Data Processing Agreement — Scope for Teams
Diyako Tech Innovations Pvt. Ltd.
Last updated: 29 August 2026
1. Parties and structure
This Data Processing Agreement ("DPA") is entered into between:
- The Customer (the organisation subscribing to Scope for Teams) — the Controller (Data Fiduciary), and
- Diyako Tech Innovations Pvt. Ltd. ("Diyako", "Processor") — the Processor (Data Processor).
This DPA forms part of, and is governed by, the Scope for Teams Master Services Agreement between the parties. In case of conflict on data-protection matters, this DPA prevails.
Applicable data-protection laws include, as relevant: India's Digital Personal Data Protection Act, 2023 ("DPDP"); the EU General Data Protection Regulation and UK GDPR ("GDPR"); and the California Consumer Privacy Act as amended ("CCPA/CPRA").
2. Definitions
Terms such as "personal data", "processing", "data subject", "controller", "processor", "sub-processor", "personal data breach", and "supervisory authority" have the meanings given in the applicable laws. "Customer Personal Data" means personal data of the Customer's personnel (employees/members) processed by Diyako under the Agreement.
3. Roles and scope of processing
3.1 The Customer is the Controller of Customer Personal Data; Diyako is the Processor, processing only on the Customer's documented instructions.
3.2 Subject matter, duration, nature, and purpose of processing; categories of data and data subjects are set out in Annex A below.
3.3 The Agreement, this DPA, and the Customer's configuration of the Services constitute the Customer's documented instructions. Diyako will not process Customer Personal Data for any other purpose, and specifically will not sell Customer Personal Data or process it for its own independent commercial purposes.
3.4 Diyako will inform the Customer if, in its opinion, an instruction infringes applicable data-protection law.
4. Diyako's obligations as Processor
Diyako will:
- Process Customer Personal Data only on documented instructions, including for international transfers (Section 8).
- Ensure persons authorised to process Customer Personal Data are bound by confidentiality.
- Implement appropriate technical and organisational security measures (Section 6 and Annex B).
- Respect the conditions for engaging sub-processors (Section 5).
- Assist the Customer, by appropriate measures, in responding to data-subject requests (Section 7).
- Assist the Customer in ensuring compliance with security, breach-notification, DPIA, and prior-consultation obligations (Sections 6, 9).
- At the Customer's choice, delete or return Customer Personal Data at the end of the Services and delete existing copies, unless retention is required by law (Section 10).
- Make available information necessary to demonstrate compliance and allow for and contribute to audits (Section 11).
5. Sub-processors
5.1 The Customer provides general authorisation for Diyako to engage sub-processors to provide the Services. Diyako's current sub-processors are listed in Annex C and at growyourscope.com/teams/sub-processors.
5.2 Diyako will impose data-protection obligations on each sub-processor no less protective than those in this DPA, and remains liable for its sub-processors' performance.
5.3 Diyako will give the Customer prior notice (minimum 30 days) of any intended addition or replacement of a sub-processor, allowing the Customer to object on reasonable data-protection grounds.
6. Security
6.1 Diyako implements appropriate technical and organisational measures as described in Annex B, including:
- Encryption of personal data in transit and at rest.
- Access controls and authentication; least-privilege access.
- Architectural privacy boundaries ensuring individual practice content (reps, reflections, Diya conversations, wellbeing signals) is not accessible to the Customer or its personnel — only aggregate and verified-outcome data is exposed to the Customer, by design.
- Rate limiting, monitoring, and error tracking.
- Measures to restore availability and access after an incident.
- Regular review of measures.
7. Data-subject requests
7.1 Diyako will assist the Customer, by appropriate measures, in fulfilling the Customer's obligation to respond to data-subject requests under applicable law.
7.2 If Diyako receives a request directly from a data subject, it will promptly inform the Customer and not respond directly except on the Customer's instruction or as legally required — except that Diyako may directly facilitate an individual's access to and portability of their own personal Evidence Pack and personal account, consistent with the Data Ownership & Portability Terms.
8. International transfers
8.1 Customer Personal Data is hosted in the United States and may be processed by sub-processors in other countries. Diyako will ensure a valid transfer mechanism for such transfers, including Standard Contractual Clauses (SCCs) for transfers from the EEA/UK, and, as applicable, the UK International Data Transfer Addendum.
8.2 The parties agree the SCCs are incorporated and completed as set out in Annex D.
9. Personal data breach
9.1 Diyako will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information to help the Customer meet its notification obligations (including GDPR's 72-hour duty and DPDP breach-notification duties).
