This Data Processing Agreement ("DPA") is entered into between you (the "Controller" / "Customer") and LigimeX (the "Processor"), an MSME Udyam registered enterprise based in Lucknow, Uttar Pradesh, India, operating the LigiComms platform. This DPA applies automatically when you use LigiComms to process personal data.
Scope & parties
This DPA applies to all personal data that the Customer submits to or processes through the LigiComms platform ("Customer Data"), and governs LigimeX's obligations as a data processor on the Customer's behalf.
- Customer (Controller) — the organisation or individual who has registered a LigiComms account and determines the purposes and means of processing Customer Data.
- LigimeX (Processor) — processes Customer Data solely on the Customer's instructions to provide the LigiComms service.
Controller / processor roles
- For account data (Customer's own name, email, organisation) — LigimeX is the controller, as this data is necessary to provide and secure the service.
- For Customer Data (contact lists, message recipients, audience data, content) — the Customer is the controller and LigimeX is the processor, acting only on the Customer's documented instructions.
- For staff data (names and emails of staff invited by the Customer) — LigimeX is a joint controller with the Customer, as both parties determine aspects of processing.
Data categories processed
- Contact/identity data — names, email addresses, phone numbers of the Customer's audience (as uploaded or entered by the Customer).
- Message content — email bodies, SMS text, WhatsApp messages, social-media posts, templates, and media files created by the Customer.
- Channel credentials — OAuth tokens, API keys, and provider-specific credentials stored in encrypted form.
- Engagement data — comments, direct messages, and interaction metrics retrieved from connected platforms at the Customer's request.
- Billing data — transaction records, invoice details, and wallet activity.
- Technical data — IP addresses, device/browser information, and platform usage logs.
Data subjects: the Customer's employees/staff, the Customer's end customers and audience members, and social-media users who interact with the Customer's published content.
Processing purposes
LigimeX processes Customer Data solely for the following purposes, as instructed by the Customer through their use of the platform:
- Publishing content to the Customer's connected social-media channels.
- Sending messages (email, SMS, WhatsApp) to the Customer's specified recipients.
- Retrieving and displaying engagement data (comments, metrics, inbox messages) from connected channels.
- Storing and managing templates, contact lists, and brand assets.
- Processing payments and maintaining billing records.
- Providing AI-assisted content generation when requested by the Customer.
- Maintaining platform security, detecting abuse, and fulfilling legal obligations.
Processor obligations
LigimeX undertakes to:
- Process Customer Data only on the Customer's documented instructions, unless required by applicable law.
- Ensure that personnel authorised to process Customer Data are bound by appropriate confidentiality obligations.
- Implement and maintain appropriate technical and organisational security measures (see section 07).
- Not engage a sub-processor without informing the Customer of the categories of sub-processors used (see section 06).
- Assist the Customer in responding to data subject requests (see section 09).
- Assist the Customer in meeting data-protection impact assessment obligations where applicable.
- Delete or return Customer Data upon termination, at the Customer's choice (see section 12).
- Make available information necessary to demonstrate compliance with this DPA.
Sub-processors
LigimeX engages the following categories of sub-processors to deliver the service. Each sub-processor processes only the minimum data necessary for its function:
- Cloud infrastructure provider — hosting, database, and compute services (data centre located in a secure facility).
- Payment gateway — PCI DSS-compliant processor for card transactions and payment verification.
- SMS delivery partners — regional (India) and global telephony providers for SMS dispatch.
- AI inference provider — processes prompt text for AI-assisted content generation (no personal data or credentials are sent).
- Email delivery infrastructure — tenant-configured or platform-level SMTP services for email dispatch.
- Social-media & messaging platforms — the specific platforms the Customer chooses to connect (Meta, Google, X, LinkedIn, Pinterest, Telegram, etc.).
If LigimeX engages a new category of sub-processor, Customers will be notified via email or in-product notice at least 15 days in advance. If you object to a new sub-processor, you may terminate the affected service component.
Security measures
LigimeX implements and maintains the following technical and organisational measures to protect Customer Data:
- Encryption at rest — sensitive credentials and tokens are encrypted using authenticated encryption with keys managed separately from the data store.
- Encryption in transit — all data in transit is protected by HTTPS with modern transport-layer security.
- Access control — role-based access controls with dynamic, server-enforced permissions. Authentication uses short-lived tokens with automatic rotation.
- Tenant isolation — logical separation ensures each tenant's data is accessible only to that tenant's authorised users.
- Password protection — passwords are processed through a high-iteration one-way key-derivation function with per-account random salts.
- Webhook verification — inbound webhooks are validated using cryptographic signatures before processing.
- Monitoring — platform errors are logged with full context for incident investigation. Operational logs are retained for a limited period and then purged.
- Incident response — documented procedures for identifying, containing, and remediating security incidents.
For a client-facing overview, see our Security page.
Breach notification
- LigimeX will notify the Customer of any confirmed personal data breach without undue delay and in any event within 72 hours of becoming aware of it.
- The notification will include: the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
- LigimeX will cooperate with the Customer and provide reasonable assistance in the Customer's own breach-notification obligations to supervisory authorities and data subjects.
Data subject requests
If LigimeX receives a request directly from a data subject (e.g., a request to access, correct, or delete their data), LigimeX will promptly redirect the request to the Customer, unless legally required to respond directly.
LigimeX will provide the Customer with reasonable technical assistance to fulfil data subject requests, including access, rectification, erasure, portability, restriction, and objection — to the extent the platform's functionality permits.
International transfers
Customer Data may be processed in India and in the regions where LigimeX's sub-processors operate. For transfers from the EU/UK/EEA to countries not recognised as providing adequate protection, LigimeX relies on:
- Standard Contractual Clauses (SCCs) as approved by the European Commission, where required.
- Equivalent transfer mechanisms recognised under the applicable data-protection law of the Customer's jurisdiction.
Regardless of where data is processed, the security measures described in section 07 apply uniformly.
Audit rights
The Customer (or an independent auditor appointed by the Customer) may, upon reasonable written notice and no more than once per year, audit LigimeX's compliance with this DPA. Audits will be conducted during normal business hours, at the Customer's expense, and in a manner that minimises disruption to LigimeX's operations.
LigimeX will provide reasonable cooperation and access to relevant records and personnel. Confidential business information of LigimeX unrelated to the processing of Customer Data is excluded from the scope of any audit.
Data return & deletion
Upon termination of the service or upon the Customer's written request:
- LigimeX will, at the Customer's choice, return Customer Data in a portable format or delete it permanently within 30 days.
- LigimeX may retain copies of Customer Data only where required by applicable law (e.g., tax or accounting records), and only for the minimum period and scope required by that law.
- After the 30-day period, all Customer Data not subject to a legal retention requirement is permanently and irreversibly deleted.
Term
This DPA takes effect when the Customer begins using LigiComms and remains in effect for the duration of the service agreement. Obligations related to data deletion, confidentiality, and breach notification survive termination.
Contact
For questions about this DPA or to exercise your rights under it, contact us at info@ligicomms.in with "Data Processing" in the subject line, or visit our contact page.