Requesting an agreement
This page sets out proposed data processing terms for customers of AstrologyAPI. It is not an executed agreement. Viewing this page, opening an account or using an API does not sign this DPA. The parties must agree and execute the DPA together with the service-specific schedules and any required transfer instruments before relying on it as their processing contract.
To begin, email mail@astrologyapi.com with your organisation's legal name, business address, account email, the services you intend to use and the countries and types of personal data involved. Include any specific security, deletion or transfer requirements. Do not include production personal data or credentials in the request.
The provider is Vedic Rishi Astro Solutions Pvt Ltd, trading as AstrologyAPI, with registered office at D-3/60, SVP Nagar, Versova MHADA, Andheri-West, Mumbai - 400053, Maharashtra, India. The customer, underlying services agreement, authorised signatories, operational contacts and effective date are identified in the executed agreement.
1. Scope and roles
These proposed terms apply to personal data that Provider processes on Customer's behalf in delivering the services specified in the processing schedule (“Covered Services”). “Customer Personal Data” includes the inputs, outputs, records and associated personal information identified in that schedule. “Applicable Data Protection Law” means the data protection law applicable to the covered processing. Terms such as controller, processor, personal data, processing and personal data breach have the meanings given by that law.
Customer acts as controller and Provider as processor, except where Customer acts as processor for another controller, in which case Provider acts as subprocessor. Customer must have authority to give the relevant instructions and authorisations.
Information processed for purposes Provider independently determines, such as its own account administration and billing, is outside this DPA and is addressed in the Privacy Policy. This distinction does not permit unrelated use of Customer Personal Data.
2. Documented instructions and permitted use
Provider shall process Customer Personal Data only on Customer's documented instructions, including instructions concerning international transfers. The executed DPA, processing schedule, services agreement and authorised use of agreed service controls form the initial instructions. Changes must be documented between the parties through the contacts identified in the agreement.
Where Article 28 GDPR applies, a legal exception to instructions is limited to the applicable Union or Member State law, or corresponding domestic law for UK GDPR processing. Provider shall inform Customer before legally required processing unless the relevant law prohibits that notice. Conflicting third-country demands must be addressed through the applicable transfer instrument and law, rather than treated as an unrestricted exception to Customer's instructions.
Provider shall inform Customer immediately if, in its opinion, an instruction infringes Applicable Data Protection Law. The parties shall address the affected processing before continuing an unlawful instruction.
Provider shall not use Customer Personal Data for advertising, unrelated profiling or training general-purpose models under these instructions. AstrologyAPI never trains models on user data. Provider shall prohibit its AI subprocessors from using Customer Personal Data for their own evaluation. Service-specific supplier arrangements must be reflected in the executed schedules.
3. Customer responsibilities
Customer shall determine lawful purposes, provide required notices and establish the legal bases and authorisations necessary for the data it submits. It shall send only information necessary for the Covered Services, issue lawful instructions, protect its applications and credentials, and handle the individual rights requests for which it is responsible.
Customer shall identify restrictions affecting children, sensitive information, images and data about other people in the processing schedule. These responsibilities do not reduce Provider's own obligations under the DPA or applicable law.
4. Confidentiality and security
Provider shall ensure that persons authorised to process Customer Personal Data are bound by confidentiality commitments or an appropriate statutory duty. Access shall be limited to what is needed for authorised tasks.
Provider shall implement appropriate technical and organisational measures, taking account of the nature, scope, context and purposes of processing, the state of the art, implementation costs and risks to individuals. Where applicable, the measures shall meet Article 32 GDPR requirements. The concrete measures and their service scope must be recorded in the security schedule agreed at execution.
Provider shall maintain a process for assessing the effectiveness of the relevant measures. Updates must not materially reduce the overall protection required by the agreement. The schedule governs any agreed communication of material changes. These proposed obligations do not represent a certification or a claim that a particular unlisted control is already implemented.
5. Subprocessors
Provider shall engage subprocessors for Customer Personal Data only with the written authorisation recorded in the executed agreement. The subprocessor schedule identifies the authorised providers, legal entities, functions, data and locations.
If the parties agree general written authorisation, Provider shall inform Customer of intended additions or replacements in advance, using the agreed notice route, and give Customer a meaningful opportunity to object on reasonable data protection grounds before the affected processing begins. Any agreed notice period and resolution process form part of that authorisation. A silent update to a public page does not replace an agreed notification requirement.
Provider shall impose substantially the same applicable data protection obligations on each subprocessor by written agreement and require sufficient guarantees of appropriate measures. Provider remains responsible for its subprocessors' performance as required by Applicable Data Protection Law, including Article 28(4) GDPR where applicable.
The public provider overview is a starting point for discussions. It does not replace the executed authorisation or service-specific register.
6. Individual rights
Taking account of the nature of processing, Provider shall assist Customer through appropriate technical and organisational measures, insofar as possible, with requests to exercise individual rights under Applicable Data Protection Law.
Provider shall promptly notify Customer of a request concerning Customer Personal Data and may direct the individual to Customer. It shall not respond substantively on Customer's behalf except on documented instructions or as required by law. Assistance shall address relevant records and linked outputs, as applicable to access, correction, restriction, portability and deletion.
