Data Processing Agreement
This DPA sets out how SkinsIndia Solutions processes personal data as your processor when you use the ShivMail platform.
Last updated: 19 May 2026
1. Introduction
This Data Processing Agreement (“DPA”) forms part of the agreement between you (the “Customer”) and SkinsIndia Solutions for the use of ShivMail(the “Service”). It governs the processing of personal data that SkinsIndia Solutions carries out on the Customer’s behalf.
This DPA applies automatically to every customer and requires no separate signature. Where there is a conflict between this DPA and other parts of the agreement on the subject of data processing, this DPA prevails.
2. Definitions
- Personal data, processing, controller, processor, and data subject have the meanings given in applicable data protection law, including the GDPR and the Digital Personal Data Protection Act, 2023.
- Customer Personal Data means personal data contained in Customer Content that SkinsIndia Solutionsprocesses on the Customer’s behalf.
- Sub-processor means a third party engaged by SkinsIndia Solutions to process Customer Personal Data.
3. Roles of the parties
For Customer Personal Data, the Customer is the controller (or, where applicable, processor acting for another controller) and SkinsIndia Solutions is the processor. SkinsIndia Solutionswill process Customer Personal Data only on the Customer’s documented instructions, including those given through the Service, unless required to act otherwise by law.
4. Subject matter, duration, and nature of processing
Subject matter: provision of the ShivMail email delivery, marketing, automation, and analytics Service.
Duration: for the term of the agreement and any period during which SkinsIndia Solutions retains Customer Personal Data thereafter.
Nature and purpose: collecting, storing, transmitting, analysing, and deleting personal data as necessary to operate the Service.
Types of data: contact identifiers (such as email address and name), contact attributes, message content, and engagement events.
Categories of data subjects:the Customer’s contacts, subscribers, and recipients.
5. Obligations of the processor
- process Customer Personal Data only on documented instructions;
- ensure personnel authorised to process data are bound by confidentiality;
- implement appropriate technical and organisational security measures;
- assist the Customer with data-subject requests and compliance obligations;
- make available information necessary to demonstrate compliance; and
- not engage a sub-processor except as permitted in this DPA.
6. Security measures
SkinsIndia Solutions maintains technical and organisational measures appropriate to the risk, including encryption of data in transit and at rest, access controls, network segmentation, logging, monitoring, and regular review. A description of current measures is available on our Security page and may be updated provided the level of protection is not reduced.
7. Sub-processors
The Customer authorises SkinsIndia Solutions to engage sub-processors to provide the Service. Each sub-processor is bound by a written contract imposing data-protection obligations no less protective than those in this DPA. SkinsIndia Solutions remains responsible for the performance of its sub-processors and will provide notice of intended changes so the Customer may object on reasonable, data-protection grounds.
8. Data-subject requests
Taking into account the nature of the processing, SkinsIndia Solutionswill assist the Customer by appropriate technical and organisational measures, insofar as possible, to fulfil the Customer’s obligation to respond to requests from data subjects exercising their rights. Where SkinsIndia Solutions receives a request directly from a data subject, it will direct that person to the relevant Customer.
9. Personal data breach notification
SkinsIndia Solutions will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to assist the Customer in meeting its own notification obligations.
10. International transfers
Where the provision of the Service involves transferring Customer Personal Data across borders, SkinsIndia Solutions will ensure an appropriate transfer mechanism is in place, such as the Standard Contractual Clauses or an equivalent safeguard recognised under applicable law.
11. Audits
SkinsIndia Solutions will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality, scheduling, and security requirements.
12. Return and deletion of data
On termination of the Service, and at the Customer’s choice, SkinsIndia Solutions will delete or return Customer Personal Data and delete existing copies, unless retention is required by law. Routine deletion timelines are described in our Privacy Policy.
13. Contact
For questions about this DPA or to raise a data-protection request, contact:
- Email: privacy@skinsindiasolutions.in
- Post: SkinsIndia Solutions, KATJURIDANGA, KENDUADIHI, BANKURA, West Bengal, PIN: 722102, India
Questions about this policy?
Contact our team at privacy@skinsindiasolutions.in or write to SkinsIndia Solutions, KATJURIDANGA, KENDUADIHI, BANKURA, West Bengal, PIN: 722102, India.