Data Processing Agreement (template)

The data processing agreement Rejynx offers business customers, with Rejynx as processor: the GDPR Article 28 terms, international transfers under the Standard Contractual Clauses, India's DPDP Act, the CCPA's service-provider terms, our security measures and our subprocessors.

Updated 27 September 2026

This Data Processing Agreement ("DPA") is between the customer’s name, the customer’s address (the "Customer"), and Raheed Mujawar, Gogol, Aquem, Goa 403601, India ("Rejynx"). It forms part of the agreement under which Rejynx provides the Rejynx service to the Customer (the "Main Agreement"), and applies whenever Rejynx processes Customer Personal Data on the Customer's behalf.

1. Definitions

  • Data Protection Law means every law on the processing of personal data that applies to the processing under this DPA, including, where they apply: Regulation (EU) 2016/679 (the "GDPR"); the UK GDPR and the Data Protection Act 2018; the Swiss Federal Act on Data Protection; India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (the "DPDP Act"); the data protection laws of Saudi Arabia, the United Arab Emirates, Qatar, Bahrain, Oman, Kuwait and Egypt; and the California Consumer Privacy Act, as amended (the "CCPA").
  • Customer Personal Data means personal data that Rejynx processes on the Customer's behalf under the Main Agreement, as described in Annex I.
  • Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
  • Subprocessor means a processor engaged by Rejynx to process Customer Personal Data.
  • SCCs means the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914 of 4 June 2021. The UK Addendum means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner, in force since 21 March 2022.
  • "Controller", "processor", "data subject", "personal data" and "processing" have the meanings in the GDPR; they include "data fiduciary", "data processor" and "data principal" under the DPDP Act, and "business" and "service provider" under the CCPA.

2. Roles and scope

2.1 The Customer is the controller of Customer Personal Data, and Rejynx is its processor.

2.2 Rejynx's app processes most data only on each user's phone, where Rejynx has no access to it. That data isn't Customer Personal Data processed by Rejynx under this DPA; the users and the Customer control it.

2.3 Annex I describes the subject matter, duration, nature and purpose of the processing, and the types of personal data and categories of data subjects.

3. Instructions

3.1 Rejynx processes Customer Personal Data only on the Customer's documented instructions, including about transfers to a third country or an international organisation, unless required to do so by a law to which Rejynx is subject: for personal data under the GDPR, only Union or Member State law; for personal data under the UK GDPR, only domestic law of the United Kingdom; for other Customer Personal Data, the law that applies to that processing. In that case Rejynx tells the Customer of that legal requirement before processing, unless that law forbids it on important grounds of public interest. This DPA, the Main Agreement and the Customer's use of the service's settings are the Customer's instructions.

3.2 Rejynx tells the Customer at once if, in its opinion, an instruction infringes Data Protection Law.

3.3 Other countries' laws and public authorities. Rejynx is established outside the EEA and the UK, and its server is in Singapore. For personal data under the GDPR or the UK GDPR, a law of another country (for example India's or Singapore's), or a public authority's request under one, isn't an exception to section 3.1. If one would require Rejynx to process, disclose or keep such data other than on the Customer's instructions, Rejynx: (a) tells the Customer promptly, and, where that law forbids telling it, uses its best efforts to obtain a waiver so that it can; (b) reviews whether the request is lawful, and challenges it where, after careful assessment, it concludes there are reasonable grounds to consider it unlawful, including by appeal; (c) discloses or keeps no more than the minimum that a reasonable reading of the request or law requires; and (d) keeps a record of the request and what it did, and gives it to the Customer where allowed. Where the SCCs apply, their Clauses 14 and 15 govern, and this section doesn't reduce them.

4. Confidentiality

Rejynx ensures that everyone it authorises to process Customer Personal Data is bound by confidentiality, by contract or by law.

5. Security

5.1 Rejynx implements the technical and organisational measures in Annex II, to ensure a level of security appropriate to the risk, as Article 32 of the GDPR and section 8(5) of the DPDP Act require.

5.2 Rejynx may update those measures as long as the overall level of protection isn't reduced.

6. Subprocessors

6.1 The Customer gives Rejynx general authorisation to engage the Subprocessors listed in Annex III.

6.2 Rejynx will tell the Customer at least 30 days before engaging a new Subprocessor, by updating its subprocessor page and emailing the Customer's contact. The Customer may object on reasonable data protection grounds within 15 days. If the parties can't resolve the objection, the Customer may terminate the affected part of the service and receive a pro-rata refund of any prepaid fees for it.

6.3 Rejynx imposes on each Subprocessor, by contract, data protection obligations that give at least the same protection as this DPA, and remains responsible to the Customer for each Subprocessor's performance.

