WORK VISA CRM
WorkVisaCRM
  • Features
  • Solutions
  • Pricing
  • About
  • FAQ
  • Contact
  • Features
  • Solutions
  • Pricing
  • About
  • FAQ
  • Contact
Legal & Compliance

Data Processing Agreement

Effective: 1 January 2026

Between Green Outdoors Global Private Limited ("Processor") and the Customer ("Controller")

1. Introduction & Purpose

This Data Processing Agreement ("DPA") forms part of the agreement between Green Outdoors Global Private Limited ("Processor"), the operator of WorkVisaCRM, and the Customer ("Controller") who subscribes to the WorkVisaCRM service. This DPA governs the processing of personal data by the Processor on behalf of the Controller, in accordance with the General Data Protection Regulation (GDPR), the Digital Personal Data Protection Act 2023 (DPDPA 2023), and any other applicable data protection laws.

By using WorkVisaCRM, the Controller agrees to the terms of this DPA. In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to the subject matter of personal data processing.

2. Definitions

  • Data Controller: The Customer (overseas manpower agency or recruitment firm) who determines the purposes and means of processing personal data.
  • Data Processor: Green Outdoors Global Private Limited, which processes personal data on behalf of the Controller using the WorkVisaCRM platform.
  • Personal Data: Any information relating to an identified or identifiable natural person (data subject).
  • Processing: Any operation performed on personal data, including collection, storage, retrieval, use, disclosure, or deletion.
  • Data Subject: The individual whose personal data is being processed (primarily candidates / workers managed on the platform).
  • Sub-Processor: Any third party engaged by the Processor to process personal data on the Processor's behalf.

3. Scope of Processing

The Processor shall process personal data on behalf of the Controller for the purpose of providing the WorkVisaCRM recruitment and deployment management platform. The subject matter and categories of personal data processed include:

  • Data subjects: Candidates (workers) managed by the Controller's agency
  • Categories of personal data: Name, contact details (email, phone, address), passport information, employment history, educational qualifications, medical records and fitness certificates, visa and immigration records, biometric data (where uploaded as part of documentation), and any other data the Controller uploads to the platform
  • Purpose: Candidate pipeline management, visa case tracking, document management, employer communication, compliance monitoring, and analytics as enabled by the platform
  • Duration: For the term of the Controller's subscription, plus any data retention period agreed under Section 10

4. Instructions

The Processor shall process personal data only on the documented instructions of the Controller. The Controller's instructions are provided through the Controller's use of the WorkVisaCRM platform features and settings, and through any written instructions separately communicated to the Processor.

The Processor shall promptly inform the Controller if, in the Processor's opinion, any instruction infringes applicable data protection law. In such cases, the Processor may decline to act on that instruction.

5. Sub-Processors

The Controller grants the Processor a general authorisation to engage sub-processors in connection with the provision of the WorkVisaCRM service. The Processor shall:

  • Maintain a list of current sub-processors, available to the Controller on request
  • Provide the Controller with at least 30 days' written notice before engaging any new sub-processor or materially changing the role of an existing sub-processor
  • Impose data protection obligations on all sub-processors equivalent to those set out in this DPA
  • Remain liable to the Controller for the acts and omissions of sub-processors

To request the current sub-processor list, contact crm@gogpl.in.

6. Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligations to respond to requests from data subjects exercising their rights under applicable data protection law. These rights include access, rectification, erasure, restriction of processing, data portability, and objection to processing.

The Processor will forward any data subject requests received directly to the Controller within 7 calendar days and will provide the Controller with reasonable technical assistance in responding to such requests.

7. Security Measures

The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

  • AES-256 encryption of personal data at rest
  • TLS 1.3 encryption of personal data in transit
  • Role-Based Access Control (RBAC) and the principle of least privilege
  • Comprehensive audit logging of all access and modification events
  • Regular security testing and vulnerability assessments

Full details are set out in the WorkVisaCRM Security Policy.

8. Breach Notification

The Processor shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting data processed under this DPA. The notification shall include, to the extent available:

  • A description of the nature of the breach, including categories and approximate number of data subjects and records affected
  • The name and contact details of the Processor's data protection contact
  • The likely consequences of the breach
  • The measures taken or proposed to address the breach and mitigate its effects

9. Data Transfers

Personal data shall not be transferred outside India or the European Economic Area (EEA) without appropriate safeguards. Where transfers are necessary, the Processor will rely on:

  • Standard Contractual Clauses (SCCs) adopted by the European Commission, where applicable
  • Adequacy decisions by relevant data protection authorities
  • Any other lawful transfer mechanism recognised under applicable law

The Controller will be notified of any cross-border transfer arrangements applicable to its data.

10. Retention & Deletion

Upon termination or expiry of the Controller's subscription, the Processor shall, at the Controller's election:

  • Delete all personal data processed under this DPA within 30 days; or
  • Return all personal data to the Controller in a standard machine-readable format within 30 days

The Processor may retain personal data beyond 30 days only to the extent required by applicable law, and only for the purposes and duration specified by that law. The Controller will be notified of any such mandatory retention.

11. Audit Rights

The Controller may, not more than once per calendar year and with at least 30 days' prior written notice, request that the Processor:

  • Complete a security questionnaire or provide relevant audit documentation
  • Facilitate an audit of the Processor's data processing activities by the Controller or an independent third-party auditor bound by confidentiality obligations

The Controller shall bear the reasonable costs of any such audit. The parties shall cooperate in good faith to minimise disruption to the Processor's operations.

12. Liability

Each party shall be liable for damages caused by processing that infringes applicable data protection law to the extent that it is responsible for such infringement. The Processor's liability under this DPA is subject to the limitations set out in the WorkVisaCRM Terms of Service.

13. Governing Law

This DPA shall be governed by and construed in accordance with the laws of India. Any disputes arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the courts in Vadodara, Gujarat, India.

14. Contact

For all data protection enquiries relating to this DPA:

Green Outdoors Global Private Limited
Email: crm@gogpl.in
Vadodara, Gujarat, India

Legal Disclaimer: This document is provided for informational purposes only and does not constitute legal advice. WorkVisaCRM recommends that you consult a licensed legal professional for advice specific to your jurisdiction and circumstances before relying on this document.

WorkVisaCRM

The CRM built for overseas manpower agencies and international recruitment firms. Digitize your candidate pipeline, visa tracking, and employer communication in one platform.

in f ig ▶
Product
  • Features
  • Solutions
  • Pricing
  • Integrations
  • Product Updates
  • Login
Company
  • About
  • Contact
  • Help Centre
  • FAQs
  • Status
  • Request Demo
Legal
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Security Policy
  • Data Processing Agreement
  • Acceptable Use Policy
© 2026 WorkVisaCRM. All rights reserved.
Privacy Policy Terms of Service Cookie Policy