Legal
Data Processing Addendum
Last updated: 2026-08-24
This Data Processing Addendum ("DPA") supplements the Terms of Service between you (the customer) and Hyperneural Technologies LLP ("HyperFiling") and governs our processing of personal data on your behalf.
1. Roles of the parties
For personal data uploaded to your workspaces, you act as the Data Fiduciary and we act as a Data Processor in the sense of the Digital Personal Data Protection Act, 2023.
2. Scope of processing
- Subject matter: the workspace, document, query, draft, and audit log data your team uploads or generates.
- Duration: the term of the subscription, plus the export and deletion windows described in section 7.
- Nature and purpose: operating the AI compliance workspace, including citation-grounded research, document drafting, notice tracking, and billing.
- Categories of data: account data, usage data, content data, and communications.
3. Sub-processors
We engage cloud infrastructure providers, transactional email providers, payment processors, and LLM/embedding providers as sub-processors. The current list is available on request and is updated when the list materially changes.
4. Security measures
- Client data is stored in India (database and document storage located in Mumbai).
- TLS 1.2+ encryption in transit.
- Workspace isolation enforced in the application layer: every query is scoped to the workspaces the requesting user belongs to.
- Role-based access control on every authenticated surface.
- An audit log recording create, update, delete and export actions with the acting user and timestamp.
- AI processing enters via the Mumbai region; the provider profile in use may route outside India under load.
5. Breach notification
We notify you without undue delay and within seventy-two hours of becoming aware of a personal data breach affecting your data. The notice describes the nature of the breach, its likely consequences, and the measures taken or proposed.
6. Audit rights
We make available all information necessary to demonstrate compliance with this DPA. On reasonable notice and at most once per year, you may audit our security posture remotely. On-site audits require mutual agreement and may be subject to confidentiality undertakings.
7. Data return and deletion
On termination of the subscription, we will provide your workspace content on request. A self-service export is not yet available, so this is handled by our team; we would rather describe the process we actually operate than one we do not. Deleting a workspace removes its records from the database immediately. Deletion of the underlying stored files, and purging of backups within a defined window, are in progress and are not yet complete. Records that a law applicable to us requires us to retain are retained.