Skip to content
CipherCruCipherCru

Menu

Data Processing Agreement

This is the agreement that governs CipherCru processing personal data on a client's behalf. It is published so you can read the commitments before you ask for a copy to sign.

Last updated 1 September 2026

This Data Processing Agreement (“DPA”) is Version 1.0. It supplements the Master Services Agreement between CipherCru Innovations Private Limited (“CipherCru”) and its client, and applies wherever CipherCru processes personal data on that client's behalf. The version below is the standard form; an executable copy naming the parties is issued as part of each engagement.

Part I: Definitions and interpretation

1. Definitions

1.1 In this DPA, the following terms have the meanings assigned below.

Applicable Data Protection Laws
All laws and regulations applicable to the processing of Personal Data under this DPA, including the Digital Personal Data Protection Act, 2023 (India) and all rules, regulations, guidelines and circulars made thereunder (“DPDP Act”); the Information Technology Act, 2000 and the SPDI Rules 2011; the General Data Protection Regulation (EU) 2016/679, as retained in UK law by the European Union (Withdrawal) Act 2018 (“UK GDPR”), where applicable; the California Consumer Privacy Act 2018 as amended by the California Privacy Rights Act 2020 (“CCPA/CPRA”), where applicable; and any other applicable national or regional data protection legislation in force from time to time, in each case as amended, updated, or replaced.
Breach Notification Period
Under the DPDP Act, as soon as reasonably practicable and within the period prescribed by the Data Protection Board of India, currently expected to be seventy-two (72) hours of CipherCru becoming aware. Under the GDPR and UK GDPR, seventy-two (72) hours of CipherCru becoming aware. Under the CCPA and CPRA, the period required by applicable state law; in California, an expedient time, generally within 72 hours of awareness for processors.
Controller
The Client, being the entity that determines the purposes and means of processing Personal Data. Under the DPDP Act, the Controller is referred to as the Data Fiduciary.
Data Principal
The individual to whom Personal Data relates, equivalent to a Data Subject under the GDPR and a Consumer under the CCPA.
Data Protection Board
The Data Protection Board of India established under the DPDP Act.
Data Subject
Has the meaning given in the GDPR and, where applicable, includes a Data Principal under the DPDP Act.
Data Subject Rights Request (DSRR)
A request by a Data Principal or Data Subject exercising rights conferred under Applicable Data Protection Laws.
EEA
The European Economic Area.
GDPR
The General Data Protection Regulation (EU) 2016/679.
Personal Data
Any information relating to an identified or identifiable natural person, including digital personal data as defined in Section 2(t) of the DPDP Act; personal data as defined in Article 4(1) GDPR; and personal information as defined in Cal. Civ. Code 1798.140(v).
Personal Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed by CipherCru in the course of performing Services.
Processing
Any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure, or destruction.
Processor
CipherCru, being the entity that processes Personal Data on behalf of and under the instructions of the Controller. Under the DPDP Act, the Processor is referred to as the Data Processor.
Sensitive Personal Data (SPD)
Personal Data revealing racial or ethnic origin, political opinions, religious beliefs, health or biometric data, financial data, sexual orientation, or other categories designated as sensitive under Applicable Data Protection Laws, including sensitive personal data or information under the SPDI Rules 2011.
Sub-Processor
Any third party engaged by CipherCru, as Processor, to carry out any Processing activities in respect of Personal Data on behalf of the Controller.
Standard Contractual Clauses (SCCs)
For EEA transfers, the standard contractual clauses approved by the European Commission under Article 46(2)(c) GDPR, as updated from time to time. For UK transfers, the UK International Data Transfer Addendum issued by the ICO. For other cross-border transfers, equivalent mechanisms as agreed between the Parties.
Technical and Organisational Measures (TOMs)
The security measures described in Schedule B, as may be updated from time to time.

2. Interpretation

2.1 This DPA supplements and is incorporated into the MSA. In the event of a conflict between this DPA and the MSA on matters of data protection, this DPA prevails.

