Registered Company Name: TTL Media Private Limited ("Platform")
Parties:
- Enterprise Client ("Controller"): Individuals, companies, or other entities commissioning campaigns and determining the purposes and means of Personal Data processing.
- Creators ("Data Providers"): Influencers or content creators who supply Personal Data to the Platform and retain control over their personal information.
- TTL Media Private Limited, trading as Oye Creators ("Processor"): A marketplace platform that aggregates, facilitates, and operates campaigns using AI, human resources, and RPAs. Processor acts on documented instructions of Controllers and Creators and processes Personal Data—including publicly available data from social media—to deliver services.
This Data Processing Agreement ("Agreement") is an integral part of the Services Agreement between the Parties. It ensures all Personal Data processing activities comply with:
- The EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR").
- The Indian Digital Personal Data Protection Act, 2023 ("DPDP Act").
- Other relevant international and local privacy laws.
1. Definitions
1.1 Personal Data: Any information relating to an identified or identifiable natural person, including names, contact details, demographic attributes, usage logs, and special categories like health or biometric data when applicable.
1.2 Processing: Any operation performed on Personal Data, such as collection, storage, retrieval, modification, deletion, disclosure, or analysis.
1.3 Controller: The Party (Enterprise Client or Creator) that determines the why and how of Personal Data Processing.
1.4 Processor: TTL Media Private Limited, executing Processing on behalf of Controllers or assisting Creators as Data Controllers of their own data.
1.5 Sub-processor: Any third-party vendor engaged by Processor to carry out specific Processing tasks under a binding contract.
1.6 Data Subject: A natural person whose data is processed.
1.7 Services Agreement: The primary contract under which services are delivered, incorporating this DPA by reference.
2. Scope & Purpose of Processing
2.1 Subject Matter: The Processor will handle Personal Data to deliver services under Controllers' instructions, including campaign planning, analytics, billing, onboarding, and marketplace operations.
2.2 Duration: Processing continues for the duration of the Services Agreement and thereafter as required by law or for legitimate archival and defense of claims.
2.3 Categories of Data Subjects: Employees, contractors, customers of Controllers; Creators and audience members; end users.
2.4 Types of Personal Data: Identity, Contact, Demographic, Technical, Usage, Performance, Public, and Special Category Data.
3. Roles & Responsibilities
3.1 Allocation of roles: For Personal Data that an Enterprise Client uploads, supplies or directs us to collect for its campaigns, the Enterprise Client acts as Controller (Data Fiduciary under the DPDP Act) and TTL Media Private Limited acts as Processor (Data Processor). For Personal Data we collect to operate, secure, bill and improve the platform — including account records, payout records and platform telemetry — we act as Controller in our own right.
3.2 Creators: A Creator is the Controller of the content and profile information they choose to publish. When a Creator participates in a campaign, we process their Personal Data as Controller for onboarding, payment and compliance, and as Processor for campaign reporting delivered to the Enterprise Client.
3.3 Controller obligations: The Controller warrants that it has a lawful basis for the Processing it instructs, that it has given the notices and obtained the consents required by applicable law, and that its instructions do not require us to act unlawfully. The Controller is responsible for the accuracy, quality and legality of the Personal Data it supplies.
3.4 Processor obligations: We shall Process Personal Data only on the Controller's documented instructions, including this Agreement and the configuration choices made in the platform, unless required otherwise by law. If we believe an instruction infringes applicable data-protection law, we shall inform the Controller without undue delay and may suspend the affected Processing.
3.5 Personnel: We ensure that persons authorised to Process Personal Data are bound by confidentiality obligations, are granted access on a least-privilege basis, and receive appropriate data-protection guidance.
3.6 Assistance: Taking into account the nature of the Processing and the information available to us, we shall provide reasonable assistance to the Controller with data-protection impact assessments, prior consultation with a supervisory authority, security of Processing, and responses to data-principal requests.
4. Security Measures
4.1 We implement and maintain appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access. These measures are described in the Security Policy, which forms part of this Agreement.
4.2 Those measures include, at minimum:
- encryption of Personal Data in transit using TLS, and encryption at rest for Confidential and Highly Confidential classifications;
- role-based access control, individual accounts and multi-factor authentication for administrative and production access;
- network segregation between production, staging and development environments, and the use of non-production data for testing wherever practicable;
- logging and monitoring of access to production systems, with logs retained for a defined period;
- secure software-development practices, dependency and vulnerability management, and timely patching;
- encrypted, access-controlled backups, and documented restoration procedures;
- secure disposal of media and deletion routines as set out in the Data Retention Policy.
4.3 We may update these measures from time to time provided the overall level of security is not reduced.
4.4 The Controller is responsible for the security of its own systems, for the confidentiality of its account credentials, and for configuring within the platform the access rights granted to its own users.
5. Sub-Processors
5.1 General authorisation: The Controller grants a general authorisation for us to engage Sub-processors to assist in providing the platform. The current list is maintained on the Vendor & Subprocessor List and summarised in Appendix A.
