Legal
Data Processing Agreement
Last updated: July 1, 2026
This Data Processing Agreement (the "DPA") forms part of the agreement between Manav Research Lab Pvt. Ltd. and the customer who uses the Manav platform. It sets out how Manav processes personal data on the customer's behalf, including security measures, sub-processors, audit rights, and breach notification.
Parties
This Data Processing Agreement ("DPA") is entered into between:
-
Manav Research Lab Pvt. Ltd., a company incorporated in India with its registered office at 2165 Sushant Lok, Gurugram – 122002, Haryana, India ("Manav", the "Processor"); and
-
The customer identified in the relevant Order Form, Master Services Agreement, online sign-up, or other commercial agreement ("Customer", the "Controller").
Each a "Party", together the "Parties".
This DPA is incorporated into and forms part of the parties' main commercial agreement (the "Main Agreement"). If the Main Agreement and this DPA conflict, this DPA governs to the extent of the conflict, but only with respect to the processing of Personal Data.
1. Definitions
Capitalised terms used in this DPA have the meanings set out below. Terms used in this DPA but not defined here have the meaning given to them in the GDPR.
| Term | Meaning |
|---|---|
| Applicable Data Protection Law | All data-protection and privacy laws applicable to the processing of Personal Data under this DPA, including (a) the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"); (b) the United Kingdom GDPR; (c) the California Consumer Privacy Act ("CCPA") as amended by the CPRA; (d) the Digital Personal Data Protection Act, 2023 ("DPDP Act") of India; (e) any other applicable equivalent regional or national laws. |
| Personal Data | Any information relating to an identified or identifiable natural person, processed by Manav on behalf of the Customer in connection with the Services. |
| Data Subject | An identified or identifiable natural person to whom the Personal Data relates. |
| Processing | Any operation performed on Personal Data, including collection, storage, use, disclosure, transfer, and deletion. |
| Services | The Manav platform, agents, marketplace, APIs, and any related services provided by Manav to the Customer under the Main Agreement. |
| Sub-processor | Any third party engaged by Manav to process Personal Data on the Customer's behalf in the course of providing the Services. |
| Personal Data Breach | A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data processed under this DPA. |
| Standard Contractual Clauses or "SCCs" | The Standard Contractual Clauses approved by the European Commission for the transfer of personal data to third countries (Commission Implementing Decision (EU) 2021/914), and any successor instrument. |
2. Subject matter and duration
2.1 Subject matter. Manav processes Personal Data on the Customer's behalf strictly for the purpose of providing the Services and as documented in this DPA.
2.2 Duration. This DPA takes effect on the date the Customer enters into the Main Agreement and continues for as long as Manav processes Personal Data under the Main Agreement, including any post-termination period required for return or deletion of data under Section 14.
2.3 Description of processing. The categories of Data Subjects, categories of Personal Data, processing operations, purposes, and retention periods are described in Annex I to this DPA.
3. Roles of the parties
3.1 Customer is Controller. The Customer acts as the data Controller (or, where the Customer is itself a processor for an upstream controller, as a processor) of the Personal Data it submits to or generates through the Services.
3.2 Manav is Processor. Manav acts as a processor (or, where applicable, sub-processor) of the Personal Data and processes it only on the Customer's documented instructions.
3.3 Compliance responsibility. Each Party is responsible for compliance with its own obligations under Applicable Data Protection Law. Nothing in this DPA relieves the Customer of any of its obligations as a Controller (including obtaining valid consent or other lawful basis for the processing).
