Data Processing Addendum
Data Processing Addendum
How TEAL Infotech processes Customer Data in LeadArivo on a customer’s instructions. This is an informational customer-facing DPA, not a claim of universal GDPR certification.
Parties and relationship to Terms
This Data Processing Addendum (“DPA”) is between the Customer and TEAL Infotech (proprietorship of Varinder Pal Singh, GSTIN 03BQPPS8444C1ZM). It applies when LeadArivo processes Customer Data on the Customer’s instructions. It forms part of the Terms of Service. For a signed copy, email info@LeadArivo.com.
This DPA does not mean LeadArivo is certified under GDPR, ISO 27001 or similar schemes. International transfer clauses (including Standard Contractual Clauses) are not attached to this public page and would require separate legal adoption.
Roles, purpose and duration
For Customer Data, Customer is the business that determines why leads are processed. TEAL Infotech processes that Customer Data to provide LeadArivo, including hosting, security, support, backups and configured AI or integration features the Customer enables.
Processing lasts for the subscription or trial and a wind-down period needed to delete or return data, unless law requires longer retention of specific records.
Categories of data and people
Customer Data typically includes names, contact details, enquiry content, source/channel labels, Assignee, follow-up, activity and outcome fields the Customer chooses to store. Data subjects are usually the Customer’s leads, contacts, staff (Authorized Users) and other people the Customer records.
Customer must not instruct us to process special-category health data or children’s data unless a written agreement says otherwise. LeadArivo is not offered as a HIPAA product on this website.
Instructions, confidentiality and security
We will process Customer Data only on documented instructions from Customer (including use of the product) unless law requires otherwise. Personnel who handle Customer Data are expected to keep it confidential. Technical and organisational measures we can describe publicly are on the Security page.
Subprocessors, requests and incidents
We may use subprocessors listed at /subprocessors. We remain responsible for their processing of Customer Data for LeadArivo. We will update that list when production vendors are confirmed.
We will assist with reasonable data-subject requests that concern Customer Data we process, after verifying the request. Customer is primarily responsible for requests from its own leads.
If we become aware of a personal-data breach affecting Customer Data, we will notify the Customer without undue delay using account or notice email, with information we can share without increasing security risk.
Return, deletion, audits and liability
On termination, Customer may request return or deletion of Customer Data, except copies we must keep for law, security or accounting. Audit rights are limited to information we can reasonably provide (for example this DPA, the Security page and subprocessor list). On-site audits are not offered as a default public right.
Liability under this DPA follows the limitation of liability in the Terms, except where applicable data-protection law does not allow that limit.

