Version 1.1 · Effective Sep 03, 2026
This Data Processing Agreement ("DPA") is between the Customer that accepts it (the "Customer" or "Fiduciary") and SKAD Business Solutions Private Limited, Promenade 3 - 606, 6th Floor, LBS Road, Opp. R City Mall, Ghatkopar (West), Mumbai, Maharashtra 400086, India ("SKAD" or "Processor"). It forms part of the Terms of Service and is accepted by ticking the single acceptance checkbox at sign-up or by confirming acceptance when a new version is presented. Version 1.1, effective 3 September 2026. Replaces version 1.0 dated 3 September 2026.
1.1 "Workforce Data" means personal data about the Customer's employees, former employees, candidates, contractors, signatories and other individuals that the Customer uploads to or generates in the Service.
1.2 "Processing", "Data Fiduciary", "Data Processor", "Data Principal" and "personal data breach" have the meanings in the Digital Personal Data Protection Act, 2023 ("DPDP Act").
1.3 "Sub-processor" means a third party SKAD engages to process Workforce Data.
2.1 The Customer is the Data Fiduciary for all Workforce Data, including workforce, candidate and employee data. SKAD is the Data Processor and processes Workforce Data only on behalf of and under the documented instructions of the Customer. SKAD does not process Workforce Data for its own purposes.
2.2 SKAD is a Data Fiduciary in its own right only for the Customer's own account data, billing data and usage data, as described in the Privacy Policy. This DPA does not apply to that data.
2.3 An HR consultant that accepts this DPA does so both for itself and as agent for each client company it adds. The consultant warrants that it holds written authority from each client to do so and that each client is bound as the Fiduciary for its own Workforce Data. The consultant indemnifies SKAD against all claims, losses and penalties arising from any lack of that authority.
3.1 SKAD will process Workforce Data only: (a) as needed to provide the Service features the Customer uses; (b) as instructed through the Service's settings and controls; (c) as instructed in writing by the Customer; and (d) as required by law, in which case SKAD will inform the Customer unless the law prohibits it.
3.2 The Terms of Service, this DPA and the Customer's use of the Service's features are the Customer's complete and documented instructions. SKAD will tell the Customer if it believes an instruction breaks the law.
3.3 Annex A describes the subject matter, duration, nature, purpose, categories of data and categories of Data Principals.
4.1 The Customer warrants that: (a) it has a lawful basis under the DPDP Act and applicable employment law for every item of Workforce Data it processes through the Service; (b) it has given each Data Principal the notice required by section 5 of the DPDP Act, including the Employee Notice presented at portal invitation where applicable; (c) for every Aadhaar number it records or Aadhaar image it uploads, the Customer is the Data Fiduciary and holds the employee's consent in the form the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and the Aadhaar Regulations require, the purpose is limited to PF, ESIC, professional tax and other statutory registrations and filings, SKAD acts as Data Processor only, and the Customer indemnifies SKAD for any unlawful collection or use; (d) its instructions comply with law.
4.2 The Customer is responsible for responding to Data Principal requests and for the accuracy of Workforce Data.
4.3 The Customer will keep its own copies of statutory records (wage registers, payslips, filings, appointment letters) outside the Service. The Service is not a system of record for statutory compliance.
4.4 The Customer will configure roles, access and retention settings appropriately and is responsible for the acts of its users. Aadhaar numbers are shown only to the Customer's owner and admin roles and are retained only for as long as the Customer instructs.
5.1 The Customer authorizes SKAD to engage the Sub-processors listed in Annex B. SKAD publishes the current list at hrtailor.ai/sub-processors and keeps it up to date.
5.2 SKAD will give at least 15 days' notice, in the Service or by email, before adding or replacing a Sub-processor that will process Workforce Data. The Customer may object in writing on reasonable data protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Service feature or the Service, and SKAD will refund any prepaid fees for the unused period.
5.3 SKAD will impose data protection obligations on each Sub-processor no less protective than this DPA and remains responsible for their performance.
