Vendor and Processing Schedule
This schedule supplements the Privacy Policy. It identifies the third-party infrastructure processors SACAR relies on, the purpose of each processing activity, the categories of data elements handled, and the technical safeguards enforced, in alignment with global and regional data-protection frameworks including India’s Digital Personal Data Protection Act.
1Master data-processor matrix
| Entity and contact | Purpose of processing | Categories of data elements | Processing and storage location |
|---|---|---|---|
| Google LLC and its authorised affiliates. Contact: Google Cloud Data Protection Team, via a data-privacy-officer enquiry. | Hosting cloud infrastructure, processing form submissions and surveys, and database storage through Google Forms and Google Workspace services. | Data subjects: website visitors, registered users, leads and form respondents. Data types: identification details (name, email address, telephone number) and any custom textual data provided voluntarily within form fields. | Global infrastructure: personal data may be transferred to and processed across Google’s global network of data centres, including the United States, Europe and Asia. Verified against Google Cloud’s data-centre locations and its third-party sub-processor registry. |
No other processor receives personal data collected through this website. Where one is added, this schedule is updated before the processing begins.
2Technical, organisational and security measures
Pursuant to Google’s standard Data Processing Addendum and to architectural assessment, the processing environment maintains the following security and compliance baselines:
- Security certifications and external audits: the infrastructure undergoes independent verification and maintains active certification under ISO/IEC 27001, together with SOC 3 evaluation reports.
- Encryption standards: data is protected by cryptographic protocols — encryption in transit (HTTPS/TLS) during transmission over public networks, and encryption at rest within physical storage.
- Privacy frameworks: the processor adheres to international standard safeguards, including the Data Privacy Framework mechanism for cross-border transfers, and to strict internal access-control limitations.
3Data transfer and representative information
For users located in regions requiring local representation, or where operations cross jurisdictions outside established locales, structural enquiries and localised privacy mandates are routed through Google’s designated privacy representatives where statutory rules apply.