6.4 Where Rejynx must replace a Subprocessor urgently to keep the service running safely, it may do so with shorter notice, and tells the Customer as soon as it can; the Customer's right to object still applies.

7. Data subjects' rights

7.1 Taking into account the nature of the processing, Rejynx helps the Customer, by appropriate technical and organisational measures where possible, to respond to requests from data subjects to exercise their rights.

7.2 If Rejynx receives such a request directly about Customer Personal Data, it forwards it to the Customer without undue delay and doesn't respond itself, except to direct the person to the Customer.

7.3 Most data is on users' phones, where users can see and delete it themselves. Rejynx doesn't store the content of questions (Annex I).

8. Assistance

Taking into account the nature of the processing and the information available to it, Rejynx helps the Customer meet its obligations on security, Personal Data Breach notification, data protection impact assessments and prior consultation with supervisory authorities (Articles 32 to 36 of the GDPR), and the equivalent duties under other Data Protection Law.

9. Personal Data Breaches

9.1 Rejynx notifies the Customer without undue delay, and in any case within 72 hours, after becoming aware of a Personal Data Breach.

9.2 The notice describes, as far as known then: the nature of the breach, including the categories and approximate number of data subjects and records concerned; the likely consequences; the measures taken or proposed; and a contact for more information. Information that isn't available at first is provided in phases, without undue delay.

9.3 Rejynx cooperates with the Customer and takes reasonable steps to contain and remedy the breach. The Customer, as controller, decides on and makes notifications to supervisory authorities and data subjects, including those due within 72 hours under the GDPR and the DPDP Rules, and any report that India's CERT-In Directions require of the Customer itself. Where those Directions apply to Rejynx, Rejynx reports a cyber incident on its own systems to CERT-In within 6 hours of noticing it, as they require of it, and tells the Customer that it has, without waiting for the Customer's decision on its own notifications. Rejynx's written breach response procedure is available to the Customer on request.

9.4 Notifying or responding to a Personal Data Breach isn't an admission of fault.

10. Deletion and return

When the Main Agreement ends, Rejynx deletes Customer Personal Data, and any copies (or returns it, if the Customer asks within 30 days and it's still held), unless Union or Member State law (for personal data under the GDPR), domestic law of the United Kingdom (for personal data under the UK GDPR), or for other Customer Personal Data the law that applies to it, requires it to be kept; any other country's requirement to keep it is handled as section 3.3 describes. Because Rejynx doesn't store the content of questions, in practice this concerns only logs, which are deleted on their normal schedule (Annex I). Rejynx confirms deletion in writing on request.

11. Information and audits

11.1 Rejynx makes available to the Customer all information necessary to demonstrate compliance with this DPA and Article 28 of the GDPR.

11.2 Rejynx allows for and contributes to audits, including inspections, by the Customer or an independent auditor it mandates, bound by confidentiality: on at least 30 days' written notice, no more than once in any 12 months (unless a supervisory authority requires it or after a Personal Data Breach), during business hours, without disrupting the service, and at the Customer's cost. Rejynx may first offer written answers and documents, and an on-site audit takes place only if those aren't enough.

12. International transfers

12.1 Rejynx's server is in Singapore, and some Subprocessors process data in the United States and elsewhere (Annex III).

12.2 EEA. To the extent the Customer's transfer of Customer Personal Data to Rejynx is a restricted transfer under the GDPR, Module Two (controller to processor) of the SCCs is incorporated into this DPA by reference, with these choices: Clause 7 (docking clause) applies; in Clause 9(a), Option 2 (general written authorisation) applies, with the notice period in section 6.2; the optional wording in Clause 11 doesn't apply; in Clause 13, the competent supervisory authority is the Data Protection Board of India; Clauses 17 and 18 choose the law and courts of Ireland; Annexes I, II and III of the SCCs are completed by the Annexes of this DPA.

12.3 United Kingdom. For restricted transfers under the UK GDPR, the UK Addendum applies, with its tables completed by the Annexes of this DPA and section 12.2, and neither party may end it under its Section 19 (changes to the Approved Addendum) except as that section allows.

12.4 Switzerland. For transfers under the Swiss Federal Act on Data Protection, the SCCs apply as in section 12.2, with references to the GDPR read as references to that Act, and the Federal Data Protection and Information Commissioner as the competent authority.

12.5 Onward transfers. Rejynx ensures that each transfer to a Subprocessor outside the EEA, the UK or Switzerland is covered by an adequacy decision (such as the EU–US Data Privacy Framework, for a certified Subprocessor) or by the SCCs (Module Three, processor to processor) or the UK Addendum, and helps the Customer with any transfer impact assessment.

12.6 India. Rejynx won't transfer Customer Personal Data to a country the Central Government has restricted under section 16 of the DPDP Act.

