Version 1.0 · Effective 24 August 2026
This Data Processing Addendum ("Addendum" or "DPA") forms part of the agreement between Learnture Ventures Pvt. Ltd. (CIN U74999MH2017PTC460694), a company incorporated in India with its office at 6th Floor, Agnel Technical Complex, Centre for Incubation and Business Acceleration (CIBA), Sector 9A, Vashi, Navi Mumbai, Maharashtra 400703 ("Board Infinity", "we", "us") and the customer that has entered into that agreement ("Customer", "you") for the provision of the Board Infinity and InfyLearn platforms, including white-labelled tenant instances (the "Services").
It governs personal data that we process on your behalf and on your instructions when you use the Services. It does not govern personal data for which we decide the purpose ourselves — that is covered by our Privacy Policy, which is the notice for individuals whose data we hold in our own right.
No signature is required for this Addendum to apply: it takes effect automatically as part of your agreement with us. If your procurement process requires a counter-signed copy, or a copy on your own paper, write to admin@boardinfinity.com and we will arrange it.
Terms not defined here have the meaning given in the applicable Data Protection Laws or in the agreement between us.
Data Protection Laws means all laws applicable to the processing of personal data under this Addendum, including India's Digital Personal Data Protection Act, 2023 and the rules made under it ("DPDPA"); Regulation (EU) 2016/679 ("EU GDPR") and the UK GDPR together with the Data Protection Act 2018, where applicable to you.
Customer Personal Data means personal data contained in the data you or your users submit to, or generate within, the Services, and which we process on your behalf.
Data Fiduciary, Data Processor and Data Principal have the meanings given in the DPDPA. Controller, Processor, Data Subject and Personal Data Breach have the meanings given in the GDPR.
Sub-processor means a third party engaged by us to process Customer Personal Data in connection with the Services.
Standard Contractual Clauses or SCCs means the clauses annexed to European Commission Implementing Decision (EU) 2021/914.
Board Infinity operates in two distinct roles, and it matters which one applies to a given set of data. Conflating them is the most common error in platform contracts, so the split is stated plainly here.
Where we act as Data Processor / Processor. When a partner institution, employer or other organisation uses the Services to run its own cohorts, programmes, assessments or hiring, that organisation decides the purpose and means of the processing. It is the Data Fiduciary under the DPDPA and the Controller under the GDPR. Board Infinity is its Data Processor (Section 8(2), DPDPA) and Processor (Article 28, GDPR). This Addendum governs that processing.
Where we act as Data Fiduciary / Controller. When an individual signs up directly at www.boardinfinity.com for our own courses, coaching or placement services, we decide the purpose ourselves and we are the Data Fiduciary and Controller for that data. This Addendum does not apply to it; our Privacy Policy does.
Our own business records. We are also the Data Fiduciary and Controller for the limited personal data of your staff that we hold to run the commercial relationship — the names, work email addresses and roles of your administrators and billing contacts, and our records of support requests. That data is not Customer Personal Data under this Addendum.
You confirm that you have a lawful basis for the Customer Personal Data you provide to us, that you have given the notices and obtained the consents your role requires, and that your instructions to us will not put us in breach of Data Protection Laws.
We process Customer Personal Data only to provide, secure, support and maintain the Services, and only for the duration of your agreement with us. The subject matter, duration, nature and purpose of the processing, the categories of personal data and the categories of Data Principals are set out in Annex 1.
4.1 Documented instructions. We process Customer Personal Data only on your documented instructions, including as to transfers, unless required to do otherwise by law — in which case we will inform you of that requirement before processing, unless the law prohibits us from doing so. Your agreement with us, your configuration of the Services, and this Addendum together constitute your documented instructions. If we consider an instruction to infringe Data Protection Laws, we will tell you.
4.2 We do not use your data for our own purposes. We do not sell Customer Personal Data, we do not share it for cross-context behavioural advertising, and we do not use it to train or fine-tune general-purpose machine-learning models. Where the Services use AI to review a submission, generate feedback or score an assessment, that processing is performed to deliver the Service to you and on your instruction.
4.3 Confidentiality. We ensure that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and are granted access on a need-to-know basis only.
4.4 Security. We implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against a personal data breach, as required by Section 8(5) of the DPDPA and Article 32 of the GDPR. Those measures are described in Annex 2. We may update them as the Services evolve, provided the level of protection is not reduced.
4.5 Assistance with rights requests. Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures in responding to requests from Data Principals or Data Subjects to exercise their rights — access, correction, completion, updating, erasure, withdrawal of consent, restriction, objection and portability. Where an individual approaches us directly about data we process on your behalf, we will not respond substantively on your behalf; we will refer them to you and tell you promptly, unless the law requires otherwise.
