Canopus Software & Engineering — home
Legal

Data Processing and Sub-processors

The GDPR Article 28 position for clients who need it before signing: which role we are in, what the data processing agreement commits us to, how data reaches India lawfully, and every sub-processor by name.

Last updated:

Summary

This page sets out how Canopus handles personal data on a client's behalf: when we act as controller and when as processor, what our GDPR Article 28 data processing agreement covers, the safeguards applying to data processed from India, and every sub-processor we use, including the payment providers that join the list when online payment goes live.

1. Which role we are in, and when

Canopus IT Solutions Private Limited is registered in India. Under GDPR and UK GDPR we sit in one of two roles, and the difference decides who owes what to whom.

  • Controller — for enquiries through canopussoft.com, correspondence with your team, and our own invoicing records. Detail in the privacy policy.
  • Processor — when we build, migrate or operate software handling your own users' personal data. You remain the controller. We act only on your documented instructions under a signed data processing agreement, and never use your users' data for our own purposes: not for benchmarking, marketing or model training.

The practical consequence: a request from one of your users goes to you. We help you answer it; we do not answer on your behalf unless your agreement says so.

2. What the data processing agreement records

Article 28(3) requires the particulars of the processing to be fixed in writing before it starts. Ours are agreed during discovery and attached to the master services agreement, settled before any engineer has access:

  • Subject matter and duration — the application, integration or migration named in the statement of work, for its term plus the deletion window in section 3.
  • Nature and purpose — design, development, testing, deployment, support and, where you ask for it, operation. Nothing outside those verbs.
  • Categories of personal data — account identifiers, contact details, transaction records, support history; special-category data only where you have told us it exists and we agreed to handle it.
  • Categories of data subject — your customers, employees, suppliers, or whichever combination applies.
  • Your instructions — the statement of work is the standing instruction; changes go through the written change-request route, never something half-remembered from a call.

If an instruction looks unlawful to us, we say so in writing and pause that part of the work rather than invoicing for it.

3. The Article 28 commitments in plain terms

CommitmentWhat it means here
ConfidentialityA written confidentiality clause binds every engineer, and a mutual NDA is signed before discovery. Access is named per person, scoped to the role, revoked at exit.
Security measuresEncryption in transit and at rest, secrets in a managed vault, code review on every change, dependency and secret scanning in CI, staging on anonymised data. Detail on our security and compliance page.
Data subject requestsYou send us the request; within 10 business days we return what we hold or confirm deletion, in a format you can hand to the person who asked. We never contact your user.
Breach notificationWithin 48 hours of confirming a breach affecting your data, by email and phone to your named contact, with what we know at that point rather than a tidier version later. A written root-cause account follows within 10 business days.
Deletion or returnWithin 30 days of the engagement ending. Where we deployed into your own cloud account there is nothing to return, so you get written confirmation of which credentials were revoked, and when.
Audit rightsOne audit per 12 months on 30 days' written notice, under NDA, plus a security questionnaire answered within 10 business days. We hold no ISO 27001 or SOC 2 certification, so no report substitutes for it.

4. Processing from India, and how transfers are covered

Our engineers work from India, so for an EEA or UK client, engaging us means a restricted transfer. India is not the subject of a European Commission adequacy decision, and we do not pretend otherwise.

The basis is the European Commission's Standard Contractual Clauses, executed as part of the DPA — Module Two where you are the controller, Module Three where you are yourself a processor for someone else. UK data adds the ICO's International Data Transfer Addendum; Swiss data adds the FDPIC amendments. A transfer impact assessment is available on request.

The safeguard that matters more than the paperwork is architectural: we deploy into your cloud account, in your region. An EU client's production data stays in eu-west-1 or europe-west1, reached by a named engineer over an audited session — accessed from India, not copied to India.

We are also subject to India's Digital Personal Data Protection Act, 2023. If a government or law-enforcement demand reaches us for data we process for you, we notify you before responding unless legally barred. No authority has standing or direct access to your systems through us.

5. Sub-processor list

Third parties that may process personal data during an engagement. The list is short because the default architecture keeps your data in infrastructure you own.

Sub-processorWhat it doesWhere it processesStatus
Amazon Web Services, Microsoft Azure or Google CloudHosting, managed databases, storage and backup. Which one depends on the engagement.Your own account, in the region you choose before any infrastructure is createdIn use
GitHubSource control, code review, issue tracking and CI. Holds code and tickets; it should never hold your users' personal data, and reviews check for that.United StatesIn use
Business email and collaboration platformCorrespondence with your team and documents you send us. Named in your signed DPA, since it is scoped per engagement.Provider's US or EU regionIn use
Razorpay, CCAvenue, Cashfree, PayUCard, UPI, netbanking and wallet processing for invoices billed in INR.IndiaNot live yet — see below
StripeCard and bank payments for invoices billed in currencies other than INR.United States and IrelandNot live yet — see below
PayPalCard and PayPal account payments for international invoices.United States and LuxembourgNot live yet — see below

Scroll the table sideways for the full detail.

The payment providers are listed for completeness, not because they process anything today. Online invoice payment is not live; each becomes a sub-processor on the day the first live transaction runs through it, and this page changes before that, not afterwards. Even then they handle billing contact details of our clients — never your users' data, which does not reach a payment provider through us. Their checkout cookies are covered in the cookie policy.

6. We never receive card numbers

Card details will be entered on the payment provider's own hosted page or embedded field, going from your browser to the regulated provider without touching any server or form we control.

We do not store card numbers, because we never receive them. What comes back is a transaction reference, the amount, the currency, a status and, where the provider shows it, a card brand and last four digits. There is no cardholder data environment on our side to breach, and we claim no PCI DSS level of our own — that obligation sits with the provider holding the data. How invoices are raised and settled is in payment terms.

7. Adding a sub-processor, and how to object

Signing the DPA authorises the sub-processors above. Before a new one starts processing your data:

  • We email your named DPA contact at least 30 days in advance, naming the provider, what it will do and where it processes.
  • You may object in writing within those 30 days, with your reasons. Silence is not treated as approval of anything we have not described.
  • If we cannot offer a workable alternative — another provider, another region, or keeping that component out of scope — you may end the affected part of the engagement on 30 days' notice with no penalty, the same notice that applies either way across our engagement models.

We stay liable for a sub-processor's acts and omissions, and each is bound by data protection terms no weaker than your DPA.

8. Requesting the signed DPA

Email [email protected] with your legal entity name, the jurisdictions your users are in and the SCC module you need. We return the drafted DPA with the clauses and sub-processor schedule attached; an engineer replies within one business day. No charge, and no need to be a client first.

If your legal team would rather paper it on your own template, send it — we read redlines and do not treat a marked-up DPA as a warning sign. Two things we will not sign, so nobody spends a week discovering it: unlimited liability for data protection claims, and an unqualified obligation to keep all processing inside a jurisdiction where we have no presence.

9. Questions and escalation

Write to [email protected], call +91 817 979 7732, or use the form on our contact page. A question about a live engagement reaches your delivery lead the same day.

If our answer does not resolve it, escalation routes and response times are in grievance redressal. EEA and UK clients keep the right to complain to their supervisory authority.