← Back to FreWork

Data Processing Agreement

Version 1.0 · Effective 11 October 2026

This DPA forms part of the Terms of Service between the Customer and FreWork Business Solutions (“FreWork”). It applies to personal data inside Customer Data, for example the names, PAN, phone numbers and bank details of the Customer's customers, suppliers and employees. For that data the Customer is the Data Fiduciary and FreWork is the Data Processorunder the Digital Personal Data Protection Act, 2023. It is accepted with the Terms; a signed copy is available on request.

1. Scope of processing

  • Subject matter: providing FreBook and the FreWork service.
  • Duration: the term of the agreement plus the deletion period in section 8.
  • Nature: storing, organising, displaying, analysing and exporting accounting records; AI drafting; sending data to Tally or the GST provider when the Customer asks.
  • Data principals: the Customer's customers, suppliers, employees, partners and its own staff users.
  • Data: names, addresses, phone, email, PAN, GSTIN, bank account details, invoice and payment details, salary details where payroll is used.

2. Customer instructions

FreWork processes this data only on the Customer's documented instructions, which are these Terms and the Customer's use of the app. FreWork will tell the Customer if an instruction appears to break the law. The Customer is responsible for having a lawful basis and giving any notice required to its own data principals.

3. Confidentiality

Only staff and contractors who need access to support the service can reach Customer Data, and they are bound by confidentiality.

4. Security measures

  • Encryption in transit (TLS) and at rest.
  • Separation of each business's data by row-level security in the database.
  • Role-based access for team members invited by the Customer.
  • Posted entries cannot be edited; corrections are made by reversal, so there is a full audit trail.
  • Service keys kept only on the server; no portal or bank passwords stored.
  • Backups by the database provider.

5. Sub-processors

The Customer authorises the sub-processors below. FreWork binds each to data protection terms no less protective than this DPA and stays responsible for them. We will give at least 15 days' notice of a new sub-processor by email or on this page; the Customer may object, and if we cannot resolve it, may terminate and receive a pro-rata refund.

Sub-processorPurposeDataLocation
Supabase Inc.Database, file storage and sign-inAll account and accounting dataCloud region chosen for the project (may be outside India)
Vercel Inc.Hosting the website and appRequests and logs in transitGlobal edge network
Google LLC (Gemini API)AI drafting of entries and reading documentsChat text, uploaded documents, ledger names needed for the draftUnited States / global
Anthropic PBC (Claude API)AI drafting (backup model)Same as above, only when usedUnited States
Sandbox (Quicko Infosoft Pvt Ltd)GST filing status and tax document readingGSTIN, uploaded Form 168 / 130 PDFsIndia
PhonePe Pvt Ltd / Razorpay Software Pvt LtdPaymentsOrder amount, name, email, phone (never card or UPI credentials)India
Meta Platforms (WhatsApp Business)WhatsApp messages you choose to send or receivePhone number and message textGlobal

6. Help with data principal requests

If a data principal contacts FreWork directly about Customer Data, we will pass the request to the Customer and not answer it ourselves unless the Customer asks. The app lets the Customer find, correct, export and delete records; we will help further on reasonable request.

7. Personal data breaches

FreWork will tell the Customer without undue delay, and in any case within 48 hours of becoming aware of a breach affecting Customer Data, with what is known, the likely effects and the steps taken. We will help the Customer meet its duty to inform the Data Protection Board and affected data principals.

8. Return and deletion

The Customer can export its data at any time. When the account closes, FreWork keeps Customer Data for 30 days for export, then deletes it from live systems; backups roll off within a further 30 days. Data FreWork must keep by law is kept only for that purpose.

9. Audits

On written request, once a year, FreWork will answer a reasonable security questionnaire and share summaries of its sub-processors' security certifications. On-site audits need 30 days' notice, are at the Customer's cost and must not expose other customers' data.

10. Liability and order of precedence

Liability under this DPA is subject to the limits in the Terms. If this DPA and the Terms conflict on personal data, this DPA prevails.