Data Processing Agreement

Effective 23 September 2026

This DPA should be read with the Beginso Terms of Use, Privacy Policy, Acceptable Use Policy, Free Tier / Fair Use Policy, and any applicable order form, subscription plan or enterprise agreement (collectively, the "Agreement").

1. Parties, Status and Scope

1.1 Parties

This DPA is entered into between the customer, organisation, business, institution or other entity that uses Beginso and determines the purposes and means of processing Customer Personal Data ("Customer"), and Beginso and/or its parent company, affiliates, subsidiaries and group entities operating the Beginso Platform ("Beginso").

1.2 When This DPA Applies

This DPA applies to the extent Beginso processes Customer Personal Data on behalf of Customer in connection with the Services. It does not apply to personal data for which Beginso independently determines the purposes and means of processing, including account administration, platform security, fraud and abuse prevention, support, billing, legal compliance and Beginso's own operational analytics, which are governed by the Privacy Policy.

1.3 Roles

Where applicable, Customer acts as the Data Fiduciary, Controller, Business or equivalent principal decision-maker, and Beginso acts as the Data Processor, Processor, Service Provider, Contractor or equivalent processor on Customer's behalf. The parties acknowledge that legal terminology differs by jurisdiction and the functional allocation of responsibilities controls.

1.4 Order of Precedence

For processing governed by this DPA, this DPA prevails over conflicting provisions of the Agreement on data-processing matters. Applicable Standard Contractual Clauses or mandatory transfer terms prevail over this DPA to the extent of any conflict.

2. Definitions

Applicable Data Protection Law: all privacy, data-protection, breach-notification and cross-border-transfer laws applicable to the relevant processing, including, where applicable, the DPDP Act and Rules, GDPR, UK GDPR, Swiss data-protection law, CCPA/CPRA and successor legislation.

Customer Personal Data: Personal Data processed by Beginso on behalf of Customer through the Services, including data collected through Customer-created Forms, Submissions, uploaded files and related Workspace data.

Data Subject / Data Principal: the identified or identifiable individual to whom Personal Data relates, using the terminology of the applicable law.

Personal Data: information relating to an identified or identifiable individual, including any equivalent term under Applicable Data Protection Law.

Processing: any operation performed on Personal Data, including collection, recording, organisation, storage, retrieval, consultation, use, disclosure, transmission, restriction, erasure or destruction.

Security Incident: a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.

Subprocessor: a third party engaged by Beginso to process Customer Personal Data on Beginso's behalf in connection with the Services.

Services: the Beginso form-management, publishing, response-management, file-upload, analytics, reporting, Workspace, team and related SaaS services made available through the Platform.

3. Customer Instructions and Responsibilities

3.1 Documented Instructions

Beginso shall process Customer Personal Data only on Customer's documented instructions, including the Agreement, Customer's configuration and use of the Services, and other written instructions accepted by Beginso, unless processing is required by Applicable Law. Where legally permitted, Beginso will inform Customer before processing required by law.

3.2 Lawfulness of Customer Processing

Customer is solely responsible for ensuring that its collection and use of Customer Personal Data is lawful. Customer shall provide all required notices, obtain all necessary consents or other lawful bases, respect data-minimisation requirements, and ensure that its Forms, questions, uploads, exports, integrations and instructions comply with Applicable Data Protection Law.

3.3 Sensitive, Regulated and Children's Data

Customer shall not use Beginso to process highly regulated or specially protected data unless Customer has determined that such processing is lawful and appropriate and has implemented all legally required safeguards. Where particular processing requires a sector-specific contract, regulatory authorisation, heightened security control or Beginso's prior written approval, Customer shall obtain it before using the Services for that processing.

3.4 Instructions Contrary to Law

If Beginso reasonably believes an instruction violates Applicable Data Protection Law, Beginso may notify Customer and suspend the affected processing until the parties resolve the issue. Beginso is not required to execute an unlawful instruction.

4. Beginso Processing Obligations

4.1 Purpose Limitation

Beginso shall process Customer Personal Data only as necessary to provide, secure, maintain and support the Services, comply with Customer's documented instructions, comply with Applicable Law, and exercise rights expressly permitted by the Agreement.

4.2 Confidentiality

Beginso shall ensure that persons authorised to process Customer Personal Data are subject to confidentiality obligations or an appropriate statutory duty of confidentiality and receive access only to the extent reasonably necessary for their functions.

