Data Processing Agreement
Last updated: 3rd August 2026
Version 1.0
This Data Processing Agreement ("DPA") forms part of the agreement between Netscience Technologies Private Limited, trading as NSOffice.AI ("Processor," "we," "us") and the customer entering into an agreement with us ("Controller," "Customer," "you") for use of the NSOffice.AI platform (the "Service").
1. Definitions
"Data Protection Laws" means India's Digital Personal Data Protection Act, 2023 and the UK GDPR / Data Protection Act 2018, as applicable to the processing under this Agreement. "Personal Data," "Processing," "Data Subject," and "Personal Data Breach" carry the meanings given under applicable Data Protection Laws. "Connector" means an integration into a Customer-authorized third-party business system. "Bee" means a specialized AI agent performing a purpose-built task (e.g., image generation, video generation, research, or policy question-answering).
2. Subject Matter and Duration
Processing continues for the duration of the Customer's subscription, and thereafter only as necessary to complete the deletion process described in Section 11.
3. Nature and Purpose of Processing
NSOffice.AI processes Personal Data solely to provide the Service, comprising three capabilities:
- Think - AI-assisted chat, document analysis, and generation of business documents (Word, PowerPoint, Excel, PDF, CSV);
- Know - secure, real-time retrieval of Customer's enterprise knowledge from connected business systems, uploaded documents, and organizational memory, to ground responses in Customer's own data; and
- Do - performing actions on the Customer's instruction through Connectors and Bees, such as sending communications, creating or updating records, querying databases, and triggering workflows, strictly within the scope of authorization the Customer has granted.
4. Categories of Data and Data Subjects
Personal Data processed may include: Customer employee account and identity data; content submitted through chat, document uploads, and Bee usage; data accessed through Customer's connected business systems via Connectors; usage and billing metadata; and security and audit log data. Data Subjects are principally the Customer's employees, contractors, and authorized users, and may incidentally include third parties whose personal data appears within content the Customer submits or accesses through a Connector.
5. Data Residency and No International Transfer
- Personal Data is stored exclusively within the Customer's regional environment: data belonging to Indian organizations is stored and processed on servers located in India; data belonging to UK organizations is stored and processed on servers located in the United Kingdom. NSOffice.AI does not transfer stored Personal Data across these regional boundaries.
- Where a request draws on a connected business system (Know), the Service retrieves the relevant information in real time to fulfill that request, rather than maintaining a separate long-term copy of that connected-system data outside the Customer's assigned regional environment.
- Where a request requires an AI-generated response, the relevant content is first processed by our guardrails layer, which detects and redacts personal data, before any content is submitted to the underlying AI model for inference. This applies consistently regardless of which region the Customer's data resides in.
6. Actions Performed on Customer Instruction
Where the Service performs an action through a Connector or Bee at the Customer's instruction — for example, sending a communication to a third party, or updating a record in a connected system — any resulting transmission or disclosure of Personal Data to a further recipient occurs at the Customer's direction. The Customer remains responsible, as Controller, for ensuring it has an appropriate legal basis for any such instructed disclosure.
7. Processor Obligations
NSOffice.AI shall: process Personal Data only on the Customer's documented instructions, including as set out in Section 3 and Section 6; ensure personnel authorized to process Personal Data are bound by confidentiality; implement the security measures described in Annex 2; assist the Customer in responding to Data Subject rights requests; and notify the Customer without undue delay, and in any event within 72 hours of becoming aware, of any Personal Data Breach affecting the Customer's data.
8. Sub-processors
The Customer provides general authorization for NSOffice.AI to engage the sub-processors listed in Annex 3 and at our Sub-processor List. We will give the Customer at least 14 days' notice before engaging a new sub-processor, during which the Customer may object on reasonable data-protection grounds. We impose data protection obligations on each sub-processor no less protective than those in this Agreement.
9. Security Measures
NSOffice.AI maintains an Information Security Management System certified to ISO/IEC 27001:2022. Full technical and organizational measures are set out in Annex 2.
10. International Standards Alignment
Beyond data protection law, NSOffice.AI's AI governance practices - including model risk assessment, human oversight requirements, and guardrail testing - are aligned with ISO/IEC 42001, the international AI management system standard.
11. Deletion of Data on Termination
On termination, Customer Personal Data enters a 30-day recoverable soft-delete period, followed by permanent deletion within 180 days across all production systems, including any derived AI memory data, except where retention is required by law.
12. Audit Rights
NSOffice.AI will make available its current ISO/IEC 27001:2022 certificate and, on reasonable request and subject to confidentiality, a summary of its most recent security audit findings. Where this is insufficient to satisfy the Customer's own regulatory obligations, NSOffice.AI will permit an on-site audit no more than once per year, on reasonable notice, at the Customer's cost.
13. Liability
Each party's liability arising under this DPA is subject to the limitations and exclusions of liability set out in the main service agreement between the parties.
Annex 1 — Details of Processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the NSOffice.AI enterprise AI workspace platform |
| Duration | Length of Customer's subscription, plus the deletion timeline in Section 11 |
| Nature of processing | Collection, storage, retrieval, AI-assisted analysis and generation, and instructed transmission of Customer Content, as described in Section 3 |
| Purpose of processing | To provide AI-assisted chat, document processing, enterprise knowledge retrieval, and instructed actions through Connectors and Bees |
| Categories of Data Subjects | Customer's employees, contractors, and authorized users; incidentally, third parties referenced within Customer Content |
| Categories of Personal Data | Account/identity data; chat, document, and Bee-generated content; connected-system data accessed via Connectors; usage and billing metadata; security and audit log data |
| Special category data | Processed only to the extent the Customer chooses to submit it as part of Customer Content; not intentionally processed as part of standard platform operation |
Annex 2 — Technical and Organizational Measures
- Information Security Management System certified to ISO/IEC 27001:2022.
- Multi-tenant architecture with logically isolated databases per customer organization.
- Encryption of data at rest and in transit.
- Enterprise authentication: passwordless login, multi-factor authentication, and single sign-on.
- Role-based access control, applying the principle of least privilege.
- AI guardrails applied to every request prior to model inference, including personal data detection/redaction and unsafe-content screening.
- Continuous automated cloud security posture scanning.
- 24/7 security monitoring.
- Formal change management process, with review prior to production deployment.
- Comprehensive audit logging across platform activity.
- Documented incident response process with defined notification timelines.
- Two-stage data deletion lifecycle: 30-day recoverable period, 180-day permanent purge.
- Regional Data Plane architecture, keeping Indian and UK customer data in their respective regions.
Annex 3 — Sub-processors
The current sub-processor list is maintained at our Sub-processor List and includes our AI model providers (for guardrail-screened request processing) and our cloud infrastructure provider (for regional hosting). The Customer will be notified of additions per Section 8.