Data Processing Agreement
Last Updated: January 01, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Inmind Pakistan (“Inmind,” “Processor”) and the contracting entity (“Client,” “Controller”) and governs the processing of personal data by Inmind on behalf of the Client in connection with the Subscription Service.
1. Subject Matter & Scope
This DPA applies exclusively to personal data processed by Inmind within the scope of the service contract. The categories of personal data processed and the purposes for which they are processed are as described in Annex 1 of this Agreement and in the applicable Order Form.
Inmind shall process personal data only to the extent necessary to fulfil its obligations under the service agreement and shall not process personal data for any other purpose.
2. Roles & Responsibilities
The Client acts as the data controller and determines the purposes and means of processing. Inmind acts as the data processor and processes personal data solely on behalf of and in accordance with the documented instructions of the Client.
Inmind shall never process personal data for its own purposes and shall promptly inform the Client if, in its opinion, an instruction infringes applicable data protection law.
3. Security Measures
Inmind shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk of processing. These measures include, but are not limited to:
- Restricting access to personal data to authorised personnel only, on a need-to-know basis
- Encrypting personal data in transit and at rest where technically feasible
- Regularly identifying, assessing, and mitigating vulnerabilities in processing systems
- Maintaining confidentiality obligations for all staff who handle personal data
- Implementing formal information security management processes covering change management, access controls, cryptographic controls, and backup procedures
- Conducting periodic third-party security audits, including automated scans and penetration testing
4. Data Subject Rights
When data subjects (individuals whose personal data is processed) exercise their rights — including rights of access, rectification, erasure, restriction, portability, or objection — Inmind shall promptly forward such requests to the Client and provide reasonable assistance to the Client in fulfilling its obligations under applicable data protection law.
5. Sub-Processors
Inmind shall not engage any sub-processor without the prior written consent of the Client. Where sub-processors are engaged, Inmind shall impose data protection obligations on them that are no less protective than those set out in this DPA. Inmind remains fully liable to the Client for the performance of the sub-processor's obligations.
A list of current sub-processors is available upon request and the Client will be notified in advance of any intended changes.
6. Third-Party Data Sources
Where the Subscription Service integrates with third-party platforms (such as e-commerce marketplaces or logistics APIs), personal data received from those platforms shall be used solely for the authorised business activities specified in the service agreement. Inmind shall not use such data to generate competitive intelligence about third parties or for any purpose beyond service delivery.
7. Security Incident Notification
In the event of a personal data breach or security incident affecting the personal data processed under this DPA, Inmind shall notify the Client without undue delay and, where feasible, within 24 hours of becoming aware of the incident. The notification shall include:
- The nature of the breach and the categories of personal data affected
- The approximate number of individuals and records affected
- The likely consequences of the breach
- The measures taken or proposed to address the breach and mitigate its effects
8. International Data Transfers
Inmind shall not transfer personal data outside of Pakistan without the Client's prior written consent and unless appropriate safeguards are in place, such as standard contractual clauses or other legally recognised transfer mechanisms. Inmind maintains a register of all international data transfers, documenting destination countries and the legal basis for each transfer.
9. Data Retention & Deletion
Upon termination or expiry of the service agreement, Inmind shall, at the Client's election, either securely delete or return all personal data processed under this DPA, and shall confirm in writing that deletion has been completed. Inmind shall also notify all relevant sub-processors of the termination and ensure they comply with equivalent deletion obligations.
Inmind may retain personal data for longer periods only where required by applicable law, in which case Inmind shall inform the Client and continue to protect the data in accordance with this DPA.
10. Audit Rights
The Client has the right to audit Inmind's compliance with this DPA upon reasonable prior written notice. Inmind shall provide the Client and its authorised representatives with access to all information reasonably necessary to demonstrate compliance with this DPA. Inmind may require that such audits are conducted by independent third-party auditors under an appropriate confidentiality obligation.
11. Governing Law
This DPA is governed by the laws of Pakistan. Any disputes arising from this DPA shall be subject to the exclusive jurisdiction of the courts of Lahore, Pakistan. This DPA supersedes any conflicting provisions in the main service agreement with respect to the processing of personal data.
Annex 1 — Categories of Personal Data Processed
The following categories of personal data are processed under this DPA in connection with the Subscription Service:
| Category | Examples | Purpose |
|---|---|---|
| Contact Information | Name, email address, phone number | Order management, customer communications |
| Delivery Information | Shipping address, city, postal code | Fulfilment and logistics operations |
| Order Data | Order IDs, items, quantities, order status | Order processing and tracking |
| Invoice Data | Billing address, invoice number | Billing and financial record-keeping |
Annex 2 — Security Standards
Inmind's security programme includes the following controls:
- Access Control: Role-based access controls, multi-factor authentication for administrative access, and regular access reviews
- Encryption: TLS 1.2+ for data in transit; AES-256 encryption for data at rest
- Vulnerability Management: Automated vulnerability scanning, regular penetration testing, and timely patch management
- Business Continuity: Regular data backups, tested disaster recovery procedures, and geographic redundancy
- Change Management: Formal change management processes for all system and application changes
- Incident Response: Documented incident response plan with defined escalation paths and notification procedures
- Staff Training: Mandatory data protection and security awareness training for all employees
Contact Us
For questions about this Data Processing Agreement or our data protection practices, please contact us: