Data Processing Addendum
How we process personal data on behalf of organizers using Perical.
Last updated: October 2026
01Scope and Applicability
This Data Processing Addendum ("DPA") describes how Perical processes personal data when it does so on behalf of an organizer or event using the Platform.
This DPA is a business-to-business document. It applies where Perical processes personal data as a service provider on the instructions of a customer (for example, an event organizer), and it supplements the Terms of Service. Where a customer hosts events, the organizer verification requirement (identity verification through DigiLocker before an event can be created) applies and is described in the Terms of Service and the Acceptable Use Policy. This DPA does not describe every processing activity: where Perical processes data in its own capacity - for example, for its own security, analytics, or legal obligations - our Privacy Policy applies.
02Definitions
- "Personal data" means information relating to an identified or identifiable individual that is processed through the Platform.
- "Data principal" (or data subject) means the individual to whom the personal data relates.
- "Customer" means the organizer or entity that uses Perical to process personal data in connection with its event.
- "Service" means the Perical platform and related services.
03Roles and Responsibilities
The roles of Perical and the Customer depend on the circumstances and on the applicable law.
In many cases, an event organizer decides why and how guest and event information is collected for their event, while Perical processes that information to provide the Service. In that scenario, the Customer acts in a controller or fiduciary-style role for that processing and Perical acts as a processor or service provider on the Customer's instructions.
This does not apply to every category of data. Where Perical processes personal data for its own legitimate purposes (for example, security, fraud prevention, platform analytics, or legal compliance), Perical acts in its own capacity and the Privacy Policy governs.
04Processing Instructions
Where Perical processes personal data on behalf of a Customer, it will do so only on the Customer's documented instructions, except where applicable law requires otherwise. The Customer is responsible for the lawfulness of the instructions it gives, including ensuring it has an appropriate basis for the processing.
05Categories of Personal Data
Personal data processed through the Service may include: account and profile information (such as name and email), guest list information, event and registration information, attendance records, messages and communications, guest and announcement content, and check-in-related information. The categories will depend on how the Customer uses the Service.
06Categories of Data Principals (Data Subjects)
Personal data may relate to the Customer's organizers, guests, volunteers, event participants, and other individuals the Customer adds to the Platform in connection with its event.
07Processing Purposes
Where Perical processes personal data on the Customer's behalf, it does so to provide the Service the Customer requested, including: event and guest list management, event planning and registration, attendance tracking, communications and notifications, guest messaging, ticket scanning and guest check-in, and file sharing.
08Confidentiality
Perical ensures that personnel authorized to process personal data are subject to appropriate confidentiality obligations and will process the data only as necessary to provide the Service.
09Security Measures
Perical maintains reasonable technical and organizational measures to protect personal data, including:
- encryption in transit;
- authenticated access and role-based authorization;
- least-privilege access to production systems;
- audit logging of privileged actions;
- security logging and monitoring;
- rate limiting and abuse controls;
- regular backups; and
- an incident-response process.
Details of internal infrastructure, credentials, and security configuration are not disclosed.
10Sub-processors and Third-Party Services
Perical uses third-party providers to operate the Service, including providers of authentication (Clerk), database hosting (Turso/LibSQL), file storage (Cloudflare R2), email delivery (Resend), and observability (Grafana Cloud).
A current list of sub-processors and third-party services is maintained by the operator and made available on request. Whether a particular provider is a sub-processor of the Customer's data depends on the provider's role and the applicable arrangements. Where Perical engages a sub-processor to process Customer data, it will ensure the sub-processor is bound by appropriate obligations.
11Data Principal (Data Subject) Requests
The Platform provides data principals with mechanisms to exercise supported requests, including access, correction, export, deletion, and privacy grievances, through the Privacy area of their Settings. Where a data principal contacts a Customer directly, the Customer is responsible for responding. Where Perical receives a request that relates to a Customer's processing, Perical will, where appropriate, direct the request to the Customer and provide reasonable assistance.
12Data Breach / Incident Assistance
Where a security incident affects personal data processed on a Customer's behalf, Perical will follow its incident-response process and provide reasonable assistance to the Customer, where required, to support the Customer's obligations - for example, with information about the incident needed for notification or reporting. Perical does not automatically report every incident to authorities on the Customer's behalf; notification obligations are determined by the Customer and applicable law.
13Retention and Deletion
Perical processes personal data for as long as needed to provide the Service, subject to the Platform's retention practices, which include:
- product/navigation activity retained for approximately 90 days;
- security events retained for approximately 365 days;
- admin audit records retained for approximately 730 days;
- temporary data exports expiring within approximately 7 days; and
- check-ins and attendance records retained for verification and operational purposes.
On an approved account-deletion request, Perical removes or anonymizes the relevant personal data in accordance with its deletion workflow. Backup copies may persist for the backup lifecycle and expire according to the backup retention schedule.
14International Transfers
Some third-party providers used to operate the Service may process or store data outside India as part of providing their services, in accordance with their service terms and applicable contractual arrangements. Where transfers occur, they are subject to the provider's applicable safeguards and Perical's arrangements with the provider.
15Audit / Compliance Assistance
Perical will provide reasonable assistance to a Customer in connection with the Customer's compliance obligations under applicable data protection law, including by making available information about Perical's processing and security practices, subject to confidentiality and without exposing internal security details.
16Termination
This DPA applies while a Customer uses the Service. On termination of the Service, Perical will, where applicable, delete or return personal data processed on the Customer's behalf in accordance with the Terms of Service, unless applicable law requires retention.
17Liability
Liability under this DPA is subject to the limitations set out in the Terms of Service. Each party remains responsible for its own obligations and for any liability arising from its own processing.
18Contact
Questions about this DPA may be directed to support@perical.in.
Questions about this document? Contact us at support@perical.in.