Data Processing Agreement
Last updated: September 30, 2026
1. Who Is Who
This Agreement forms part of the Terms of Service between Maple Mind ("Processor") and the client subscribing to the Service ("Controller"). Where Maple Mind processes personal data on the Controller's behalf, this Agreement governs that processing. Where the two documents conflict on a data protection question, this Agreement takes precedence.
The Controller decides why and how the personal data of its own callers, leads, tenants and staff is processed. Maple Mind processes that data only on the Controller's documented instructions, which include the configuration the Controller sets in the dashboard.
2. Subject Matter, Duration, Nature and Purpose
- Subject matter: operation of an AI system that answers and places calls, captures leads, and maintains records on the Controller's behalf.
- Duration: for as long as the subscription is active, plus the retention window in section 8.
- Nature and purpose: receiving, transcribing and summarising calls; creating and updating lead, contact, property and work order records; sending notifications; producing usage and billing records.
3. Categories of Data and Data Subjects
Data subjects: the Controller's callers, leads, customers, tenants, and the Controller's own staff who hold dashboard logins.
Categories of personal data: names, phone numbers, email addresses, property and address details supplied during a call or entered in the dashboard, call audio and transcripts, call metadata (time, duration, outcome), notes and messages recorded against a record, and — for staff — login email, hashed password, role and session records.
The Service is not intended for special category data (health, biometric, financial account numbers, government identifiers). The Controller must not enter such data into the Service, and must not configure the AI to solicit it.
4. Our Obligations as Processor
- We process personal data only on the Controller's instructions, unless law requires otherwise, in which case we notify the Controller unless that notice is itself prohibited.
- Personnel with access to personal data are bound by confidentiality.
- We do not sell personal data, and we do not use a Controller's data to train AI models.
- A Controller's data is separated by tenant. Every request to the platform is bound to the session's own tenant at the gateway, so a request naming another tenant returns only the requester's own data.
- Actions taken by client users are recorded in an audit log that stores the identity and the action, not the message content.
5. Security Measures
- Encryption in transit (TLS) for all dashboard, API and webhook traffic.
- Encryption at rest for backups, with the backup key held separately from the backups.
- Passwords stored only as salted hashes; session tokens stored only as SHA-256 hashes, never in plain text.
- Role-based access enforced at the gateway rather than in the interface alone, so a restricted role cannot reach data by calling the API directly.
- Rate limiting, request size limits, and lockout after repeated failed logins.
- Administrative tooling is not exposed to the public internet.
- Daily backups with a documented restore procedure.
6. Sub-processors
The Controller authorises the following sub-processors. We will give at least 15 days notice by email before adding or replacing one, and the Controller may terminate the subscription without penalty if it objects to a new sub-processor before that change takes effect.
| Sub-processor | Purpose | Data reached |
|---|---|---|
| Omnidim | Voice AI: call answering, placing, transcription | Call audio, transcripts, caller phone number |
| Google (Gemini API) | Summarisation and drafting inside the product | Call summaries and record text sent for processing; not used for model training |
| Hostinger | Application and database hosting | All stored service data |
| Vercel | Hosting of the public websites | No client record data; web request logs only |
| Wise Business | Invoicing and payment collection | Billing contact and payment details |
| GoDaddy | Outbound email delivery | Recipient address and message content of service emails |
7. Data Subject Requests
Requests from data subjects (access, correction, deletion, portability, or withdrawal of consent) are the Controller's responsibility to answer. The dashboard lets the Controller read, correct, export and delete the records it holds. Where a request cannot be satisfied from the dashboard, we will assist within 7 days of a written request to privacy@maplemind.co.in. If a data subject contacts us directly, we redirect them to the Controller and do not act on the request ourselves.
8. Retention, Return and Deletion
- Paid accounts: after cancellation or non-payment the account is retained for 30 days so the Controller can export, then permanently deleted from live systems.
- Unpaid trials and pilots that were never converted: retained for 14 days after the trial ends, then permanently deleted.
- Deletion removes the tenant's records from every table that carries their account identifier, including calls, leads, contacts, properties, work orders, usage records, logins and sessions.
- Encrypted backups age out on their own retention cycle of up to 14 days after deletion, after which no copy remains.
- Billing and tax records are kept for the period Indian law requires, in a form that is not used to deliver the Service.
9. Personal Data Breach
We will notify the Controller without undue delay and in any case within 48 hours of becoming aware of a personal data breach affecting their data, describing what happened, which categories and roughly how many records are involved, the likely consequences, and the steps taken. The Controller remains responsible for any notification it owes to a regulator or to data subjects.
10. Audit
On written request, and no more than once in a 12-month period, we will provide a written description of the security measures in place and answer a reasonable security questionnaire. On-site audits are available where a supervisory authority requires one, at the Controller's cost and on 30 days notice.
11. International Transfers
Service data is stored on infrastructure located in India. Sub-processors listed in section 6 may process data outside India in the course of delivering their part of the Service. Where such a transfer occurs, it is made under the transfer terms of that sub-processor's own agreement with us, and limited to what that sub-processor needs.
12. Applicable Law
This Agreement is read alongside the Digital Personal Data Protection Act, 2023 and, for clients whose data subjects are in the United States, CCPA/CPRA. Where Maple Mind acts as a service provider under CCPA/CPRA, it does not retain, use or disclose personal information for any purpose other than performing the Service.
13. Contact
Maple Mind
Data protection: privacy@maplemind.co.in
Grievance Officer: grievance@maplemind.co.in
General: hello@maplemind.co.in