Skip to content
sedwis

Last updated 28 July 2026

Data protection

How we handle personal data we process on behalf of clients — under India's DPDP Act 2023 and the GDPR.

Template — not yet reviewed

This page is a starting point drafted against Indian DPDP Act 2023 and GDPR expectations. It must be reviewed by a qualified lawyer and have company specifics filled in before launch. Set NEXT_PUBLIC_LEGAL_REVIEWED=true to remove this notice.

Which document applies to you

Our privacy policy covers data we collect about visitors to this website. This page covers personal data we process on behalf of clients while building and running their systems — which is what a Data Processing Agreement concerns.

Our role

When we build or operate a system for you, you are the Data Fiduciary under the DPDP Act 2023 and the Data Controller under the GDPR. We act as your Data Processor. We process personal data only on your documented instructions, and never for our own purposes.

What we commit to

  • Instruction-bound processing. We act on your documented instructions and will tell you if an instruction appears to breach applicable law.
  • Confidentiality. Every individual with access is bound by an NDA, not just our company.
  • Security. The measures set out on our security page, including encryption in transit and at rest, least-privilege access and mandatory 2FA.
  • Sub-processors. No new sub-processor without notifying you first and giving you the chance to object.
  • Assistance. We help you respond to data subject requests, impact assessments and regulator queries.
  • Breach notification. We notify you within 24 hours of confirming an incident affects your data — before we fully understand it, not after.
  • Deletion or return.At the end of the engagement, we delete or return the data as you instruct, and confirm in writing when it's done.
  • Audit. We make available the information you need to demonstrate compliance, and will accommodate a reasonable audit.

Where data is processed

By default, in Indian data-centre regions. We can deploy to EU, UK, UAE, Canadian, Australian, Singapore or US regions where you require it — commonly for data residency obligations.

For transfers out of the EEA or UK, we use Standard Contractual Clauses together with a transfer risk assessment. For Indian clients, we handle data in line with DPDP Act requirements including any restrictions the government notifies.

Sub-processors

We use a small number of infrastructure and tooling providers. Typical categories are cloud hosting, error tracking, transactional email and — only where you have specifically agreed — AI model providers. The current list, with the purpose and location of each, is available on request before you sign anything.

Where AI providers are involved, we use enterprise tiers that contractually exclude your data from model training. Where that is not acceptable, we deploy open-weight models entirely within your own environment.

Development practice

  • Production personal data is not copied to developer machines
  • Development and testing use anonymised or synthetic data
  • Access is granted per project and revoked within 24 hours of someone leaving it
  • Logs are configured to avoid capturing personal data wherever possible

Data subject rights

If you are an individual whose data we process on behalf of one of our clients, please contact that organisation directly — they are the controller and hold the relationship with you. If you contact us, we will forward your request to them promptly and assist them in responding.

Grievance Officer

As required by the DPDP Act 2023, our Grievance Officer can be reached at contact@sedwis.com.

Getting a DPA in place

We'll sign a Data Processing Agreement before any engagement involving personal data — ours or yours. Email contact@sedwis.com and we'll send our standard DPA along with the sub-processor list.