12.7 Other countries. Where another Data Protection Law restricts transfers (for example Saudi Arabia's Transfer Regulations), the parties use a mechanism that law allows, such as its standard contractual clauses.

13. India: the DPDP Act

Where the DPDP Act applies: this DPA is the valid contract under which the Customer, as data fiduciary, engages Rejynx as data processor (section 8(2)); Rejynx processes Customer Personal Data only for the purposes in Annex I; Rejynx keeps the reasonable security safeguards in Annex II; Rejynx notifies Personal Data Breaches under section 9 so that the Customer can inform the Data Protection Board and each affected data principal (section 8(6) and Rule 7); and Rejynx erases Customer Personal Data when the Customer instructs it to, or when the Main Agreement ends (section 8(7)), except where the law requires it to be kept.

14. California: service-provider terms

Where the CCPA applies, Rejynx is the Customer's service provider, and: (a) doesn't sell or share Customer Personal Data; (b) doesn't retain, use or disclose it for any purpose, including any commercial purpose, other than the business purposes in the Main Agreement, or outside the direct business relationship with the Customer; (c) doesn't combine it with personal information it receives from anyone else or collects itself, except as the CCPA regulations allow; (d) complies with the CCPA and provides the same level of privacy protection the CCPA requires of the Customer; (e) tells the Customer if it can no longer meet its obligations under the CCPA; and (f) allows the Customer to take reasonable and appropriate steps to make sure Rejynx uses Customer Personal Data consistently with the Customer's CCPA obligations, and to stop and remedy any unauthorised use. Rejynx certifies that it understands and will comply with these restrictions.

15. The Middle East

Where the data protection laws of Saudi Arabia, the United Arab Emirates, Qatar, Bahrain, Oman, Kuwait or Egypt apply, the parties apply this DPA in the way that meets their equivalent requirements, including the shorter breach notification deadlines some of them set (Rejynx's breach response procedure lists them), and Rejynx gives the Customer reasonable help with any registration, licence or local representative those laws require of the Customer.

16. Liability, term and precedence

16.1 Each party's liability under this DPA is subject to the limits in the Main Agreement, except where Data Protection Law or the SCCs don't allow that.

16.2 This DPA lasts as long as Rejynx processes Customer Personal Data.

16.3 If they conflict, the SCCs (or UK Addendum) prevail over this DPA, and this DPA prevails over the Main Agreement.

16.4 This DPA is governed by the law that governs the Main Agreement (the laws of India), except where the SCCs or the UK Addendum say otherwise.

Signatures

CustomerRejynx
Namethe customer’s signatoryRaheed Mujawar
Title
Date
Signature

Annex I: Description of the processing

A. Parties

Data exporter (controller)Data importer (processor)
Namethe customer’s nameRaheed Mujawar
Addressthe customer’s addressGogol, Aquem, Goa 403601, India
Contactthe customer’s contacthello@raheed.dev
ActivitiesProvides Rejynx to its authorised usersProvides the Rejynx service

B. The processing

Data subjectsThe Customer's authorised users of the Rejynx app; people or businesses named in their questions or bills (typically billers)
Personal dataThe text of questions users send to the cloud, and the earlier cloud messages of that chat (at most 20, each at most 8,000 characters); for questions about bills or money, bill summaries limited to payee, category, amount, minimum due, due date and status (at most 50), from bills typed, pasted, imported from a PDF or read from the user's SMS (never from the user's Gmail); a random installation ID; IP address; the app's user agent. Never the text of SMS or emails, OTPs, transactions or balances
Sensitive dataNone intended. Users could type or paste sensitive information into a question, such as a biller's message with account digits: the app sends a question as written (a bank's message about an account excepted, which it keeps on the phone), and the server doesn't check its text. Safeguards: questions sealed to the server, no storage of content, AI providers that keep nothing (Annex III), "Ask before using cloud", and the user's own ledger of what left the phone
FrequencyContinuous: each time a user sends a question to the cloud
NatureReceiving a question, relaying it to an AI provider and streaming the answer back; rate limiting; security logging
PurposeAnswering users' questions; keeping the service secure and available
RetentionQuestions, chats and bill summaries: in memory only, for the length of the answer (at most 5 minutes); the reverse proxy may hold a large request, sealed, in a temporary file on the server's disk while passing it on, deleted when the request ends (Annex II). Each question's random nonce: in memory, 5 minutes, to refuse replays. Installation ID: in memory, forgotten within about 90 seconds of a user's last question. IP addresses in the reverse proxy's access and error logs: 14 days. The server's own error lines (designed to hold no personal data): until overwritten (the log is capped at 30 MB)
SubprocessorsAs in Annex III, for the same processing, for the duration of the Main Agreement

C. Competent supervisory authority: the Data Protection Board of India.

Annex II: Technical and organisational measures

Minimising what's processed

  • The app processes bills, messages (the SMS it reads on Android with the user's permission, the bill emails it reads in the user's Gmail, pasted text), statements, transactions, balances and chats on the phone. It never sends the server the text, senders, account numbers or UPI IDs of the messages and statements it reads, OTPs, the user's transactions and balances, or anything read from the user's Gmail, the bills found there included. The only free text the server receives is what users write in their questions, which can include anything a user pastes there.
  • The server accepts only an allow-listed set of bill fields and refuses any request with another field before any AI provider is called; an automated test fails if this check is loosened.
  • Each request is limited: at most 40 messages of at most 8,000 characters, at most 50 bills, at most 700 KB sealed (about 512 KB before sealing).

