Reach out to us to redefine hiring. Contact us

LEGAL & COMPLIANCE

Data Processing Agreement

Effective Date: November, 2025Operator: EMELEX Business Solutions LLPPlatform: PI DOT

1. Definitions

For the purposes of this Agreement:

Controller

The entity that determines the purposes and means of processing Personal Data.

Processor

EMELEX Business Solutions LLP, which processes Personal Data on behalf of the Controller through the PI DOT platform.

Personal Data

Any information relating to an identified or identifiable individual.

Processing

Any operation performed on Personal Data including collection, storage, use, transmission, analysis, or deletion.

Subprocessor

A third-party service provider engaged by the Processor to assist in delivering the services.

2. Scope and Purpose of Processing

PI DOT processes Personal Data only for the purpose of delivering the platform services, which may include:

  • operating learning simulations
  • managing user accounts
  • delivering training modules
  • generating learning analytics
  • facilitating institutional learning programs
  • supporting AI-assisted educational environments.

Processing shall occur only in accordance with the documented instructions of the Controller.

3. Categories of Data Subjects

The Personal Data processed under this DPA may relate to:

  • students
  • trainees
  • employees of enterprise clients
  • instructors or trainers
  • institutional administrators
  • individual users of the platform.

4. Types of Personal Data Processed

Depending on the services used, PI DOT may process:

  • names and contact information
  • user account identifiers
  • login credentials
  • institutional affiliation
  • learning and assessment data
  • simulation interaction data
  • performance analytics.

The Controller determines which categories of Personal Data are uploaded to the platform.

5. Processor Obligations

PI DOT shall:

  • Process Personal Data only on documented instructions from the Controller.
  • Ensure personnel accessing Personal Data are bound by confidentiality obligations.
  • Implement appropriate technical and organizational measures to protect Personal Data.
  • Not use Personal Data for purposes other than providing the services.
  • Notify the Controller if an instruction violates applicable data protection laws.

6. Confidentiality

PI DOT shall ensure that any employee, contractor, or agent who processes Personal Data:

  • is subject to a confidentiality obligation
  • accesses data only where necessary for performing their duties.

These obligations shall continue even after the termination of employment or engagement.

7. Security Measures

PI DOT shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including but not limited to:

  • encryption of data in transit and at rest
  • access control mechanisms
  • infrastructure monitoring
  • vulnerability assessments
  • environment segmentation
  • regular security audits.

These safeguards are designed to protect Personal Data against unauthorized access, loss, alteration, or disclosure.

8. Subprocessors

PI DOT may engage Subprocessors to assist in providing services.

Typical categories include:

  • cloud infrastructure providers
  • analytics services
  • AI processing tools
  • payment processors
  • communication systems.

PI DOT shall ensure that all Subprocessors are bound by contractual obligations that provide data protection standards equivalent to those in this DPA.

A current list of Subprocessors is maintained in the PI DOT Subprocessor Disclosure.

9. International Data Transfers

Where Personal Data is transferred outside the jurisdiction of the Controller, PI DOT shall ensure appropriate safeguards are implemented.

These safeguards may include:

  • Standard Contractual Clauses
  • contractual confidentiality obligations
  • technical protections such as encryption and access controls.

10. Assistance with Data Subject Rights

PI DOT shall assist the Controller, where reasonably possible, in responding to requests from individuals exercising their data protection rights.

These may include:

  • access requests
  • correction requests
  • deletion requests
  • restrictions on processing.

The Controller remains responsible for responding to such requests.

11. Personal Data Breach Notification

In the event of a Personal Data Breach affecting Controller data, PI DOT shall:

  • Notify the Controller without undue delay after becoming aware of the breach.
  • Provide information regarding the nature of the breach.
  • Assist in investigating and mitigating the impact of the breach.
  • Cooperate with regulatory or legal reporting requirements where applicable.

12. Data Retention and Deletion

Upon termination or expiration of the service agreement, PI DOT shall:

  • delete Personal Data processed on behalf of the Controller, or
  • return such data to the Controller if requested.

Retention may occur where required by law or for legitimate operational purposes such as dispute resolution or legal compliance.

13. Audit and Compliance Rights

The Controller may request reasonable information necessary to demonstrate PI DOT’s compliance with this DPA.

Where required, PI DOT shall cooperate with:

  • compliance reviews
  • regulatory audits
  • security documentation requests.

Audits must be conducted in a manner that does not disrupt PI DOT operations or compromise other customers’ data.

14. Liability

Each party shall remain responsible for its respective obligations under applicable data protection laws.

PI DOT shall be liable for damages resulting from processing activities that violate this DPA or applicable regulations.

15. Term and Termination

This DPA remains in effect for the duration of PI DOT’s processing of Personal Data on behalf of the Controller.

This DPA remains in effect for the duration of PI DOT’s processing of Personal Data on behalf of the Controller.

16. Governing Law

This DPA shall be governed by the laws of India, unless otherwise required by the applicable jurisdiction of the Controller.

Disputes arising from this agreement shall be subject to the jurisdiction of courts located in [Insert City – likely Hyderabad].

17. Contact Information

For questions regarding this Data Processing Agreement or PI DOT’s data handling practices, please contact:

EMELEX Business Solutions LLP

PI DOT Data Governance Team

Email: support@pidot.in

Address: 10-1-194\1, Pipe Line Rd, Shobana Colony, Balanagar, Hyderabad, Telangana 500018