Draft under legal review — this template has not yet been signed off by counsel. Placeholders marked [●] are pending. Do not rely on this text until the review banner is removed.

DATA PROCESSING ADDENDUM (DPA)

To the Creatorgoose Platform Terms of Service | Version 1.0 (Draft) | Effective: on Brand account acceptance

DRAFTING NOTE (remove in production): Drafted against the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the DPDP Rules, 2025 (notified 13/14 Nov 2025; substantive obligations in Rules 3, 5–16, 22–23 phase in by ~May 2027 — we build compliant now so brands can point to this DPA in their own compliance programmes). Section 8(2), DPDP Act requires a fiduciary to engage a processor only under a valid contract — this is that contract. Review by licensed counsel before production.


1. Roles and scope

1.1 This DPA applies wherever Creatorgoose processes End-User Personal Data on behalf of a Brand. For that data: the Brand is the Data Fiduciary; Creatorgoose is the Data Processor acting on the Brand's documented instructions.

1.2 Dual capacity acknowledged: for account data of Brands and Creators themselves (registration, KYC, usage logs, billing), Creatorgoose is an independent Data Fiduciary under its Privacy Notice — that processing is outside this DPA.

1.3 "End-User Personal Data" means personal data of the Brand's customers, followers, or audience processed through the Platform, including: Instagram usernames and public interaction data (comments, DMs to connected accounts), phone numbers and WhatsApp identifiers captured through opt-in flows, order and customer records from connected commerce systems (e.g., Shopify), and derived attributes linking the foregoing.

2. Instructions and purpose limitation

2.1 Creatorgoose shall process End-User Personal Data only: (a) to provide the Platform services the Brand has enabled (comment moderation and reply, DM automation, opt-in capture, order matching/attribution, segmentation, campaign analytics); (b) per the Brand's configuration and documented instructions; and (c) as required by law (in which case we notify the Brand unless legally barred).

2.2 No sale, no independent use. Creatorgoose shall not sell End-User Personal Data, use it to build profiles for its own purposes, use it for advertising unrelated to the Brand, or combine it across Brands in personally identifiable form. (Aggregated, anonymised, non-reidentifiable statistics are not personal data, and Creatorgoose may use them to improve the Platform.)

2.3 If we believe an instruction violates the DPDP Act or platform terms of a source (e.g., Meta Platform Terms), we will inform the Brand and may suspend the instructed processing.

3. Consent management (operative core)

3.1 The Platform captures End-User consent through configurable flows (e.g., phone-number opt-in within DM conversations). For each consent, Creatorgoose records and retains a consent artefact: identity reference, timestamp, the notice text shown, purposes consented to, channel, and campaign/creator context.

3.2 The Brand is responsible for the legal sufficiency of the notice and purposes (as Fiduciary); Creatorgoose provides the tooling and will not process beyond the purposes recorded in the artefact.

3.3 Withdrawal: when an End-User withdraws consent (including "STOP" keywords, in-flow opt-out, or a request routed by the Brand), Creatorgoose shall cease the corresponding processing without undue delay and flag the record across dependent systems (messaging suppression list, segments, attribution store), per Section 6(6), DPDP Act.

3.4 When the Consent Manager framework under the DPDP Rules becomes operational, the parties will cooperate in good faith to integrate registered Consent Managers where required.

4. Security safeguards (Rule 6 mirror)

4.1 Creatorgoose shall implement reasonable security safeguards to prevent personal data breach, at minimum: (a) encryption in transit and at rest; (b) role-based access control and access logging with [1-year] log retention; (c) data segregation per Brand (tenant isolation); (d) masking/tokenisation of phone numbers in analytics views; (e) backups and tested recovery; (f) personnel confidentiality undertakings and least-privilege access; (g) secure development and vulnerability management.

4.2 These safeguards shall be no less protective than those the DPDP Rules require of the Brand as Fiduciary (Rule 6 flow-down).

5. Personal data breach

5.1 Creatorgoose shall notify the Brand without undue delay, and in any case within [48] hours of confirming a personal data breach affecting End-User Personal Data, with: nature and scope, categories and approximate volume, likely consequences, and measures taken.

5.2 The Brand (as Fiduciary) owns statutory notifications to the Data Protection Board and affected Data Principals; Creatorgoose shall provide all reasonable assistance and shall not notify End-Users directly unless instructed or legally required.

6. Data Principal rights assistance

Creatorgoose shall, within [7] days of a routed request, provide the Brand the data and tooling needed to honour rights under Chapter III, DPDP Act: access/summary of processing, correction, erasure, and grievance follow-up. Where the Platform offers self-serve tooling (export, delete, suppression), using it satisfies this clause.

7. Erasure and retention

7.1 On the earlier of (a) consent withdrawal (for consent-based processing), (b) purpose exhaustion, or (c) the Brand's erasure instruction, Creatorgoose shall erase the relevant End-User Personal Data and cause sub-processors to erase it, per Section 8(7), DPDP Act — retaining only what law requires (e.g., tax/audit records), which remains protected under Clause 4.

7.2 On termination of the Brand's account: export window of [30] days, then deletion within [60] days, with written confirmation on request.

8. Sub-processors

8.1 The Brand generally authorises the sub-processors listed in Schedule 1 (hosting/cloud [●]; escrow and payments — Cashfree; messaging/BSP [●]; analytics infrastructure [●]). Creatorgoose shall bind each to terms no less protective than this DPA and remains responsible for their performance.

8.2 Changes to Schedule 1 will be notified [15] days in advance; the Brand may object on reasonable data-protection grounds, in which case the parties will discuss alternatives (including the Brand disabling the affected feature).

8.3 Source-platform terms: processing of Instagram/WhatsApp data is additionally subject to Meta Platform Terms; commerce data to the commerce platform's API terms. In conflict with this DPA, the stricter (more protective) term governs.

9. Location and cross-border transfer

End-User Personal Data is stored and processed in India by default. No transfer outside India except (a) to a sub-processor location listed in Schedule 1, and (b) subject to any restrictions the Central Government notifies under Section 16, DPDP Act and the DPDP Rules.

10. Audit and information

10.1 On [15] days' notice, not more than once per year (plus after any breach), the Brand may audit compliance with this DPA via: written questionnaire, summary of independent audit reports/certifications, or — where those are insufficient — a remote or on-site inspection during business hours under confidentiality, at the Brand's cost.

10.2 Creatorgoose shall maintain records of processing activities for End-User Personal Data sufficient to demonstrate compliance with this DPA.

11. Children's data

The Platform is not designed to target children. Where processing implicates a child's data (as defined by the DPDP Act), the Brand must instruct it explicitly and satisfy verifiable-consent requirements (Section 9; Rule 10); absent that, Creatorgoose will suppress records identified as belonging to children.

12. Liability and precedence

12.1 Liability under this DPA is subject to ToS Clause 17, except that the cap for breach of this DPA is the greater of (a) the ToS cap and (b) ₹[●].

12.2 In conflict between this DPA and the ToS regarding End-User Personal Data, this DPA prevails.

12.3 This DPA terminates with the Brand's account, surviving as needed for Clause 7 (erasure) and audit of the final period.


SCHEDULE 1 — APPROVED SUB-PROCESSORS

Sub-processor Service Data categories Location
[Cloud provider ●] Hosting, storage All categories India ([region])
Cashfree Payments India Pvt. Ltd. Escrow, payouts Creator payout data; order values India
[BSP ●] WhatsApp messaging Phone numbers, message metadata India
[●] [●] [●] [●]

SCHEDULE 2 — PROCESSING DESCRIPTION