Data processing agreement
The DPA is signed per school and carries your name, so it is not published here. This is its contents page — what it commits us to, before you ask for it.
Why there is one at all
Under India's Digital Personal Data Protection Act, 2023, a school that collects a child's data is the Data Fiduciary — it decides what is collected and why, and it answers for it. Vempus Technologies Pvt. Ltd. is the Data Processor: we hold and process that data on the school's written instructions and on no authority of our own. The DPA is the document that says so in those words, and it is what your board or your auditor will ask to see.
What the agreement covers
Who is who
Your school is the Data Fiduciary and decides what is collected and why. Vempus Technologies is the Data Processor and acts on your written instructions. Both terms are the ones the Digital Personal Data Protection Act, 2023 uses.
Purpose limitation
We process what is in your account to run the service you bought, and for nothing else. Not to train models, not to build a profile, not to sell, not to advertise.
Children
Almost every record in a school is a child's. Obtaining whatever consent the school needs is the school's role as Fiduciary; ours is to hold what you have collected and to hand it back or delete it when you say so.
Sub-processors
The four on the sub-processor page, each bound to the same terms. Notice before that list changes, not after.
Security measures
Row-level isolation enforced inside the database, per-transaction school context, encryption at rest and in transit, nightly encrypted backups and a quarterly restore drill from a cold copy.
Our people
Support access to your live data is off by default, is turned on by you, is limited to a named person, expires after 24 hours, and is written to a log you can read.
Breach notice
Within 24 hours of us confirming an incident that touches your data — by phone to the account holder, then in writing, with what happened, what was reached and what we did.
Return and deletion
You export everything as CSV at any time without asking us. On closure we keep it for 90 days so you can change your mind, then delete it.
Audit
You may ask what we do and we answer in writing. Trust-plan schools may witness the quarterly restore drill.
How to get it
Write to hello@timelino.com and ask. We send it before you sign an order form, not after — a DPA produced once the money has moved is a DPA nobody read. If your school has its own template, send that instead; we would rather review yours than insist on ours.
Where it sits against everything else
Where the signed DPA or order form and the terms of service disagree, the signed document wins. The privacy page describes the same arrangement for a parent or a teacher rather than for a lawyer, and the sub-processor list names everybody the DPA binds alongside us.
What it is not
It is not a service-level agreement, and we do not sell one. What we commit to operating — nightly encrypted backups, a quarterly restore drill from a cold copy, 24-hour breach notice — is on the security page and in the DPA itself, the same on every plan. We do not sell safety as an upgrade.
Ask for the DPA before you ask for a price.
We will send it unsigned, to read at your own pace, with no expectation that you come back. A school that reads it and walks away has still made the right decision.