2.2 References to processing, controller, processor, data subject, and personal data shall be construed in accordance with the relevant Applicable Data Protection Law in each context.

2.3 Schedule A (Processing Activities), Schedule B (Technical and Organisational Measures), and Schedule C (Sub-Processor List) are incorporated into and form part of this DPA.

Part II: Roles and processing scope

3. Roles of the parties

3.1 Controller. The Client is the Controller (Data Fiduciary) in respect of Personal Data processed by CipherCru under this DPA. The Client determines the purposes and means of processing.

3.2 Processor. CipherCru is the Processor (Data Processor) in respect of Personal Data processed on behalf of the Client under this DPA. CipherCru shall process Personal Data only in accordance with documented instructions from the Client.

3.3 Independent Controllers. Where the Parties each independently determine the purposes and means of processing particular Personal Data, for example CipherCru's processing of Client contact information for its own business records, each Party acts as a separate, independent Controller for its own processing activities and is responsible for compliance with Applicable Data Protection Laws in respect of those activities. This DPA does not govern such independent processing.

3.4 No Sale of Personal Data. CipherCru shall not sell, share for cross-context behavioural advertising, rent, or otherwise commercialise Personal Data processed under this DPA. CipherCru shall include equivalent obligations in all Sub-Processor agreements.

4. Processing instructions

4.1 Documented Instructions. CipherCru shall process Personal Data only on the documented instructions of the Client, including instructions given in the MSA, applicable SOW, and this DPA; as necessary to perform the Services; or as required by Applicable Data Protection Laws to which CipherCru is subject, in which case CipherCru shall inform the Client before processing, unless Applicable Law prohibits such notification.

4.2 Instruction Register. The primary processing instructions are set out in Schedule A to this DPA. The Client may issue additional written instructions from time to time. CipherCru will implement reasonable additional instructions within the timeframe agreed. If an instruction would require CipherCru to incur additional costs or is technically impracticable, CipherCru shall notify the Client and the Parties shall agree a change in scope and fee under the Change Order procedure in the MSA.

4.3 Unlawful Instructions. If CipherCru reasonably believes that an instruction from the Client infringes Applicable Data Protection Laws, CipherCru shall promptly notify the Client. CipherCru is not required to comply with instructions that would result in CipherCru violating Applicable Data Protection Laws.

4.4 Scope of Processing. The subject matter, nature, purpose, type of Personal Data, categories of Data Principals, and duration of processing are set out in Schedule A.

5. Client obligations

5.1 The Client shall, as Controller:

  1. comply with Applicable Data Protection Laws in its capacity as Controller, including ensuring there is a lawful basis for processing and that appropriate notices are provided to Data Principals;
  2. ensure that Personal Data transferred to CipherCru for processing has been collected and may be transferred in accordance with Applicable Data Protection Laws;
  3. ensure that all instructions given to CipherCru comply with Applicable Data Protection Laws;
  4. notify CipherCru in writing of any changes to applicable regulatory requirements that may affect CipherCru's processing obligations;
  5. obtain all necessary consents, authorisations, and approvals required to enable CipherCru to process Personal Data for the Purpose.

Part III: Security

6. Technical and organisational measures

6.1 Security Obligation. CipherCru shall implement and maintain appropriate Technical and Organisational Measures to protect Personal Data against accidental or unlawful destruction, loss and alteration; unauthorised disclosure or access; and all other unlawful forms of processing. The measures shall ensure a level of security appropriate to the risk, taking into account the state of the art, implementation costs, the nature, scope, context and purposes of processing, and the likelihood and severity of risks to Data Principals.

6.2 Minimum Measures. The TOMs shall include, as a minimum, the measures set out in Schedule B, and shall cover pseudonymisation and encryption of Personal Data where appropriate; the ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems; the ability to restore availability and access to Personal Data in a timely manner in the event of a physical or technical incident; and a process for regularly testing, assessing and evaluating the effectiveness of the TOMs.

