Avik Consultancy

Data Processing Addendum

Last updated: 4 October 2026

In short: your clients’ data belongs to you. We store and process it only to run Clientflow for you, keep it secure and separate from other businesses, tell you quickly if something goes wrong, and delete it when you leave.

This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Avik Consultancy and each business that uses Clientflow (“you”). It applies to personal data of your clients and contacts that you or your clients enter into Clientflow (“Client Data”).

1. Roles

For Client Data, you are the Data Fiduciary and Avik Consultancy is your Data Processor, as those terms are used in the Digital Personal Data Protection Act, 2023.

2. What we process

PeopleYour clients, prospective clients and their parents or guardians where relevant
DataNames, mobile numbers, email addresses, appointment details, payment status, ratings and feedback, and notes, tags and follow-ups you add
PurposeProviding Clientflow to you: booking, reminders, client records, payments tracking, reports and the features you choose to use
DurationFor as long as you use Clientflow, plus the export and deletion period in section 8

3. Our commitments

  • We process Client Data only on your documented instructions, which are the Terms, this DPA and the way you configure and use Clientflow. We do not sell it or use it for our own purposes.
  • We keep Client Data logically separated so that no other business can access it.
  • Everyone at Avik Consultancy who can access Client Data is bound by confidentiality and accesses it only when needed, for example to give you support you asked for.
  • We maintain reasonable security safeguards, including encryption in transit, access controls, logging and monitoring of access, and backups, as expected under the DPDP Rules, 2025.

4. Sub-processors

We use carefully chosen service providers to run Clientflow: cloud hosting and database providers, email and messaging providers, Razorpay for payments, AI providers for drafts you request, and Google if you connect Google Calendar. Each is bound by written terms that protect Client Data at least as well as this DPA. We will tell you before adding or replacing a sub-processor that processes Client Data, and you may object by contacting us; if we cannot address the objection, you may cancel and receive a pro-rata refund of prepaid fees for the remaining period.

5. Helping you with your clients’ rights

If one of your clients contacts us about their data, we will pass the request to you and not respond directly unless you ask us to or the law requires it. Clientflow lets you view, correct and delete client records; if you need more help to answer a request, we will assist within a reasonable time.

6. Personal data breaches

If we become aware of a breach affecting Client Data, we will inform you without undue delay, and in any case within 24 hours, with the information we have about its nature, likely impact and the steps taken. We will keep you updated and help you meet your duty to inform affected clients and the Data Protection Board of India.

7. Your responsibilities

  • Give your clients a clear notice about how you use their data and obtain any consent needed.
  • Obtain verifiable consent from a parent or lawful guardian before entering a child’s data.
  • Keep Client Data accurate, collect only what you need, and delete it when you no longer need it.
  • Respond to your clients’ requests to access, correct or erase their data.

8. Return and deletion

You can export Client Data at any time while your account is active and for 30 days after it is closed. After that, we delete Client Data from our live systems within 60 days, and from backups as they expire, unless the law requires us to keep it.

9. Information and audits

On reasonable written request, we will provide information needed to show that we comply with this DPA. Contact support@myclientflow.org.

Questions about this page? Write to support@myclientflow.org.