4.3 No Sale or Unrelated Commercial Use

Beginso shall not sell Customer Personal Data or use it for unrelated advertising or unrelated commercial purposes. Beginso shall not use the substantive content of Customer Forms, Respondent Submissions or uploaded files to train, develop or fine-tune generative AI or machine-learning models unless an appropriate lawful basis and, where required, Customer's clear authorisation exists.

4.4 Return and Deletion

Upon termination of the Services or Customer's valid deletion instruction, Beginso shall delete or return Customer Personal Data in accordance with the Agreement and applicable product functionality, except to the extent retention is required by Applicable Law, necessary for legal claims, security, fraud prevention, backup cycling or other legally permitted purposes. Residual backup copies may remain until overwritten in the ordinary course, subject to continued protection.

5. Security of Processing

5.1 Appropriate Measures

Beginso shall implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, taking into account the nature, scope, context and purposes of processing and the risks to individuals.

5.2 Security Programme

Without representing that any online service is absolutely secure, Beginso's security programme may include, as appropriate to the Services and risk:

  • access controls and role/permission management
  • authentication and session controls
  • encryption in transit and other encryption or protection mechanisms appropriate to the relevant systems
  • logging, monitoring and security-event review
  • cloud and infrastructure security controls
  • vulnerability and patch management
  • backup, resilience and recovery measures appropriate to the service
  • personnel confidentiality and access limitation
  • incident-response procedures
  • periodic review of technical and organisational safeguards

5.3 Customer Security Responsibilities

Customer remains responsible for configuring Forms, Workspaces, roles, permissions, sharing settings, exports and integrations appropriately; securing its own devices and credentials; removing former users; and protecting Customer Personal Data after export or transfer outside Beginso.

6. Security Incidents

6.1 Notification

Beginso shall notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data, to the extent required by Applicable Data Protection Law.

6.2 Information and Cooperation

To the extent reasonably available, Beginso shall provide information regarding the nature of the incident, affected data and individuals, likely consequences, containment or remediation measures and other information reasonably required for Customer to meet its legal obligations. Information may be provided in phases as the investigation develops.

6.3 No Admission

Security Incident notification or cooperation does not constitute an admission of fault or liability by Beginso.

6.4 Customer Notifications

Customer is responsible for determining whether notification to Data Subjects, regulators or other persons is required, except where Applicable Law directly requires Beginso to notify them.

7. Data Subject / Data Principal Requests

7.1 Customer Responsibility

Customer is primarily responsible for responding to requests from Data Subjects or Data Principals concerning Customer Personal Data where Customer acts as Controller or Data Fiduciary.

7.2 Assistance

Taking into account the nature of the processing and functionality available to Customer, Beginso shall provide reasonable assistance to Customer in fulfilling applicable requests for access, correction, completion, updating, deletion, restriction, portability, objection, consent withdrawal or other legally recognised rights.

7.3 Direct Requests

If Beginso receives a request relating solely to Customer Personal Data processed on Customer's behalf, Beginso may direct the requester to Customer and, where appropriate, notify Customer, unless Applicable Law requires Beginso to respond directly.

8. Data Protection Impacts, Consultations and Compliance Assistance

8.1 Reasonable Assistance

Taking into account the nature of processing and information available to Beginso, Beginso shall provide reasonable assistance with Customer's data-protection impact assessments, risk assessments, prior consultations and similar statutory obligations where required by Applicable Data Protection Law.

8.2 Costs

If Customer requests substantial assistance beyond standard product functionality or ordinary compliance support, Beginso may charge reasonable fees based on the effort required, unless Applicable Law prohibits such charges.

9. Subprocessors

9.1 General Authorisation

Customer grants Beginso general written authorisation to engage Subprocessors to provide the Services, including providers of cloud hosting, databases, object/file storage, authentication, email delivery, monitoring, security, analytics, support, payments and other technical functions.

9.2 Subprocessor Obligations

Beginso shall impose data-protection obligations on each Subprocessor that are materially protective of Customer Personal Data and appropriate to the services the Subprocessor performs. Beginso remains responsible for its Subprocessors to the extent required by Applicable Data Protection Law and the applicable contractual framework.

