Data Processing Agreement

Add your company details, then download the completed agreement as a PDF. No sales call required.

Add your company name above to complete the agreement.

This DPA forms part of the Guidejar Terms of Service and applies automatically to all customers — the download is for your records.

Guidejar data processing agreement

AppMacha Labs · Last updated: August 25, 2026

1. Parties and background

This Data Processing Agreement ("DPA") is entered into between AppMacha Labs, a sole proprietorship registered in India, trading as Guidejar ("Guidejar", "we", "us"), and [Customer legal name] ("Customer", "you"). It forms part of, and is subject to, the Guidejar Terms of Service.

This DPA applies where Guidejar processes personal data on Customer’s behalf in the course of providing the Guidejar service — creating, hosting, and sharing interactive product guides, demos, and related features.

Effective date: August 25, 2026.

2. Key terms

Controller — that’s you. You decide what personal data is collected through the guides, forms, and content you create, and why.

Processor — that’s Guidejar. We process that data only to provide the service to you.

Subprocessor — vendors we use to help provide the service, such as hosting, storage, and payment providers.

"Personal data", "processing", "data subject", and "personal data breach" have the meanings given in the GDPR or other applicable data protection law.

3. Details of processing

Nature and purpose: hosting and delivery of guides and demos; storage and processing of screenshots, screen and audio recordings; AI-assisted features such as step text generation, voiceovers, and translations, when Customer uses them; collection of form responses; and analytics on guide views.

Duration: for as long as Customer maintains an account with Guidejar, plus the deletion periods described in Section 11.

Categories of data subjects: Customer’s team members; end users who view guides or submit forms; and individuals whose personal data appears in content Customer uploads (for example, in screenshots).

Categories of personal data: account data (such as name and email address); content data that may contain personal data (screenshots, recordings, voiceovers, form responses); and usage data (view events, device identifiers, approximate location derived from IP address).

4. Processing on instructions

Guidejar processes personal data only on Customer’s documented instructions — including as configured through the features Customer chooses to use — unless required otherwise by applicable law, in which case Guidejar will inform Customer of that legal requirement unless the law prohibits it. Guidejar does not sell personal data and does not use Customer content for its own marketing or advertising.

5. Confidentiality

Guidejar ensures that persons authorised to process personal data under this DPA are bound by appropriate confidentiality obligations.

6. Security

Guidejar implements appropriate technical and organisational measures to protect personal data, including encryption in transit (TLS) for all traffic, encryption at rest by our infrastructure providers, application-level encryption of stored secrets, role-based access controls, and per-user rate limiting on sensitive endpoints. A current description of these measures is maintained at guidejar.com/security.

7. Subprocessors

Customer provides a general authorisation for Guidejar’s use of subprocessors. The current list is maintained at guidejar.com/subprocessors, and we update that page when we add or replace subprocessors.

If Customer objects to a new subprocessor on reasonable data protection grounds within 30 days of the list being updated, the parties will discuss a resolution in good faith. If none is found, Customer may terminate the affected service.

Guidejar imposes data protection obligations on its subprocessors consistent with those in this DPA and remains responsible for their performance.

8. International data transfers

Guidejar’s infrastructure is located primarily in the United States (see the subprocessor list for locations). Where personal data of EU/EEA, UK, or Swiss data subjects is transferred internationally, the parties rely on the European Commission’s Standard Contractual Clauses (Module 2: controller to processor), which are incorporated into this DPA by reference, together with the UK Addendum and Swiss adaptations where applicable.

9. Assistance

Taking into account the nature of the processing, Guidejar will provide reasonable assistance to Customer in responding to data subject requests (access, correction, deletion, export) and in meeting Customer’s obligations regarding security, breach notification, and data protection impact assessments, insofar as the relevant information is available to Guidejar.

10. Personal data breach

If Guidejar becomes aware of a personal data breach affecting Customer’s data, Guidejar will notify Customer without undue delay, and in any case within 72 hours of becoming aware of it. The notification will describe the nature of the breach, the categories of data involved, and the measures taken or proposed to address it.

11. Retention, return, and deletion

Content deleted by Customer is moved to trash, where it can be restored for 30 days, after which it is permanently deleted from the application database.

On termination of the service, or on Customer’s written request, Guidejar will delete or return the personal data processed on Customer’s behalf, unless applicable law requires its retention.

Deletion and export requests can be sent to [email protected].

12. Audits and information

Guidejar will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits conducted by Customer or its mandated auditor. This obligation is normally satisfied by providing documentation, subprocessor certifications, and responses to written security questionnaires, no more than once per year unless a personal data breach has occurred.

13. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Guidejar Terms of Service.

14. Term

This DPA applies for as long as Guidejar processes personal data on Customer’s behalf.

15. Governing law

This DPA is governed by the laws of India. Any disputes arising from it will be resolved exclusively by the courts of India.

16. Agreement

This DPA forms part of the Guidejar Terms of Service and applies automatically to all customers by their use of the Guidejar service. No signature is required for it to take effect.

Questions about this agreement, or need a countersigned copy? Email [email protected].