Skip to content
Legal

Data Processing Agreement

Last updated: September 2026

This Data Processing Agreement ("DPA") applies when Slinai Technologies Pvt. Ltd. ("Processor") processes personal data in customer camera footage, events, clips, or related platform data on behalf of a business customer ("Customer", the Data Fiduciary) in connection with Slinai services. A signed order or master agreement may attach a negotiated DPA that supersedes this website version.

1. Roles

Customer determines the purposes and means of monitoring (locations, cameras, detections, retention, who may view clips). Customer is the Data Fiduciary under the DPDP Act. We process that data only to provide the services and on Customer's documented instructions, including configuration in the product.

For our own marketing website and billing contacts, we are a Data Fiduciary — that is covered by the Privacy Policy, not this DPA.

2. Nature of processing

  • Subject matter: video analytics on Customer's existing CCTV and the resulting events, alerts, dashboards, and optional integrations.
  • Duration: the subscription term plus deletion/return as below.
  • Types of data: video frames or streams, derived events, short clips, account identifiers of Customer's users, and any metadata Customer connects (for example POS timestamps). We do not require names of store visitors. Biometric identification is out of scope unless separately agreed in writing.
  • Data subjects: people who appear in Customer's cameras (staff, visitors, contractors) and Customer's authorised users of the platform.

3. Processor obligations

  • Process only on Customer's instructions, unless Indian law requires otherwise — in which case we notify Customer unless the law forbids it.
  • Ensure staff and contractors with access are bound by confidentiality.
  • Implement technical and organisational measures appropriate to the risk (encryption in transit, access control, audit logs, optional edge/on-prem so video need not leave the site). Details: Security page.
  • Help Customer respond to data-principal requests that relate to Processor-held data, within reasonable effort and the product's capabilities.
  • Notify Customer without undue delay after becoming aware of a personal-data breach affecting Customer data, with facts we reasonably have.
  • Delete or return Customer personal data when the services end, within 30 days of a written request, except copies we must keep under law or isolated backups that rotate out.

4. Customer obligations

Customer warrants it has a lawful basis to monitor and to instruct us (including notices to staff and visitors, workplace policies, and sector rules). Customer will not instruct processing that is unlawful. Customer configures retention, roles, and zones. Customer is responsible for how alerts are used (including WhatsApp groups they choose).

5. Sub-processors

Customer authorises us to use infrastructure sub-processors required to run the contracted deployment. Cloud deployments currently use Google Cloud. Edge and on-prem deployments keep primary video on Customer's equipment. We will not replace core hosting in a way that materially reduces protection without notice where the contract requires it. We remain responsible for sub-processors we appoint.

6. International transfers

Where Customer selects India residency, we process primary service data in India as offered. If Customer agrees to another region, or uses a channel (such as WhatsApp) that transmits outside India, Customer instructs that transfer.

7. Audits

On reasonable written notice, no more than once per year (unless a competent authority or a confirmed breach requires more), Customer may review our security summary and ask written questions. On-site or intrusive testing requires a mutually agreed scope so other customers are not put at risk.

8. Liability and term

Liability under this DPA follows the limitation of liability in the principal agreement (or the Terms of Use if there is no other agreement). This DPA lasts for the services term and survives for deletion, confidentiality, and liability.

9. Contact

Privacy and processing questions: hello@slinai.com. Related: Privacy Policy, Security, Terms of Use.

Slinai Technologies Pvt. Ltd. · Bengaluru, India · hello@slinai.com

Chat