Data Protection

Data Processing Agreement

This Data Processing Agreement (DPA) describes the terms under which Think Pixel processes personal data on behalf of clients.

It is intended to establish clear responsibilities between Think Pixel, acting as the Data Processor, and the applicable client, acting as the Data Controller, where such roles apply under applicable data protection laws.

Last updated:

This DPA governs the processing of personal data carried out by Think Pixel on behalf of its clients in connection with agreed services.

Where applicable, processing is performed in accordance with:

  • The applicable service agreement
  • Client instructions
  • Applicable data protection requirements
  • GDPR requirements where applicable
  • Other applicable data protection laws and regulations

Think Pixel acts as a Data Processor where it processes personal data on behalf of a client acting as the Data Controller.

Think Pixel processes personal data only as necessary to provide the services agreed with the applicable client.

Depending on the service, processing activities may include:

  • Data storage
  • Data backup
  • Technical support
  • System administration
  • Infrastructure operations
  • Other processing activities specifically described in the applicable service agreement

Think Pixel will process personal data according to the documented instructions applicable to the relevant service relationship.

Think Pixel implements appropriate technical and organizational measures intended to protect personal data against unauthorized access, loss, misuse, alteration, disclosure, or destruction.

Security measures may include:

  • Encryption
  • Access controls
  • Least-privilege access
  • Secure data transmission
  • Security monitoring
  • Regular security reviews
  • Security audits
  • Appropriate backup and recovery controls

The specific measures applicable to a particular service may depend on the nature and sensitivity of the data being processed.

Where required by applicable law, Think Pixel will provide reasonable assistance to Data Controllers in responding to data subject requests.

These may include requests relating to:

  • Access
  • Rectification
  • Erasure
  • Data portability
  • Other applicable data protection rights

The nature and scope of assistance will depend on applicable law and the relevant service agreement.

Think Pixel may use third-party sub-processors where required to provide contracted services.

Where applicable, sub-processors will be subject to appropriate contractual and data protection obligations.

The original Think Pixel terms provide that sub-processors may be engaged only with the prior written consent of the Data Controller.

Where a sub-processor is engaged, Think Pixel will require appropriate data protection obligations consistent with the applicable processing requirements.

If Think Pixel becomes aware of a personal data breach affecting personal data processed on behalf of a client, we will notify the applicable Data Controller without undue delay, subject to applicable law and contractual requirements.

The original DPA specifies notification within 72 hours of becoming aware of a personal data breach.

Where applicable, the notification will include relevant information reasonably available to Think Pixel to assist the Data Controller with its legal and compliance obligations.

For DPA-related inquiries, contact:

[email protected]

This DPA is intended to operate under the laws of India and the EU General Data Protection Regulation (GDPR) where applicable.

Think Pixel periodically reviews its data-processing practices and may update this DPA to reflect changes in services, processing activities, technology, or applicable data protection requirements.