4.6 Personal data breach. We will notify you of a personal data breach affecting Customer Personal Data without undue delay and in any event within 48 hours of becoming aware of it. The notification will describe the nature of the breach, the categories and approximate volume of data and individuals affected so far as known, the likely consequences, and the measures taken or proposed. We will provide further information as the investigation progresses and will assist you in meeting your own notification duties — including intimation to the Data Protection Board of India and to affected Data Principals under Section 8(6) of the DPDPA and the DPDP Rules, and notification to a supervisory authority and data subjects under Articles 33 and 34 of the GDPR. Where we are separately required to report an incident to CERT-In, we will do so and will tell you that we have.
4.7 Assistance with assessments. We will provide you with reasonable information and assistance for any data protection impact assessment and any prior consultation with a supervisory authority, to the extent these relate to our processing and the information is not otherwise available to you.
4.8 Deletion and return. On termination or expiry of your agreement, and at your choice, we will delete or return Customer Personal Data and delete existing copies, unless a law to which we are subject requires continued storage. Unless you request return, deletion is completed within 60 days of termination. Where you withdraw consent or instruct erasure during the term, we will cease the relevant processing and cause our Sub-processors to cease it, in line with Sections 6(6) and 8(7) of the DPDPA.
One honest qualification about backups. Data already written to encrypted backup media is not selectively erasable. Rather than delete it out of a sealed backup, we suppress the record so that it is not reinstated on restore, and the backup itself expires on its normal retention cycle. Until it expires, that data remains protected by this Addendum and is not used for any other purpose.
4.9 Audit and information. We will make available the information reasonably necessary to demonstrate our compliance with this Addendum and will allow for and contribute to audits, including inspections, conducted by you or an auditor you mandate. We will first offer our then-current security documentation and any third-party assessment reports. Where those do not answer your question, you may conduct an on-site or remote audit no more than once in any twelve-month period, on at least 30 days' written notice, during business hours, subject to confidentiality and without unreasonable disruption to our operations. You may audit more frequently where a supervisory authority requires it or following a personal data breach affecting your data.
You give general authorisation for us to engage Sub-processors to deliver the Services. Every Sub-processor is engaged under a written contract that imposes data protection obligations no less protective than those in this Addendum, and we remain fully liable to you for their performance.
Our current Sub-processors are listed in Annex 3. We will give you at least 30 days' notice before adding or replacing a Sub-processor, by email to your registered administrator contact. If you have a reasonable, documented data protection objection, tell us within that period and we will work with you in good faith to offer a change in configuration or an alternative that avoids the objection. Where none is reasonably available, you may terminate the affected part of the Services without penalty for the remainder of the term.
Where your data is held. Customer Personal Data is hosted in India, in the Asia Pacific (Mumbai) region of Amazon Web Services. It is not routinely transferred out of India.
Transfers under the DPDPA. Any transfer of personal data outside India is made in accordance with Section 16 of the DPDPA and any restriction notified by the Central Government, and we require the recipient to provide an equivalent level of protection.
Transfers subject to the GDPR. Where you are established in the European Economic Area, the United Kingdom or Switzerland, or the processing is otherwise subject to the EU or UK GDPR, our processing of Customer Personal Data in India is a restricted transfer. For those transfers the Standard Contractual Clauses, Module Two (controller to processor) are incorporated into and form part of this Addendum, with you as data exporter and Board Infinity as data importer, completed as follows: the optional docking clause applies; in Clause 9, Option 2 (general written authorisation) applies with the notice period in Section 5 above; in Clause 11, the optional independent dispute resolution body does not apply; in Clause 17, the governing law is that of Ireland; in Clause 18(b), the courts of Ireland have jurisdiction; and Annexes I, II and III to the SCCs are populated by Annexes 1, 2 and 3 of this Addendum respectively. For transfers subject to the UK GDPR, the International Data Transfer Addendum issued by the UK Information Commissioner is incorporated and completed using the same information, with Tables 1 to 4 populated accordingly. For transfers subject to Swiss law, references to the GDPR are read as references to the Swiss Federal Act on Data Protection and the competent authority is the Swiss Federal Data Protection and Information Commissioner.
A small number of Sub-processors listed in Annex 3 process limited data outside India. Those transfers are covered by the same mechanisms and are identified in Annex 3 so that you can see them rather than having to ask.
If there is a conflict, the following order applies: the Standard Contractual Clauses or UK Addendum (where they apply), then this Addendum, then the rest of your agreement with us, then our Terms and Conditions. Nothing in this Addendum is intended to contradict or restrict the SCCs.
Each party's liability under this Addendum is subject to the limitations and exclusions of liability in your agreement with us, except where Data Protection Laws do not permit that limitation. This Addendum takes effect when your agreement with us takes effect and continues until we have deleted or returned all Customer Personal Data in accordance with Section 4.8.
