B2B Master Services & SaaS AgreementLast Updated: August 2026

Terms of Service & Master Agreement

These Master Terms of Service (“Terms”) govern access to and usage of the PrivacyOS compliance platform, APIs, SDKs, and advisory services provided by Vexalix Technology Private Limited.

1. Acceptance & Master Agreement Structure

In Plain English: By accessing PrivacyOS, executing an Order Form, or using our compliance APIs, your organization agrees to these legally binding terms.

These Terms of Service, together with any executed Order Form, Data Processing Agreement (DPA), and Service Level Agreement (SLA), constitute the complete binding Master Agreement between Vexalix Technology Private Limited (“PrivacyOS”, “Company”, “we”, “us”) and the subscribing entity (“Customer”, “Client”, “you”).

2. Platform Access & Scope of Services

Subject to timely payment of fees and compliance with these Terms, PrivacyOS grants Customer a non-exclusive, non-transferable, worldwide right to access and utilize the subscribed modules:

  • Consent & Cookie Management: Dynamic bilingual notice delivery, consent capture SDKs, and immutable audit logs.
  • DSR Automation: Data subject rights request intake portals, SLA workflow engines, and identity verification gates.
  • Data Discovery & Mapping: PII scanning across relational databases, data lakes, APIs, and automated RoPA generation.
  • DPIA & Breach Response: Risk matrices, CERT-In 6-hour and DPDPA 72-hour dual-clock tracking incident vaults.
  • Vendor Risk Management: Third-party processor questionnaires and DPA repository tracking.
  • Advisory & Security Services: CIPP/E-led DPO-as-a-Service, ISO 27001 readiness, SOC 2 guidance, and CERT-In empanelled VAPT.

3. Account Security & Tenant Responsibilities

Customer is responsible for maintaining the confidentiality of all administrator login credentials, enforcing Multi-Factor Authentication (MFA) across its authorized users, and ensuring that all activities conducted through its tenant comply with applicable laws. Customer shall immediately notify PrivacyOS upon discovering any unauthorized tenant access or credential compromise.

4. Data Protection & Statutory Processing Terms (Section 8(2))

To the extent PrivacyOS processes personal data on behalf of Customer as a Data Processor under Section 8(2) of the DPDP Act 2023 or Article 28 of the GDPR:

  • PrivacyOS shall process personal data solely in accordance with Customer's documented lawful instructions and the executed Data Processing Agreement.
  • PrivacyOS shall implement reasonable technical and organizational security safeguards under Section 8(5) to prevent personal data breaches.
  • PrivacyOS shall ensure all personnel authorized to process data are bound by strict contractual confidentiality obligations.
  • Upon termination of services, PrivacyOS shall delete or return all Customer Personal Data within 30 days in accordance with Customer instructions.

5. Intellectual Property Rights

Platform IP: PrivacyOS and its licensors retain all right, title, and interest (including all patent, copyright, trademark, and trade secret rights) in and to the software, algorithms, AI compliance classifiers, UI designs, and documentation.

Customer Data IP: Customer retains 100% ownership and intellectual property rights in all data, customer files, and confidential materials ingested into the platform (“Customer Data”). PrivacyOS acquires no ownership rights in Customer Data.

6. Subscription Fees, Invoicing & Taxes

Customer shall pay all fees specified in the applicable Order Form. Fees are billed annually or quarterly in advance. All amounts are exclusive of applicable Indian Goods and Services Tax (GST) or international withholding taxes, which shall be added to the invoice at the prevailing statutory rate. Invoices are payable within thirty (30) days of invoice date.

7. Service Level Agreement (SLA) & Availability

PrivacyOS commits to maintaining a 99.9% Monthly Uptime Percentage for the core SaaS platform, excluding scheduled maintenance windows notified at least 48 hours in advance. In the event of an SLA breach, Customer shall be eligible for proportional service credits against future subscription fees as detailed in our Enterprise SLA Exhibit.

8. Limitation of Liability & Super Cap

General Cap: To the maximum extent permitted by Indian law, each party's total aggregate liability arising out of or related to this Agreement shall be limited to the total fees paid by Customer to PrivacyOS in the twelve (12) months preceding the incident giving rise to liability.

Super Cap for Data Protection & Confidentiality: For claims arising directly from a material breach of confidentiality obligations or Section 8(2) DPA terms, each party's liability shall be subject to an enhanced super cap of two times (2x) the fees paid in the preceding twelve (12) months.

Consequential Damages Waiver: Neither party shall be liable for indirect, incidental, punitive, or consequential damages (including loss of profits, business interruption, or reputational loss).

9. Term, Termination & Data Retrieval Window

Either party may terminate this Agreement upon thirty (30) days written notice if the other party materially breaches these Terms and fails to cure such breach within the notice period.

Upon termination, Customer shall have a thirty (30) day window to export its audit trails, consent records, and RoPA documentation in standard formats (JSON/CSV/PDF). Following this period, PrivacyOS shall securely delete all Customer Data in accordance with our cryptographic sanitization standards.

10. Governing Law, Jurisdiction & Dispute Resolution

This Agreement shall be governed by, interpreted, and construed in accordance with the substantive laws of the Republic of India, without regard to its conflict of law principles.

Any dispute, controversy, or claim arising out of or in connection with this Agreement shall be referred to and finally resolved by binding arbitration under the Arbitration and Conciliation Act, 1996. The seat and venue of arbitration shall be Gurugram / New Delhi, India, and proceedings shall be conducted in English before a sole arbitrator appointed mutually by the parties.

Contact for Legal Inquiries:
Vexalix Technology Private Limited
Attn: Legal & Compliance Counsel
C-042C, 4th Floor, Supermart, DLF Phase IV, Gurugram, Haryana 122009, India
Email: legal@privacyosglobal.com | Phone: +91 8887946496