Legal · Data Processing & AI
DPA & AI Addendum
How Moserly processes your data as a processor, and how it uses AI.
On this page
- 1. Introduction & roles
- 2. Definitions
- 3. Subject-matter & scope of processing
- 4. Processing on instructions
- 5. Confidentiality
- 6. Security measures
- 7. Sub-processors
- 8. Sub-processor list
- 9. International transfers
- 10. Assistance & data-subject rights
- 11. Personal-data breaches
- 12. Return & deletion
- 13. Audits
- 14. AI Addendum — how Moserly uses AI
- 15. AI — data, boundaries & safeguards
- 16. AI — your responsibilities
- 17. Liability & order of precedence
- 18. Contact
1Introduction & roles
This Data Processing Addendum and AI Addendum (“DPA”) forms part of the Terms of Service between Moserly Technologies Private Limited (“Moserly”, “Processor”) and the Client (“you”, “Data Fiduciary” / “Controller”). It governs Moserly’s processing of personal data contained in Client Content on your behalf, and reflects the requirements of the Digital Personal Data Protection Act, 2023 and other applicable Indian law.
For Client Content, you are the Data Fiduciary and Moserly is the Data Processor. For our own account and website data, Moserly is the Data Fiduciary (see the Privacy Policy).
2Definitions
“Personal Data”, “Processing”, “Data Principal”, “Data Fiduciary” and “Data Processor” have the meanings given under the DPDP Act, 2023. “Client Content” means the data you upload or provide for processing. “Sub-processor” means a third party engaged by Moserly to process Client Content.
3Subject-matter & scope of processing
| Subject-matter | Provision of the Moserly reporting-automation Services |
|---|---|
| Duration | For the term of your subscription and any retention/deletion period thereafter |
| Nature & purpose | Ingesting, validating, storing, processing (rule-based report generation) and making available reports from Client Content |
| Types of personal data | As determined by you; may include names, contact details, vehicle/consignment details, party details, amounts and — if you enable it — driver/vehicle compliance documents |
| Categories of Data Principals | Your staff and Authorised Users, and third parties whose data appears in your files (e.g. drivers, employees, counterparties) |
4Processing on documented instructions
Moserly will process Client Content only to provide the Services and on your documented instructions (which include these Terms, the product’s configuration, and the rules you confirm), unless required otherwise by law — in which case, where permitted, we will inform you. Moserly will not sell Client Content, use it for advertising, or use it to train any machine-learning model.
5Confidentiality
Moserly ensures that personnel authorised to process Client Content are bound by appropriate confidentiality obligations and access it strictly on a need-to-know basis.
6Security measures
Moserly implements appropriate technical and organisational measures, including: encryption of data in transit; strict multi-tenant isolation enforced on every request; access to stored files only via short-lived signed URLs (never public paths); role-based access control; hashed credentials; audit logging of sensitive actions; least-privilege cloud access; and secrets management. Production infrastructure is hosted on AWS in the Mumbai (ap-south-1) region. Measures may evolve, but protection will not be materially reduced.
7Sub-processors
You authorise Moserly to engage the sub-processors listed in Section 8 to process Client Content. Moserly imposes data-protection obligations on each sub-processor no less protective than those in this DPA and remains responsible for their performance. We will maintain the list below and give you a reasonable opportunity to object to a material new sub-processor before it begins processing Client Content; a reasonable objection is handled in good faith (including, if unresolved, a right to terminate the affected Service).
8Sub-processor list
Current sub-processors engaged in providing the Services:
| Sub-processor | Function | Data processed | Location |
|---|---|---|---|
| Amazon Web Services (AWS) | Hosting, database, object storage, transactional email (SES) | Account data & Client Content (files & reports) | India — Mumbai (ap-south-1) |
| Anthropic PBC | AI drafting of rules during onboarding only (Setup Assistant / “Fix with AI”) | Column headers + a small sample of rows + your business-logic description (not full files) | United States |
| Razorpay Software Pvt. Ltd. | Subscription payments, NACH/UPI mandates, GST invoicing | Billing & payment-mandate data | India |
| Google LLC | Optional Google sign-in (OAuth) | Authentication profile & email | United States / global |
| Cloudflare, Inc. | Bot/abuse protection on public forms (Turnstile) | Request metadata for public forms | Global |
This list is versioned; the effective date at the top of this page reflects its latest revision. Material changes will be notified as described in Section 7.