5.4 AI providers: SKAD will route Workforce Data only to AI Sub-processors that contractually commit not to use API inputs to train their models. The Customer may disable AI features for its company account. Workforce Data is never used to train or improve SKAD's own prompts or models without the Customer's separate written instruction.
SKAD will ensure that staff and contractors who access Workforce Data are bound by confidentiality, are trained, and access it only as needed to provide and support the Service. Administrative access is logged.
7.1 SKAD will implement and maintain reasonable security safeguards appropriate to the nature of Workforce Data, as required by section 8(5) of the DPDP Act, including at least: encryption in transit; encryption of stored credentials and provider keys; tenant isolation enforced on every request; signed, expiring download links; role-based access; rate limiting and abuse controls; vulnerability and patch management; daily backups; personal data removed from logs; and access logging for administrative tools. Annex C summarizes the measures.
7.2 SKAD may update the measures provided the overall level of protection is not reduced.
8.1 SKAD will, at the Customer's request, provide reasonable assistance for the Customer to respond to Data Principal requests (access, correction, erasure, nomination, grievance), using the Service's export and deletion features where available.
8.2 SKAD will provide information reasonably needed for the Customer's own compliance assessments, subject to clause 11.
8.3 Assistance beyond what the Service provides as standard is chargeable at SKAD's then-current professional rates, unless caused by SKAD's breach.
9.1 SKAD will notify the Customer without undue delay and in any event within 24 hours after confirming a personal data breach affecting Workforce Data, by email to the account owner and the Customer's nominated security contact. Notification is triggered only by a confirmed breach affecting personal data; suspected incidents that are found not to involve personal data are not notified.
9.2 The notice will describe, as far as known: the nature of the breach; categories and approximate numbers of Data Principals and records; likely consequences; measures taken or proposed; and a contact point. SKAD will provide updates as facts emerge. A notice is given to inform the Customer and is not an admission of liability by SKAD.
9.3 The Customer, as Data Fiduciary, is responsible for notifying the Data Protection Board of India and the affected Data Principals. SKAD will assist with those notifications and will not notify the Customer's Data Principals directly unless the law requires or the Customer asks. The Customer bears the cost of its own notifications.
9.4 Where SKAD is itself required to notify the Board or affected users as a Data Fiduciary for its own data, it will do so without undue delay, aiming for 72 hours from confirmation, and bears the cost of those notifications only.
10.1 During the term, the Customer may export Workforce Data through the Service and delete records at any time.
10.2 Within 30 days after the end of the Service, SKAD will delete Workforce Data from live systems, and backups will age out within 14 days after that, except data SKAD must keep by law, which stays subject to this DPA. On request made before the end of the Service, SKAD will return the Workforce Data by providing an export in a common machine-readable format.
10.3 SKAD will certify deletion in writing on request.
11.1 Written questionnaire. The Customer may send SKAD a reasonable written security or data protection questionnaire at any time. SKAD will answer within a reasonable period and will make available summaries of any third-party security assessments or certifications it holds.
11.2 Audit. Where the Customer has documented cause (for example a regulator's requirement, or a confirmed breach affecting the Customer's Workforce Data), the Customer may conduct one on-site or remote audit in any 12-month period, on 30 days' written notice, during SKAD's business hours, at the Customer's cost, by the Customer or an independent auditor bound by confidentiality. The audit is limited to the systems and records that process the Customer's Workforce Data and will never access, copy or touch another customer's data.
12.1 Workforce Data is hosted in India. The Sub-processors in Annex B may process it in the countries listed there. In particular, OpenAI, L.L.C., Cloudflare, Inc. and Google LLC process data in the United States and, through their global networks, in other countries, and Dodo Payments, Inc. processes account and billing data in the United States. By accepting this DPA the Customer acknowledges and consents to these transfers.