6.3 Updates to TOMs. CipherCru may update the TOMs over time provided the level of security is not reduced below the minimum required by this DPA and Applicable Data Protection Laws. CipherCru shall notify the Client of any material reduction in the TOMs not less than thirty (30) calendar days in advance.

6.4 Personnel. CipherCru shall ensure that all personnel authorised to process Personal Data are subject to contractual obligations of confidentiality; limited to those who need access for the performance of the Services; and trained on data protection and security requirements applicable to their role.

7. Personal data breach

7.1 Detection and Containment. CipherCru shall maintain procedures for detecting, containing, and assessing Personal Data Breaches.

7.2 Notification to Client. CipherCru shall notify the Client of a Personal Data Breach without undue delay, and in any event within forty-eight (48) hours of becoming aware of the breach. That is ahead of the regulatory deadline, to give the Client sufficient time to make regulatory notifications if required.

7.3 Content of Notification. The breach notification shall include, to the extent available at the time of notification, a description of the nature of the Personal Data Breach, including categories and approximate number of Data Principals and Personal Data records affected; the name and contact details of CipherCru's data protection contact; a description of the likely consequences of the breach; and a description of measures taken or proposed by CipherCru to address the breach and mitigate its effects. Where full information is not available at the time of initial notification, CipherCru shall provide information in phases as it becomes available.

7.4 Assistance with Regulatory Notification. CipherCru shall provide reasonable assistance to the Client in making any required notifications to the Data Protection Board of India, supervisory authorities, or Data Principals as required by Applicable Data Protection Laws.

7.5 No Admission. Notification of a Personal Data Breach by CipherCru does not constitute an admission of liability, fault, or negligence.

7.6 Breach Record. CipherCru shall maintain an internal record of all Personal Data Breaches, including those that are not required to be notified, in accordance with applicable regulatory requirements.

Part IV: Data subject rights

8. Data subject rights assistance

8.1 Rights under the DPDP Act. The DPDP Act confers the following rights on Data Principals, which CipherCru shall assist the Client to fulfil: Section 11, the right of access, being the right to obtain a summary of Personal Data being processed and information about processing activities; Section 12, the right to correction and erasure; Section 13, the right of grievance redressal; and Section 14, the right to nominate another individual to exercise rights upon death or incapacity.

8.2 Rights under the GDPR and UK GDPR. Where the GDPR or UK GDPR applies, CipherCru shall assist the Client to fulfil the right of access (Article 15); the right to rectification (Article 16); the right to erasure (Article 17); the right to restriction of processing (Article 18); the right to data portability (Article 20); the right to object (Article 21); and rights in relation to automated decision-making and profiling (Article 22).

8.3 Rights under the CCPA and CPRA. Where the CCPA or CPRA applies, CipherCru shall assist the Client to fulfil Data Subject rights including the right to know, the right to delete, the right to correct, the right to opt out of sale or sharing, the right to limit use of sensitive personal information, and the right of no retaliation.

8.4 Mechanism for Assistance. CipherCru shall promptly forward any Data Subject Rights Request received by CipherCru directly to the Client and not respond to the request independently, except as required by law; provide the Client with reasonable technical and organisational assistance to enable the Client to respond to DSRRs within the applicable legal timeframe, being as prescribed under the DPDP Act and one calendar month from receipt under the GDPR; and make available to the Client any Personal Data held by CipherCru in respect of a DSRR within ten (10) Business Days of a written request from the Client.

8.5 Costs. Assistance under this Section 8 that goes beyond what is reasonably practicable within CipherCru's standard service delivery may be charged at CipherCru's then-current rates, provided CipherCru notifies the Client of the anticipated costs in advance and the Client approves.

Part V: Sub-processors

9. Sub-processors

9.1 General Authorisation. The Client grants a general written authorisation for CipherCru to engage Sub-Processors to assist in performing the Services, subject to the conditions in this Section 9.

