Legal
Data Processing Agreement
Effective 2 October 2026 · AutoRelay is operated by HLP Technologies (GSTIN 07HRDPS5150Q1Z0), Delhi, India.
1. Parties and roles
This Data Processing Agreement (“DPA”) is between HLP Technologies (GSTIN 07HRDPS5150Q1Z0), Delhi, India(“Processor”, “we”) and the customer using AutoRelay (“Controller”, “you”). It forms part of the Terms of Service and applies automatically, with no signature needed. You are the controller (data fiduciary under the DPDP Act) of the personal data described below, and we process it on your behalf.
2. Scope of processing
| Subject matter | Providing the email service under the Terms |
| Duration | While you use the service, then as set out in “Return and deletion” |
| Nature and purpose | Storing contacts; sending email; recording delivery, bounces, complaints, opens, clicks and reply counts; AI features you choose to use; support |
| Data subjects | Your contacts and email recipients; your team members |
| Personal data | Email addresses, names, custom contact attributes you add, email content, delivery and engagement events (including the IP address of opens and clicks), suppression records |
| Special categories | None intended. Do not upload sensitive personal data unless the law allows it and you have assessed the risk |
3. Our obligations
- Process personal data only on your documented instructions (your use of the app and API, and these Terms), unless the law requires otherwise; we will tell you if we think an instruction breaks the law.
- Ensure staff with access are bound by confidentiality.
- Apply the security measures below.
- Help you respond to data subject requests (see the export and erasure tools) and with data protection impact assessments where reasonable.
- Notify you of a personal data breach affecting your data without undue delay, and within 72 hours of becoming aware of it, with the information we have.
- Make available information reasonably needed to show compliance with this DPA, and answer reasonable security questionnaires.
4. Your obligations
You confirm you have a lawful basis (including consent where needed) and have given the required notices for the data you upload and the email you send, that your instructions comply with the law, and that you follow our Acceptable Use Policy.
5. Security measures
- Encryption of data in transit (TLS) and at rest (by our hosting providers).
- Logical separation of each customer's data, with role-based access inside accounts.
- API keys stored as one-way hashes; passwords handled by our sign-in provider.
- Logging of administrative and security-relevant actions.
- Rate limiting, abuse detection and automatic suspension of risky sending.
- Restricted production access for our staff.
6. Sub-processors
You authorise us to use the sub-processors below. We impose data protection terms on them that are no less protective than this DPA. We will give at least 15 days' notice of a new sub-processor (on this page and by email to account owners), and you may object on reasonable grounds.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services, Inc. (SES, S3) | Email delivery and inbound replies | AWS regions we use (incl. United States) |
| Supabase, Inc. | Database and authentication | Region of our Supabase project |
| Cloudflare, Inc. (R2) | Storage of uploaded files | Global |
| Google LLC (Gemini API) | AI features you choose to use | Global |
| Our payment partner (HLP Pay) | Payment processing (account billing only) | India |
7. International transfers
Personal data may be processed outside the country where it was collected. For transfers from the EEA/UK we rely on the Standard Contractual Clauses or equivalent safeguards offered by our sub-processors, and we comply with any transfer restrictions notified under the DPDP Act.
8. Data subject requests
You can export or erase a contact's data per project in Settings → Privacy. Erasure removes the contact, their sends and their email events in that project and keeps the address on the suppression list so they are not emailed again. If a data subject contacts us directly, we will refer them to you.
9. Return and deletion
You can export and delete your data at any time using the app and API. When your account is closed, we delete your personal data within 30 days, except where we must keep it by law (for example, tax records) or need it to enforce our policies (for example, suppression and abuse records), as described in the Privacy Policy. Residual copies in backups are overwritten in the normal backup cycle.
10. Liability and precedence
Liability under this DPA is subject to the limits in the Terms of Service. If this DPA conflicts with the Terms on data protection, this DPA prevails.