Data Processing Addendum

Last updated: 30 April 2026

Roles

For the purposes of the DPDP Act 2023, the customer is the data fiduciary for Customer Data uploaded to the platform. OnGravy acts as the data processor, processing such data only on the customer’s instructions to deliver the service.

Sub-processors

OnGravy uses the following sub-processors. Use of each is necessary for the service. By accepting the Terms, you authorise these sub-processors. We will give 30 days’ notice of any new sub-processor; you may object by emailing grievance@ongravy.com.
Supabase
Database, auth, file storage
Singapore
Vercel
Application hosting
Global edge (primary: Singapore)
Razorpay
Subscription billing
India
Anthropic
AI inference (when invoked)
United States
OpenAI
AI inference fallback (when invoked)
United States
Google AI
AI inference fallback (when invoked)
United States / EU
Resend
Transactional email (OTP, invoices)
United States
Sentry
Error monitoring (no Customer Data)
United States / EU
Upstash
Rate-limit counters (no PII)
AP-Southeast

Security commitments

  • Encryption at rest (AES-256) and in transit (TLS 1.2+).
  • Row-Level Security on every multi-tenant table; no direct DB access without RLS context.
  • Hash-chained audit trail (tamper-evident) for every voucher, journal entry, and approval.
  • Annual third-party security audit; quarterly internal review.
  • Critical CVEs patched within 7 days; high within 30.

Breach notification

We will notify you within 72 hours of becoming aware of a personal-data breach affecting your data, with the information required under DPDP §8(6) and follow-up details as the investigation progresses.

Data return and deletion

On termination, you can export everything for 30 days. After that, personal-identifying fields are anonymised; transaction-level audit records are retained for 7 years per Companies Act §128 (DPDP §17 legal exemption).

Audit rights

You may, no more than once per year, request a copy of our most recent security audit report or a SOC 2 Type II / ISO 27001 certificate (when available). We do not permit on-site audits at our infrastructure provider but will reasonably cooperate with your auditor.

Contact

DPA-related queries: support@ongravy.com. Privacy/DPDP rights: grievance@ongravy.com.