This Data Processing Agreement ("DPA") forms part of the agreement between Luit Infotech Pvt. Ltd. ("Luit Infotech", "LuitBiz", "Processor") and the customer organization ("Customer", "Controller") that uses LuitBiz products and services.
This DPA outlines the responsibilities, obligations, and commitments relating to the processing of personal data in connection with the provision of LuitBiz software and services.
This DPA should be read together with:
The purpose of this DPA is to establish a transparent framework governing:
Luit Infotech processes personal data solely for the purpose of:
Luit Infotech does not process personal data for unrelated purposes without authorization from the Customer.
Depending on customer usage, personal data may include:
User Information
Customer Information
System Information
Documents & Records
Data uploaded by customers into:
Customers remain responsible for determining what data is stored within the system.
Luit Infotech agrees to:
Process Data Only on Instructions
Process personal data solely according to documented instructions from the Customer unless otherwise required by law.
Maintain Confidentiality
Ensure that personnel with access to personal data are bound by confidentiality obligations.
Implement Security Measures
Maintain reasonable administrative, technical, and organizational safeguards designed to protect customer data.
Assist the Customer
Provide reasonable assistance in responding to:
Luit Infotech maintains security controls designed to protect customer data against unauthorized access, disclosure, alteration, or destruction.
Security controls may include:
Security practices are reviewed periodically to address evolving threats and business requirements.
LuitBiz cloud environments are hosted on enterprise-grade infrastructure designed to provide:
Customer data may be processed within approved infrastructure locations necessary for service delivery.
Luit Infotech may engage trusted third-party service providers ("Subprocessors") to support service delivery.
Examples may include:
Luit Infotech remains responsible for ensuring that subprocessors maintain appropriate data protection obligations.
Where personal data is transferred across jurisdictions, Luit Infotech will implement reasonable safeguards designed to support applicable privacy and data protection requirements.
Such safeguards may include:
Where applicable, Luit Infotech will provide reasonable assistance to Customers in responding to requests relating to:
Customers remain responsible for managing and responding to requests from their users and data subjects.
In the event of a confirmed security incident affecting customer personal data, Luit Infotech will:
Notification timing may vary depending on the nature and severity of the incident.
Customer data will be retained only as necessary to:
Upon termination of services and subject to applicable agreements:
Customers may request information reasonably necessary to evaluate:
Luit Infotech may satisfy such requests through:
Customers are responsible for:
Luit Infotech cannot determine the legality of customer data processing activities.
Luit Infotech may update this DPA periodically to reflect:
Updated versions will be published on this page with a revised effective date.
Liability relating to data processing activities shall be governed by applicable contractual agreements, Terms of Service, and applicable laws.
Nothing in this DPA expands liability beyond limitations otherwise agreed between the parties.
For questions regarding data processing, privacy, security, or compliance matters, please contact:
Luit Infotech Pvt. Ltd.
Email: sales[AT]luitinfotech.com
Website: https://www.luitbiz.com
Luit Infotech is committed to responsible data stewardship, strong security practices, and transparent processing activities. This Data Processing Agreement reflects our commitment to helping customers meet privacy, security, governance, and compliance obligations while using LuitBiz products and services.
A Data Processing Agreement defines how a service provider processes and protects personal data on behalf of customers.
The Customer acts as the Controller and determines how personal data is used. Luit Infotech acts as the Processor and processes data according to customer instructions.
No. Luit Infotech does not sell customer personal data.
Yes. Luit Infotech follows privacy and data protection practices designed to support GDPR-related obligations and modern privacy principles.
Luit Infotech utilizes access controls, authentication, audit logging, backups, monitoring, and security practices designed to protect customer information.