OptimReach

Legal & Trust

Data Processing Agreement

Last updated · September 2026MetaGrad Labs Private Limited12 sections
Contents · 12 sections
  1. 1. Definitions
  2. 2. Scope and Purpose
  3. 3. Duration of Processing
  4. 4. Controller's Obligations
  5. 5. Processor's Obligations
  6. 6. Sub-processors
  7. 7. International Data Transfers
  8. 8. Technical and Organisational Measures (TOMs)
  9. 9. Audit Rights
  10. 10. Personal Data Breach Notification
  11. 11. Return and Deletion
  12. 12. Governing Law

1. Definitions

  • "Personal Data" — any information relating to an identified or identifiable natural person, as defined under applicable Data Protection Laws.
  • "Processing" — any operation or set of operations performed on Personal Data.
  • "Data Protection Laws" — EU GDPR, UK GDPR, India DPDP Act 2023, and any other applicable data protection legislation.
  • "Sub-processor" — a third party engaged by OptimReach to process Personal Data to deliver the Services.
  • "Standard Contractual Clauses (SCCs)" — EC Implementing Decision 2021/914 of 4 June 2021.

2. Scope and Purpose

This DPA governs OptimReach's processing of Personal Data provided by the Controller as part of the Services. OptimReach shall process Personal Data only on documented instructions from the Controller, for the purpose of providing the Services as described in the Agreement.

3. Duration of Processing

OptimReach will process Personal Data for the duration of the Agreement. Upon termination, OptimReach will, at the Controller's election, return or delete all Personal Data within 90 days, except where retention is required by applicable law.

4. Controller's Obligations

  • The Controller warrants it has a valid lawful basis under applicable Data Protection Laws to provide Personal Data to OptimReach for processing.
  • The Controller is responsible for providing appropriate privacy notices to its End Users.
  • The Controller shall promptly notify OptimReach of any revocation of consent by a Data Subject.
  • The Controller shall promptly notify OptimReach of any data subject rights requests, regulatory enquiries, or data breach notifications relating to data processed under this DPA.

5. Processor's Obligations

  • Process Personal Data only on documented instructions from the Controller, unless required by applicable law.
  • Ensure personnel authorised to process Personal Data are bound by appropriate confidentiality obligations.
  • Implement and maintain appropriate technical and organisational security measures (see Section 8).
  • Assist the Controller in responding to Data Subject rights requests to the extent reasonably possible.
  • Notify the Controller within 72 hours upon becoming aware of a Personal Data Breach.
  • Provide all information reasonably necessary to demonstrate compliance with this DPA and cooperate with audits.
  • Delete or return Personal Data at the end of the Agreement as instructed by the Controller.

6. Sub-processors

The Controller grants general authorisation to OptimReach to engage Sub-processors. The current list is at optimreach.in/sub-processors. OptimReach will notify the Controller at least 14 days before adding a new Sub-processor. The Controller may object within that period by emailing privacy_optimreach@metagrad.in. All Sub-processors are bound by data protection obligations no less protective than this DPA.

7. International Data Transfers

Where Personal Data is transferred outside the EEA or UK, such transfers are governed by the Standard Contractual Clauses (EU Commission Decision 2021/914, Module 2: Controller to Processor) and/or the UK International Data Transfer Addendum (IDTA), as applicable, incorporated into this DPA by reference.

To request a signed copy of the SCCs: privacy_optimreach@metagrad.in.

8. Technical and Organisational Measures (TOMs)

Encryption

  • AES-256-GCM encryption for all sensitive credentials at rest (access tokens, app secrets, verify tokens)
  • TLS 1.2 or higher for all data in transit
  • SHA-256 one-way hashing for lookup tokens and API keys

Access Controls

  • Role-based access control (RBAC) with least-privilege principles
  • Multi-tenant data isolation — each workspace's data is logically and technically separated
  • JWT-based authentication for all staff and admin sessions
  • API key authentication with hashed key storage — plaintext keys never persisted

Operational Security

  • Webhook HMAC-SHA256 signature verification for all inbound Meta API events
  • Inbound message deduplication to prevent replay processing
  • Rate limiting on all public endpoints
  • All schema changes are managed through versioned migrations. No ad-hoc DDL is used in production.

Incident Response

  • Personal Data Breaches notified to the Controller within 72 hours of discovery
  • Breach notifications include: nature of breach, categories and approximate number of affected data subjects, likely consequences, and measures taken

9. Audit Rights

Upon 30 days' prior written notice, the Controller may conduct, or commission a third party to conduct, an audit of OptimReach's processing activities. OptimReach will provide reasonable cooperation. The Controller bears the cost of the audit. Any audit must not disrupt OptimReach's operations.

10. Personal Data Breach Notification

OptimReach shall notify the Controller without undue delay, and where feasible within 72 hours, upon becoming aware of a Personal Data Breach. Notification will be sent to the email address on the Customer account.

To report a security issue: privacy_optimreach@metagrad.in

11. Return and Deletion

Within 90 days following termination or expiry of the Agreement, OptimReach will, at the Controller's election: (a) return all Personal Data in a commonly used format; or (b) securely delete all Personal Data and certify deletion in writing. Copies held in automated backups will be deleted within 30 days of the scheduled backup deletion cycle.

12. Governing Law

This DPA is governed by the laws of India, except where applicable Data Protection Laws (including EU GDPR / UK GDPR) require the application of other law, in which case those requirements prevail.

Contact: privacy_optimreach@metagrad.in · MetaGrad Labs Private Limited, #9 MetaGrad Labs Pvt Ltd, Akilandeshwari Templedeva, Budigere, Bangalore Rural, Hoskote, Karnataka, India, 562129

Questions about this document? Email hello_optimreach@metagrad.in or reach us via the contact page.