Processing Framework

Data Processing Agreement

The DPA framework for engagements where Vinkura processes personal data on behalf of an institution. An executable agreement is provided during procurement.

Version
v1.0
Effective
Jul 2026
Last updated
July 2026
Status
Published

Roles

In official deployments, the engaging institution acts as the data fiduciary (controller) and Vinkura acts as a data processor. This Data Processing Agreement (DPA) framework describes how Vinkura processes personal data on behalf of the institution.

Scope & Purpose

Vinkura processes personal data only on documented instructions from the institution and solely for the purposes defined in the governing master service agreement. Processing is scoped to what is necessary for the agreed operational outcome.

Security Measures

The executed DPA identifies the technical and organisational measures applicable to the deployment. Depending on scope, these may include role-based access control, encryption, logging, backup, change management, and incident response. Security documentation and any current third-party assurance artefacts are provided during due diligence subject to appropriate confidentiality terms.

Data Residency

Deployments can be configured for on-premise, sovereign-cloud, or hybrid boundaries so that personal data remains within jurisdictional and infrastructure constraints defined by the institution.

Sub-Processors

The executed DPA defines whether sub-processors may be used, the notice or approval process, and the obligations passed to them. A current list of applicable sub-processors is provided to the institution on request.

Data Subject Rights & Breach Notification

Vinkura assists the institution in responding to data principal requests and in meeting breach-notification obligations under the DPDP Act and applicable law, within the timelines defined in the governing agreement.

Return, Deletion, and Audit

The executed DPA defines data return or deletion at the end of services, lawful retention exceptions, evidence of deletion where applicable, and the institution’s audit or information rights.

Requesting an Executed DPA

This page describes the DPA framework and is not itself a contract. An executable DPA is provided as part of institutional procurement. To request a copy, contact our team.

This is a summary framework, not an executed agreement. Request an executable DPA via our contact channels.