Data processing agreement
For institutions that need a processor agreement on file. This is the document your review team will ask for.
- Revised
- 30 August 2026
- Sub-processors
- Named on request, before you begin
- Data stored in
- India
1. Parties and roles
This agreement is between you (“Customer”) and Stringify AI Pvt Ltd (“Processor”). It supplements the terms of service and applies wherever we process personal data on your behalf.
For personal data contained in your research content, you are the Data Fiduciary / Controller and we are the Data Processor. You are responsible for having a lawful basis for that data and for any notices or consents required from the individuals concerned.
2. Scope and duration
We process personal data only for the duration of your use of the service and for the retention periods set out in section 9.
| Item | Detail |
|---|---|
| Subject matter | Provision of the woodle.cloud research record service |
| Nature and purpose | Hosting, storing, indexing, generating previews and derived metadata, transmitting and displaying content at your direction |
| Types of personal data | See Annexe A |
| Categories of data subjects | Your researchers, students and staff; any individuals named in your content |
3. Our obligations
- Instructions. We process personal data only on your documented instructions, including the instruction implicit in your use of the service, unless required otherwise by law. If we believe an instruction breaches applicable law, we will tell you.
- No secondary use. We do not use your content for our own purposes. We do not use it to train machine learning models, and we do not sell or share it.
- Confidentiality. Personnel with access are bound by confidentiality obligations and access is limited to those who need it.
- Assistance. We will assist you, so far as reasonable, with data subject requests, impact assessments and consultations with a supervisory authority.
4. Security measures
We maintain technical and organisational measures appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Role-based access control, with administrative actions logged
- Segregation of customer data
- Regular backup, with tested restoration
- Vulnerability management and dependency patching
- Personnel security screening and training appropriate to role
- An incident response process
A fuller description is available in our security pack — request it.
5. Sub-processors
You authorise us to engage sub-processors for infrastructure, email delivery, error monitoring and payment processing. Each is engaged under written terms imposing obligations no less protective than these. We remain liable for their performance.
The current list is at Annexe B. We will give you 30 days' notice before adding or replacing a sub-processor. If you reasonably object on data protection grounds, we will work with you to find a solution; if none is available, you may terminate the affected service and receive a pro-rata refund.
6. Data subject requests
If we receive a request from an individual relating to your content, we will not respond substantively but will refer them to you and notify you without undue delay, unless prohibited by law. The service provides export and deletion functions that allow you to respond directly.
7. Personal data breach
We will notify you without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting your content. The notification will describe, so far as known, the nature of the breach, the categories and approximate numbers affected, the likely consequences, and the measures taken or proposed.
We will cooperate with you and take reasonable steps to mitigate the effects.
8. Location and transfers
Personal data is stored in India. Storage location is set per workspace and is not changed without your instruction.
Derived data — previews, extracted tables and structural metadata — is stored in the same place as its source workspace and is treated as your personal data, not as our metadata.
Any cross-border transfer will be made only where permitted under applicable law and under appropriate safeguards.
9. Return and deletion
On termination, and at your choice, we will return or delete personal data:
- Export is available at any time, free, without contacting us, in an open format.
- Linked files in your own storage are never held by us and are unaffected.
- Copies we hold at your request are released 90 days after a subscription ends.
- Derived data is removed after 12 months of dormancy.
- Full deletion on written request, subject to legal retention requirements and to backup cycles.
10. Audit
We will make available the information reasonably necessary to demonstrate compliance with this agreement, and will respond to reasonable written questionnaires no more than once a year. Where an on-site audit is required by law or by your regulator, we will cooperate on reasonable notice, at your cost, subject to confidentiality and to not disrupting other customers.
11. Liability and precedence
Liability under this agreement is subject to the limitations in the terms of service. Where this agreement conflicts with those terms in relation to the processing of personal data, this agreement prevails.
Annexe A — Types of personal data
- Account and identity — name, work email, institution, role, authentication data
- Attribution — who created, ran, edited or approved each item, with timestamps
- Content — any personal data you place in records, notes, files or file paths
- Derived — personal data appearing in previews, extracted tables or file metadata
- Technical — IP address, device and browser information, logs
Not permitted without a separate written agreement: personal health information, identifiable patient data, and other sensitive categories.
Annexe B — Sub-processors
We use a small number of providers for cloud infrastructure and object storage, transactional email, error monitoring and payment processing. The current list, with the region each operates in, is available on request — ask us and we will send it.
Contact
Stringify AI Pvt Ltd · contact@stringifyai.com
Grievance Officer: Gopal Joshi, contact@stringifyai.com