4. Manav's processing obligations
Manav shall:
(a) process the Personal Data only on the Customer's documented instructions, including with regard to transfers to third countries, unless required to do so by law (in which case Manav will inform the Customer of that legal requirement before processing, unless that law prohibits such information on important grounds of public interest);
(b) ensure that persons authorised to process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
(c) implement and maintain the technical and organisational measures described in Annex II to ensure a level of security appropriate to the risk;
(d) only engage Sub-processors in accordance with Section 7;
(e) assist the Customer in fulfilling its obligation to respond to requests for the exercise of Data Subject rights, by appropriate technical and organisational measures, taking into account the nature of the processing;
(f) assist the Customer in ensuring compliance with the obligations relating to security of processing, notification of Personal Data Breaches, data protection impact assessments, and prior consultation with supervisory authorities, taking into account the nature of the processing and the information available to Manav;
(g) at the choice of the Customer, delete or return all Personal Data to the Customer after the end of the provision of the Services, and delete existing copies unless retention is required by law (see Section 14); and
(h) make available to the Customer all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits as set out in Section 13.
5. Customer's instructions
5.1 Documented instructions. The Customer's documented instructions to Manav consist of (a) this DPA and the Main Agreement; (b) the configuration choices the Customer makes within the Services (including roles, permissions, retention settings, BYOLLM configuration, and sub-processor selections); and (c) any further written instructions issued by the Customer that Manav reasonably accepts.
5.2 Lawfulness of instructions. Manav will inform the Customer if, in Manav's reasonable opinion, an instruction infringes Applicable Data Protection Law. Manav is not obliged to follow an instruction that would, in its reasonable opinion, place it in breach of any law.
5.3 Additional fees. If an instruction requires Manav to perform work beyond the scope of the Services, Manav may charge reasonable fees, agreed in advance.
6. Confidentiality
6.1 Manav personnel authorised to process Personal Data are bound by written confidentiality obligations either by employment contract or by separate confidentiality agreement.
6.2 Access to Personal Data inside Manav is restricted on a need-to-know basis and is governed by role-based access controls. Manav reviews access entitlements at least annually.
6.3 Manav will not disclose Personal Data to a third party except as permitted by this DPA or as required by law. Where Manav is required by law to disclose Personal Data (for example, in response to a court order or government request), Manav will, where legally permitted, notify the Customer in advance and assist the Customer in challenging or limiting the scope of the disclosure.
7. Sub-processors
7.1 General authorisation. The Customer grants Manav a general authorisation to engage Sub-processors to process Personal Data on the Customer's behalf, subject to the safeguards in this Section 7.
7.2 Approved list. The current list of Manav's Sub-processors is set out in Annex III to this DPA and is published at manavagi.com/dpa#annex-iii-sub-processors.
7.3 Equivalent obligations. Manav will impose on each Sub-processor, by way of a written contract, data-protection obligations that are substantially the same as those set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures.
7.4 Change notification. Manav will give the Customer at least thirty (30) days' prior written notice before adding or replacing a Sub-processor. Notice may be given by email to the Customer's billing contact or by publication on the page referenced in Section 7.2 (with email notification to subscribed Customers).
7.5 Right to object. If the Customer has a legitimate, data-protection-related objection to a new Sub-processor, the Customer must notify Manav in writing within fifteen (15) days of the change notification. The Parties will work in good faith to find a resolution. If no resolution is possible within thirty (30) days, the Customer may terminate the affected portions of the Main Agreement with respect to the Services that cannot be provided without the new Sub-processor; the Customer's exclusive remedy in this event is termination, and termination fees do not apply to the affected portion.
7.6 Liability for Sub-processors. Manav remains fully responsible to the Customer for the performance of any Sub-processor's data-protection obligations.
8. Data Subject rights
8.1 Assistance. Taking into account the nature of the processing, Manav will assist the Customer by appropriate technical and organisational measures, insofar as possible, for the fulfilment of the Customer's obligation to respond to requests for the exercise of Data Subject rights (including access, rectification, erasure, restriction, portability, objection, and rights related to automated decision-making) under Applicable Data Protection Law.
8.2 Direct requests. If Manav receives a request directly from a Data Subject relating to Personal Data processed under this DPA, Manav will, unless legally required to respond, redirect the Data Subject to the Customer without disclosing any Personal Data to other parties, and notify the Customer of the request without undue delay.