9.2 Current Sub-Processors. The Sub-Processors currently engaged by CipherCru in connection with the Services are listed in Schedule C. The Client confirms awareness and acceptance of those Sub-Processors as at the Effective Date.

9.3 Changes to Sub-Processors. CipherCru shall notify the Client of any intended addition or replacement of Sub-Processors, including the name, location and nature of processing, at least fourteen (14) calendar days before the change takes effect; and shall maintain an up-to-date Sub-Processor list, accessible by the Client on request.

9.4 Client Objection. The Client may object to the engagement of a new Sub-Processor on reasonable data protection grounds by notifying CipherCru in writing within ten (10) calendar days of receiving notice under Section 9.3. CipherCru shall work in good faith with the Client to resolve the objection. If the Parties cannot reach agreement within twenty (20) calendar days of the objection notice, either Party may terminate the affected SOW on thirty (30) calendar days' written notice without liability for termination fees, provided the Client's objection is on genuine and reasonable data protection grounds.

9.5 Sub-Processor Obligations. Before engaging any Sub-Processor, CipherCru shall carry out appropriate due diligence to ensure the Sub-Processor can provide sufficient guarantees about its security measures and data protection practices; impose data protection obligations on the Sub-Processor that are equivalent in substance to those in this DPA, including in particular obligations regarding security, breach notification, and Data Subject rights; and remain fully liable to the Client for the acts and omissions of each Sub-Processor as if CipherCru had performed the processing directly.

Part VI: Cross-border transfers

10. Cross-border data transfers

10.1 India, domestic. CipherCru primarily processes Personal Data on infrastructure located in India and shall comply with the DPDP Act's cross-border transfer provisions, including any restrictions on transfer of Personal Data to countries that have not been designated as permissible by the Central Government.

10.2 GDPR and UK GDPR transfers. Where Personal Data is subject to the GDPR or UK GDPR and is transferred outside the EEA or UK, the transfer shall be made only pursuant to a decision by the European Commission or the UK Secretary of State that the destination country ensures an adequate level of protection; subject to appropriate safeguards under Article 46 GDPR or its UK equivalent, including Standard Contractual Clauses or binding corporate rules; or in reliance on a specific derogation under Article 49 GDPR where applicable.

10.3 SCCs. Where SCCs are required, the Parties shall execute the applicable SCC module as an addendum to this DPA. The appropriate module is determined by the roles of the Parties: Module 2 (controller to processor) where the Client is Controller and CipherCru is Processor, and Module 3 (processor to processor) where CipherCru transfers to a Sub-Processor.

10.4 Alternative Transfer Mechanisms. Where SCCs or other transfer mechanisms are amended, replaced, or supplemented by Applicable Data Protection Laws, the Parties shall cooperate to execute updated documentation within a reasonable timeframe and no later than the deadline prescribed by the relevant authority.

10.5 Sensitive Personal Data. CipherCru shall not transfer Sensitive Personal Data outside India without the explicit prior written consent of the Client and compliance with any additional requirements under Applicable Data Protection Laws, including the SPDI Rules 2011 and the DPDP Act as updated.

Part VII: Audits and accountability

11. Records and accountability

11.1 Processing Records. CipherCru shall maintain complete and accurate records of all processing activities carried out on behalf of the Client in accordance with Article 30(2) GDPR and equivalent requirements under the DPDP Act, including the name and contact details of CipherCru and the Client; the categories of processing carried out on behalf of the Client; transfers of Personal Data to third countries or international organisations; and a general description of the TOMs. CipherCru shall make these records available to the Client and, where required, to competent supervisory authorities on request.

11.2 Data Protection Contact. CipherCru's data protection point of contact for the purposes of this DPA is reachable at privacy@ciphercru.com.

