Legal

Data Processing Addendum (DPA)

Last updated: 21 July 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between the customer named on the applicable Order Form or workspace registration ("Customer") and Seers Pvt. Ltd., registered at Bengaluru, Karnataka, India ("Seers"). It applies whenever Seers processes Personal Data on Customer's behalf in the course of providing the Service. In the event of any conflict between this DPA and the Terms of Service on matters of data protection, this DPA prevails.

1. Subject matter and duration

Seers processes Personal Data on behalf of Customer for the purpose of providing the HR and payroll management Service described in the Terms of Service. Processing begins on the date Customer first submits Personal Data to the Service (including during a free trial) and continues for the duration of the active subscription, the 30-day post-termination export window, and any statutory retention period that applies to specific categories of data. After all applicable periods expire, Seers will delete Personal Data from production and backup systems as set out in §11 below.

2. Nature and purpose of processing

Seers processes Personal Data as necessary to perform the following functions on Customer's behalf:

  • Employee and contractor record management (creation, updates, role assignment, status changes).
  • Payroll computation, payslip generation, and period reconciliation.
  • Attendance event recording, geofence evaluation (if enabled by Customer policy), and leave management.
  • Audit log maintenance for all write operations within the workspace.
  • Notifications and communications to Authorized Users on Customer's behalf (e.g. payslip release notifications, leave approval emails).
  • Export and reporting functions initiated by Authorized Users.
  • Technical support when Customer raises an incident or support ticket.

Seers does not process Personal Data for any purpose beyond those listed above and Customer's documented instructions. Seers will promptly inform Customer if, in Seers' opinion, an instruction infringes applicable data protection law.

3. Categories of Data Principals

Personal Data processed under this DPA relates to the following categories of individuals:

  • Employees of Customer - current and former.
  • Contractors and consultants of Customer whose records are managed in the Service.
  • Candidates - where Customer uses any applicant-tracking features to manage prospective hires.
  • Customers of the Customer - only to the extent Customer enters third-party data into the Service (e.g. client billing contact for commission tracking). Customer warrants it has a lawful basis for this.

4. Categories of personal data

  • Identifiers - name, employee code, email address, mobile number, date of birth (if entered by Customer).
  • Contact and employment data - residential address (if entered), department, designation, reporting structure, hire date, employment type, and current status.
  • Payroll and financial data - compensation structure, allowances, deductions, net pay, bank account number for salary disbursement, PAN, and (last four digits only where required) Aadhaar reference.
  • Attendance and geolocation data - clock-in/out timestamps, source device identifier, and GPS coordinates only when Customer has enabled a geolocation attendance policy and Authorized Users consent to location sharing in the mobile or web client.
  • Biometric data - Seers does not collect biometric data directly. If Customer integrates a third-party biometric device, raw biometric templates remain on the device or in Customer's chosen integration; Seers receives only the derived attendance event (a timestamp and employee identifier).
  • Communications and support data - content of support tickets, in-app messages, and any attachments submitted by Authorized Users.

5. Roles of the parties

  • Customer = Data Fiduciary (DPDPA) / Data Controller (GDPR) - Customer determines the purposes for which and the manner in which Personal Data is processed. Customer is responsible for having a valid lawful basis for processing and for providing required notice to Data Principals.
  • Seers = Data Processor (DPDPA and GDPR) - Seers processes Personal Data only on the documented instructions of Customer and not for its own purposes. Seers acts as Data Fiduciary only for data it independently collects for account management and marketing (described in the Privacy Notice).

6. Processor obligations

  • Instructions - Seers will process Personal Data only in accordance with Customer's documented instructions, including those set out in this DPA and the Terms of Service. Where Seers is required to process Personal Data by applicable law, Seers will inform Customer unless prohibited.
  • Confidentiality - Seers will ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations.
  • Security - Seers will implement the technical and organisational measures described in Annex II (§9) of this DPA.
  • Sub-processor disclosure - Seers will engage sub-processors only as permitted under §7 and will remain responsible to Customer for sub-processor compliance with this DPA.
  • Assistance with Data Principal requests - Seers will provide reasonable technical assistance to enable Customer to honour Data Principal rights requests (access, correction, erasure, portability) within 7 days of a documented request from Customer.
  • Breach notification - Seers will notify Customer of any confirmed or suspected Personal Data breach as set out in §10.
  • Deletion or return - Seers will delete or return Personal Data on termination as set out in §11.
  • Audit cooperation - Seers will make available to Customer all information reasonably necessary to demonstrate compliance with this DPA and will cooperate with audits as set out in §11 (Audit rights).

7. Sub-processors

Customer grants Seers a general authorisation to engage the sub-processors listed at /sub-processors. Seers will provide Customer with at least 14 days' advance notice of any new sub-processor or material change to an existing sub-processor via email to the registered tenant Owner and via the sub-processor list page.

  • Customer may object to a new sub-processor on reasonable data protection grounds during the 14-day notice period by emailing legal@seers.co.in. Seers will work with Customer in good faith to resolve the objection; if unresolved, Customer may terminate the affected services without penalty.
  • Seers enters into a written data processing agreement with each sub-processor containing data protection obligations equivalent to those in this DPA.
  • Seers remains fully liable to Customer for any breach of this DPA caused by a sub-processor acting on Seers' instructions.

