Processor Agreement
Data Processing Agreement.
April 21, 2026GDPR-Aligned StructureNepal Jurisdiction
1. Parties and Purpose
This Data Processing Agreement ("DPA") forms part of the agreement between "Sanothimi" — the software and technology services operated by Chandan Sharma ("Sanothimi," "Processor") — and the customer identified in the applicable Order Form ("Customer," "Controller"), and governs the processing of personal data by Sanothimi on Customer's behalf in connection with the Services.
Where the main Terms of Service and this DPA conflict with respect to the processing of personal data, this DPA controls to the extent of that conflict.
2. Definitions
"Controller," "Processor," "Personal Data," "Processing," and "Data Subject" have the meanings given in applicable data protection law, or if no such definition applies, their generally accepted meaning. "Customer Data" means personal data submitted to a Service by or on behalf of Customer. "Subprocessor" means a third party engaged by Sanothimi to process Customer Data. "Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data.
3. Roles of the Parties
Where Customer determines the purposes and means of processing personal data submitted to a Service, Customer acts as the Controller and Sanothimi acts as the Processor with respect to that Customer Data.
4. Processing Instructions
Sanothimi will process Customer Data only in accordance with Customer's documented instructions, as reflected in the applicable Order Form, Service configuration, and this DPA, unless required to do otherwise by applicable law, in which case Sanothimi will inform Customer of that legal requirement before processing, unless prohibited from doing so.
5. Processing Details
Subject matter: the provision of the Service purchased by Customer. Duration: the Subscription Term plus any post-termination retention period described in the Terms. Purpose: providing, securing, maintaining, and supporting the Service. Categories of personal data and data subjects: as determined by Customer's use of the Service (which may include Customer's staff, students, employees, or clients). Nature of processing: collection, storage, organization, retrieval, and deletion, as necessary to operate the Service.
6. Confidentiality
Sanothimi ensures that personnel authorized to process Customer Data are subject to appropriate confidentiality obligations, whether contractual or statutory.
7. Security Measures
Sanothimi implements technical and organizational measures designed to protect Customer Data, as further described in our Security Policy, available at /security, including access controls, encryption in transit, and monitoring appropriate to the nature of the data processed.
8. Subprocessors
Customer authorizes Sanothimi's use of the Subprocessors listed at /subprocessors. Sanothimi will provide reasonable notice of the addition of a new Subprocessor where practical, and Customer may object on reasonable data-protection grounds, in which case the parties will work in good faith toward a resolution.
9. Data Subject Requests
Where Sanothimi receives a request from a data subject relating to Customer Data, Sanothimi will promptly notify Customer and, taking into account the nature of the processing, provide reasonable assistance to Customer in responding to that request, without responding directly unless required by law.
10. Security Incidents
Sanothimi will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Data, and will provide reasonably available information to help Customer meet its own notification obligations, and take reasonable steps to investigate, contain, and remediate the incident.
11. Government Requests
Where legally permitted, Sanothimi will notify Customer of a legally binding request for disclosure of Customer Data from a government or law enforcement authority before disclosing it, unless prohibited from doing so by law.
12. International Transfers
Where Sanothimi transfers Customer Data across borders in connection with the Service, it will use appropriate safeguards required by applicable law for such transfers.
13. Deletion and Return
Upon termination or expiry of the Subscription, Sanothimi will make Customer Data available for export for the period described in the Terms, after which Customer Data will be deleted from production systems, with backups deleted on a rolling schedule thereafter, subject to any legal retention obligations.
14. Audit and Compliance
On reasonable request, and no more than once per year absent a Security Incident or legal requirement, Sanothimi will provide Customer with reasonably available information to demonstrate compliance with this DPA, which may include making available relevant security documentation in lieu of an on-site audit.
15. Liability
Each party's liability arising out of this DPA is subject to the limitations of liability set out in the Terms of Service or applicable Order Form.
16. Term
This DPA remains in effect for as long as Sanothimi processes Customer Data on Customer's behalf under the Services.
Need a Signed Copy?
Enterprise and institutional customers can request a countersigned Data Processing Agreement for their records.
