01Scope and roles
1.1This Addendum forms part of the Atrium terms of service between Sehsaa Solutions Private Limited ("Sehsaa") and the customer ("you"), and applies whenever Sehsaa processes personal data on your behalf in providing Atrium.
1.2Terms used here have the meaning given in India's Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. "Personal data", "Data Principal", "Data Fiduciary", "Data Processor" and "personal data breach" carry their statutory meanings.
1.3You are the Data Fiduciary. Sehsaa is your Data Processor. You decide what personal data goes into Atrium, for what purpose, and on what basis. We hold and process it for you and for no purpose of our own.
1.4This Addendum is the "valid contract" required by section 8(2) of the Act before a Data Fiduciary may involve a Data Processor.
1.5Sehsaa is separately a Data Fiduciary in its own right for the personal data of your account owners and staff that it collects to run the commercial relationship — names, work email addresses, mobile numbers, billing details, sign-in records. That processing is not governed by this Addendum; it is described in the Privacy notice, section 3.
1.6Where you are subject to a data protection law of another country as well as India's, tell us before you sign. We will not silently take on obligations under a regime we have not read.
02Our instructions
2.1Sehsaa will process personal data only on your documented instructions, including as regards transfers, unless required to do otherwise by Indian law. Where a law compels us, we will tell you before processing unless that law forbids it.
2.2Your documented instructions are: the Atrium terms of service, this Addendum, the configuration choices you make inside the product, and any further written instruction you give us (an email from an account owner counts).
2.3Using the product is itself an instruction. Creating a booking instructs us to store it; enabling a WhatsApp reminder instructs us to send it; switching on visitor photograph capture instructs us to store photographs.
2.4Sehsaa will not: sell personal data; use it for its own marketing; share it for anyone's advertising; use it to train machine learning models; or use it to build any product or dataset other than your workspace.
2.5If we believe an instruction breaches the Act, we will tell you promptly and may pause that processing until it is resolved. We are not obliged to make a legal determination about your processing, and telling you does not make us responsible for your basis.
2.6An instruction that requires material work outside the ordinary operation of Atrium — a bespoke extract, a bulk transformation, an unusual retention rule — may be chargeable at our standard rates, agreed in writing first.
03Your obligations
3.1You warrant that you have a lawful basis under the Act for every category of personal data you put into Atrium, and that you have given the affected Data Principals the notice section 5 of the Act requires.
3.2That includes the parts of Atrium that are optional and intrusive. If you switch on visitor photograph capture, or you upload identity or address documents for members, you are the one who owes those people a notice and a basis. Atrium requires neither feature to work.
3.3You are responsible for the accuracy of the personal data you enter, for who you give staff logins to, and for removing access when someone leaves.
3.4You will not put into Atrium any category of data it is not built for — health records, biometric templates, financial account credentials, card numbers — and you will not use free-text fields to store data you would not put in a labelled field.
3.5You will set a retention period appropriate for each category of data you hold, and tell us if you want us to enforce one. Atrium does not delete your records on its own initiative, and we will not decide for you what should go.
04Our people
4.1Access to personal data processed under this Addendum is limited to those Sehsaa personnel who need it to provide or support the service.
4.2Those personnel are bound by written confidentiality obligations that survive the end of their engagement.
4.3Support access to a customer workspace is through an audited route in our platform console which records the person, the workspace, the time and the stated reason. That record is written server-side and cannot be edited from within the product. We will produce the entries for your workspace on request.
4.4We will say plainly what we can and cannot claim: Sehsaa is a small company, our engineering and support are performed by a small number of named people, and separation of duties between them is limited by that fact. We compensate with the audit trail in 4.3 rather than by pretending to a structure we do not have.
05Security
5.1Sehsaa will implement and maintain reasonable technical and organisational security safeguards to prevent a personal data breach, as section 8(5) of the Act requires. The measures in force are listed in Annexure B, which forms part of this Addendum.
5.2We may change a measure, but not so as to materially reduce the overall level of security. Annexure B is kept current.
5.3Sehsaa holds no ISO 27001, SOC 2 or comparable certification and does not represent that it does. Any statement to the contrary from any source is unauthorised.