8. International transfers

Personal Data is stored and processed within the AWS Mumbai (ap-south-1) region. No Personal Data is routinely transferred outside of India under current operations.

If a future sub-processor engagement requires transfer of Personal Data outside India (e.g. a global SMTP relay, CDN, or error-monitoring service), Seers will:

  • Update the sub-processor list and provide 14 days' advance notice as required under §7.
  • Apply contractual safeguards equivalent to the EU Standard Contractual Clauses (SCCs) or other mechanisms approved under applicable law.
  • Ensure the receiving entity provides an equivalent level of protection for the transferred data.

9. Security measures (Annex II - Technical and Organisational Measures)

Seers implements the following technical and organisational measures:

  • Encryption in transit - All data transmitted between clients and Seers servers is protected by TLS 1.2 or higher. Older protocol versions are rejected.
  • Encryption at rest - Database backups and managed file storage are encrypted at rest (AES-256). Platform credentials (SMTP keys, payment API keys) are encrypted using pgcrypto with per-record keys.
  • Password security - User passwords are hashed with argon2id with per-user salt. Passwords are never stored or logged in recoverable form.
  • Role-based access control (RBAC) - Access within each tenant is governed by roles assigned by Customer's Owner. Seers engineering staff access to production data is restricted to authorised personnel and recorded.
  • Tenant isolation - Row-level scoping in the database and middleware-level tenant checks prevent cross-tenant data access at every layer.
  • Audit logging - Every write operation is recorded with actor identity, action type, affected resource, and timestamp. Audit logs are retained for 7 years and are read-only to all users.
  • Backup and recovery - Automated daily backups with point-in-time recovery capability. Backups are retained in-region and tested periodically.
  • Key rotation - Encryption keys and API credentials are rotated on a defined schedule and upon any suspected compromise.
  • Vulnerability management - Seers conducts periodic dependency audits and reviews for known vulnerabilities. Security patches are applied on a risk-prioritised basis.
  • Incident response - Seers maintains an internal incident response procedure covering detection, classification, containment, eradication, and post-incident review. All confirmed incidents are logged and assessed for breach notification obligations.
  • Certifications - Seers does not currently hold ISO 27001 or SOC 2 certifications. We are happy to provide a detailed security questionnaire response or arrange a controls walkthrough for enterprise customers.

10. Breach notification

In the event of a confirmed Personal Data breach:

  • Seers will notify affected Customers within 72 hours of becoming aware of the breach, to the extent information is available at the time of notification.
  • The notification will include: the nature of the breach, categories and approximate number of Data Principals and records affected, likely consequences, and measures taken or proposed to address the breach.
  • For severe incidents meeting CERT-In reporting thresholds, Seers will file the required notification to CERT-In within the applicable window (currently 6 hours) in parallel with Customer notification.
  • Customer is responsible for its own notifications to affected Data Principals and, where applicable, regulatory bodies, once informed by Seers.
  • Breach notifications will be sent to the email address of the registered tenant Owner. Customers should ensure this address is kept current.

11. Audit rights

  • Customer may audit Seers' compliance with this DPA once per year upon at least 30 days' written notice, or at any time following a confirmed breach.
  • Standard audits are conducted on a summary-report basis (Seers provides a written responses to a standardised security questionnaire and evidence pack). On-site audits are available for Enterprise plan customers on mutual agreement.
  • All audit activities are subject to confidentiality obligations at least as protective as those in the Terms of Service §8.
  • Customer bears its own costs of any audit. If Customer engages a third-party auditor, that auditor must sign a confidentiality agreement acceptable to Seers before accessing any Seers systems or documentation.

12. Return and deletion of data

On termination or expiry of the Terms of Service:

  • Customer retains the ability to export Customer Data via built-in CSV and PDF exports for a 30-day export window.
  • After the export window, Seers will delete Personal Data from production systems within 60 days, subject to backup retention of up to 35 days for disaster recovery purposes.
  • Seers may retain data longer than the above periods only where required by applicable Indian law (e.g. payroll records under the Income-Tax Act). Such data will be retained for the minimum period required and will not be used for any other purpose.
  • On request, Seers will provide written confirmation of deletion to Customer.

13. Liability

Each party's liability under this DPA is subject to the limitation of liability provisions in the Terms of Service §14. Seers is not liable for breaches caused by Customer's own instructions, Customer's misconfiguration of access controls, or Customer's failure to notify Seers of incorrect or unlawful processing instructions.

14. Governing law

This DPA is governed by the laws of India. Disputes arising under this DPA are subject to the exclusive jurisdiction of courts at Bengaluru, Karnataka, unless the parties have agreed to arbitration in an Order Form. Where the EU GDPR applies, this DPA shall be interpreted consistently with GDPR requirements, and Customer and Seers agree to co-operate to incorporate any supplementary measures required by applicable supervisory authority guidance.

This document is governed by Indian law. For enterprise customers requiring a signed counterpart of this DPA, email legal@seers.co.in with your workspace slug and registered legal entity name.

See also: Privacy Notice · Sub-processor list · Terms of Service · SLA.