Section 01
Scope and definitions
This Data Processing Agreement ("DPA") supplements the Terms of Service for customers (typically Practitioner and Enterprise) who use Kaalveda to process personal data of their own clients. Terms used here ("controller", "processor", "personal data", "processing", "sub-processor") have the meanings given in the GDPR Article 4 and the DPDPA 2023 Section 2.
Section 02
Roles
The customer is the Controller of client personal data uploaded to Kaalveda. Webliska.AI (operating Kaalveda) is the Processor acting on the Controller's documented instructions. For data Webliska.AI collects directly (billing, support tickets), Webliska.AI is the Controller; this DPA does not apply to that data.
Section 03
Subject matter and duration
Subject matter: computation of astrological / numerological readings from client DOB, time, place, name supplied by the Controller. Duration: for the duration of the Controller's active subscription. Termination triggers Article 11 below.
Section 04
Nature and purpose of processing
Nature: storage, computation, PDF generation, share-link delivery. Purpose: providing the Controller's requested service to its clients. No secondary purposes — no analytics on client data, no marketing, no enrichment.
Section 05
Types of personal data and data subjects
Personal data: name, date of birth, time of birth, place of birth, language preference, optional notes. Special-category data: none — none of these data points are themselves sensitive under GDPR Article 9. Data subjects: the Controller's clients (whose charts the Controller uploads to compute).
Section 06
Sub-processors
Webliska.AI uses sub-processors listed in the public sub-processor list (PayU, PayTM, Razorpay, Stripe, Amazon Web Services, Google). Adding a new sub-processor requires 30 days' advance notice; the Controller may object in writing, in which case Webliska.AI will offer a commercially reasonable alternative or allow termination.
Section 07
Security measures
Encryption at rest (AES-256). Encryption in transit (TLS 1.3). Access control: production data access limited to engineering staff with role-based permissions and audit logging. Password hashing: bcrypt with industry-standard cost factor. Payment data: tokenised at the browser; never stored on Kaalveda servers.
Section 08
Data subject rights
Where a data subject contacts Webliska.AI directly with a GDPR Article 15–22 request, we will redirect to the Controller within 5 business days. Where the Controller forwards a data subject request, we will assist within the 30-day GDPR window (typically 5–10 business days).
Section 09
Breach notification
Webliska.AI will notify the Controller without undue delay (and in any case within 72 hours) of becoming aware of a personal data breach affecting the Controller's data. Notification includes: nature of breach, categories and approximate numbers of data subjects, likely consequences, and mitigation measures.
Section 10
International transfers
Transfers outside the EEA are governed by Standard Contractual Clauses (Module 2 — Controller to Processor) as approved by the European Commission Decision 2021/914. Indian transfers follow DPDPA Section 16 with the relevant adequacy assessment.
Section 11
Audit rights
The Controller may audit Webliska.AI's compliance with this DPA once per year, on 30 days' written notice, during business hours, at the Controller's cost. Webliska.AI provides ISO 27001-equivalent self-assessment reports on request and will reasonably cooperate with on-site audits.
Section 12
Termination
On termination of the underlying subscription, Webliska.AI will (at the Controller's choice) delete or return all personal data within 30 days. The Controller may export a JSON / CSV bundle of client data before termination. Payment-related metadata is retained per the Privacy Policy.
Questions or feedback about this document? Email [email protected] for general inquiries, or [email protected] for legal matters.