9International transfers
Client Content is primarily stored and processed in India (AWS Mumbai). The onboarding AI feature transfers a limited sample (headers and sample rows, plus your description) to Anthropic in the United States, and Google sign-in may involve processing outside India. Such transfers are made in compliance with applicable Indian law and under contractual safeguards with the relevant sub-processor.
10Assistance & data-principal rights
Taking into account the nature of processing, Moserly will provide reasonable assistance to help you meet your obligations, including responding to Data Principals’ requests (access, correction, erasure, nomination) and conducting any required assessments. If a Data Principal contacts Moserly directly about Client Content, we will, unless legally required to act, refer them to you.
11Personal-data breaches
Moserly will notify you without undue delay after becoming aware of a personal-data breach affecting Client Content, provide the information reasonably available to help you meet your notification obligations, and take reasonable steps to mitigate and remediate. Notifications are not an acknowledgement of fault.
12Return & deletion
On termination or expiry, and on your written request, Moserly will make Client Content available for export for a reasonable period, and thereafter delete or de-identify it, except where retention is required by law. Routinely, generated reports move from hot to cold storage after six months (restorable on request) and are not hard-deleted on an automatic schedule; on account closure, deletion follows the agreed period.
13Audits
Moserly will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and subject to confidentiality, allow for and contribute to audits, including by responding to reasonable security questionnaires, no more than once per year absent a specific legal requirement or a suspected breach.
14AI Addendum — how Moserly uses AI
This section describes Moserly’s use of artificial intelligence, so you can assess and document it.
- Daily report generation is fully deterministic and uses no AI/LLM. Reports are produced by a fixed, rule-based engine executing only the rules your organisation has confirmed. The same numbers a correct manual calculation would produce are the numbers the engine produces.
- AI is confined to onboarding. The Setup Assistant (and the optional “Fix with AI” helper) uses a large-language-model service (Anthropic) to draft candidate mapping and calculation rules from the samples you provide.
15AI — data, boundaries & safeguards
- What is sent: only column headers, a small number of sample rows, and the plain-text business-logic description you supply — not your full files and not your daily production data.
- Where: to Anthropic PBC in the United States (see Sections 8–9).
- No training: Client Content is not used to train Moserly’s or any sub-processor’s models.
- No automated decision-making: the AI drafts suggestions; it does not make decisions producing legal or similarly significant effects on any individual.
- Human-in-the-loop: AI-drafted rules are never auto-applied. A project goes live only after the rules are validated against your samples and explicitly confirmed by a person.
16AI — your responsibilities
When using the Setup Assistant, upload only representative samples suitable for drafting rules, minimise unnecessary personal or sensitive data in those samples, and review every AI-suggested rule before confirming it. You remain responsible for the correctness and lawfulness of the rules you confirm and the reports produced from them.
17Liability & order of precedence
Liability under this DPA is subject to the limitations in the Terms of Service. In case of conflict on the subject of processing of Client Content, this DPA prevails over the rest of the Terms; otherwise the Terms govern.
18Contact
For DPA or AI-related queries, or to raise a data-protection concern, contact legal@moserly.com.
Grievance Officer
In accordance with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 (and the rules thereunder), the Grievance Officer for Moserly Technologies Private Limited is:
Nagesh Chotia
Moserly Technologies Private Limited
3D 1204, Orris Aster Court, Sector 85, Gurugram – 122004, Haryana, India
Email: legal@moserly.com
We aim to acknowledge every complaint within 48 hours and to resolve it within the timelines prescribed under applicable law (ordinarily within 15 days).
Registered office: 3D 1204, Orris Aster Court, Sector 85, Gurugram – 122004, Haryana, India
CIN: U62091HR2026PTC149216 | GSTIN: 06AAVCM3611K1Z5
General: info@moserly.com | Legal & privacy: legal@moserly.com | Sales: sales@moserly.com
Grievance Officer: Nagesh Chotia — legal@moserly.com