12.2 If the Central Government restricts transfers to a country under section 16 of the DPDP Act and a Sub-processor processes Workforce Data in that country, SKAD will suspend that Sub-processor for Workforce Data until the transfer is lawful again or a replacement is in place, and will notify the Customer. SKAD gives no further guarantee about the laws of the countries in which Sub-processors operate.
13.1 Each party's liability under this DPA is subject to the limitations and exclusions in clause 13 of the Terms of Service, and the INR 25,000 aggregate cap there applies to this DPA and the Terms together, not separately.
13.2 The Customer is liable for regulatory penalties, claims and losses arising from its own processing decisions, lack of lawful basis, consent or notice, or unlawful instructions, including penalties imposed on SKAD as Data Processor because of the Customer's instructions, and indemnifies SKAD for them under clause 4.4 of the Terms. Only penalties caused solely by SKAD's own breach are excluded.
13.3 SKAD is liable for losses caused by its breach of this DPA, subject to clause 13.1.
14.1 This DPA lasts as long as SKAD processes Workforce Data for the Customer.
14.2 On any conflict about data protection, this DPA prevails over the Terms of Service.
14.3 Governing law and disputes: clause 15 of the Terms of Service applies.
| Item | Description |
|---|---|
| Subject matter | HR operations of the Customer through the Service |
| Duration | Term of the Customer's use of the Service, plus the deletion periods in clause 10 |
| Nature and purpose | Storage, organization, retrieval, document generation (including AI drafting), payroll computation, attendance and leave management, electronic acceptance of documents, communication with Data Principals at the Customer's instruction, deletion |
| Categories of Data Principals | Employees, former employees, candidates, contractors, interns, signatories, emergency contacts named by employees |
| Categories of data | Identity and contact; employment details; government identifiers (PAN, UAN, passport, visa, Aadhaar where required for statutory registrations and filings, stored encrypted); financial and payroll; attendance and one-time clock-in location; leave including any reason stated; documents and signatures; survey, review, exit-interview and background-check responses; uploaded files |
| Special categories | Only as incidentally entered by the Customer or the Data Principal in free-text fields |
| Sub-processor | Location | Purpose |
|---|---|---|
| DigitalOcean LLC | Bangalore, India | Hosting, storage, backups |
| Cloudflare, Inc. | Global edge, including the United States | CDN, DDoS and bot protection, TLS |
| OpenAI, L.L.C. | United States | AI generation (API, no training on inputs under its API terms) |
| OpenRouter, Inc. (configured, currently disabled) | United States | AI generation through third-party models for free tools only; never Workforce Data unless the route is marked no-training |
| Zoho Corporation (ZeptoMail) | India | Transactional email at the Customer's instruction |
| Google LLC (Maps Platform) | United States and global | Address auto-complete and geocoding |
| Dodo Payments, Inc. | United States | Billing (Customer account data only, not Workforce Data) |
Transport encryption (TLS 1.2 or higher); bearer tokens with hashed storage and 30-day expiry; passwords hashed with bcrypt; provider secrets encrypted at rest; per-request tenant scoping validated against membership records; signed, expiring, user-bound download links; uploads stored outside the web root or blocked from direct access; content sanitization of generated HTML; rate limiting per IP and per account; email recipients restricted to the Customer's own workforce directory; daily encrypted database backups with 14-day retention; personal data excluded from application logs; administrative actions logged; vulnerability patching of the operating system and dependencies; annual review of these measures.
Change summary (version 1.1): roles restated (SKAD processor for all workforce, candidate and employee data, fiduciary only for account data); consultant written-authority warranty and indemnity; Aadhaar consent, purpose limit, visibility and retention terms; no SKAD training on Workforce Data; breach notice limited to confirmed breaches, no admission of liability, cost allocation and 72-hour target; questionnaire any time and one audit per year on documented cause; named cross-border sub-processors with the suspension rule; liability aligned to the INR 25,000 cap and processor-penalty indemnity; en-US spelling.
Earlier versions are listed on the legal history page.