9.3 Changes and Objections

Where Applicable Data Protection Law requires notice of new or replacement Subprocessors, Beginso shall provide notice through the Platform, a published subprocessor list, email or another reasonable method. Customer may object on reasonable data-protection grounds within the stated notice period. The parties shall work in good faith to resolve the objection; if no reasonable resolution is available, Customer may terminate the affected Services as its sole contractual remedy, subject to mandatory rights.

10. International Data Transfers

10.1 General

Customer authorises Beginso and its Subprocessors to process Customer Personal Data in countries where Beginso or its Subprocessors operate, subject to Applicable Data Protection Law and appropriate transfer safeguards where required.

10.2 EEA Transfers

Where Customer Personal Data subject to the GDPR is transferred to a country not covered by an applicable adequacy decision and a transfer safeguard is required, the European Commission Standard Contractual Clauses adopted by Commission Implementing Decision (EU) 2021/914 ("EU SCCs") are incorporated into this DPA by reference. Module Two (Controller to Processor) applies where Customer is a Controller and Beginso is a Processor; Module Three (Processor to Processor) applies where Customer is a Processor and Beginso is a Subprocessor. The Annexes to this DPA populate the corresponding SCC Annexes to the extent applicable. The docking clause applies. Optional clause choices and competent supervisory authority shall be determined by the facts and applicable law.

10.3 United Kingdom Transfers

For restricted transfers subject to the UK GDPR, the parties shall use the then-current UK International Data Transfer Agreement or the UK International Data Transfer Addendum to the EU SCCs, as applicable. Where the Addendum is used, its mandatory clauses are incorporated by reference in the manner permitted by the UK Information Commissioner, and the information in the Annexes to this DPA shall populate the relevant tables to the extent applicable.

10.4 Switzerland

For transfers subject to Swiss data-protection law, the EU SCCs apply with the modifications necessary to reflect Swiss terminology, competent authority and mandatory Swiss law, to the extent recognised as an appropriate safeguard.

10.5 Transfer Assessments and Supplementary Measures

Each party shall reasonably cooperate, where required, with transfer impact or risk assessments and implementation of supplementary safeguards. Beginso may provide relevant information about its processing and security practices subject to confidentiality and security restrictions.

10.6 India and Other Jurisdictions

Cross-border processing involving India shall be handled in accordance with the DPDP Act, the DPDP Rules and any restrictions or notifications issued under them as applicable from time to time. For other jurisdictions, the parties shall use a legally recognised transfer mechanism where one is required.

11. Audit and Compliance Information

11.1 Information Rights

Upon reasonable written request, Beginso shall make available information reasonably necessary to demonstrate compliance with processor obligations applicable to the relevant processing, subject to confidentiality, security and privilege restrictions.

11.2 Audits

Where Applicable Data Protection Law grants Customer an audit right, Customer may conduct an audit no more than once annually unless a Security Incident, regulator or material compliance concern reasonably requires more frequent review. Audits must be conducted during normal business hours, on reasonable advance notice, in a manner that does not disrupt operations or compromise other customers' confidentiality or security. Beginso may satisfy audit requests through independent audit reports, certifications, questionnaires or remote evidence where legally sufficient.

11.3 Audit Costs

Customer bears its own audit costs and shall reimburse Beginso for reasonable costs of on-site or unusually burdensome audits unless the audit identifies a material breach by Beginso or Applicable Law requires otherwise.

12. Government and Law-Enforcement Requests

12.1 Legally Binding Requests

Beginso may disclose Customer Personal Data where required by a valid and binding legal process or lawful request of a competent authority.

12.2 Notice and Challenge

Where legally permitted, Beginso shall endeavour to notify Customer before disclosure and may challenge or seek to narrow requests that appear unlawful, overbroad or disproportionate.

13. Jurisdiction-Specific Terms

13.1 India

Where the DPDP Act applies, Customer is responsible for its obligations as Data Fiduciary where it determines the purpose and means of processing, and Beginso shall process relevant Customer Personal Data on Customer's behalf as Data Processor where that classification applies. The parties shall cooperate in good faith to meet obligations applicable to their respective roles as the DPDP framework comes into force and evolves.

13.2 EEA / GDPR

To the extent Article 28 GDPR applies, Sections 3 through 12 and Annexes A-C are intended to satisfy the mandatory controller-processor contractual requirements, including documented instructions, confidentiality, security, subprocessors, Data Subject assistance, breach assistance, deletion/return, compliance information and audits.

