LEGAL FRAMEWORK // PROTOCOL 04

Data Processing Addendum.

ORGANIZATION: CX24 DIGITAL TECHNOLOGIES PVT. LTD.
EFFECTIVE: JULY 13, 2026
UPDATED: JULY 13, 2026
This Data Processing Addendum ("DPA") forms an integral part of any agreement between CX24 Digital Technologies Pvt. Ltd. ("CX24", "Processor") and its customers ("Customer", "Controller") where CX24 processes Personal Data on behalf of the Customer in connection with the provision of its services.

Contents

1. Introduction

This DPA is intended to satisfy the requirements of Article 28 of Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and other applicable data protection and privacy laws. It defines the respective responsibilities of the Controller and the Processor and establishes the safeguards implemented by CX24 to ensure the lawful, secure, and confidential processing of Personal Data.

CX24 processes Personal Data solely on documented instructions from the Customer and implements appropriate technical and organizational measures to protect Personal Data against unauthorized access, disclosure, alteration, loss, or destruction.

2. Scope

This DPA applies whenever CX24 processes Personal Data on behalf of a Customer in connection with the delivery of its services, including but not limited to:

  • Business Process Management (BPM) Services
  • Customer Experience (CX) Services
  • Engineering Services
  • Technical Support Services
  • Managed Services
  • AI-enabled Business Services

3. Roles and Responsibilities

The Customer acts as the Data Controller and determines the purposes and means of processing Personal Data.

CX24 acts as the Data Processor and processes Personal Data solely on documented instructions received from the Customer.

4. Processing of Personal Data

CX24 shall:

  • Process Personal Data only on documented instructions from the Customer.
  • Ensure that personnel authorized to process Personal Data are subject to confidentiality obligations.
  • Process Personal Data solely for the purpose of delivering contracted services.
  • Not sell, disclose, or use Personal Data for unauthorized purposes.

5. Security Measures

CX24 maintains appropriate technical and organizational measures to protect Personal Data, including:

  • Role-Based Access Controls (RBAC)
  • Multi-Factor Authentication (MFA)
  • Encryption of data where appropriate
  • Security monitoring and logging
  • Vulnerability management
  • Secure backup procedures
  • Employee security awareness training
  • Incident response procedures

These measures are designed to protect the confidentiality, integrity, and availability of Personal Data.

6. Sub-processors

CX24 Digital Technologies Pvt. Ltd. engages the following third-party sub-processor in connection with the provision of its services:

Sub-Processor Details:

Sub-Processor: Microsoft Corporation (Microsoft 365 – Outlook and Microsoft Teams)
Service Provided: Business email, collaboration, communication, and document sharing services that may involve the processing of Customer Personal Data in the course of providing CX24 services.
Processing Location: Microsoft global data centre infrastructure, including data centres located in India (where applicable) and other regions as determined by Microsoft's service architecture and applicable data residency commitments.

CX24's production applications and customer-hosting infrastructure are operated exclusively on internally managed on-premises systems. Microsoft is not used to host or operate CX24's production application or customer databases.

CX24 has executed appropriate contractual arrangements with Microsoft, including applicable data protection commitments, to ensure that any processing of Customer Personal Data is performed in accordance with applicable data protection laws.

Should CX24 appoint any sub-processor in the future, CX24 shall:

  • Conduct appropriate due diligence prior to engagement.
  • Enter into a written agreement imposing data protection obligations substantially equivalent to those contained in this DPA.
  • Remain fully responsible for the acts and omissions of the sub-processor relating to Customer Personal Data.
  • Maintain an up-to-date Sub-Processor Register.
  • Notify affected Customers of any new sub-processor, where required under applicable law or contractual commitments.

7. Data Subject Rights

CX24 shall provide reasonable assistance to Customers in responding to requests from data subjects, including:

  • Right of Access
  • Right to Rectification
  • Right to Erasure
  • Right to Restriction of Processing
  • Right to Data Portability
  • Right to Object

8. Personal Data Breach Notification

CX24 shall notify the Customer without undue delay upon becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data.

Such notification shall include:

  • Nature of the incident
  • Categories of data affected
  • Potential impact
  • Corrective actions taken
  • Recommended mitigation measures

9. International Transfers

CX24 primarily processes and stores Customer Personal Data using its internally managed infrastructure located within India. As of the Effective Date of this Data Processing Addendum, CX24 does not intentionally transfer Customer Personal Data outside the jurisdiction in which it is collected unless such transfer is required for the performance of the agreed services or is expressly authorized by the Customer.

Where an international transfer of Personal Data is necessary, CX24 shall ensure that such transfer is carried out in accordance with applicable data protection laws, including Chapter V of the General Data Protection Regulation (GDPR), and shall implement appropriate safeguards to ensure an adequate level of protection for Personal Data.

Such safeguards may include, where applicable:

  • European Commission Standard Contractual Clauses (SCCs);
  • An Adequacy Decision issued by the European Commission;
  • Binding Corporate Rules (BCRs), where applicable;
  • Approved Codes of Conduct or Certification Mechanisms recognized under the GDPR; or
  • Any other lawful transfer mechanism permitted under applicable data protection legislation.

CX24 shall maintain appropriate documentation demonstrating the legal basis for any international transfer of Personal Data and shall provide reasonable assistance to Customers in meeting their own cross-border data transfer obligations where required.

Transfer Assessment: As of the Effective Date of this DPA, CX24 has assessed its processing operations and confirms that Customer Personal Data is primarily processed within India. Should future business requirements necessitate international transfers, CX24 will implement the appropriate legal transfer mechanism before such transfers commence.

10. Audits and Compliance

Upon reasonable request, CX24 may provide information necessary to demonstrate compliance with this DPA and applicable data protection requirements.

11. Data Retention and Deletion

Upon termination of services, CX24 shall, subject to applicable legal or regulatory retention requirements:

  • Return Personal Data to the Customer; or
  • Securely delete Personal Data from its systems.

12. Contact Information

For privacy, data protection, or DPA-related inquiries, please contact:

CX24 Digital Technologies Pvt. Ltd.
Email: privacy@cx24.comWebsite: www.cx24.com

13. Updates

CX24 may periodically update this DPA to reflect operational, legal, regulatory, or security changes. The latest version shall always be available on this website.

Version: 1.1
Last Updated: 05th August 2026