Data Processing Addendum
The terms on which Graciax processes personal data on behalf of its customers. Part of the Terms & Conditions for every workspace.
This Data Processing Addendum (“DPA”) forms part of the Terms & Conditions between Keyakash Technologies Private Limited, trading as Graciax (“Graciax”, “we”), and the customer that holds a Graciax workspace (“Customer”, “you”). It applies whenever Graciax processes personal data on your behalf, including data that reaches Graciax from a platform you connect — a Shopify store, a Meta ad account, a WhatsApp Business number, a calendar or a telephony line.
1. Parties and Roles
For personal data in your workspace — your leads, your customers, their orders, calls and messages — you are the controller (or a processor acting for your own client) and Graciax is your processor. For the account data of your own team members, and for the website, Graciax is the controller as described in the Privacy Policy.
2. Scope, Purpose and Duration
Subject matter. The provision of the Graciax CRM and the AI features you enable. Nature. Storage, retrieval, display, transmission (messages, calls, emails you send), analysis and automated replies by AI agents within limits you set. Purpose. Running your sales, support and operations in your workspace. Data subjects. Your leads, customers, contacts, callers and, where you connect them, your store’s customers. Categories. Names, phone numbers, email addresses, city and country, order and enquiry details, call recordings and transcripts, messages, notes and the outcomes your team records. Duration. For as long as you hold a workspace, plus the deletion periods in Section 11.
3. Processing on Instructions
Graciax processes personal data only on your documented instructions: the Terms, this DPA, the features you configure and the requests your users make in the product. We will tell you if we believe an instruction breaks the law. We do not use your data for our own marketing, we do not sell it, and we do not use it to train AI models — nor do we permit our model providers to.
4. Confidentiality
Graciax staff who can reach production data are limited to those who need to run and support the service, are bound by confidentiality obligations, and act only on a support request or an operational need that is logged.
5. Security Measures
- Encryption. TLS on every connection; data encrypted at rest; credentials and access tokens for connected platforms encrypted with keys held outside the database and never sent to a browser.
- Isolation. Every row is bound to a workspace and enforced with row-level security; one customer’s data is never visible to another.
- Access control. Roles inside your workspace (admin, manager, user) decide who sees what; your admin can further restrict who may open customer details from a connected store.
- AI guardrails. Agents act only within the limits you configure, verify the person they are talking to before disclosing a record, keep internal data internal, and log every action they take.
- Operations. Signed webhooks, rate limits, audit logs, encrypted backups, and a documented incident process. More on the Security page.
6. Sub-processors
You authorise the sub-processors below. Each is bound by a written contract imposing data-protection obligations no less protective than this DPA. We will post any addition on this page at least 30 days before it processes customer data; if you object on reasonable grounds, you may terminate the affected feature or your subscription without penalty.
| Sub-processor | Purpose | Location |
|---|---|---|
| Cloud database and authentication provider (named on request) | Database, file storage, authentication | United States / Singapore |
| Cloud hosting provider (named on request) | Application hosting | United States (global edge) |
| Cloudflare | DNS, edge network and protection | Global |
| Anthropic, OpenAI, Google | AI models for AI Studio and agents (no training on your data) | United States |
| Meta Platforms | WhatsApp Business API messaging, Lead Ads, Marketing API | United States / Ireland |
| Twilio, Exotel, Plivo | Telephony and SMS | United States / India |
| ElevenLabs, Deepgram, Cartesia | Voice AI, speech recognition and synthesis | United States |
| Microsoft, Google | Calendar and booking sync, when connected | United States / EU |
| Shopify | Store data, when a store is connected | Canada / United States |
| Resend / your SMTP provider | Transactional email from your own sender | United States / as configured |
7. Data Subject Requests
Your workspace lets you find, correct, export and delete a person’s record yourself. If a data subject contacts Graciax directly, we will not respond on the merits; we will pass the request to you within five business days and act on your instruction. Requests that arrive through a platform (Shopify’s customers/data_request and customers/redact, Meta’s data deletion callbacks) are honoured automatically as described on the data deletion page.
8. Personal Data Breaches
We will notify you without undue delay, and in any case within 72 hours of becoming aware of a personal data breach affecting your data, with what we know: the nature of the breach, the data and people concerned, the likely consequences and the measures taken. We will update you as the investigation proceeds and cooperate with any notification you must make.
9. Assistance and Audits
We assist you with data-protection impact assessments and regulator consultations that concern our processing, at cost where the effort is material. On written request, no more than once a year unless a breach or a regulator requires it, we will provide the information reasonably needed to demonstrate compliance with this DPA — our security documentation and our sub-processors’ current audit reports (our hosting, database and edge-network providers each hold SOC 2 Type II attestations). The named list of infrastructure sub-processors is provided under this DPA on request to support@graciax.com.
10. International Transfers
Graciax is operated from India. Data is stored with our sub-processors in the locations listed above and may be accessed from India for support. Where a transfer of personal data out of India, the EEA, the UK or another jurisdiction with transfer rules is involved, it is made under the sub-processor’s standard contractual clauses or an equivalent mechanism, in line with the Digital Personal Data Protection Act, 2023 and the applicable law of the data’s origin.
11. Return and Deletion
While you hold a workspace you may export your data at any time. When you delete your workspace or your subscription ends, we delete your personal data within 30 days and from encrypted backups within a further 30, except what the law requires us to keep (invoices, tax records). Data from a connected platform follows that platform’s notices as well — for Shopify, the mirror is deleted on the shop/redact notice 48 hours after uninstall. See the data deletion page.
12. Platform Data: Shopify, Meta and Others
When you connect a platform, you confirm you have the rights and consents needed to share that data with Graciax, and Graciax processes it only to operate the features you enabled, under that platform’s developer terms as well as this DPA. For Shopify in particular, we hold the minimum needed: order, customer contact, product and checkout data as described in the Privacy Policy; never the full delivery address or payment card data; access limited to your workspace by role; and deletion on disconnect, uninstall and Shopify’s redaction notices.
13. Liability and Precedence
Each party’s liability under this DPA is subject to the limitations in the Terms. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails. Changes to this DPA are posted on this page with a new date; material changes are notified to the workspace admin.
14. Contact
Data protection enquiries: support@graciax.com (subject line “Data protection”). Keyakash Technologies Private Limited, Rainmakers Workspace, Sree Gururaya Mansion, 8th Main Rd, KSRTC Layout, 3rd Phase, J. P. Nagar, Bengaluru 560078, Karnataka, India.