Skip to main content

ENTERPRISE COMPLIANCE

DPDP & Security Addendum

Data Processing Addendum (DPA)

Standard data processing agreement between RedBlackTree Technologies Pvt. Ltd. ("Data Processor") and Enterprise Customers ("Data Fiduciary").

1. Purpose & Processing Instructions

This Data Processing Addendum governs the processing of customer personal data by RedBlackTree Technologies Pvt. Ltd. on behalf of the customer. Methodical processes customer data strictly in accordance with documented customer instructions and solely for the purpose of delivering the platform services.

2. Approved Sub-Processors Registry

Methodical maintains a strict, vetted registry of third-party sub-processors located within India:

Sub-ProcessorProcessing FunctionData Location
Amazon Web Services (AWS)Cloud infrastructure, Postgres databases, vector storageMumbai & Hyderabad, India
Digio (DigitSecure)Aadhaar OTP eSign gateway & KYC verificationBangalore, India
Razorpay SoftwarePayment gateway & credit pack billingBangalore, India

3. Technical & Organizational Measures (TOMs)

  • Encryption in Transit & at Rest: TLS 1.3 for all web and API traffic; AES-256 for database storage and backups.
  • Role-Based Access Control (RBAC): Strict least-privilege access enforcement inherited by all automated agent tasks.
  • Multi-Factor Authentication (MFA): Mandatory MFA for all engineering and administrative console access.
  • Continuous Vulnerability Scanning: Automated container and code dependency vulnerability checks before every production release.