Draft — pending legal review
Data Processing Addendum
Last updated: 26 September 2026
This is a structural draft, not legal advice and not an executed agreement. It requires review by qualified legal counsel before publication or reliance, and must be countersigned to take effect for any studio or business customer.
1. Subject matter and roles (to be confirmed by counsel)
This draft anticipates Maṅgalya processing personal data on behalf of studio customers — guest lists, RSVPs, leads, and client records entered into Partner Studio — while the studio remains responsible for the lawful collection of that data. Final controller/processor designation per data category requires legal validation.
2. Processing instructions and scope
- Processing only to provide the invitation, studio, and payment features.
- Subprocessors limited to those listed in our Subprocessors inventory, with change notice to be defined by counsel.
- Tenant isolation: studio data is scoped per studio and never shared across tenants; self-service erasure preserves tenant data by design.
- Data-subject requests: in-app request tooling plus support escalation, with audit trails.
3. Security and breach handling (to be confirmed by counsel)
Technical and organisational measures are described in our Security overview. Breach-notification duties, timelines, and contact points must be set by counsel — this draft states none.
4. Contact
To request a countersigned DPA, write to mangalya.app@gmail.com. Executed DPAs, once available, will be listed from the Trust Center.