Data Processing Addendum
Last updated: July 2026
This Data Processing Addendum ("DPA") forms an integral part of the SaaS subscription Terms of Service between Pistio AI and the subscribing merchant. It regulates the processing of customer personal data under the Digital Personal Data Protection (DPDP) Act 2023 of India and other applicable data protection regulations.
1. Scope & Roles of Parties
The parties acknowledge and agree that:
- Merchant acts exclusively as the Data Controller. The merchant determines the purpose and scope of automated customer chat interactions.
- Pistio AI acts strictly as the Data Processor. We handle and process customer phone numbers, text chat strings, and integrated order tracking numbers solely on behalf of the merchant and in accordance with merchant settings.
2. Sub-processor Approvals & Audits
Pistio AI utilizes enterprise-contracted sub-processors to host platform data and run large language model queries. The currently authorized sub-processors are:
- Amazon Web Services (AWS Mumbai): Primary database cloud hosting and backups.
- OpenAI / Anthropic / Google Gemini APIs: Secure natural language processing models. Zero data retention policies are active to prevent model training.
- Meta Platforms (WhatsApp Business API): Messaging transmission channels.
Pistio AI maintains strict network monitoring. In the event of an unauthorized security breach or database exposure affecting personal data processed on your behalf, Pistio AI will notify the affected merchant within 72 hours of incident identification. We will provide a comprehensive log of the data categories affected and action steps taken to secure the system.
3. Technical & Organizational Security Measures
Pistio AI commits to implementing state-of-the-art security safeguards to isolate and protect merchant data:
- Encrypted storage of Meta tokens and store connection keys using AES-256 GCM.
- Logical database partition schemas ensuring no cross-tenant data visibility.
- Mandatory multi-factor authentication for administrative infrastructure tools.
4. Data Return and Deletion Timeline
Upon subscription cancellation, platform data is locked. After 30 days of subscription termination, Pistio AI will automatically delete all customer conversation history transcripts and API access keys from active databases, unless retention is required by local Indian commercial law.
To request manual execution of this deletion timeline immediately upon cancellation, please send a written request to support@pistioai.com.
