Macha

Data Processing Agreement

Effective date: April 1, 2024 · Last reviewed: August 2026

This agreement outlines how Macha AI (AGZ Technologies Private Limited) handles personal data as a data processor on behalf of customers.

1. Purpose and Scope

Macha processes data to provide AI assistant services, ticket analysis, and customer support optimization.

2. Roles and Responsibilities

  • Customer = Data Controller
  • Macha = Data Processor

3. Data Categories and Subjects

Types of data processed:

  • Customer end-user information (names, emails, messages)
  • Support ticket content and metadata
  • Help center articles and product data

Data subjects include employees and customer end-users.

4. Processing Instructions

Processing occurs only per customer documentation, applicable laws like GDPR, and purposes outlined in the Privacy Policy.

5. Sub-processors

Macha engages vetted partners including:

  • MongoDB (Frankfurt, Germany), database and configuration data
  • DigitalOcean (Frankfurt, Germany), hosting infrastructure and file storage
  • OpenAI, AI model provider for generative responses
  • Anthropic, AI model provider for generative responses
  • Groq, AI model provider for generative responses
  • Stripe, payment processing
  • Postmark, transactional email delivery
  • Chargebee, subscription and billing management

6. Data Location & Transfers

Primary processing in Frankfurt, Germany. International transfers use Standard Contractual Clauses or the EU-U.S. Data Privacy Framework.

7. Security Measures

  • Field-level AES-256-GCM encryption at rest
  • TLS 1.2+ in transit between all systems
  • Email OTP authentication
  • Role-based access control
  • Key separation
  • PII redaction
  • Data minimization policies

8. Data Subject Rights

Macha assists customers in responding to GDPR data subject requests (access, correction, deletion).

9. Data Retention and Deletion

  • Conversation content: 45 days from last activity, deleted automatically
  • Trial account data: 30 days post-trial
  • Paid account data: 30 days post-termination
  • Early deletion available upon request

The 45-day window applies to conversation content; the 30-day windows apply to account-level data after termination. Retention periods for each category of personal data are set out in full in the Privacy Policy.

10. Breach Notification

Macha notifies customers within 72 hours of confirmed breaches, detailing nature, impact, mitigation steps, and contact information.

11. Audit Rights

Customers may audit practices with reasonable notice (max once yearly) while protecting other customers' confidentiality.

12. Liability

Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, and any reference in those Terms to a party’s liability means that party’s aggregate liability under the Terms and this DPA taken together.

13. Term and Termination

Agreement remains active during data processing; Macha deletes or returns data upon termination unless law requires retention.

14. Contact

For questions, contact [email protected].

Registered office: AGZ Technologies Private Limited, M1801 Meghana Shalini Apartments, Banashankari 2nd Stage, Bangalore - 560070, Karnataka, India.

Built For Trust.
Designed For Privacy.

Your data is safe with Macha AI. We meet the highest security standards so you can focus on support without compromise.

GDPR Compliant

Fully aligned with global data protection and security standards.

No Training On Your Data

Your content is never used to train AI models, and is kept only for the periods set out in our Privacy Policy.