8.3 Self-service tools. Where the Services include self-service tools (for example, dashboards to view, export, or delete Personal Data), Manav makes these tools available to the Customer to facilitate response to Data Subject requests.
9. Personal Data Breaches
9.1 Notification timeline. Manav will notify the Customer of a Personal Data Breach affecting the Customer's Personal Data without undue delay and in any event within seventy-two (72) hours after Manav becomes aware of the breach.
9.2 Contents of notification. The notification will, to the extent then known to Manav, include:
- a description of the nature of the breach, including, where possible, the categories and approximate number of Data Subjects and Personal Data records concerned;
- the likely consequences of the breach;
- the measures Manav has taken or proposes to take to address the breach, including measures to mitigate its possible adverse effects;
- the name and contact details of Manav's data-protection contact for further information.
9.3 Updates. Where, due to investigation timelines, the information cannot be provided at the same time, the information may be provided in phases without further undue delay.
9.4 Manav's notification obligation does not replace the Customer's own obligation to notify supervisory authorities or Data Subjects of a Personal Data Breach. Manav will reasonably assist the Customer in meeting any such obligation.
9.5 Notification mechanism. Notifications under this Section will be sent by email to the address designated by the Customer for security and incident-response notices, with a follow-up via the Customer's account dashboard.
10. Data Protection Impact Assessments
Manav will provide reasonable assistance to the Customer in carrying out data protection impact assessments and any prior consultation with supervisory authorities required under Articles 35 and 36 of the GDPR (or equivalent provisions of other Applicable Data Protection Law), taking into account the nature of the processing and the information available to Manav.
11. International data transfers
11.1 Hosting location. Personal Data submitted to the Services is stored primarily in the Republic of India (in the case of customers whose Order Form designates India) or in the Asia–Pacific (Mumbai, AWS ap-south-1) region. Where the Customer's Order Form designates a different region, that region applies.
11.2 Cross-border processing. Notwithstanding Section 11.1, processing operations may involve transfers to Sub-processors located outside the European Economic Area, the United Kingdom, or the Customer's home jurisdiction (see Annex III).
11.3 Transfer mechanism for EU/UK Personal Data. Where the Customer transfers Personal Data subject to the GDPR or the UK GDPR to Manav in a country that has not been recognised by the European Commission or the UK as providing an adequate level of protection, the Parties agree that:
(a) the Standard Contractual Clauses (Module 2: Controller to Processor) of Commission Implementing Decision (EU) 2021/914 are hereby incorporated by reference into this DPA and apply to such transfers;
(b) for the UK Addendum, the International Data Transfer Addendum issued by the UK Information Commissioner is hereby incorporated by reference;
(c) the optional clauses are completed as follows: docking clause (Clause 7) — applies; sub-processor change notification (Clause 9) — General authorisation, 30 days' notice (as in Section 7.4); option to use the SCCs as a stand-alone agreement (Clause 17) — governing law of the Member State in which the data exporter is established; choice of forum (Clause 18) — courts of the Member State in which the data exporter is established;
(d) Annex I.A (List of Parties), Annex I.B (Description of Transfer), Annex II (Technical and Organisational Measures), and Annex III (List of Sub-processors) of the SCCs are populated by the corresponding annexes to this DPA.
11.4 Transfer Impact Assessment. Manav has performed an internal transfer impact assessment evaluating the laws and practices of the destination countries. A summary is available to the Customer on request.
12. Compliance and records
12.1 Manav will maintain records of the processing of Personal Data on behalf of the Customer in accordance with Article 30(2) of the GDPR.
12.2 On reasonable written request, Manav will make available to the Customer the information necessary to demonstrate compliance with this DPA, including the records referred to in Section 12.1 (in redacted form to the extent necessary to protect Manav's confidential information or other customers' data).