5.2 Flow-down obligations: Each Sub-processor is engaged under a written contract imposing data-protection obligations that are no less protective than those in this Agreement, and restricting Processing to what is necessary to deliver the relevant service.
5.3 Changes: We shall give the Controller at least thirty (30) days' notice before adding or replacing a Sub-processor that Processes Personal Data, by updating the Vendor & Subprocessor List and, where the Controller has subscribed to notifications, by email.
5.4 Objection: The Controller may object on reasonable data-protection grounds within fifteen (15) days of notice. We shall use reasonable efforts to make the service available without the objected-to Sub-processor or to propose an alternative. If no reasonable alternative exists, the Controller may terminate the affected service on written notice, with a pro-rata refund of pre-paid fees for the unused period as its sole remedy.
5.5 Liability: We remain responsible to the Controller for the performance of each Sub-processor's data-protection obligations.
6. Data Subject Rights & Breach Notification
6.1 Requests: Where a data principal or data subject exercises a right of access, correction, completion, updating, erasure, restriction, objection, portability, withdrawal of consent, or nomination, and the request relates to Processing carried out on the Controller's behalf, we shall promptly forward the request to the Controller and shall not respond substantively ourselves except to confirm receipt or as required by law.
6.2 Assistance: Taking into account the nature of the Processing, we shall provide reasonable technical and organisational assistance to enable the Controller to fulfil such requests within the statutory timeframe. Where the request concerns data for which we are Controller, it is handled under the Privacy & Cookies Policy and the Grievance Redressal process, and deletion requests through Data Deletion.
6.3 Breach notification to the Controller: We shall notify the Controller without undue delay, and in any event within seventy-two (72) hours, after becoming aware of a Personal Data Breach affecting Personal Data Processed on the Controller's behalf.
6.4 Contents of the notice: So far as the information is available, the notice shall describe the nature of the breach, the categories and approximate number of data principals and records concerned, the likely consequences, the measures taken or proposed to address it, and a point of contact. Information not available at the time may be provided in phases without undue further delay.
6.5 Regulatory notification: We shall notify the Data Protection Board of India where required of us under the Digital Personal Data Protection Act, 2023, and shall cooperate with the Controller so that it can meet its own notification obligations to regulators and affected individuals. Neither party shall name the other in a public notification without prior consultation, except where required by law.
6.6 Records: We maintain a record of Personal Data Breaches, including the facts, effects and remedial action taken, and make it available to the Controller on reasonable request.
7. Audit & Inspection
7.1 We shall make available to the Controller the information reasonably necessary to demonstrate compliance with this Agreement, including our security documentation, policies and any third-party certifications or assessment reports we hold.
7.2 The Controller may, not more than once in any twelve (12) month period and on at least thirty (30) days' written notice, audit our compliance with this Agreement. Additional audits may be conducted where required by a supervisory authority or following a confirmed Personal Data Breach affecting the Controller's data.
7.3 Audits shall be conducted during business hours, shall not unreasonably disrupt our operations, and shall be subject to confidentiality obligations. The Controller shall not access systems or data belonging to other customers, and shall not conduct penetration testing without our prior written consent and an agreed scope.
7.4 Where an auditor is appointed, that auditor shall not be a competitor of ours and shall be bound by confidentiality obligations. The Controller bears the cost of the audit, save where the audit reveals a material breach of this Agreement by us, in which case we shall bear the reasonable cost.
7.5 We shall remedy any material non-compliance identified by an audit within a reasonable agreed period.
8. International Data Transfers
8.1 Personal Data is primarily hosted in India. Certain Sub-processors listed in Appendix A Process Personal Data outside India, including in the United States and the European Union.
8.2 Transfers outside India are made in accordance with the Digital Personal Data Protection Act, 2023, and are not made to any territory in respect of which the Central Government has issued a restriction.
8.3 Where Personal Data protected by the EU or UK General Data Protection Regulation is transferred to a country without an adequacy decision, the transfer is made under the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Addendum, together with any supplementary technical measures identified by a transfer impact assessment.
8.4 We shall inform the Controller if we become subject to a legally binding request from a public authority for disclosure of Personal Data Processed on its behalf, unless prohibited from doing so by law, and shall challenge a request that appears unlawful or disproportionate.
9. Term & Data Deletion
9.1 This Agreement takes effect when the Controller first uses the platform and continues for as long as we Process Personal Data on its behalf.
9.2 On expiry or termination, and at the Controller's election, we shall delete or return the Personal Data Processed on its behalf, and delete existing copies, unless retention is required by applicable law.
9.3 The Controller may request export of its data within thirty (30) days of termination, in a commonly used machine-readable format. After that period, deletion proceeds in accordance with the schedule in the Data Retention Policy.
9.4 Deletion from live systems is effected within thirty (30) days of the request or of the end of the applicable retention period. Encrypted backups are overwritten on their normal rotation cycle, and Personal Data in backups is not restored to live systems except for disaster recovery.