No storage of content

  • The server keeps no content: questions and answers exist only in memory while an answer is written, and the server never writes them to a file, a database or a log. Its only database holds the optional accounts (a random ID, an HMAC of the provider's user ID, the email if given, encrypted with its own key, the day made, the plan and its end), sessions' hashes, plans and each day's count of answers, on a disk the host encrypts at rest. The reverse proxy (nginx) writes a request larger than its body buffer (8 or 16 KB by default) to a temporary file while passing it on, sealed; the file is unlinked at once and its space freed when the request ends.
  • The server's own log contains no questions, answers, keys, IP addresses or installation IDs: only the provider, tier, model, status and the provider's error message (cut to 300 characters when a provider refuses a request). The reverse proxy's access and error logs hold IP addresses, times, request lines, status codes and user agents, never content (Annex I).

Encryption

  • All traffic between the app and the server, and between the server and AI providers, uses HTTPS (TLS). Plain HTTP is redirected to HTTPS.
  • Inside HTTPS, each question is sealed on the phone to the server's public key (HPKE, RFC 9180: DHKEM(X25519, HKDF-SHA256), HKDF-SHA256, ChaCha20-Poly1305) and opened only in the server's process, so the reverse proxy, its logs and anything between see only the sealed body. Each answer is sealed for the phone that asked, piece by piece, with a key from the same exchange and fresh server randomness; a changed, missing, repeated or reordered piece fails. Questions sealed more than 2 minutes from the server's clock, or already seen in the last 5 minutes by the server process that receives them, are refused; a copy that reaches another of its processes is answered, sealed afresh, which only the phone that asked could read.
  • The server's private key is kept in the owner-only environment file, never logged, and rotated with a next key while phones move over. The container is started with that file as its environment, so the key is also readable there by anyone with Docker or root access on the host; moving it to a read-only file or a Docker secret is planned.

Access and secrets

  • The server listens only on the machine's local interface, behind a reverse proxy; its container port is bound to localhost.
  • Provider keys and the app key are kept in a file with owner-only permissions, never in source code, and never logged. The app key is compared in constant time.
  • Administrative access is over SSH with a key, limited to Raheed Mujawar, the only person with access to the servers.
  • Browser (CORS) access is off in production.

Availability and resilience

  • Rate limits per network address (at the reverse proxy) and per installation (in the server); admission control that refuses new requests when a worker is nearly out of CPU; time limits on every answer; automatic restarts; CPU and memory caps on the container.

Isolation

  • The server runs in its own container, network and project, as an unprivileged user, with CPU and memory caps.

AI providers

  • OpenRouter is used with zero-data-retention routing and data collection denied (set on every request by the server's code); Cloudflare is used without any storage service; Groq is used with zero data retention on in its console's Data Controls (an account setting, on for the whole account and for its inference APIs, confirmed on 27 September 2026), so it doesn't log or store inputs or outputs.

On the phone (not Customer Personal Data processed by Rejynx, listed for completeness)

  • The database encrypted with SQLCipher under a key made on the phone and kept in its secure storage, for that device only; deleted chats and bills overwritten in the database; backups off unless the user turns them on (then only the encrypted database, with its key in iCloud Keychain on iPhone, or on Android only into a backup encrypted end to end with the screen lock); PDF reading in a sandboxed view with no network or file access; no third-party analytics, advertising or crash-reporting code.

Organisation

  • Confidentiality commitments for everyone with access; a documented breach response procedure; a data protection impact assessment and records of processing (each available to the Customer on request), reviewed at least once a year and before significant changes; dependencies checked for security advisories before each release.

Annex III: Subprocessors

SubprocessorProcessingLocation
Oracle (Oracle Cloud Infrastructure)Hosting of Rejynx's serverSingapore
Groq, Inc.AI model inferenceUnited States
Cloudflare, Inc.AI model inference (Workers AI)Worldwide (Cloudflare's network)
OpenRouter, Inc., and the zero-data-retention model hosts it selectsRouting to, and inference by, AI modelsUnited States and varies

The current list, with what each receives, is at Who processes data for us.