11.3 Grievance Officer (DPDP Act). In accordance with Section 13 of the DPDP Act and Rule 4 of the IT (Intermediaries Guidelines and Digital Media Ethics Code) Rules 2021, CipherCru's Grievance Officer is reachable at privacy@ciphercru.com, at 602, The Elysian, A-31, Swej Farm Circle, Swej Farm, New Sanganer Road, Sodala, Jaipur, Rajasthan 302019, India. CipherCru shall acknowledge grievances within forty-eight (48) hours and resolve them within fifteen (15) Business Days.

12. Audit rights

12.1 Information. CipherCru shall make available to the Client, on reasonable written request of at least ten (10) Business Days' notice, all information reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Laws.

12.2 Audit. The Client, or a mutually agreed independent third-party auditor bound by confidentiality, may, no more than once per calendar year unless a Personal Data Breach has occurred or a regulatory investigation is underway, and on at least thirty (30) calendar days' written notice, conduct an audit or inspection to verify CipherCru's compliance with this DPA. Such audit shall be conducted during normal business hours and in a manner that minimises disruption to CipherCru's operations; shall not involve access to data belonging to CipherCru's other clients; shall be subject to the Client's auditors signing a confidentiality undertaking acceptable to CipherCru; and shall be at the Client's cost, unless the audit reveals a material breach of this DPA, in which case CipherCru shall bear the reasonable cost of the audit.

12.3 Certifications and Reports. In lieu of an audit under Section 12.2, CipherCru may provide the Client with current third-party audit reports, such as SOC 2 Type II or ISO 27001 certification, where such reports are available and cover the subject matter of the requested audit, provided such reports are subject to appropriate confidentiality undertakings.

12.4 Regulatory Cooperation. CipherCru shall, to the extent permitted by Applicable Law, promptly inform the Client of any inquiry, investigation, or enforcement action by any supervisory authority or data protection regulator relating to CipherCru's processing of Personal Data under this DPA, and cooperate with the Client in responding.

Part VIII: Data impact assessments and prior consultation

13. Data protection impact assessments

13.1 Where a particular type of processing is likely to result in a high risk to the rights and freedoms of Data Principals, and the Client as Controller is required to conduct a Data Protection Impact Assessment (DPIA) under GDPR Article 35 or an equivalent under Applicable Data Protection Laws, CipherCru shall provide reasonable assistance to the Client in conducting that DPIA, including by making available information about CipherCru's processing activities and TOMs.

13.2 CipherCru shall notify the Client if it becomes aware that any intended processing activity constitutes high-risk processing requiring a DPIA.

13.3 Where required by Applicable Data Protection Laws, including under GDPR Article 36, CipherCru shall assist the Client in consulting with the relevant supervisory authority prior to commencing high-risk processing.

Part IX: AI tools and automated processing

14. AI tools and automated processing

14.1 AI Tool Restrictions. Where CipherCru uses AI Tools, as defined in the MSA, in connection with the Services:

  1. CipherCru shall not input identifiable Personal Data into publicly accessible AI tools or platforms without the Client's prior written consent;
  2. where CipherCru uses enterprise-tier AI services, such as Azure OpenAI, AWS Bedrock or Google Vertex AI, CipherCru shall ensure those services are used under appropriate data processing terms with the relevant AI provider that prohibit use of Personal Data for training or improving the AI model;
  3. CipherCru shall maintain a register of AI tools used in connection with each SOW and make this available to the Client on request;
  4. CipherCru shall apply data minimisation principles, so that only the minimum Personal Data necessary for the specific AI-assisted task is processed.

14.2 Automated Decision-Making. CipherCru shall not make automated decisions that produce legal effects or similarly significantly affect Data Principals using Personal Data processed under this DPA without the prior written consent of the Client. Where the Client instructs CipherCru to implement automated decision-making, CipherCru shall disclose to the Client the logic involved; the Client as Controller remains responsible for ensuring GDPR Article 22 and equivalent DPDP Act requirements are met; and CipherCru shall implement suitable measures to safeguard Data Principal rights, including the right to obtain human intervention and to contest decisions.

14.3 Profiling. CipherCru shall not carry out profiling of Data Principals using Personal Data processed under this DPA except as expressly instructed by the Client in a SOW.