9.5 Where we are required by law to retain Personal Data — for example tax, accounting or statutory record-keeping obligations — we shall retain only what is required, for only as long as required, and shall continue to protect it under this Agreement.
10. Confidentiality
10.1 Each Party shall keep confidential all non-public information disclosed by the other in connection with this Agreement, including Personal Data, security documentation, audit findings, commercial terms and campaign data.
10.2 Confidential information may be disclosed only to personnel and advisers who need it for the purposes of this Agreement and who are bound by equivalent confidentiality obligations.
10.3 These obligations do not apply to information that is or becomes public without breach of this Agreement, was lawfully known to the recipient before disclosure, is independently developed without use of the disclosing Party's information, or is lawfully received from a third party without restriction.
10.4 Where disclosure is required by law or a competent authority, the recipient shall, where lawful, give prior notice to the disclosing Party and limit disclosure to what is required.
10.5 Confidentiality obligations survive termination and continue for so long as the information retains its confidential character; obligations relating to Personal Data continue indefinitely.
11. Indemnification
11.1 Each Party shall indemnify the other against Claims and Losses arising from its own breach of this Agreement or of applicable data-protection law, subject to the procedure and exclusions set out in the Mutual Indemnity Agreement, which applies to this Agreement.
11.2 The Controller shall indemnify us against Claims and Losses arising from Processing instructions that breach applicable law, from the absence of a lawful basis for Processing it directed, or from the inaccuracy or unlawful supply of Personal Data it provided.
11.3 We shall indemnify the Controller against Claims and Losses arising from a Personal Data Breach caused by our failure to implement the security measures required by Section 4, to the extent of our responsibility as Processor.
11.4 Where both Parties are responsible for the same damage, liability shall be apportioned according to each Party's share of responsibility for the event giving rise to it.
12. Limitation of Liability
12.1 Each Party's liability arising out of or related to this Agreement is subject to the limitations and exclusions of liability set out in the Enterprise Client Terms & Conditions or other principal agreement between the Parties, and any reference in that agreement to the liability of a Party means the aggregate liability of that Party under that agreement and this Agreement together.
12.2 Nothing in this Agreement limits liability that cannot lawfully be limited, including liability for death or personal injury caused by negligence, for fraud, or any penalty that applicable data-protection law requires a Party to bear itself.
12.3 Neither Party excludes liability for compensation payable to a data principal or data subject where such exclusion is prohibited by applicable data-protection law.
13. Governing Law & Dispute Resolution
13.1 This Agreement is governed by the laws of India.
13.2 Disputes are subject to the dispute-resolution mechanism, seat and courts identified in the Jurisdiction & Governing Law Notice and in the principal agreement between the Parties.
13.3 Where Processing is subject to the EU or UK General Data Protection Regulation, nothing in this Section deprives a data subject of the protection of the mandatory provisions of the law of their habitual residence, or of the right to lodge a complaint with their supervisory authority.
14. Miscellaneous
14.1 Order of precedence: In the event of conflict, this Agreement prevails over the principal agreement in respect of the Processing of Personal Data, except where the principal agreement expressly states otherwise for a specific matter.
14.2 Severability: If any provision is held invalid or unenforceable, the remainder continues in force and the invalid provision is replaced by a valid provision achieving the closest permissible result.
14.3 Variation: We may update this Agreement to reflect changes in law, in Sub-processors or in our services. Material changes will be notified through the platform or by email, and the "last updated" date will change. Where a change materially reduces the protection afforded to Personal Data, the Controller may terminate the affected service.
14.4 Notices: Notices under this Agreement are given in writing to Support@ttlmedia.in, and to the Controller at the contact details held on its account. Data-protection notices may additionally be directed to the Grievance Officer identified on the Grievance Redressal page.
14.5 No agency: Nothing in this Agreement creates a partnership, joint venture or employment relationship between the Parties.
14.6 Entire agreement: This Agreement, together with the policies it incorporates, is the entire agreement between the Parties on the subject matter of data Processing and supersedes prior understandings on that subject.
Appendix A: Authorized Sub-Processors
The Sub-processors below Process Personal Data on our behalf. The authoritative and current list, including categories of data and known onward subprocessors, is maintained on the Vendor & Subprocessor List.
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Amazon Web Services | Cloud hosting, storage and backups | India, USA, Europe |
| Cloudflare | Content delivery and DDoS protection | Global |
| Google Cloud Storage | Media storage for creator uploads | India, USA |
| Google Analytics | Web and app analytics | USA, Europe |
| SendGrid (Twilio) | Transactional email delivery | USA |
| Twilio | SMS and OTP delivery | USA, India |
| Stripe | Payment processing | USA, EU |
| PayPal | Payment processing | USA, Europe |
| Intercom | Customer support messaging | USA |
We give at least thirty (30) days' notice before adding or replacing a Sub-processor, as set out in Section 5.3.