Data Processing Addendum
For clients whose own customers' personal data passes through software we host. This forms part of your agreement with us.
Last updated
Roles
Where we host or operate software for you, you are the Controller (Data Fiduciary) and we are the Processor (Data Processor). You decide why and how personal data is processed; we act only on your documented instructions.
This addendum applies automatically to hosted engagements and forms part of the Terms of Service. A separately signed DPA is available on request and is required for most enterprise procurement.
Our obligations as processor
- Process personal data only on your documented instructions, including on international transfers, unless legally required otherwise — in which case we will tell you first unless the law forbids it.
- Ensure personnel with access are bound by confidentiality.
- Implement appropriate technical and organisational measures, as set out in Security below.
- Not engage a sub-processor without your general written authorisation, and give you at least 30 days' notice of any addition so you can object.
- Assist you in responding to data subject rights requests, and in your data protection impact assessments and breach notifications.
- Notify you without undue delay, and in any event within 48 hours, of becoming aware of a personal data breach.
- On termination, delete or return personal data at your choice, subject to legal retention obligations.
- Make available the information needed to demonstrate compliance, and allow audits no more than once a year unless a breach or regulator requires otherwise.
Security measures
- Encryption in transit (TLS 1.2 or higher) and at rest.
- Role-based access control with least privilege, reviewed on personnel changes.
- Separation of production and development environments; production data is never copied into development unmasked.
- Automated encrypted backups with tested restore procedures.
- Audit logging of access to personal data.
- Dependency scanning and a defined patching cadence.
- Secrets held in managed secret storage, never in source control.
Sub-processors
Our current sub-processors are listed in the Privacy Policy. We remain fully liable to you for their performance.
International transfers
We operate from India. Where you are in the EEA or UK, transfers rely on the Standard Contractual Clauses (with the UK Addendum where applicable), incorporated into this addendum by reference.
Where you require data residency in a specific region, we will host in that region. Say so before the engagement starts, because it affects architecture and cost.
Liability
Liability under this addendum is subject to the limitations in the Terms of Service, except where applicable data protection law does not permit that limitation.