Home/Data Processing Agreement
Legal · DPA

Data Processing Agreement

Last updated: 13 May 2026Document version: 2.0

For Practitioner and enterprise customers who process personal data of their own clients on Kaalveda. This DPA defines the controller / processor relationship under GDPR Article 28 and equivalent regulations.

Section 01

Scope and definitions

This Data Processing Agreement ("DPA") supplements the Terms of Service for customers (typically Practitioner and Enterprise) who use Kaalveda to process personal data of their own clients. Terms used here ("controller", "processor", "personal data", "processing", "sub-processor") have the meanings given in the GDPR Article 4 and the DPDPA 2023 Section 2.

Section 02

Roles

The customer is the Controller of client personal data uploaded to Kaalveda. Webliska.AI (operating Kaalveda) is the Processor acting on the Controller's documented instructions. For data Webliska.AI collects directly (billing, support tickets), Webliska.AI is the Controller; this DPA does not apply to that data.

Section 03

Subject matter and duration

Subject matter: computation of astrological / numerological readings from client DOB, time, place, name supplied by the Controller. Duration: for the duration of the Controller's active subscription. Termination triggers Article 11 below.

Section 04

Nature and purpose of processing

Nature: storage, computation, PDF generation, share-link delivery. Purpose: providing the Controller's requested service to its clients. No secondary purposes — no analytics on client data, no marketing, no enrichment.

Section 05

Types of personal data and data subjects

Personal data: name, date of birth, time of birth, place of birth, language preference, optional notes. Special-category data: none — none of these data points are themselves sensitive under GDPR Article 9. Data subjects: the Controller's clients (whose charts the Controller uploads to compute).

Section 06

Sub-processors

Webliska.AI uses sub-processors listed in the public sub-processor list (PayU, PayTM, Razorpay, Stripe, Amazon Web Services, Google). Adding a new sub-processor requires 30 days' advance notice; the Controller may object in writing, in which case Webliska.AI will offer a commercially reasonable alternative or allow termination.

Section 07

Security measures

Encryption at rest (AES-256). Encryption in transit (TLS 1.3). Access control: production data access limited to engineering staff with role-based permissions and audit logging. Password hashing: bcrypt with industry-standard cost factor. Payment data: tokenised at the browser; never stored on Kaalveda servers.

Section 08

Data subject rights

Where a data subject contacts Webliska.AI directly with a GDPR Article 15–22 request, we will redirect to the Controller within 5 business days. Where the Controller forwards a data subject request, we will assist within the 30-day GDPR window (typically 5–10 business days).

Section 09

Breach notification

Webliska.AI will notify the Controller without undue delay (and in any case within 72 hours) of becoming aware of a personal data breach affecting the Controller's data. Notification includes: nature of breach, categories and approximate numbers of data subjects, likely consequences, and mitigation measures.

Section 10

International transfers

Transfers outside the EEA are governed by Standard Contractual Clauses (Module 2 — Controller to Processor) as approved by the European Commission Decision 2021/914. Indian transfers follow DPDPA Section 16 with the relevant adequacy assessment.

Section 11

Audit rights

The Controller may audit Webliska.AI's compliance with this DPA once per year, on 30 days' written notice, during business hours, at the Controller's cost. Webliska.AI provides ISO 27001-equivalent self-assessment reports on request and will reasonably cooperate with on-site audits.

Section 12

Termination

On termination of the underlying subscription, Webliska.AI will (at the Controller's choice) delete or return all personal data within 30 days. The Controller may export a JSON / CSV bundle of client data before termination. Payment-related metadata is retained per the Privacy Policy.


Questions or feedback about this document? Email [email protected] for general inquiries, or [email protected] for legal matters.