13.3 United Kingdom

To the extent Article 28 UK GDPR applies, this DPA shall be interpreted to provide substantially equivalent processor obligations, together with the UK transfer mechanism described in Section 10.3 where required.

13.4 California

To the extent the CCPA/CPRA applies and Beginso processes Personal Information as a Service Provider or Contractor, Beginso shall not sell or share such Personal Information for cross-context behavioural advertising; shall not retain, use or disclose it outside the direct business relationship or for purposes other than the specified business purposes permitted by law and the Agreement; and shall provide the level of privacy protection required of Service Providers/Contractors. Customer may take reasonable and appropriate steps to help ensure Beginso processes such Personal Information consistently with applicable contractual requirements, subject to this DPA's audit procedures.

13.5 Other Laws

If another Applicable Data Protection Law imposes mandatory processor terms not expressly addressed here, those mandatory terms are incorporated to the minimum extent required by law. The parties may enter into a supplemental addendum where reasonably necessary.

14. Liability, Indemnity and Relationship to Agreement

14.1 Agreement Controls Commercial Risk Allocation

Except to the extent mandatory law or applicable transfer clauses require otherwise, liability arising from this DPA is subject to the exclusions, limitations, indemnities and other risk-allocation provisions in the Agreement. Nothing in this DPA expands Beginso's aggregate liability beyond the liability cap in the Terms of Use unless expressly agreed in writing.

14.2 Customer Responsibility

Customer remains responsible for claims, investigations or losses arising from Customer's unlawful collection, instructions, Form design, failure to provide notice or obtain consent, misuse of Respondent Data, unauthorised exports, or use of the Services in breach of Applicable Data Protection Law, subject to the Terms of Use and mandatory law.

14.3 Mandatory Rights

Nothing in this DPA limits any liability, Data Subject right or regulatory power that cannot lawfully be limited or excluded.

15. Term and Termination

15.1 Term

This DPA takes effect when Customer accepts or enters into the Agreement and continues while Beginso processes Customer Personal Data on Customer's behalf.

15.2 Survival

Confidentiality, deletion/retention, audit, international-transfer, liability and other provisions that by their nature should survive termination remain effective for as long as Beginso retains Customer Personal Data or as otherwise required by law.

16. General

16.1 Electronic Acceptance

This DPA may be accepted electronically, by execution, by incorporation into an order form or enterprise agreement, or by continued use of the Services where the Agreement provides for incorporation of this DPA.

16.2 Amendments

Beginso may update this DPA where reasonably necessary to reflect changes in Applicable Data Protection Law, approved transfer mechanisms, Subprocessor practices or the Services. Material changes will be notified as required by law or the Agreement. Any amendment to mandatory Standard Contractual Clauses is effective only to the extent permitted by those clauses.

16.3 Severability

If any provision is invalid or unenforceable, it shall be modified to the minimum extent necessary or severed without affecting the remaining provisions.

16.4 Governing Law

Except where mandatory Applicable Data Protection Law or transfer clauses require otherwise, this DPA is governed by the governing-law and dispute-resolution provisions of the Beginso Terms of Use, including the agreed arbitration framework and Mumbai, Maharashtra, India seat.

17. Contact

PurposeContact
Privacyprivacy@beginso.com
Legal / DPA Noticeslegal@beginso.com
General Supportsupport@beginso.com
Security Incidentssecurity@beginso.com
Grievancegrievance@beginso.com
Registered AddressMumbai, Maharashtra, India
Platformhttps://beginso.com/

