Asteryx

Data Processing Addendum

This addendum forms part of the agreement between the Customer and [Legal entity name] (“Asteryx”) and applies to personal data Asteryx processes on the Customer's behalf. The Customer is the data fiduciary / controller and Asteryx the data processor under the Digital Personal Data Protection Act 2023 (India), the GDPR and similar laws.

1. Instructions

Asteryx processes Customer personal data only to provide the service and on the Customer's documented instructions, including those given through product settings.

2. Data and subjects

Employees, contractors and travellers of the Customer: identity and contact data, travel and expense records, approvals, receipts, security and audit records (detail in the Privacy Policy).

3. Confidentiality and staff access

Personnel are bound by confidentiality. Asteryx support and billing staff can view Customer data only inside a reason-required, time-boxed support session and change it only with a one-time override issued by an Asteryx administrator; every access is logged, written to the Customer's audit log and notified to the Customer's administrators.

4. Security measures

  • Encryption in transit (TLS) and at rest; private storage buckets with short-lived signed links.
  • Per-organization isolation enforced by database row-level security and tested automatically on every change.
  • Multi-factor authentication (mandatory for Asteryx staff and travel partners; configurable for Customer users).
  • Tamper-evident, hash-chained audit log with independent verification and export.
  • Rate limiting, CSRF and open-redirect protections, dependency scanning, and periodic penetration testing.
  • Backups with point-in-time recovery and an encrypted off-provider copy, with periodic restore tests.

5. Sub-processors

The Customer authorises the listed sub-processors. Asteryx gives at least 30 days' notice of changes; the Customer may object on reasonable data-protection grounds, and the parties will work in good faith to resolve it (failing which the Customer may terminate the affected service).

6. Data-subject requests

Asteryx provides in-product tools for access, portability, correction and erasure (per-user export, member erasure, tenant export) and assists with requests it receives directly by referring them to the Customer.

7. Personal-data breaches

Asteryx notifies the Customer without undue delay — and in any case within 48 hours — after becoming aware of a breach affecting Customer personal data, with the information the Customer needs to meet its own notification duties (to the Data Protection Board of India, a supervisory authority within 72 hours under the GDPR, and affected individuals).

8. International transfers

Primary storage is [Primary data region, e.g. AWS ap-south-1 (Mumbai)]. Transfers to sub-processors in other countries follow applicable law, including standard contractual clauses where required.

9. Retention, return and deletion

On termination the Customer may export its data for 30 days; Asteryx then deletes it, except records it must keep by law, which are anonymised or retained only for the legally required period. Audit logs are retained per the configured policy (default 7 years), archived and then deleted.

10. Audits

Asteryx makes available the information reasonably necessary to demonstrate compliance (security documentation, penetration test summaries, audit-log exports) and allows audits on reasonable notice, at most once a year unless required by a regulator or after a breach.

[Legal entity name] · [Registered office address] · privacy@asteryx.io