Data Processing Agreement
Effective date: April 1, 2024 · Last reviewed: August 2026
This agreement outlines how Macha AI (AGZ Technologies Private Limited) handles personal data as a data processor on behalf of customers.
1. Purpose and Scope
Macha processes data to provide AI assistant services, ticket analysis, and customer support optimization.
2. Roles and Responsibilities
- Customer = Data Controller
- Macha = Data Processor
3. Data Categories and Subjects
Types of data processed:
- Customer end-user information (names, emails, messages)
- Support ticket content and metadata
- Help center articles and product data
Data subjects include employees and customer end-users.
4. Processing Instructions
Processing occurs only per customer documentation, applicable laws like GDPR, and purposes outlined in the Privacy Policy.
5. Sub-processors
Macha engages vetted partners including:
- MongoDB (Frankfurt, Germany), database and configuration data
- DigitalOcean (Frankfurt, Germany), hosting infrastructure and file storage
- OpenAI, AI model provider for generative responses
- Anthropic, AI model provider for generative responses
- Groq, AI model provider for generative responses
- Stripe, payment processing
- Postmark, transactional email delivery
- Chargebee, subscription and billing management
6. Data Location & Transfers
Primary processing in Frankfurt, Germany. International transfers use Standard Contractual Clauses or the EU-U.S. Data Privacy Framework.
7. Security Measures
- Field-level AES-256-GCM encryption at rest
- TLS 1.2+ in transit between all systems
- Email OTP authentication
- Role-based access control
- Key separation
- PII redaction
- Data minimization policies
8. Data Subject Rights
Macha assists customers in responding to GDPR data subject requests (access, correction, deletion).
9. Data Retention and Deletion
- Conversation content: 45 days from last activity, deleted automatically
- Trial account data: 30 days post-trial
- Paid account data: 30 days post-termination
- Early deletion available upon request
The 45-day window applies to conversation content; the 30-day windows apply to account-level data after termination. Retention periods for each category of personal data are set out in full in the Privacy Policy.
10. Breach Notification
Macha notifies customers within 72 hours of confirmed breaches, detailing nature, impact, mitigation steps, and contact information.
11. Audit Rights
Customers may audit practices with reasonable notice (max once yearly) while protecting other customers' confidentiality.
12. Liability
Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, and any reference in those Terms to a party’s liability means that party’s aggregate liability under the Terms and this DPA taken together.
13. Term and Termination
Agreement remains active during data processing; Macha deletes or returns data upon termination unless law requires retention.
14. Contact
For questions, contact [email protected].
Registered office: AGZ Technologies Private Limited, M1801 Meghana Shalini Apartments, Banashankari 2nd Stage, Bangalore - 560070, Karnataka, India.
Built For Trust.
Designed For Privacy.
Your data is safe with Macha AI. We meet the highest security standards so you can focus on support without compromise.
GDPR Compliant
Fully aligned with global data protection and security standards.
No Training On Your Data
Your content is never used to train AI models, and is kept only for the periods set out in our Privacy Policy.
Shopify
Stripe
Slack
Notion
Google Workspace
Confluence