Annex A. Details of Processing

ItemDescription
Subject matterProvision of the Beginso Services, including creation and publication of Forms, collection and management of Submissions, uploaded-file handling, analytics, reporting, Workspace collaboration, team permissions, account-related functionality and related support.
DurationFor the duration of the Agreement and any limited post-termination period during which Customer Personal Data remains in active systems or backups in accordance with the Agreement and Applicable Law.
Nature of processingCollection, receipt, recording, organisation, storage, hosting, retrieval, consultation, display, access control, analysis, reporting, export facilitation, transmission, support, security processing, deletion and other processing necessary to provide the Services.
PurposeTo provide, secure, maintain, support and improve the Services for Customer in accordance with Customer's documented instructions and the Agreement.
Categories of Data SubjectsRespondents; Customer personnel; Workspace members; employees, contractors, applicants, clients, customers, students, members, patients or other individuals whose information Customer chooses to collect through Forms, subject to Applicable Law.
Categories of Personal DataNames; email addresses; telephone numbers; addresses; identifiers; employment, education or business information; questionnaire responses; dates; free-text responses; documents and uploaded files; technical and security metadata; and any other Personal Data Customer chooses to collect through the Services.
Special categories / sensitive dataOnly where Customer chooses to collect such data and has a lawful basis and required safeguards. This may include health, financial, biometric, government-identifier, children's or other specially protected data. Use may be subject to additional restrictions or approval.
FrequencyContinuous or intermittent, depending on Customer use of the Services.
RetentionAs configured by Customer, provided by the applicable plan, required by the Agreement, or required/permitted by Applicable Law. Deleted data may remain temporarily in backups until overwritten in the ordinary course.
Customer instructionsThe Agreement, Customer's configuration and use of the Services, and additional written instructions accepted by Beginso.

Annex B. Technical and Organisational Measures

Beginso maintains a security programme designed to provide a level of security appropriate to the risk. Measures may evolve with the Platform and threat environment. The following describes the categories of safeguards that may apply; it does not constitute a representation that every listed technology is deployed identically across every component or plan.

Control AreaSafeguard Category
Access controlRole-based and permission-based access, least-privilege principles where appropriate, account/session controls and administrative access restrictions.
AuthenticationUser authentication mechanisms, session management and controls designed to reduce unauthorised account access.
Transmission securityEncryption in transit or comparable transport protection for supported production communications.
Storage and infrastructureCloud infrastructure security, logical separation, restricted administrative access and appropriate provider controls.
Logging and monitoringOperational, security and audit logging appropriate to the Services, together with monitoring for anomalous or abusive activity.
Vulnerability managementReasonable processes for security updates, patching, vulnerability review and remediation based on risk.
Availability and resilienceBackup, redundancy, recovery and service-continuity measures appropriate to the service architecture and plan.
Incident responseProcesses for triage, containment, investigation, remediation, communication and post-incident review.
PersonnelConfidentiality obligations, role-based access and security awareness appropriate to personnel responsibilities.
Subprocessor governanceContractual data-protection and security obligations appropriate to the services performed by Subprocessors.
Data lifecycleControls supporting deletion, retention, export and account/workspace access management in accordance with product functionality and the Agreement.
Testing and reviewPeriodic review of safeguards and security practices, with improvements implemented based on risk, system changes and legal obligations.

Annex C. Subprocessors and Processing Locations

Beginso may use Subprocessors in categories including cloud infrastructure, database services, object/file storage, identity and authentication, email/notification delivery, monitoring, analytics, security, customer support, payment processing and other technical services. A current Subprocessor list may be published or made available by Beginso. Customer authorises these categories subject to Section 9.

Because providers and hosting locations may change as the Platform evolves, this DPA does not hard-code provider names or data-centre locations. Where Applicable Data Protection Law requires notice, transparency or a transfer mechanism, Beginso will provide or implement it as required.

Annex D. International Transfer Particulars

Transfer ItemParticulars
Data exporterCustomer or the relevant Customer affiliate exporting Personal Data.
Data importerBeginso and/or the relevant Beginso group entity receiving or accessing the Personal Data.
Exporter roleController or Processor, depending on Customer's role for the relevant processing.
Importer roleProcessor or Subprocessor, depending on Customer's role.
Data subjects and dataAs described in Annex A.
Frequency and natureAs described in Annex A.
Purpose and durationAs described in Annex A.
Security measuresAs described in Annex B.
SubprocessorsAs described in Annex C and any current Subprocessor list made available by Beginso.
Competent supervisory authorityDetermined under the applicable EU SCCs or other transfer mechanism based on the exporter's establishment, representative, affected Data Subjects and Applicable Law.
Governing Member State for EU SCCsWhere a Member State law must be selected, the parties shall select a jurisdiction permitted by the EU SCCs and connected to the relevant transfer; if an order form or enterprise agreement specifies a valid selection, that selection controls.
UK AddendumThe parties intend the then-current ICO-approved Addendum or IDTA to apply where required, populated using this DPA and these Annexes to the extent permitted.

Annex E. Execution / Acceptance

This DPA may be incorporated electronically into the Agreement. Where the parties require signatures, they execute this DPA through a signed order form, enterprise agreement, or other executed document incorporating it by reference, rather than through this published version.