Part X: Sensitive personal data

15. Sensitive personal data

15.1 Additional Safeguards. Where the Services involve the Processing of Sensitive Personal Data, CipherCru shall:

  1. apply enhanced access controls, restricting access to those personnel who strictly need access;
  2. apply encryption in transit and at rest using industry-standard algorithms, being a minimum of AES-256 for data at rest and TLS 1.2 or later for data in transit;
  3. not share Sensitive Personal Data with Sub-Processors without specific written authorisation from the Client in addition to the general Sub-Processor authorisation in Section 9.1;
  4. apply field-level encryption or pseudonymisation to Sensitive Personal Data where technically feasible;
  5. conduct enhanced due diligence on Sub-Processors who will process Sensitive Personal Data.

15.2 Financial Data. Where the Personal Data includes financial data, including bank account details, payment card data, or tax information, CipherCru shall comply with applicable requirements under the Payment Card Industry Data Security Standard where payment card data is involved, and with RBI guidelines where applicable to Indian financial data.

15.3 Health Data. Where the Personal Data includes health or biometric data, CipherCru shall comply with any additional sector-specific requirements under Indian law, including those under the National Digital Health Mission framework or any applicable health data protection regulations.

Part XI: Return and deletion of personal data

16. Return and deletion

16.1 Upon Termination. Upon expiry or termination of the MSA or the relevant SOW, CipherCru shall, at the Client's written election made within thirty (30) calendar days of termination, either securely return to the Client all Personal Data and copies thereof in CipherCru's possession or control in a commonly used, machine-readable format; or securely delete or destroy all Personal Data and copies thereof from CipherCru's systems, including from backup systems, subject to Section 16.2.

16.2 Certification. Within twenty (20) Business Days of completing the return or deletion, CipherCru shall provide the Client with a written certificate, signed by an authorised officer of CipherCru, confirming that all Personal Data has been returned or deleted.

16.3 Retention Exceptions. CipherCru may retain Personal Data beyond the termination date to the extent required by Applicable Data Protection Laws or other mandatory legal obligations, in which case CipherCru shall notify the Client of the applicable law and the extent of the retention; or by standard automated backup retention cycles, provided such backups are subject to the same security measures and are overwritten in the ordinary course within the retention period applicable to CipherCru's backup systems. Any retained Personal Data remains subject to the obligations of this DPA until deleted.

16.4 During Engagement. CipherCru shall implement a data minimisation policy and delete or anonymise Personal Data that is no longer necessary for the performance of the Services, in accordance with the retention periods set out in Schedule A.

Part XII: Liability and indemnity

17. Liability

17.1 Liability Cap. CipherCru's total liability to the Client under or in connection with this DPA shall be subject to the liability cap set out in the MSA, save that the liability cap shall not apply to CipherCru's liability to Data Principals for damage suffered as a result of CipherCru's processing in violation of this DPA and Applicable Data Protection Laws, where applicable law provides for direct liability of a Processor; any fraud, wilful misconduct, or gross negligence by CipherCru; or any liability that cannot be limited under Applicable Law.

17.2 Regulatory Fines. Regulatory fines and penalties imposed by a supervisory authority on the Client as a result of CipherCru's breach of this DPA or Applicable Data Protection Laws are not subject to the MSA liability cap, provided the Client can demonstrate that the fine arises directly and solely from CipherCru's breach and not from the Client's own breach of its Controller obligations.

17.3 Indemnity. CipherCru shall indemnify the Client against any third-party claims, regulatory fines, costs, and damages arising directly from CipherCru's breach of this DPA, subject to the Client providing prompt written notice of any claim; the Client giving CipherCru control of the defence and settlement, not to be unreasonably exercised; and the Client not making any admission of liability without CipherCru's prior written consent.

17.4 Contributory Fault. Where a Personal Data Breach or regulatory sanction results from the acts or omissions of both Parties, each Party shall bear liability in proportion to its respective degree of fault.

