Legal & trust

Data Processing Agreement

B2B processing terms for customer-submitted personal and business data.

Policy architecture for product implementation and customer review. Indian legal counsel and a qualified accountant must approve final statutory wording and retention periods before commercial reliance.

Purpose and instructions

NextGenERP processes covered customer data to host and deliver the selected CRM, HRMS, ERP, accounting and support services under the agreement and documented customer instructions.

Data and people

Data may include customer, prospect, vendor, employee, attendance, leave, payroll, tax, finance, banking, document and audit information relating to customer personnel, customers, prospects, suppliers and other authorized data subjects.

Security and confidentiality

NextGenERP will maintain appropriate access control, tenant isolation, authentication, logging, secure development, backup and incident-response measures. Personnel and service providers with access must be bound by confidentiality and least-privilege requirements.

Sub-processors and incidents

NextGenERP may use the published sub-processors to deliver the service and remains responsible for appropriate contractual safeguards. Relevant incidents will be assessed and communicated under agreed and legally required procedures.

Requests, return and deletion

The customer is responsible for lawful instructions and first-line handling of its managed data subjects. NextGenERP will provide reasonable assistance, export and deletion/return mechanisms, subject to identity verification, legal retention, security logs and backup rotation.

International processing and audit

Processing locations, transfer safeguards, audit rights, liability, duration and termination assistance must be completed in the signed DPA/order form after legal review.

Last reviewed: 21 August 2026 · Version 2026-08-21