The assistance schedule records contacts and operational arrangements. Any separately agreed charges for exceptional assistance must not defeat mandatory assistance duties or legal deadlines.
7. Personal data breaches
Provider shall notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data. Notice shall go to the customer contact recorded in the agreement.
Provider shall supply the information then available about the nature of the breach; affected data and individuals, including approximate numbers where possible; likely consequences; measures taken or proposed; and a contact for further information. Information may be provided in phases without undue further delay as facts become available.
Provider shall take reasonable steps to contain, investigate and address the breach and assist Customer with its relevant obligations. Customer determines its own required notifications unless law requires Provider to act independently. Coordination must not delay a mandatory notification. Notification is not itself an admission of liability.
8. Assessments and cooperation
Taking account of the nature of processing and information available to it, Provider shall assist Customer with applicable security, breach-notification, data protection impact-assessment and prior-consultation obligations, including Articles 32–36 GDPR where applicable.
The parties shall cooperate on changes to the covered processing that affect the assessment of risk. A new feature or category of data outside the processing schedule requires an agreed update before it becomes covered.
9. Return, deletion and retained copies
At Customer's choice, Provider shall return or delete Customer Personal Data after the relevant processing services end and delete existing copies, subject to the storage required by the law applicable to that obligation. For processing governed by Article 28(3)(g) GDPR, the exception concerns Union or Member State law, or the corresponding domestic law for UK GDPR processing. Other legal conflicts must be addressed through applicable transfer safeguards and law.
The agreed return and deletion schedule shall specify request contacts, available exports, timing, active-system deletion, linked records, subprocessors and backup treatment. Product rules described on the storage and deletion page must be reconciled with that schedule. No export should be assumed to remain available after the relevant record has been deleted.
Where lawful retention remains necessary, Provider shall restrict use to the required purpose, preserve appropriate confidentiality and security, and delete the data when the requirement ends. Provider shall provide reasonable confirmation of completed return or deletion actions.
Any agreed backup sequence must be consistent with applicable law, restrict residual copies from ordinary use and prevent restored copies from reintroducing deleted data into ordinary processing. The executed schedule records the service-specific implementation and timing.
10. Information and audit
Provider shall make available information necessary to demonstrate compliance with its DPA obligations and allow for and contribute to audits, including inspections, by Customer or its mandated auditor as required by applicable law, including Article 28(3)(h) GDPR where applicable.
The parties may use relevant reports, questionnaires and remote review for efficient routine assurance. Reasonable notice, confidentiality, security and scheduling arrangements may protect other customers and service continuity, but must not prevent an effective audit or limit a supervisory authority's powers. Any agreed ordinary audit arrangements must preserve the exceptions required by law and the applicable transfer instrument.
11. International transfers
Provider shall make a restricted international transfer of Customer Personal Data only under Customer's documented instructions and with a valid safeguard or lawful exception where required. The transfer schedule records the actual chain of recipients, countries, remote access, roles and applicable mechanism.
If standard contractual clauses or a UK transfer instrument are required, the parties must execute the applicable instrument with its completed annexes before the affected transfer. This DPA does not itself execute, implicitly incorporate or replace those instruments. Required assessments, supplementary measures and onward-transfer arrangements must address the relevant processing.
Authority requests and any conflict of law shall be handled consistently with applicable law and the executed instrument, including required notice, review, challenge and minimisation. If required safeguards cannot be maintained, the affected transfer must be suspended or otherwise addressed as the law and instrument require.
12. Agreement, precedence and duration
The final DPA takes effect only upon execution by the parties and continues while Provider processes Customer Personal Data subject to it. The underlying services agreement continues to govern commercial matters, subject to the executed DPA and mandatory law.
For data protection matters, the executed DPA prevails over inconsistent service terms; a mandatory transfer instrument prevails to the extent it requires. No provision may remove a mandatory right, obligation or liability. Amendments must be documented and agreed by the parties.
Schedules included at signing
The following schedules make the agreement specific to the customer's actual processing. They are agreed contract particulars, not implied promises created by this public page.
| Schedule | What the executed agreement records |
|---|---|
| A — Processing details | Parties and contacts; services agreement; roles; applicable laws; product and endpoint scope; environments; data subjects and categories; sensitive-data restrictions; purposes and operations; frequency, duration and permitted locations. |
| B — Security measures | Concrete measures and scope for transport and storage protection, access, confidentiality, customer separation, monitoring, development, incident handling, resilience and data lifecycle. |
| C — Subprocessors | Provider legal entities, functions, affected data, locations, transfer arrangements, customer authorisation, change notices and objection process. |
| D — Assistance, return and deletion | Request contacts, agreed assistance arrangements, export availability, retention and deletion timing, linked records, supplier copies, backup handling and confirmation. |
| E — International transfers | Transfer parties, countries, roles and data; required instruments with complete annexes; relevant assessments and supplementary measures. |
To discuss these terms and prepare an agreement for signature, contact mail@astrologyapi.com.