13. Audit rights
13.1 Customer audits. Subject to the limitations in this Section 13, the Customer may, on reasonable prior written notice (not less than thirty (30) days, except in the case of a Personal Data Breach), audit Manav's compliance with this DPA.
13.2 Limitations on audits. Audits will be (a) conducted at the Customer's expense (other than where the audit reveals a material breach by Manav, in which case Manav bears the cost); (b) conducted during normal business hours and in a manner that does not unreasonably disrupt Manav's operations; (c) not more than once per twelve (12) month period (other than after a Personal Data Breach); (d) conducted by the Customer or an independent third-party auditor that is not a competitor of Manav and is bound by appropriate confidentiality obligations; and (e) limited in scope to information and systems relevant to the processing of the Customer's Personal Data.
13.3 Third-party reports. To minimise duplication of audits, Manav will, where available, make available to the Customer the most recent reports, certifications, or attestations issued by an independent third party regarding Manav's information-security controls (for example, SOC 2 or ISO 27001 reports, once obtained). The Customer agrees that, where such reports adequately address the audit scope, they fulfil the Customer's audit rights under this Section.
13.4 Supervisory authority audits. Nothing in this Section limits the rights of any data-protection supervisory authority with jurisdiction over the Customer or Manav.
14. Return and deletion of Personal Data
14.1 At end of Services. On termination or expiry of the Main Agreement, Manav will, at the Customer's choice, return all Personal Data to the Customer in a structured, commonly used, machine-readable format or delete the Personal Data, unless retention is required by Applicable Data Protection Law or by Manav's legitimate legal obligations (for example, financial-record-keeping requirements).
14.2 Deletion timeline. Manav will complete deletion within ninety (90) days of the Customer's instruction or, in the absence of an instruction, within ninety (90) days of termination of the Main Agreement.
14.3 Backups. Personal Data in routine backups will be deleted in accordance with Manav's backup-rotation policy (described in Annex II), and any Personal Data so retained remains subject to the obligations of this DPA until deletion is complete.
14.4 Audit log. Audit-log records may be retained in immutable form for the period required by Applicable Data Protection Law for accountability and dispute-resolution purposes, and will be anonymised or pseudonymised where statutory deletion obligations require so.
15. Liability
15.1 The liability of each Party under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Main Agreement.
15.2 Nothing in this DPA excludes or limits liability that cannot be excluded or limited by Applicable Data Protection Law (including the right of a Data Subject to claim compensation directly from a controller or processor under Article 82 GDPR).
16. Term and termination
16.1 This DPA continues in force for as long as Manav processes Personal Data under the Main Agreement, and survives termination of the Main Agreement to the extent necessary to give effect to Sections 9 (Personal Data Breaches), 13 (Audit rights), 14 (Return and deletion), 15 (Liability), 17 (Governing law), and 18 (Notices).
16.2 The Parties may amend this DPA in writing at any time if required to maintain compliance with Applicable Data Protection Law. Manav will notify the Customer of any such proposed amendment with reasonable advance notice.
17. Governing law and dispute resolution
17.1 Governing law. This DPA is governed by and construed in accordance with the laws of India, without regard to its conflict-of-laws principles.
17.2 Arbitration. Any dispute, controversy, or claim arising out of or in connection with this DPA, including any question regarding its existence, validity, or termination, will be referred to and finally resolved by arbitration administered by the Singapore International Arbitration Centre ("SIAC") in accordance with the SIAC Rules in force at the time of commencement of the arbitration, which rules are deemed to be incorporated by reference into this clause.
17.3 The seat of arbitration is Singapore. The Tribunal will consist of one (1) arbitrator appointed in accordance with the SIAC Rules. The language of the arbitration is English.
17.4 Equitable relief. Nothing in this Section prevents either Party from seeking urgent interim or injunctive relief from a court of competent jurisdiction to protect its intellectual property, confidential information, or other legitimate interests pending the outcome of the arbitration.
