Data Processing Agreement
This forms part of your contract with DCS Predictive Intelligence and applies automatically. It sets out who is responsible for what under the Digital Personal Data Protection Act, 2023.
1. Purpose
- This Data Processing Agreement forms part of the contract between DCS Predictive Intelligence and each business using the platform. It applies automatically; no separate signature is needed.
- It records that the business is the Data Fiduciary for its customers’ personal data and DCS Predictive Intelligence is the Data Processor.
2. Scope of processing
- Subject matter: provision of customer retention and customer-engagement software.
- Duration: for as long as the business holds an account, plus the retention periods in the privacy policy.
- Categories of data subject: business customers, leads, and business staff.
- Categories of data: identity, contact details, membership, package and payment records, visits and appointments, sector records (including clinical records for dental clinics), communication history, and derived scores.
3. Our obligations as Processor
- We process customer data only on the business’s documented instructions, which the platform’s configuration constitutes.
- Our personnel with access are bound by confidentiality.
- We maintain the technical and organisational measures described in the privacy policy.
- We assist the business in responding to data subject requests and in meeting its own breach-notification duties.
- On termination we delete customer data after 90 days, or return it on request before then.
4. The business’s obligations as Data Fiduciary
- Obtain and record valid consent from each customer before using the platform to contact them.
- Provide customers with the notice the DPDP Act requires.
- Ensure data entered is accurate, and correct it when a customer asks.
- Not upload special-category or unnecessary data.
- Obtain verifiable parental consent before enrolling anyone under 18.
5. Sub-processors
- The current list is in section 6 of the privacy policy.
- We will give 30 days’ notice before adding a sub-processor. A business that objects on reasonable data-protection grounds may terminate without penalty.
6. Cross-customer model training
- Where, and only where, an individual customer has given explicit consent, their data may contribute to training prediction models used across DCS Predictive Intelligence customers.
- Customers without that consent are still scored and served by the models. They simply do not contribute to training them, and the business loses nothing by their choice.
- Trained models contain learned patterns, not retrievable records. No business can query another business’s data through the platform.
- Data of customers under 18 is excluded entirely.
7. Audit
A business may request, once a year, information reasonably necessary to demonstrate our compliance with this agreement. We will not disclose anything that would compromise another customer’s security or confidentiality.
8. Breach
We will notify the business without undue delay, and within 72 hours of becoming aware, of any personal data breach affecting their data, with enough detail for the business to meet its own obligations to the Data Protection Board and to affected customers.
Last updated: 2 September 2026