for:

legal compliance;

tax/accounting requirements;

security;

fraud prevention;

dispute resolution;

enforcement of legal rights.

§ 19

19. Data Export

During the applicable retention period, JOY may provide reasonable mechanisms for Customer Data export.

The format and availability of export may depend on the type of data and technical capabilities of the Service.

The Customer is responsible for downloading and securely storing any required information before deletion.

§ 20

20. Data Accuracy

The Customer is responsible for the accuracy of information submitted to JOY PeopleHR.

JOY is not responsible for consequences arising solely from inaccurate, incomplete or outdated information supplied by the Customer or its users.

§ 21

21. Payroll and Compliance Processing

JOY may process employee data to calculate payroll and statutory components.

The Customer remains responsible for verifying:

salary information;

employee classification;

applicable deductions;

statutory applicability;

tax information;

PF/EPF;

ESIC;

Professional Tax;

TDS;

other payroll and statutory obligations.

JOY does not guarantee that software calculations constitute legal, tax or professional advice.

§ 22

22. Location Processing

Where GPS attendance is enabled, location information is processed in connection with employee attendance check-in/check-out.

JOY PeopleHR is not intended to provide continuous employee location tracking through the standard attendance feature.

The Customer is responsible for configuring the feature lawfully and providing appropriate employee notices.

§ 23

23. Biometric and Face Attendance

Where biometric or face-attendance features are enabled, the Customer shall ensure that the use of such functionality complies with applicable laws and organizational requirements.

The Customer shall determine:

whether such processing is necessary;

the applicable legal basis;

appropriate employee notice;

retention periods;

access permissions;

deletion requirements.

JOY shall process such information only as reasonably necessary to provide the configured Service.

§ 24

24. Audits and Compliance Information

Where reasonably necessary to demonstrate compliance with this DPA, JOY may provide information regarding its relevant security and data-processing practices.

Any audit must:

be reasonably related to Customer Data;

respect JOY's confidentiality;

not compromise other Customers;

not expose security-sensitive information;

be conducted at reasonable times;

not unreasonably disrupt JOY's operations.

§ 25

25. Aggregated and Anonymized Data

JOY may create and use properly aggregated, anonymized or de-identified information derived from Service usage for:

analytics;

product improvement;

benchmarking;

research;

reporting;

product development.

Such information will not be intentionally used to identify individual employees where it has been properly anonymized or de-identified.

§ 26

26. Customer Instructions and Unlawful Requests

JOY may refuse an instruction that it reasonably believes:

violates applicable law;

creates a material security risk;

violates third-party rights;

conflicts with the Customer's contractual obligations;

requires JOY to misuse personal data.

JOY may request clarification before implementing an instruction.

§ 28

28. Return and Deletion Upon Termination

Upon termination, JOY shall follow the data-return and deletion procedures described in this DPA.

The Customer acknowledges that permanent deletion may prevent future restoration of the affected information.

§ 29

29. Liability

The liability provisions applicable to the parties' use of JOY PeopleHR are governed by the Terms and Conditions or applicable commercial agreement.

Nothing in this DPA limits liability that cannot legally be limited.

§ 30

30. Conflict With Other Agreements

If this DPA conflicts with the standard Privacy Policy, this DPA governs the processing relationship between JOY and the Customer for Customer Data.

If a separately executed agreement contains specific data-processing obligations, that agreement may take precedence to the extent expressly stated.

§ 31

31. Changes to the DPA

JOY may update this DPA to reflect:

changes in law;

regulatory requirements;

infrastructure changes;

security improvements;

changes to Service functionality.

Where a change materially affects the Customer's obligations, JOY will provide reasonable notice where required.

§ 32

32. Governing Law

This DPA shall be governed by the laws of India.

§ 33

33. Dispute Resolution

The parties shall first attempt to resolve any dispute through good-faith negotiation.

If the dispute cannot be resolved through negotiation, it shall be referred to arbitration under applicable Indian law.

The seat and venue of arbitration shall be Coimbatore, Tamil Nadu, unless otherwise agreed in writing.

Competent courts in Coimbatore, Tamil Nadu shall have jurisdiction where court intervention is legally required.

§ 34

34. Contact

Joy Corporate Solutions Private Limited No.16, Krishna Complex, Avinashi - Coimbatore Road, Thennampalayam, Arasur, Coimbatore, Tamil Nadu 641407, India.

Data Protection Officer (DPO): privacy@joypeoplehr.com | Customer Support: support@joypeoplehr.com | Helpline: +91 99443 99088 | Website: joypeoplehr.com

Joy Corporate Solutions Private Limited

Registered Operating Entity for JOY PeopleHR

Registered Corporate Office:

No.16, Krishna Complex, Avinashi - Coimbatore Road, Thennampalayam, Arasur, Coimbatore, Tamil Nadu 641407, India.

Jurisdiction: Coimbatore, Tamil Nadu, India

General Inquiries & Contact:✉ contact@joypeoplehr.com
Support, Policies & Helpdesk:✉ support@joypeoplehr.com
Direct Phone / Helpline:+91 99443 99088