17.5 Enforcement. Each Party agrees that any arbitral award rendered under this Section may be enforced by any court of competent jurisdiction in accordance with the New York Convention on the Recognition and Enforcement of Foreign Arbitral Awards.
18. Notices
Notices under this DPA must be in writing and sent to:
-
To Manav: Manav Research Lab Pvt. Ltd., 2165 Sushant Lok, Gurugram – 122002, Haryana, India. Email: legal@manavagi.com (for legal notices) and security@manavagi.com (for security/breach notices).
-
To the Customer: the contact address and email designated in the Order Form, or, in the absence of such designation, the address and email associated with the Customer's account.
Notices are deemed received: (a) email — on the day of transmission, provided no failure notice is received; (b) registered post — five (5) business days after dispatch.
19. Miscellaneous
19.1 Order of precedence. In case of conflict between this DPA, the Main Agreement, and any Standard Contractual Clauses incorporated by reference, the order of precedence is: (1) Standard Contractual Clauses (only with respect to international transfers covered by them); (2) this DPA; (3) the Main Agreement.
19.2 Severability. If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions remain in full force and effect.
19.3 Entire agreement. This DPA, together with the Main Agreement and any Standard Contractual Clauses, constitutes the entire agreement between the Parties with respect to the processing of Personal Data and supersedes any prior written or oral agreement on this subject.
19.4 Counterparts. This DPA may be signed in counterparts, each of which is deemed an original and all of which together constitute one and the same instrument. Electronic signatures and signatures transmitted by email are valid.
Annex I — Description of processing
A. Parties
- Data Exporter (Controller): the Customer.
- Data Importer (Processor): Manav Research Lab Pvt. Ltd.
B. Categories of Data Subjects
The Personal Data processed under this DPA may relate to the following categories of Data Subjects:
- the Customer's employees, contractors, and authorised users of the Services;
- the Customer's clients, end-users, suppliers, and prospects whose data the Customer chooses to upload to or generate within the Services;
- any other natural person whose Personal Data the Customer submits to or generates through the Services.
C. Categories of Personal Data
| Category | Examples |
|---|---|
| Identity & contact data | Name, email address, phone number, organisation, job title, role. |
| Authentication data | Password hashes, multi-factor authentication tokens, API key identifiers, session tokens. |
| Usage data | Pages viewed, features used, agent invocations, API call counts. |
| Content data | Documents, files, prompts, knowledge-base entries, agent inputs and outputs, chat messages, task descriptions, comments. |
| Communications data | Email, in-product messages, support tickets. |
| Audit data | Records of who performed which action on which resource, with timestamps and request identifiers. |
| Billing data | Customer billing contact details, invoices, subscription state (card details are handled directly by the payment Sub-processor; Manav does not store card numbers or CVV codes). |
| BYOLLM credentials | When the Customer enables Bring-Your-Own-LLM, the Customer's own model-provider API keys, stored as Fernet-encrypted blobs. |
D. Special categories of data
Manav does not require or solicit special categories of Personal Data (as defined in Article 9 GDPR). The Customer must not upload special categories of Personal Data to the Services unless it has obtained appropriate consent or has another lawful basis and notifies Manav in writing in advance. Manav reserves the right to refuse or restrict processing of special categories where it lacks appropriate technical or organisational measures.
E. Processing operations and purposes
Manav processes Personal Data to:
- create and maintain the Customer's account, organisations, departments, roles, and user records;
- authenticate users and authorise actions according to the Customer's role/permission configuration;
- run agents, workflows, knowledge bases, and tools, including invoking model providers when the Customer's configuration requires;
- store and retrieve content the Customer uploads, generates, or queries through the Services;
- generate and store audit-log entries for accountability and security;
- generate and deliver invoices, process payments (via the payment Sub-processor), and manage subscription state;
- detect, investigate, and respond to security incidents, abuse, fraud, and policy violations;
- provide customer support and respond to Data Subject requests redirected by the Customer;
- improve the Services (in aggregated, pseudonymised form, and never by training foundation models on Customer Personal Data, see Section F).
