Roles
In official deployments, the engaging institution acts as the data fiduciary (controller) and Vinkura acts as a data processor. This Data Processing Agreement (DPA) framework describes how Vinkura processes personal data on behalf of the institution.
Scope & Purpose
Vinkura processes personal data only on documented instructions from the institution and solely for the purposes defined in the governing master service agreement. Processing is scoped to what is necessary for the agreed operational outcome.
Security Measures
The executed DPA identifies the technical and organisational measures applicable to the deployment. Depending on scope, these may include role-based access control, encryption, logging, backup, change management, and incident response. Security documentation and any current third-party assurance artefacts are provided during due diligence subject to appropriate confidentiality terms.
Data Residency
Deployments can be configured for on-premise, sovereign-cloud, or hybrid boundaries so that personal data remains within jurisdictional and infrastructure constraints defined by the institution.
Sub-Processors
The executed DPA defines whether sub-processors may be used, the notice or approval process, and the obligations passed to them. A current list of applicable sub-processors is provided to the institution on request.
Data Subject Rights & Breach Notification
Vinkura assists the institution in responding to data principal requests and in meeting breach-notification obligations under the DPDP Act and applicable law, within the timelines defined in the governing agreement.
Return, Deletion, and Audit
The executed DPA defines data return or deletion at the end of services, lawful retention exceptions, evidence of deletion where applicable, and the institution’s audit or information rights.
Requesting an Executed DPA
This page describes the DPA framework and is not itself a contract. An executable DPA is provided as part of institutional procurement. To request a copy, contact our team.
