Data Processing Agreement
GDPR Article 28 terms for the business data you store in Loparna ERP
Version 2026-09 · Last updated: September 2026
This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between Loparna Software Pvt Ltd (“Processor”, “we”) and the customer that uses Loparna ERP (“Controller”, “you”). It applies whenever we process personal data on your behalf that is subject to the EU General Data Protection Regulation (GDPR), the UK GDPR or the Swiss FADP. By accepting the Terms you accept this DPA. If you need a signed copy, email info@loparna.com.
1. Subject matter, nature and purpose
We host and process the data you enter into Loparna ERP solely to provide the service you subscribed to: invoicing, inventory, accounting, tax compliance, point of sale, HRM, payroll and reporting.
2. Categories of data subjects and personal data
| Data subjects | Typical personal data |
|---|---|
| Your customers and suppliers (and their contact persons) | Name, address, email, phone, tax number, bank details, transaction history |
| Your employees | Name, contact details, ID and tax numbers, nationality, salary, attendance, leave, statutory contributions, bank account |
| Your users | Name, email, phone, role, activity log |
Loparna ERP is not designed for special categories of data (Art. 9). Do not enter health, religious or similar data unless the law requires you to and you have assessed it.
3. Duration
For the term of your subscription. When it ends we keep your data for 30 days so you can export it, then delete it, unless the law requires us to keep it.
4. Our obligations as processor
- We process personal data only on your documented instructions — these Terms, this DPA and your use of the product — including for international transfers, unless EU or member-state law requires otherwise (in which case we tell you first where legally allowed).
- Everyone authorised to process your data is bound by confidentiality.
- We implement the security measures in section 6 (Art. 32).
- We engage sub-processors only as set out in section 5.
- We help you answer data-subject requests: the product lets you export, correct and delete records, and we assist on request.
- We help you with security, breach notification, data-protection impact assessments and prior consultation (Art. 32–36), taking into account the information available to us.
- At the end of the service we delete or return all personal data at your choice; the in-app export (My Account → Privacy & Data) returns everything in machine-readable JSON.
- We make available the information needed to demonstrate compliance and allow for audits, normally by providing documentation and certifications; on-site audits require 30 days’ notice and are at your cost.
- We tell you immediately if we believe an instruction infringes data-protection law.
5. Sub-processors
You give general authorisation for the sub-processors below. We will inform you by email at least 30 days before adding or replacing one, and you may object; if we cannot address the objection, you may terminate the affected service. Each sub-processor is bound by data-protection obligations at least as protective as this DPA.
| Sub-processor | Service | Data processed | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, database and storage | All customer data | India — AWS Asia Pacific (Mumbai), ap-south-1 |
| Google LLC (Gmail SMTP) | Delivery of service emails | Recipient email address and email content | USA / global |
| Stripe, PayPal, Razorpay | Online payments you choose to use | Payment details entered at checkout | Provider’s own infrastructure |
6. Technical and organisational measures (Art. 32)
- Encryption in transit with HTTPS/TLS for all connections.
- Logical separation of every customer’s data by tenant, enforced in the application.
- Role-based access control; passwords stored only as salted hashes; account lock-out after repeated failed sign-ins.
- Audit log of sign-ins and important actions; IP addresses removed after 90 days.
- Hosting in AWS data centres in the Mumbai (ap-south-1) region, with physical, environmental and network security certified to standards such as ISO 27001.
- Staff access to customer data only where needed to provide support, and under confidentiality.
- Data minimisation: fonts and scripts are self-hosted, and no tracking or advertising tools are used.
7. Personal data breaches
We notify you without undue delay, and where feasible within 48 hours, after becoming aware of a personal data breach affecting your data, with the information you need to meet your own notification duties (Art. 33–34).
8. International transfers
Loparna Software Pvt Ltd is established in India and hosts all customer data in the AWS Asia Pacific (Mumbai) region in India. Transfers of personal data from the EEA, the UK or Switzerland to us or our sub-processors in countries without an adequacy decision are covered by the European Commission’s Standard Contractual Clauses (Decision 2021/914) — Module 2 (controller to processor) between you and us, and Module 3 (processor to processor) with sub-processors — plus the UK Addendum where applicable. These clauses are incorporated into this DPA by reference.
9. Liability and precedence
Liability is governed by the Terms and Conditions. If this DPA conflicts with the Terms, this DPA prevails for the processing of personal data; the Standard Contractual Clauses prevail over both.
10. Contact
Data-protection questions and requests: info@loparna.com. See also our Privacy Policy.