Legal

Data Processing Addendum

Version 1.0 · Effective September 18, 2026 · Last Updated September 18, 2026

This Data Processing Addendum (“DPA”) forms part of the Terms of Service or other written agreement between the Customer and VNash Digital Pvt Ltd (“Processor,” “Sapyon,” “we,” or “us”) for the Sapyon AI service (the “Agreement”). If a separately signed DPA exists, that signed document controls.

This DPA applies only to Personal Data in Customer Data (including Amazon Ads Data) that we process on Customer’s behalf. We remain an independent controller of Website Data and Account Data under our Privacy Policy. This page is offered so enterprise customers can review and download (print or save) our standard addendum. It is not legal advice.

1. Controller / processor relationship

For Customer Data processed through the Service:

  • Customer is the controller (or a processor acting for a brand or advertiser, in which case Customer warrants it is authorized to appoint Sapyon as a subprocessor).
  • VNash Digital Pvt Ltd is the processor.

Amazon, Flipkart, Google (for Customer’s own Google account), and similar connected platforms are independent controllers or processors of their own services. They are not Sapyon subprocessors.

2. Subject matter, duration, nature, and purpose

Subject matter. Processing of Personal Data contained in Customer Data so that Sapyon can provide Amazon advertising optimization and related features described in the Agreement and Privacy Policy.

Duration. For the term of the Agreement and until deletion or return under Section 13.

Nature of processing. Collection (via connected APIs and Customer input), storage, hosting, organization, retrieval, display, analysis, transmission to subprocessors (including Google Gemini when Chat is used), and deletion; and, where Customer configures or confirms it, write-back of campaign, budget, bid, keyword, placement, and state changes to Amazon Ads APIs.

Purpose. To provide, secure, support, and improve the Service as instructed by Customer, including hourly analytics, recommendations, automations, reporting, and Chat. We do not process Customer Data to sell it, to serve unrelated advertising, or to train general-purpose AI models unless Customer agrees in writing.

3. Categories of personal data and data subjects

Data subjects typically include Customer’s employees, contractors, and agency operators who have Service accounts; and, to the limited extent identifiers appear in advertising or retail data the Customer connects, other individuals whose identifiers Amazon or another platform includes in that data. Sapyon is not a consumer-profiling product for Amazon shoppers.

Categories of personal data may include: names, business email addresses, user ids, role and permission data, IP and device data associated with Service use, advertising-account identifiers, campaign and performance data, and Chat prompts that a User includes. Passwords and OAuth tokens are processed to authenticate and to call connected APIs. Customer should not submit special-category data or children’s data to the Service.

4. Customer instructions

We will process Customer Data only on documented instructions from Customer, including the Agreement, this DPA, configuration in the Service (connections, rules, approvals, Chat confirmations), and written instructions from an authorized administrator, unless Union, Member State, US, Indian, or other applicable law requires otherwise. In that case we will inform Customer before processing, unless the law prohibits that notice.

If we reasonably believe an instruction infringes GDPR or other data-protection law, we will notify Customer. Customer is responsible for the lawfulness of its instructions and for having a legal basis to collect and share Customer Data with us, including advertising data obtained from Amazon.

5. Confidentiality

We will ensure that persons authorized to process Customer Data are under an appropriate confidentiality obligation. Access is limited as described in the Security Overview.

6. Security

Taking into account the state of the art, costs, nature, scope, context, and purposes of processing, we implement appropriate technical and organizational measures to protect Customer Data, including the measures in our Security Overview and Privacy Policy (authentication, RBAC, TLS in transit, AWS Secrets Manager for secrets, and related hosting controls). Customer is responsible for configuring the Service, User access, and connected-account permissions.

7. Subprocessors

Customer authorizes us to engage subprocessors to host and operate the Service. The current list is published at https://sapyon.com/subprocessors/ and includes AWS, Netlify, Cloudflare, Google (including Gemini for Chat), Microsoft Clarity (Website), and Calendly (demo booking). Amazon Ads is a connected platform of Customer, not a Sapyon subprocessor.

We will impose data-protection obligations on subprocessors that are materially no less protective of Customer Data than this DPA, to the extent applicable to the service they provide.