06Sub-processors
6.1You give general authorisation for Sehsaa to engage sub-processors. The current list is Annexure C, and it is the complete list — there are no unnamed sub-processors and no category of "affiliates and service providers" doing unspecified work.
6.2Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this Addendum, so far as they apply to what that sub-processor does.
6.3Sehsaa remains fully liable to you for the acts and omissions of its sub-processors, as if they were its own.
6.4We will give you at least thirty days' written notice before adding or replacing a sub-processor that will process your personal data. Notice goes to the email addresses of your account owners.
6.5You may object on reasonable data protection grounds within those thirty days. We will work with you to find a way round it. If there is none, you may terminate the affected part of the service, or the subscription, and receive a refund of the unused prepaid period; that is your exclusive remedy for the objection.
6.6Sehsaa may replace a sub-processor immediately where the existing one has become a security or availability risk and waiting would harm you. We will tell you as soon as we have done it and why.
07Requests from Data Principals
7.1Atrium gives you the tools to answer most requests yourself: everything about a member, a guest, a visitor or a lead is visible, editable and deletable inside your workspace, and exportable from it.
7.2If a Data Principal contacts Sehsaa directly about data in your workspace, we will not answer the substance ourselves. We will tell them we are the processor, tell them who you are, and forward the request to your account owners within three working days. We will tell them we have done that.
7.3Where you cannot fulfil a request with the tools in the product, we will help — including by making a change or an extract on your written instruction. We will do so within seven working days of a clear instruction, or sooner if your own statutory clock requires it and you tell us so.
7.4Sehsaa will not correct, erase or disclose personal data in your workspace on the request of a Data Principal without your instruction, except where Indian law compels it. That restraint is deliberate: acting on an unverified request would be the more dangerous failure.
08Personal data breach
8.1Sehsaa will notify you without undue delay, and in any event within 24 hours of becoming aware of a personal data breach affecting personal data processed on your behalf.
8.2The notification will describe, so far as we know it at the time: the nature and extent of the breach, when and where it happened, the categories and approximate number of Data Principals and records involved, its likely consequences, and what we are doing about it. We will not delay a first notification in order to make it complete, and we will keep updating you.
8.3Sehsaa will give you reasonable assistance in making the intimations the Act requires of you as Data Fiduciary — to affected Data Principals and to the Data Protection Board of India, including the detailed report due to the Board within 72 hours.
8.4Sehsaa will not notify a regulator or a Data Principal about a breach in your workspace on your behalf or in your name without your instruction, except where the law requires us to notify in our own right.
8.5Notification of a breach is not an admission of fault by either of us.
09Other assistance
9.1Taking into account the nature of the processing and what is available to us, Sehsaa will give you reasonable assistance with your own compliance obligations under the Act — including security, breach handling, and any assessment or consultation you are required to carry out.
9.2We will answer a security or privacy questionnaire honestly and in reasonable time, including where the honest answer is that we do not do the thing being asked about.
9.3Assistance under this clause is included at no charge to a reasonable extent. Sustained or unusual demands may be chargeable at our standard rates, agreed in writing first.
10Transfers outside India
10.1Personal data processed under this Addendum is stored in India, in DigitalOcean's Bangalore region. Databases, uploaded files and backups are all held there.
10.2Two flows leave India, and both are named rather than generalised:
- WhatsApp messages. A message you send to a member or visitor travels over Meta's WhatsApp Business Platform, which is outside India. The recipient's phone number and the content of the message go with it. This is inherent in using WhatsApp at all.
- Web fonts. Loading the Atrium web app fetches two typefaces from Google's servers outside India, which discloses the loading device's IP address and user agent to Google. No account or member data is sent.
10.3Section 16 of the Act permits transfer outside India except to a country the Central Government notifies as restricted. No such notification has been made as at the date of this Addendum. If one is made and it affects a flow above, Sehsaa will change the arrangement to comply, and will tell you what changed.
10.4If a sector-specific localisation requirement applies to you — for instance a Reserve Bank of India direction on payment data — tell us. Payment data is held by the payment provider, who is the regulated entity for it, not by Atrium.
10.5Sehsaa does not host, mirror or replicate customer databases outside India, and will not begin to without giving notice under clause 6.4.