F. Foundation-model training prohibition
Manav does not use Customer Personal Data, including prompts, files, content, or outputs, to train its own foundation models or those of any provider in a way that would cause that data to influence the model weights. Where the Customer uses an included model provider (instead of BYOLLM), Manav engages those providers under contracts that prohibit training on Manav's data.
G. Frequency of processing
Continuous, on demand for the duration of the Services.
H. Retention period
Personal Data is retained for the duration of the Customer's subscription, plus the periods set out in Section 14 of this DPA after termination. Audit-log records are retained for a minimum of twelve (12) months in immutable form to support security and compliance investigations, and may be retained longer where required by Applicable Data Protection Law or the Customer's instruction.
Annex II — Technical and organisational measures
These are the technical and organisational measures Manav implements to protect Personal Data. The measures are reviewed at least annually and updated as the threat landscape and the state of the art evolve.
A. Access control
- Authentication. Users authenticate via secure credentials (passwords hashed with bcrypt at cost factor ≥ 12, salted per-user; never stored in plaintext). Multi-factor authentication is available for every user account.
- Authorisation. Role-based access control (RBAC) is enforced at the application layer with fifty-seven (57) distinct resource types. Every protected route declares the required permission, scope (own / department / organisation / super-admin), and is gated by a middleware decorator before any data is read.
- Privileged access. Manav personnel access production systems on a strict need-to-know basis. Production credentials are stored in a secrets manager with audit logging on every retrieval.
- Account hygiene. Access entitlements are reviewed at least annually. Access is revoked promptly on personnel termination or role change.
B. Tenant isolation
- Every record in every production database carries an
org_idcolumn. Tenant-scoping is enforced at the middleware/query layer before any read or write reaches the database. - Cross-organisation reads are architecturally prevented; there is no admin role with cross-tenant audit-log access.
C. Encryption
- In transit. All public endpoints and internal service-to-service calls use Transport Layer Security (TLS 1.2 or higher).
- At rest — credentials. Sensitive credentials (third-party API keys, BYOLLM model keys, OAuth tokens) are stored as Fernet-encrypted blobs. Master encryption keys are stored separately from the encrypted data.
- At rest — passwords. Passwords are bcrypt-hashed with per-user salt and a cost factor commensurate with industry practice. Plain-text passwords are never stored, transmitted internally, or logged.
- At rest — data store. Production database storage is encrypted at the storage layer by the underlying cloud provider (AWS EBS encryption or equivalent).
D. Audit logging
- An append-only audit log records every action performed via an authenticated route, including: actor, action, resource type and identifier, organisation, timestamp, request identifier, and (where applicable) the change payload (before/after diff).
- Audit-log entries cannot be edited or deleted by application code.
- Audit logs are scoped to the organisation that owns the resource and are queryable by organisation administrators through the Customer's dashboard.
E. Backups and resilience
- Production databases are backed up automatically at least daily, with backups encrypted at rest.
- Backup retention follows a rolling window appropriate to the recovery-point objective (typically 7–30 days for short-term backups; longer periods for compliance backups).
- Disaster-recovery procedures are documented and tested at least annually.
F. Network and infrastructure security
- Production infrastructure is hosted with a major cloud provider (see Annex III) within isolated virtual private cloud (VPC) environments.
- Public-facing services are protected by web application firewalls and rate limiting.
- Internal services are not exposed to the public internet; access is mediated through application-layer authentication.
G. Software development lifecycle
- Code changes are submitted via pull request, reviewed by at least one other engineer, and subject to automated test suites before merge to the main branch.
- Dependencies are tracked, and known-vulnerable versions are patched on a defined cadence according to severity.
- Production deployments use signed, reproducible build artefacts.