Part XIII: Term

18. Term and termination

18.1 Term. This DPA takes effect on the Effective Date and remains in force for as long as CipherCru processes Personal Data on behalf of the Client under the MSA or any SOW.

18.2 Automatic Termination. This DPA terminates automatically upon the expiry or termination of the last SOW under which CipherCru processes Personal Data, subject to the survival provisions below.

18.3 Survival. The following provisions survive termination of this DPA: Section 1 (Definitions), Section 7 (Personal Data Breach, records obligation), Section 8 (Data Subject Rights, for any outstanding requests), Section 11 (Records, for the applicable statutory period), Section 12 (Audit, for outstanding audit requests), Section 16 (Return and Deletion, until complete), Section 17 (Liability), and any Schedule that specifies ongoing obligations.

Part XIV: General provisions

19. Governing law and dispute resolution

19.1 This DPA shall be governed by and construed in accordance with the laws of the Republic of India, including the DPDP Act, the IT Act 2000, and the Arbitration and Conciliation Act 1996.

19.2 The courts and arbitral tribunals at Jaipur, Rajasthan, India shall have exclusive jurisdiction over disputes under this DPA, subject to the dispute resolution process in the MSA.

19.3 International Counterparties. Where the Client is subject to the GDPR, UK GDPR, or CCPA and CPRA, nothing in this Section 19 limits any right of a competent supervisory authority to investigate or take enforcement action under those laws.

20. General

20.1 Integration. This DPA, including all Schedules, constitutes the entire data processing agreement between the Parties with respect to the processing of Personal Data under the MSA and supersedes all prior DPAs or data processing annexes between the Parties.

20.2 Order of Precedence. In the event of a conflict, the order is: SOW, then MSA, then this DPA, then CipherCru's policies. Where the conflict relates to a mandatory requirement of Applicable Data Protection Laws, the applicable law prevails.

20.3 Amendments. This DPA may only be amended by a written instrument signed by authorised representatives of both Parties, except that CipherCru may update Schedule B in accordance with Section 6.3 and Schedule C in accordance with Section 9.3.

20.4 Severability. If any provision of this DPA is found invalid or unenforceable, that provision shall be modified to the minimum extent necessary or severed, without affecting the remainder.

20.5 Regulatory Updates. If any change in Applicable Data Protection Laws renders any provision of this DPA unlawful or requires modification, the Parties shall in good faith negotiate updated provisions within sixty (60) calendar days of the change coming into force. In the interim, CipherCru shall comply with the updated legal requirements.

20.6 Electronic Execution. This DPA may be executed electronically, including by PDF signature or DocuSign, in counterparts. The executable copy, naming the parties and carrying the signature blocks, is issued as part of each engagement rather than published here.


Schedule A: Details of processing activities

Schedule A is completed and attached when each SOW is executed, because its content is specific to that engagement. These are the fields it records.

Subject matter of processing
What the processing is for, described concretely; for example the development and maintenance of a customer-facing web application that stores and processes end-user registration and transactional data.
Duration of processing
The term of the applicable SOW plus any post-termination retention period.
Nature and purpose of processing
The activities involved; for example development, testing, deployment and maintenance of software systems, data migration, integration with third-party APIs, and analytics and reporting.
Type of Personal Data
The categories in scope; for example contact data, account data, transaction data, device and usage data, location data, financial data or health data.
Categories of Data Principals
Whose data is processed; for example end-users or customers of the Client, employees of the Client, business partners, or suppliers.
Retention period
How long the data is kept; for example the duration of the Services plus a stated number of months, or as specified in the Client's own data retention policy.
Processing locations
Primary processing is on CipherCru infrastructure in India. Sub-Processor locations are listed separately, by country.
Lawful basis
The basis relied on under the GDPR, such as Article 6(1)(b) or 6(1)(f), and under the DPDP Act, such as consent under Section 6 or a legitimate use under Section 7, as specified by the Client.
Sensitive Personal Data involved
Yes or no. If yes, the categories and the additional authorisation required under Part X.
Automated decision-making
Yes or no. If yes, the detail, and confirmation of Article 22 and DPDP Act compliance.

