Last Updated: 23 September, 2026
Data Processing Agreement (DPA)
Supporting Your Data Protection Requirements
Softhealer Technologies Pvt. Ltd. ("Softhealer", "we", "our", or "us") develops and operates Monitor360, an enterprise workforce monitoring and productivity platform.
We are committed to protecting personal data and helping our customers meet their obligations under applicable privacy and data protection laws.
For eligible business customers, Softhealer Technologies Pvt. Ltd. provides a Data Processing Agreement (DPA) in accordance with GDPR Article 28 that outlines our commitments regarding the processing, protection and security of personal data processed through Monitor360.
This page provides an overview of our Data Processing Agreement and how it supports our customers' privacy and compliance requirements.
1. What is a Data Processing Agreement?
A Data Processing Agreement (DPA) is a legal agreement between a customer and a service provider that defines how personal data is processed, protected and managed.
It establishes the responsibilities of both parties and helps ensure that personal data is processed securely and in accordance with applicable privacy and data protection regulations.
2. Who Needs a DPA?
A DPA is commonly required when an organisation uses a third-party service provider to process personal data on its behalf.
Many organisations request a DPA as part of their:
- Vendor onboarding
- Procurement process
- Privacy and compliance programme
- Internal security requirements
3. Our Commitment
Softhealer Technologies Pvt. Ltd. is committed to responsible data processing and maintaining appropriate technical and organisational measures to protect customer information.
Our Data Processing Agreement reflects our commitment to:
- Protecting personal data
- Processing data only in accordance with customer instructions
- Maintaining appropriate security measures
- Preserving confidentiality
- Supporting customer privacy obligations
- Assisting customers with applicable compliance requirements
4. What Does Our DPA Cover?
Our Data Processing Agreement provides a framework for how personal data is managed throughout its lifecycle and includes commitments relating to:
- Personal data processing
- Privacy and confidentiality
- Information security
- Data protection responsibilities
- Subprocessor management
- International data transfers, where applicable
- Data retention and secure deletion
- Security incident management
- Security incident notification
- Compliance and regulatory obligations
For more information about our privacy and security practices, please refer to our Privacy Policy, Security, and GDPR pages.
5. Security & Privacy
Protecting customer information is a core part of the Monitor360 platform.
We implement technical and organisational measures to safeguard personal data throughout its lifecycle, including TLS 1.2 encryption in transit, AES-256 encryption at rest, multi-factor authentication (MFA), role-based access controls and audit logging. Customer data is hosted on Amazon Web Services (AWS) in the Asia Pacific (Mumbai) region (ap-south-1). In the event of a personal data breach, we notify affected customers within 72 hours of becoming aware, in accordance with applicable data protection law. Our security programme is independently audited through our ISO/IEC 27001:2022 and SOC 2 Type II certifications.
Detailed information about our security controls is available on our Security page.
6. Request a DPA
A Data Processing Agreement is available for eligible business customers using Monitor360.
If your organisation requires a DPA, our team will be happy to assist during:
- Product evaluation
- Procurement and vendor onboarding
- Customer implementation
- Any stage of your active subscription
7. Contact Us
If you have questions about our Data Processing Agreement or would like to request a copy, please Contact Us using the contact information available on our website.