Legal
Data Processing Agreement (DPA)
Last updated: 5 June 2026
This DPA forms part of the agreement between Vinpro Global Services Pvt Ltd(“Processor”) and the customer (“Controller”) and governs personal data we process on the customer's behalf when delivering EOR, HRMS, payroll and staffing services. It is intended to support DPDP, GDPR and equivalent obligations.
1. Roles & scope
The customer is the controller (or, for its own customers, processor); Vinpro Global Services Pvt Ltd is the processor (or sub-processor). We process personal data only on documented instructions.
2. Nature & purpose of processing
Vinpro Global Services Pvt Ltdprocesses personal data on the controller's documented instructions to provide the agreed Services, which may include employer-of-record administration, onboarding and offboarding, HRMS record-keeping, payroll processing and disbursement, statutory contributions and filings such as PF, ESI, PT and TDS in India, benefits and reimbursements, attendance and leave management, compliance support, invoicing, and related support.
Processing continues for the term of the agreement and any period required to complete the Services or to meet legal retention obligations. The nature of processing includes collection, storage, organisation, use, disclosure to authorised recipients as instructed, for example tax and statutory authorities, banks, and benefit providers, and return or deletion.
3. Categories of data & data subjects
Data subjectsare the controller's employees, EOR workers, contractors, candidates, and their dependents or nominees where relevant.
Categories of personal data include identity and contact details (name, address, email, phone, photograph); employment details (role, department, location, dates, compensation); payroll and financial data (salary, bank account, payslips, reimbursements); statutory and government identifiers such as PAN, UAN/PF, ESI and tax IDs, and Aadhaar, SSN or national insurance numbers only where lawfully required; tax and withholding data; attendance, leave and performance data; benefits, insurance and dependent or nominee information; and, where strictly necessary and lawful, special-category or sensitive data such as health information for benefits or background-check results. Sensitive data is processed only where necessary, lawful, and instructed.
4. Confidentiality & security
Personnel are bound by confidentiality. We maintain the technical and organisational measures described on our Security page.
5. Sub-processors
The customer authorises the sub-processors listed on our Sub-processors page; we will give notice of changes and remain responsible for their performance.
6. International transfers
The Services involve cross-border processing between India, the United States, and, where relevant, the United Kingdom, the EU/EEA, and Australia. Where personal data is transferred across borders, Vinpro applies the safeguards required by applicable law, which may include the EU and UK Standard Contractual Clauses, and the UK International Data Transfer Addendum, for transfers from the EEA or UK; equivalent contractual and security measures for transfers involving India, consistent with the Digital Personal Data Protection Act, and the United States; and supplementary technical measures such as encryption in transit and at rest and access controls.
Customer Data for the EOR client portal is hosted in the United States; Indian employee and payroll data managed through the HRMS is hosted in India.
7. Data subject requests & breach notification
We assist the controller with data-subject requests and will notify the controller without undue delay after becoming aware of a personal-data breach.
Vinpro will notify the controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a personal-data breach affecting the controller's Customer Data, and will provide the information reasonably available to help the controller meet its own notification obligations, including the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the remediation taken. Taking into account the nature of processing, Vinpro also assists the controller with responding to data-subject and Data Principal requests, with data-protection impact assessments, and with consultations with regulators, to the extent applicable.
8. Audits
Vinpro makes available to the controller the information reasonably necessary to demonstrate compliance with this DPA. The controller may audit Vinpro's processing once per twelve (12) months, and following a personal-data breach, on reasonable prior written notice, during business hours, subject to confidentiality and without disrupting Vinpro's operations. Where available, Vinpro may satisfy an audit request by providing its then-current third-party certifications and reports, such as SOC 2 Type II and ISO/IEC 27001 once obtained, together with a completed security questionnaire, which the controller agrees to accept in lieu of an on-site audit where they reasonably address the audit scope.
9. Return & deletion
On termination, we return or delete personal data per the controller's instructions, subject to legal retention requirements.
10. Annexes
Annex I — Details of processing. The subject matter, duration, nature and purpose of processing, categories of personal data, and categories of data subjects as described in sections 2 and 3 above.
Annex II — Technical & organisational measures. The measures described on our Security page, including encryption in transit and at rest, role-based access control with multi-factor authentication, network and infrastructure controls, logging and monitoring, secure development, backup and resilience, vendor management, and incident response, as updated from time to time.
Annex III — Sub-processors. The sub-processors listed on our Sub-processors page, covering, among others, cloud hosting, email, payments, content delivery and security, and authentication providers. Vinpro gives the controller prior notice of new or replacement sub-processors and a reasonable period to object on reasonable data-protection grounds.
Contact
To request a signed DPA, email info@vinproconnect.com.