8. Subprocessor authorization

Customer provides general written authorization for us to engage and replace subprocessors. We will keep the Subprocessors page current. For a material addition or replacement of a subprocessor that will process Customer Data, we will provide an opportunity to object by updating that page (and, where we have an administrator email, by notice) at least fourteen (14) days before the change takes effect, except for emergency replacements needed for security or service continuity, in which case we will notify as soon as practicable.

If Customer objects on reasonable data-protection grounds, the parties will discuss in good faith. If we cannot accommodate the objection, Customer may terminate the affected Service as its sole remedy.

9. Data-subject requests

Taking into account the nature of the processing, we will assist Customer, by appropriate technical and organizational measures and insofar as possible, in fulfilling Customer’s obligation to respond to requests to exercise data-subject rights. If we receive a request that relates solely to Customer Data we process as processor, we will, unless law requires us to act directly, redirect the individual to Customer and notify Customer. See also Privacy Requests.

10. Security incident and breach assistance

We will notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer Data we process as processor. The notice will include, as then known: the nature of the incident, likely consequences, measures taken or proposed, and a contact point. We will reasonably assist Customer with Customer’s breach-notification obligations, including information Customer reasonably needs to notify regulators or data subjects where legally required.

11. DPIA assistance

Taking into account the nature of processing and information available to us, we will provide reasonable assistance to Customer with data-protection impact assessments and prior consultation with supervisory authorities, insofar as they relate to processing by Sapyon. Additional assistance beyond a reasonable written response may be charged at then-current professional rates if it requires material engineering effort.

12. International transfers

VNash Digital Pvt Ltd is established in India. Customer Data is processed in India, the United States (including AWS us-east-1), and other locations where our subprocessors operate, as listed on the Subprocessors page. We do not offer single-region residency.

Where GDPR or UK GDPR applies to a transfer of Personal Data from the EEA, United Kingdom, or Switzerland, the parties rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses (and UK/Swiss addenda where required) module for controller-to-processor transfers, completed with the details in this DPA, and on subprocessors’ own SCCs or other approved transfer tools. On request to [email protected], we will provide the execution details reasonably needed to document those clauses.

13. Deletion and return

At the end of the provision of processing services, Customer may request return of available Customer Data in a reasonable machine-readable form while the account remains accessible. After termination or a documented deletion instruction, we will delete or anonymize Customer Data from production systems promptly, and in any event within ninety (90) days, except (a) information we must retain for legal, security, or dispute purposes, (b) backup copies that expire on the backup rotation cycle, and (c) data remaining with Amazon or another independent platform. Certification of deletion is available on written request after the production deletion window.

14. Audits

We will make available information reasonably necessary to demonstrate compliance with this DPA. Customer may audit our relevant processing of Customer Data no more than once per twelve (12) months, on thirty (30) days’ written notice, during business hours, subject to confidentiality, and in a manner that does not unreasonably disrupt operations or other customers. We may satisfy an audit request with third-party audit reports or security documentation where those reasonably address the request. On-site or invasive testing requires our prior written agreement. Customer bears its own audit costs unless the audit reveals a material breach of this DPA.

15. Government requests

If a government or law-enforcement authority requests Customer Data, we will, where legally permitted, notify Customer before disclosure so Customer may seek a protective order or other remedy. We will disclose only the Customer Data we are legally compelled to disclose. We will challenge unlawful or overbroad requests where we reasonably believe we have a legal basis to do so.

16. Liability

Each party’s liability under this DPA is subject to the limitations in the Agreement, except that those limitations do not apply to the extent they would exclude or limit liability that cannot be limited under GDPR Article 82 or other mandatory data-protection law. This DPA does not reduce either party’s obligations to data subjects who are not parties to the Agreement.

17. Contact

Processor: VNash Digital Pvt Ltd, Bangalore, India

Privacy contact: [email protected]

Print or save this page for your records. Related: Terms of Service · Privacy Policy · Subprocessors · Security Overview · Privacy Requests

Ready to Turn Hourly Signals into Higher ROAS?

Real-time analytics, automation, and AI decisions, built specifically for Amazon advertisers. Scale with confidence.

Book a Demo