H. Incident response
- Manav maintains an incident-response procedure covering detection, triage, containment, investigation, remediation, customer notification (per Section 9 of this DPA), and post-incident review.
- Security-relevant events are monitored 24/7 by an on-call rotation.
- Incidents involving Personal Data Breaches are reported to Customers within seventy-two (72) hours per Section 9.
I. Personnel
- All employees and contractors who may access Personal Data sign confidentiality agreements before joining.
- All personnel undergo security and data-protection training during onboarding and annually thereafter.
- Background checks are performed for personnel in privileged roles, to the extent permitted by Applicable Data Protection Law.
J. Sub-processor management
- Sub-processors are reviewed for data-protection and security posture before engagement.
- Sub-processors are bound by written contracts containing data-protection obligations substantially equivalent to those of this DPA.
- The Sub-processor list (Annex III) is reviewed and updated, and Customers are notified of changes per Section 7.4.
K. Customer-side controls
The Services also offer Customer-configurable security features that the Customer may use to strengthen the security of its tenant, including:
- multi-factor authentication enforcement;
- role and permission tuning;
- per-agent, per-tool, and per-knowledge-base access scoping;
- Human-in-the-Loop approval gates for irreversible actions;
- audit-log review through the dashboard;
- Bring-Your-Own-LLM for organisations that prefer that their prompts stream directly to their own model-provider account rather than Manav's.
Annex III — Approved Sub-processors
The following Sub-processors process Personal Data on the Customer's behalf as of the effective date of this DPA. This list is reviewed at least annually and is updated as Sub-processors are added or replaced (with notification per Section 7.4).
| Sub-processor | Service provided | Location of processing | Transfer mechanism (if applicable) |
|---|---|---|---|
| Amazon Web Services, Inc. | Compute, storage (including S3 for uploaded documents), and primary database hosting. | Asia–Pacific (Mumbai), ap-south-1 (primary). Secondary or backup may be in additional AWS regions as designated by the Order Form. | AWS Data Processing Addendum; SCCs where applicable. |
| Stripe, Inc. | Payment processing, billing, and invoice generation. | United States. | Stripe DPA + SCCs (Module 2). |
| Anthropic, PBC | Large-language-model inference, when the Customer uses included Anthropic models (not BYOLLM). | United States. | Anthropic DPA + SCCs (Module 2). No training on Customer data per provider terms. |
| OpenAI, L.L.C. | Large-language-model inference, when the Customer uses included OpenAI models (not BYOLLM). | United States. | OpenAI DPA + SCCs (Module 2). No training on Customer data per provider terms. |
| Cloudflare, Inc. | DNS, content delivery, distributed-denial-of-service protection. | Global edge network. | Cloudflare DPA + SCCs (Module 2). |
Transactional email provider (specific provider listed at manavagi.com/dpa#annex-iii-sub-processors) | Sending account verification, password reset, billing notifications, and system emails to the Customer's users. | Varies by provider; current provider's hosting region is listed at the link above. | Provider's DPA + SCCs (Module 2) where applicable. |
Note on BYOLLM. Where the Customer has enabled Bring-Your-Own-LLM, the Customer's prompts and content stream from the Services directly to the model provider designated by the Customer using the Customer's own API key. In that flow, the model provider is not a Sub-processor of Manav (the Customer engages the model provider directly under that provider's own terms); Manav does not retain the prompt-and-content payload alongside the BYOLLM key.
Signatures
This DPA is incorporated by reference into the Main Agreement and is binding on both Parties from the effective date of the Main Agreement, without the need for separate signature. Where the Customer or its procurement team requires an executed copy, contact legal@manavagi.com for a counter-signed PDF version.
For and on behalf of Manav Research Lab Pvt. Ltd.:
Name: [Signatory name] Title: [Signatory title] Date: __________
For and on behalf of Customer:
Name: __________ Title: __________ Date: __________