Questions about this Addendum, requests for a counter-signed copy, Sub-processor notifications and audit requests should go to our Data Protection Officer:
Mr. Rakesh Sharma
Data Protection Officer & Grievance Officer
Learnture Ventures Pvt. Ltd.
6th Floor, Agnel Technical Complex, Centre for Incubation and Business Acceleration (CIBA), Sector 9A, Vashi, Navi Mumbai, Maharashtra 400703
Email: admin@boardinfinity.com
Time: Mon - Sat (9:00 am - 6:00 pm)
| Subject matter | Provision of the Board Infinity and InfyLearn learning, assessment, coaching and placement platforms to the Customer. |
|---|---|
| Duration | The term of the Customer's agreement, plus the deletion period in Section 4.8. |
| Nature and purpose | Hosting and storage; account provisioning; delivery of learning content; running and scoring assessments, including proctored assessments where the Customer enables them; scheduling and delivering coaching sessions, including recording and transcription where enabled; generating feedback and reports; sharing candidate profiles with employers where the Customer or the individual has instructed it; support, security monitoring, backup and service maintenance. |
| Categories of Data Principals / Data Subjects | The Customer's learners and candidates; coaches and mentors engaged in delivering sessions; the Customer's administrators, faculty and recruiters. |
| Categories of personal data | Identity and contact data (name, email address, mobile number); account and authentication data; profile, education and employment history, including résumés; enrolment, attendance and progress records; assessment submissions, scores and reports; session recordings, audio and transcripts where recording is enabled; proctoring artefacts, including webcam images, where proctored assessments are enabled; support correspondence; and technical data such as IP address, device and browser information and application logs. |
| Special category / sensitive data | The Services are not designed to process special category data. Where a Customer's own process requires government identifiers to be collected from learners, those identifiers are processed solely on the Customer's instruction and are not used for any other purpose. Customers should not upload health, biometric-for-identification, or other special category data unless separately agreed in writing. |
| Frequency | Continuous, for the duration of the agreement. |
| Competent supervisory authority | For SCC purposes, determined under Clause 13 of the SCCs by reference to the Customer's place of establishment or its EU representative. For DPDPA purposes, the Data Protection Board of India. |
The measures below are those in force at the effective date of this Addendum. They are described accurately rather than aspirationally; where a control is partial, it is stated as such.
| Encryption in transit | TLS is enforced for access to the Services and for connections to the primary database. |
|---|---|
| Encryption at rest | The primary application database and object storage are encrypted at rest using managed keys. Encryption at rest is being extended across the remaining components of the estate. |
| Network isolation | Data stores are reachable only from the application tier by security-group reference, with no public network ranges permitted. The document store is reached over a private endpoint and is not internet-exposed. |
| Administrative access | Access to production hosts is through an identity-authenticated session service with no open inbound SSH port. Privileged access is granted on least privilege, approved, and reviewed periodically. Multi-factor authentication is enforced on administrative cloud accounts. |
| Logging and monitoring | Control-plane activity is logged to an append-only trail with log-file validation, delivered to a separate log store. Automated alerts are raised on privileged and security-relevant events. Managed threat detection is enabled across the account. |
| Backup and recovery | The primary database has continuous point-in-time recovery with a 30-day window, and an independent daily backup copy is held in a separate vault that survives deletion of the source. Restore is tested and the result recorded; the most recent restore test confirmed a valid, decryptable recovery point restored to a working database. |
| Segregation | The platform is multi-tenant. Customer data is segregated logically by a tenant identifier enforced in the application layer, not by a separate database per customer. Customers requiring physical separation should raise it with us before contracting. |
| Personnel | Confidentiality obligations in employment contracts; background verification for roles with production access; security and privacy awareness training; access revoked on exit. |
| Development | Peer code review and branch protection on the code repository; separated development, test and production environments. |
| Governance | A named Data Protection Officer; a maintained risk register; vulnerability scanning with tracked remediation; and an information security management system aligned to ISO/IEC 27001:2022. We are not currently certified to ISO/IEC 27001 and do not claim to be. |
The following Sub-processors may process Customer Personal Data. The list is current at the effective date above and is updated in line with Section 5.
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Amazon Web Services | Cloud hosting, storage, backup and supporting infrastructure for the Services | India (Asia Pacific, Mumbai) |
| MongoDB Atlas | Managed document database, reached over a private endpoint | India |
| OpenAI | AI review of submissions, generation of feedback and assessment support, on our instruction | Outside India |
| Google (Gemini API) | AI review of submissions and generation of feedback, on our instruction | Outside India |
| AssemblyAI | Transcription of coaching and interview session audio, where recording is enabled | Outside India |
Where a Sub-processor processes data outside India, that transfer is covered by the mechanisms in Section 6. Sub-processors used solely for our own internal business administration, and which do not process Customer Personal Data, are not listed here.
To be notified of changes to this list, write to admin@boardinfinity.com asking to be added to Sub-processor change notifications.