TouchTargets is a product of AGR Group, a proprietorship of Mukkara Rakesh Kumar Reddy, India.
GSTIN 37CPJPR8041G2ZH.
NO.28-5-711, LG 182, HOUSING BOARD COLONY, Anantapur Head Post Office, Hamali Colony, Ananthapuramu, Ananthapuramu, Andhra Pradesh, 515001
India
This DPA sits alongside our
Terms of Service and Privacy Policy, and reads together with our
Sub-processors page (which it incorporates by reference).
This Data Processing Agreement ("DPA") forms part of the agreement between AGR Group, a proprietorship of Mukkara Rakesh Kumar Reddy, India, of
NO.28-5-711, LG 182, HOUSING BOARD COLONY, Anantapur Head Post Office, Hamali Colony, Ananthapuramu, Ananthapuramu, Andhra Pradesh, 515001 ("TouchTargets", "Processor", "we") and the business that has agreed to our
Terms of Service ("Client", "Controller", "you"), for personal data Client submits to, or has
processed by, the Service (app.touchtargets.com) that is subject to the EU General Data Protection Regulation
("GDPR") and/or the UK GDPR.
This DPA applies only where Client is itself a controller of personal data under GDPR/UK GDPR and TouchTargets
processes that personal data on Client’s behalf as described below (for example, personal data appearing in
crawled site content, in Search Console/GA4 query data, or in business profile content). It does not change how
TouchTargets and Client’s own account/billing data is handled — that is described in the Privacy Policy, where
TouchTargets is itself the controller.
1. Subject matter, duration and nature of processing
- Subject matter: provision of the Service — website auditing, search/analytics reporting, AI-assisted
explanations and recommendations, and (subject to Client’s approval) applying approved changes. - Duration: for as long as Client’s workspace remains active, plus the retention/export/deletion periods in
section 8 of the Privacy Policy and section 6 of this DPA. - Nature and purpose: automated reading of Client-connected data sources and Client’s own public website;
storage, analysis and reporting on that data; generation of AI-assisted outputs; execution of Client-approved
actions. Never used to train any AI/ML model (Privacy Policy, section 3).
2. Categories of data subjects and personal data
- Data subjects: Client’s own website visitors and search users (to the extent identifiable in query/page
data), individuals named in crawled page content (e.g. staff bios, testimonials, reviews), and individuals
Client’s own team invites into the workspace. - Categories of personal data: names, contact details and other personal data that may appear in crawled
public page content, Search Console query text, GA4 event data, or business-brain content Client enters. No
special category data is knowingly processed; Client must not submit special category data to the Service.
3. Controller and processor roles
- Client is the controller (or, for the DPDP Act, "Data Fiduciary") for personal data described in section 2.
- TouchTargets is the processor ("Data Processor") and processes that personal data only on Client’s
documented instructions, being: providing the Service as described in the Terms of Service, this DPA and the
Privacy Policy, and any further written instruction Client gives through the app (for example, an approved
action). TouchTargets will inform Client if, in its opinion, an instruction infringes GDPR/UK GDPR or another
applicable data protection law.
4. Sub-processors
- Client gives TouchTargets general written authorisation to engage the sub-processors listed on the
Sub-processors page, which forms part of this DPA. - TouchTargets will update that page and give Client at least 30 days’ notice by email before adding or
replacing a sub-processor that will process personal data under this DPA (Privacy Policy, section 5; Sub-
processors page, "Changes"). Client may object on reasonable data-protection grounds within that period; if the
parties cannot resolve the objection, Client may terminate the affected part of the Service without penalty
(subject to any minimum term already running under the Terms of Service). - TouchTargets imposes data protection terms on each sub-processor that are no less protective than this DPA, and
remains liable to Client for a sub-processor’s performance of its data protection obligations.
5. Security measures
TouchTargets implements appropriate technical and organisational measures, including:
- encryption in transit (TLS) for all Service traffic;
- encrypted storage for connector credentials (Laravel’s own encrypted casts; never stored or logged in plain
text); - workspace-level data isolation enforced at the application and database layer (every client-owned table is
scoped to its own workspace; cross-workspace access is tested for automatically); - role-based access control (owner/member/viewer) and an audit log of actions taken by staff and by the Service, with
before/after state; - a crawler that only ever reads a Client’s site after domain-ownership verification, identifies itself, and
obeys robots.txt; - restricted internal access to production systems and credentials; secrets are never committed to source
control.
6. Assistance with data subject rights and deletion on termination
- TouchTargets will give Client reasonable assistance (through the app’s own self-serve tools where available, or
on request) to respond to a data subject request (access, rectification, erasure, restriction, portability or
objection) concerning personal data TouchTargets processes on Client’s behalf. - On termination of the Service (however caused), TouchTargets will, at Client’s choice, delete or return all
personal data processed under this DPA within the timelines in Privacy Policy section 6 (data stays available
for export for 30 days after cancellation, then is deleted; backups roll off within 35 days), except data
TouchTargets must keep under applicable law (e.g. billing records).
7. Breach notification
TouchTargets will notify Client without undue delay, and in any case within 72 hours of becoming aware, after
confirming a personal data breach affecting personal data processed under this DPA, with the information
reasonably available at the time (nature of the breach, categories and approximate number of data subjects and
records affected, likely consequences, and measures taken or proposed). TouchTargets will cooperate with Client
and provide further information as it becomes available.
8. Audits
On reasonable written notice (at least 30 days, no more than once per 12 months, subject to confidentiality),
TouchTargets will make available the information reasonably necessary to demonstrate compliance with this DPA and
allow for, and contribute to, an audit conducted by Client or an auditor Client mandates, at Client’s cost.
TouchTargets may instead provide a recent third-party audit report or certification covering the relevant
controls, where one exists.
9. International transfers
Personal data processed under this DPA may be transferred to and processed in India, the United States and other
countries where TouchTargets or a sub-processor operates (see the Sub-processors page). For a transfer of
personal data protected by the GDPR out of the EEA, the parties rely on the European Commission’s Standard
Contractual Clauses (controller-to-processor module); for a transfer protected by the UK GDPR, the parties rely on
the UK International Data Transfer Addendum to those Clauses. [Insert executed SCC/Addendum reference or annex
once reviewed by counsel.]
10. EU/UK representative
Where required by Article 27 GDPR or Article 27 UK GDPR, TouchTargets’ representative is named on the Privacy
Policy, shown only once one is appointed — TouchTargets has no EU/UK establishment and, as of
this document, has not yet appointed a representative because it has no EU/UK client workspace.
11. Order of precedence
If there is a conflict between this DPA and the Terms of Service or Privacy Policy on a data protection point,
this DPA prevails for personal data within its scope (section 1). Otherwise, the Terms of Service govern.
Contact
AGR Group
NO.28-5-711, LG 182, HOUSING BOARD COLONY, Anantapur Head Post Office, Hamali Colony, Ananthapuramu, Ananthapuramu, Andhra Pradesh, 515001
India
[email protected]
Company details
AGR Group (Mukkara Rakesh Kumar Reddy, proprietor)
NO.28-5-711, LG 182, HOUSING BOARD COLONY, Anantapur Head Post Office, Hamali Colony, Ananthapuramu, Ananthapuramu, Andhra Pradesh, 515001
India
GSTIN 37CPJPR8041G2ZH
[email protected]
Approved by Mukkara Rakesh Kumar Reddy, Proprietor, AGR Group, 7 Oct 2026