Data Processing Addendum
Last updated: 10 August 2026
This Data Processing Addendum ("DPA") forms part of the Korekko Terms of Service (the "Agreement") and governs the processing of Customer Data by Korekko on behalf of the user or business entity ("Customer") using the Korekko platform. By accepting this DPA — by clicking a box indicating acceptance as presented during workspace activation, or by executing an agreement that references it — the Customer agrees to these terms.
1. Definitions
- "Customer Data" means any personal data or information submitted by or on behalf of the Customer to the Korekko platform, including data received through channels the Customer connects.
- "Data Protection Laws" means all applicable laws and regulations relating to the processing of personal data, including India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made under it.
- "Subprocessor" means any third-party data processor engaged by Korekko to assist in providing the service.
2. Roles and Responsibilities
2.1 Relationship of the parties. For all Customer Data processed under this DPA, the Customer is the Data Fiduciary (or controller) and the owner of the data. Korekko acts solely as a Data Processor on behalf of the Customer, processing Customer Data under this DPA as the contract contemplated by Section 8(2) of the DPDP Act.
2.2 Lawful basis. The Customer represents and warrants that it has all rights, consents, and lawful bases required under applicable Data Protection Laws to collect Customer Data and share it with Korekko for the purposes of using the service, including consent for the communication channels the Customer operates through Korekko.
3. Processing Instructions and Scope
3.1 Documented instructions. Korekko will process Customer Data only in accordance with the Customer's documented instructions, which include the Customer's use of the product, its configuration of connected features (such as WhatsApp, Meta, and Google integrations), and its support requests.
3.2 Nature of data. Data processed may include names, contact details, enquiry records, bookings, payment-related metadata (excluding card numbers and UPI PINs, which Korekko does not access), conversation content and transcripts, reviews, and related business workflow data.
3.3 AI processing and learning. Korekko uses a third-party AI provider (Anthropic) strictly for intent classification and reply drafting. Korekko uses Customer Data to calibrate and improve the service for the Customer — for example, learning the Customer's tone, outcomes, and follow-up performance to improve the Customer's own results. Korekko shall ensure that:
- phone numbers, email addresses, and links are programmatically redacted from conversation context before reply-drafting, and no customer name or identifier is sent for intent classification;
- Korekko does not train AI models on identifiable Customer Data, and Korekko's AI provider does not train its models on Customer Data (as reflected in the provider's data processing addendum and commercial terms accepted by Korekko);
- identifiable Customer Data is never used for, or made available to, any other customer; and
- de-identified, aggregated statistical patterns that cannot be linked to any individual or to any Customer may be retained and used to improve Korekko's systems and services for all users.
4. Security Measures
4.1 Safeguards. Korekko implements and maintains reasonable technical and organizational safeguards designed to protect Customer Data against unauthorized access, disclosure, destruction, or alteration, consistent with the DPDP Act and the rules made under it.
4.2 Encryption and isolation. Customer Data is encrypted in transit (TLS 1.2+) and at rest (AES-256 at the database level). Access credentials and integration tokens are additionally encrypted at the application layer. Customer workspaces are logically separated, supported by row-level security and application-level access controls.
4.3 Incident notification. Korekko will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Data, and will provide reasonable assistance and information to enable the Customer to meet its obligations to the Data Protection Board of India and affected Data Principals under applicable Data Protection Laws.
5. Subprocessors and International Transfers
5.1 General authorization. The Customer provides general authorization for Korekko to engage Subprocessors (including Supabase, Vercel, Anthropic, Meta, Razorpay, and Google) to operate the service.
5.2 Subprocessor obligations. Korekko engages each Subprocessor under a written agreement — including, where applicable, the Subprocessor's standard data-processing terms — that imposes data protection obligations consistent with applicable Data Protection Laws and appropriate to the services provided. Korekko remains responsible to the Customer for its Subprocessors' processing of Customer Data, subject to Section 9.2.
5.3 Updates. Korekko maintains a current list of Subprocessors in its Privacy Policy. If the Customer reasonably objects to a new Subprocessor, the Customer's sole remedy is to stop using the affected service and terminate its account.
5.4 International transfers. Customer Data may be processed and stored in locations outside India, including Singapore and the United States, through the Subprocessors referenced above. Such transfers are made in accordance with Section 16 of the DPDP Act and the rules made under it; as at the date of this DPA, no restriction has been notified by the Central Government in respect of these destinations. If any such restriction is notified, Korekko will take reasonable steps to comply, including relocating the affected processing where required.
6. Personnel and Confidentiality
6.1 Access restriction. Access to Customer Data is limited to authorized Korekko personnel and service providers who require such access to operate, support, and secure the service, on a need-to-know basis.
6.2 Confidentiality. All personnel authorized to process Customer Data are bound by documented confidentiality obligations.
7. Data Principal Rights and Assistance
7.1 Customer responsibility. The Customer is responsible for responding to requests from individuals (Data Principals) exercising their rights under Data Protection Laws, including requests for access, correction, and erasure.
7.2 Korekko assistance. Korekko will provide reasonable technical assistance to enable the Customer to fulfil these obligations. If Korekko directly receives a request from a Data Principal concerning Customer Data, Korekko will redirect the individual to the Customer within a reasonable time.
8. Data Deletion
8.1 Channel disconnection. When the Customer disconnects a connected third-party channel (such as WhatsApp or Instagram), Korekko automatically deletes that channel's message data within 24 hours. Stale inbound message records are in any event automatically purged after 30 days, as described in the Privacy Policy.
8.2 Account termination. On termination of the Customer's account, or on the Customer's valid written request, Korekko will permanently delete all Customer Data within 30 days, save for: encrypted database backups, which age out within a standard 7-day retention window; records whose retention is required by applicable legal, security, fraud-prevention, billing, or recordkeeping obligations (including payment and transaction records retained for 7 years under applicable Indian financial regulations); and de-identified, aggregated patterns under Section 3.3, which identify no individual and no Customer.
9. General Provisions
9.1 Term and survival. This DPA takes effect on the Customer's acceptance and remains in force for as long as Korekko processes Customer Data on the Customer's behalf. Sections 3.3 (final bullet), 6, 8, and 9 survive termination.
9.2 Liability. Each party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
9.3 Precedence. In the event of any conflict between this DPA and the Terms of Service regarding the processing of Customer Data, this DPA governs. Where the parties have executed a separate written data processing agreement, that executed agreement prevails over this DPA to the extent of any conflict.
9.4 Governing law and dispute resolution. This DPA is governed by the laws of India. Any dispute arising out of or in connection with this DPA shall first be referred to arbitration by a sole arbitrator appointed in accordance with the Arbitration and Conciliation Act, 1996, with the seat and venue of arbitration at New Delhi and proceedings conducted in English. Subject to the foregoing, the courts at New Delhi have exclusive jurisdiction, including for interim relief.
9.5 Contact. Questions regarding this DPA may be directed to team@korekko.com.