9.2 Diyako will take reasonable steps to mitigate and remediate the breach.
10. Return and deletion
On termination or expiry of the Services, Diyako will, at the Customer's choice, delete or return all Customer Personal Data and delete existing copies, unless retention is required by law. However, individual users retain their personal accounts and personal Evidence Packs as their own personal data (converting to an individual relationship), consistent with the Data Ownership & Portability Terms.
11. Audit
Diyako will make available information necessary to demonstrate compliance with this DPA and allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, subject to reasonable confidentiality, notice, frequency, and cost terms. Diyako may satisfy audit obligations by providing third-party certifications or reports where available.
12. Liability, term, governing law
This DPA is subject to the liability, term, and governing-law provisions of the Agreement. Governing law and jurisdiction: Rajasthan, India, except where mandatory data-protection law requires otherwise.
Annex A — Details of processing
- Subject matter: provision of the Scope for Teams behavioural skill-development Services.
- Duration: the term of the Agreement.
- Nature and purpose: hosting, processing practice and verification data to deliver individual skill development and aggregate team insights.
- Categories of data subjects: the Customer's personnel enrolled in Scope (employees, managers, HR/admin, owner).
- Categories of personal data: identity/contact (name, work email), role/team, practice content (private to each user), verification outcomes, usage/technical data. Some features allow users to optionally record mood or emotional state as part of their practice. Where such data may be considered sensitive under applicable law, it is processed solely to provide the Services to the individual user, is protected as private practice content under the architectural privacy boundary described in Annex B, and is never shared with the Customer/employer. Such data is processed on the individual user's consent and/or contract grounds, as described in the Privacy Policy (Section 2) and Section 9 of the DPA.
Annex B — Technical and organisational measures
Diyako implements and maintains the following measures, reviewed periodically:
Encryption. Personal data is encrypted in transit (TLS/HTTPS) and at rest (via Google Cloud/Firebase infrastructure encryption).
Access control & authentication. User authentication via Firebase Authentication. Internal/operational access follows least-privilege principles. Privileged super-administrator functions are gated by a separate authentication path with a dedicated session secret, decoupled from standard user auth.
Architectural privacy boundary (data-layer enforcement). The separation between individual private practice content and organisation-visible data is enforced at the data and access-control layer (Firestore security rules and server-authoritative writes), not merely application logic. Individual reps, reflections, journal notes, emotion/mood entries, wellbeing signals, and Diya conversations are not accessible to the Customer or its personnel; only aggregate and verified-outcome data is exposed. This boundary is validated by an automated isolation test suite.
Server-authoritative processing. Entitlement, verification, and credential writes are performed server-side, preventing client-side manipulation.
Rate limiting & abuse prevention. Request rate limiting is applied to protect against abuse.
Monitoring & error tracking. Application errors and anomalies are monitored via error-tracking tooling across environments.
Data segregation. Staging and production environments are isolated in separate infrastructure projects.
Breach response. Diyako maintains a process to detect, investigate, mitigate, and notify personal data breaches in accordance with Section 9 of this DPA and applicable law.
Annex C — Approved sub-processors
| Sub-processor | Role | Location |
|---|---|---|
| Google LLC (Firebase / Google Cloud) | Hosting, database, authentication, cloud functions | United States |
| Anthropic, PBC | AI processing (Diya coach) | United States |
| Brevo (Sendinblue SAS) | Transactional & lifecycle email | European Union |
| Razorpay Software Pvt. Ltd. | Payment processing | India |
| Upstash, Inc. | Rate limiting / caching | United States |
| Functional Software, Inc. (Sentry) | Error monitoring | United States |
| Vercel Inc. | Web hosting and delivery | United States |
The current list is maintained at growyourscope.com/teams/sub-processors. Customers are notified of additions/replacements per Section 5.3.
Annex D — Standard Contractual Clauses
For transfers of Customer Personal Data from the EEA to a third country not subject to an adequacy decision, the parties incorporate the European Commission Standard Contractual Clauses (Decision (EU) 2021/914), Module Two (Controller-to-Processor), completed as follows: (i) the data exporter is the Customer; the data importer is Diyako; (ii) Clause 7 (docking) applies; (iii) for Clause 9(a), Option 2 (general written authorisation) applies with a minimum 30-day notice period; (iv) for Clause 11, the optional independent-dispute-resolution language does not apply; (v) for Clause 17, the governing law is Ireland; (vi) for Clause 18(b), the forum is Ireland; (vii) Annex I is populated from Annex A of this DPA; (viii) Annex II is Annex B of this DPA; (ix) Annex III is Annex C (sub-processors).
For transfers from the United Kingdom, the parties incorporate the UK International Data Transfer Addendum to the EU SCCs, completed consistently with the above. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss FADP and the competent authority is the Swiss FDPIC.
Questions about this DPA: support@growyourscope.com