11Audit and evidence
11.1Sehsaa will make available the information reasonably necessary to demonstrate compliance with this Addendum, and will respond to reasonable written questions about its processing.
11.2You may audit Sehsaa's compliance once in any twelve-month period, on thirty days' written notice, during business hours, without unreasonable disruption, and subject to confidentiality. You may audit more often where a regulator requires it or following a breach affecting your data.
11.3An audit may be carried out by you or by an independent auditor you appoint, who must not be a competitor of Sehsaa. You bear the cost of the audit; we bear the cost of our own time up to two working days per audit.
11.4An audit does not extend to other customers' data, to our source code, or to physical access to a data centre we do not own. For our hosting provider's controls we will pass on the certifications and reports they publish.
11.5We will produce, on request and within seven working days: the audited support-access log for your workspace, a written description of any change to Annexure B since you signed, and confirmation of the date and completeness of a deletion under clause 12.
12Return and deletion
12.1You can require an export of personal data processed on your behalf at any time. Clause 10 of the terms of service governs how and how fast.
12.2On the end of the subscription, your workspace remains available read-only for thirty days so you can take a final export. We then delete the workspace database and your uploaded files.
12.3Copies persisting in encrypted backups are overwritten as those backups roll off, within ninety days of deletion. Until then they remain subject to this Addendum and are not accessed for any purpose other than restoring the service.
12.4On written request Sehsaa will certify in writing when deletion is complete.
12.5Sehsaa will delete specific records on your written instruction at any time during the subscription.
12.6Sehsaa retains its own invoices and accounting records relating to your subscription for as long as Indian tax and company law requires. Those are Sehsaa's records as a Data Fiduciary in its own right, not personal data processed on your behalf.
13Liability and precedence
13.1Liability under this Addendum is subject to the limitations and exclusions in clause 18 of the terms of service, and the cap there applies to both documents taken together rather than to each separately.
13.2Where this Addendum and the terms of service conflict on the processing of personal data, this Addendum prevails. On everything else, the terms of service prevail.
13.3A signed order form or negotiated agreement between us prevails over both, to the extent of the conflict.
14Duration
14.1This Addendum takes effect when the Atrium terms of service take effect, and continues for as long as Sehsaa processes personal data on your behalf.
14.2Clauses 4, 5, 8, 11, 12 and 13 survive its end for as long as Sehsaa holds any personal data processed on your behalf, including in backups.
14.3If you need a signed counterpart, or your counsel needs changes, write to contact@sehsaa.com. We would rather negotiate a document we can keep than sign one we cannot.
The processing, described
This is the schedule a reviewer checks against. It describes what Atrium does as delivered; your own configuration decides which rows actually apply to you.
| Subject matter | Provision of the Atrium coworking management service to the customer. |
| Duration | The term of the subscription, plus the thirty-day export window and the ninety-day backup roll-off described in clause 12. |
| Nature of the processing | Collection, structuring, storage, retrieval, display, transmission, backup, restoration and erasure. Transmission of notifications over WhatsApp where the customer configures them. Transmission of payment instructions where the customer enables a payment provider. |
| Purpose | Operating the customer's coworking space: desk and room inventory, bookings, membership agreements, invoicing and payment, visitor entry, day passes, sales leads, notifications and reporting. |
| Categories of Data Principal | The customer's staff users; individuals at the customer's member companies; guests named on a booking; day-pass holders; visitors recorded at the front desk; sales leads and prospects. |
| Types of personal data | Name; work and personal email address; mobile and landline number; company name and role; billing and correspondence address; PAN of a member company; the seats and rooms a person occupies or books, and when; invoice, payment and outstanding-balance records; bank name recorded against a payment; visitor arrival and departure times and who they came to see; free-text notes recorded by the customer's staff; documents the customer chooses to upload against a member or agreement; staff sign-in records including IP address and timestamp; audit records of who changed what and when. |
| Data of a sensitive character | Atrium does not require any special category of data. Two optional features can introduce data of a sensitive character if the customer switches them on: photographs of visitors captured at the entry form, and identity or address documents uploaded as attachments. Both are the customer's decision and the customer's responsibility under clause 3.2. Atrium never stores card numbers. |
| Frequency | Continuous, for as long as the service is in use. |
| Storage location | India — DigitalOcean, Bangalore (BLR1). See clause 10 for the two flows that leave India. |
| Retention | Set by the customer. Sehsaa does not delete customer records on its own initiative. On termination, clause 12 applies. |
Security measures in force
Stated specifically, because a list of adjectives is not a control. Each of these is either true today or it is not on this list.
