ENTERPRISE COMPLIANCE
DPDP & Security AddendumData Processing Addendum (DPA)
Standard data processing agreement between RedBlackTree Technologies Pvt. Ltd. ("Data Processor") and Enterprise Customers ("Data Fiduciary").
1. Purpose & Processing Instructions
This Data Processing Addendum governs the processing of customer personal data by RedBlackTree Technologies Pvt. Ltd. on behalf of the customer. Methodical processes customer data strictly in accordance with documented customer instructions and solely for the purpose of delivering the platform services.
2. Approved Sub-Processors Registry
Methodical maintains a strict, vetted registry of third-party sub-processors located within India:
| Sub-Processor | Processing Function | Data Location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, Postgres databases, vector storage | Mumbai & Hyderabad, India |
| Digio (DigitSecure) | Aadhaar OTP eSign gateway & KYC verification | Bangalore, India |
| Razorpay Software | Payment gateway & credit pack billing | Bangalore, India |
3. Technical & Organizational Measures (TOMs)
- Encryption in Transit & at Rest: TLS 1.3 for all web and API traffic; AES-256 for database storage and backups.
- Role-Based Access Control (RBAC): Strict least-privilege access enforcement inherited by all automated agent tasks.
- Multi-Factor Authentication (MFA): Mandatory MFA for all engineering and administrative console access.
- Continuous Vulnerability Scanning: Automated container and code dependency vulnerability checks before every production release.