Separation
- Each customer's data is held in its own database with its own credentials, not in shared tables filtered by a tenant column. A query cannot cross a workspace boundary by accident.
- Access within a workspace is restricted by role permission and by branch scope, enforced on the server on every request rather than in the browser.
Authentication
- Sign-in is by a six-digit code delivered to the user's WhatsApp number, plus a personal PIN.
- Codes are stored as a SHA-256 hash and never in clear text, so a stolen database cannot be replayed to sign in.
- Codes expire after ten minutes, are limited to five attempts, and any earlier unused code is retired the moment a new one is issued.
- Session tokens are short-lived and are re-issued rather than extended.
In transit and at rest
- All traffic to the site, the app and the API is over HTTPS; the servers do not serve the application over plain HTTP.
- Database credentials and third-party API keys are held in a root-only configuration file on the server, never in the application repository.
- Payment provider secrets stored for a customer are held encrypted, and the only credential ever returned to a browser is the public key the payment provider's own checkout script requires.
Backup and recovery
- Databases are backed up daily. Each backup is verified for integrity when it is written.
- The backup of configuration secrets is encrypted with AES-256 before it is stored, and any unencrypted copy is securely shredded.
- Backups are retained for ninety days and then deleted.
- Restoration from backup has been rehearsed, not merely designed.
Access and accountability
- Support access to a customer workspace is through an audited impersonation route that records the person, the workspace, the time and the stated reason.
- Sign-in attempts are recorded with IP address and timestamp.
- Changes to customer records are recorded in an audit trail within the workspace.
- Administrative access to the server is by SSH key only.
Application security
- All database access is through parameterised statements; user input is never concatenated into SQL.
- Sort and filter parameters are checked against allowlists rather than passed through.
- Records are soft-deleted, so an accidental deletion inside the product is recoverable without a restore.
- Public forms are rate-limited.
- Payment webhooks are verified by signature, and the workspace a payment belongs to is determined from our own records rather than from anything in the incoming request.
What we do not have
- No ISO 27001, SOC 2 or comparable certification.
- No 24×7 staffed security operations centre.
- No formal separation of duties between engineering and operations; see clause 4.4.
- No offsite replication of backups to a second provider at present. Backups are held on encrypted storage in the same region as the service. confirm before signing a contract that relies on this
Sub-processors
The complete list as at the date of this Addendum. Changes are notified under clause 6.4.
| Sub-processor | What it does | Where |
|---|---|---|
| DigitalOcean | Hosting: the server, disk and database on which Atrium runs. Holds all customer data at rest. | Bangalore, India |
| Fast2SMSfast2sms.com | Delivery of WhatsApp messages: sign-in codes, booking confirmations, invoice and payment reminders. Receives the recipient's phone number and the message content. | India |
| Meta Platforms | Operates the WhatsApp Business Platform over which those messages travel to the recipient's device. Onward recipient from Fast2SMS; inherent in sending anything on WhatsApp. | Outside India |
| Razorpay | Collection of invoice payments by card, UPI and netbanking, under the customer's own Razorpay account. Receives the payer's name, contact details and amount. Engaged only if the customer enables it. Card details pass from the payer's browser to Razorpay directly and never reach Atrium. | India |
| GoogleGoogle Fonts | Serves two typefaces to the Atrium web app and the public website. Receives the loading device's IP address and user agent. No account or member data is sent. No Google analytics or advertising product is used. | Outside India |
There are no others. Sehsaa uses no analytics provider, no advertising network, no email marketing platform, no customer data platform, no session recording tool and no third-party support desk that would receive personal data.
Separately, Sehsaa uses its own Razorpay merchant account to collect payment of the Atrium subscription when the customer pays Sehsaa's invoices online. That is Sehsaa acting for itself as the seller, not processing on the customer's behalf, so it is not a sub-processor under this Addendum; it is described in section 6 of the Privacy notice.