Schedule B: Technical and organisational measures

B.1 Access control

Access control measures and how each is implemented
MeasureImplementation
Role-based access controlImplemented. Access to Personal Data restricted to roles with operational need
Principle of least privilegeAll access rights scoped to minimum necessary for the specific task
Multi-factor authenticationRequired for all access to production systems and repositories containing Personal Data
Privileged access managementPrivileged accounts logged, monitored, and reviewed quarterly
Access reviewsAccess rights reviewed at least annually and upon change of role or termination

B.2 Encryption and data protection

Encryption and data protection measures
MeasureImplementation
Encryption at restAES-256 or equivalent for all Personal Data stored in databases and file systems
Encryption in transitTLS 1.2 minimum, TLS 1.3 preferred, for all data transmission
Key managementEncryption keys managed separately from encrypted data; hardware security modules used where available
PseudonymisationApplied where technically feasible and operationally appropriate
Data maskingSensitive fields masked in non-production environments

B.3 Network and infrastructure security

Network and infrastructure security measures
MeasureImplementation
Firewall and network segmentationProduction environments isolated from development; ingress and egress rules enforced
Intrusion detection and preventionIDS and IPS monitoring on production infrastructure
DDoS protectionCloud-native DDoS protection enabled on internet-facing services
Vulnerability managementRegular vulnerability scanning; critical patches applied within 72 hours, high severity within 14 days
Penetration testingAt least annually for production systems; results remediated per severity

B.4 Incident response

Incident response measures
MeasureImplementation
Incident response planDocumented and tested at least annually
Breach detectionSIEM and logging solution for anomaly detection on systems processing Personal Data
Breach notification48-hour internal escalation procedure aligned with Section 7 of this DPA
Post-incident reviewRoot-cause analysis conducted after every significant incident

B.5 Organisational measures

Organisational measures
MeasureImplementation
Data protection trainingAll personnel handling Personal Data trained at onboarding and annually thereafter
Confidentiality obligationsAll personnel subject to contractual confidentiality and non-disclosure obligations
Vendor due diligenceSub-Processors assessed against security and data protection criteria before engagement
Data minimisationPersonal Data collected and processed limited to what is strictly necessary for the Purpose
Data retention policyPersonal Data deleted or anonymised upon expiry of the retention period in Schedule A
Backup and recoveryRegular encrypted backups; recovery tested at least quarterly

B.6 Physical security

Physical security measures
MeasureImplementation
Data centrePersonal Data hosted in certified data centres, with ISO 27001 or SOC 2 certified providers preferred, with physical access controls including badge, biometric, CCTV and visitor log
Office securityOffices with access controls; clean desk policy; locked storage for physical documents containing Personal Data
Device securityEndpoint encryption using BitLocker or FileVault; remote-wipe capability for mobile devices

Schedule C: Approved sub-processors

Current as at the Effective Date. CipherCru updates this list in accordance with Section 9.3 of this DPA.

C.1 Infrastructure and cloud

Infrastructure and cloud sub-processors
Sub-processorLocationPurposeSafeguards
Amazon Web ServicesIndia (ap-south-1), USA, EUCloud hosting, compute, storage, managed databasesAWS DPA; SCCs (EU); AWS Customer Agreement
Microsoft AzureIndia, USA, EUCloud services, Azure OpenAI where applicableMicrosoft DPA; SCCs (EU); GDPR commitments
Google Cloud PlatformIndia, USA, EUCloud hosting, Vertex AI where applicableGoogle DPA; SCCs (EU); GDPR commitments
CloudflareGlobal (edge)CDN, DDoS protection, WAF, DNSCloudflare DPA; SCCs (EU)

C.2 Development and collaboration

Development and collaboration sub-processors
Sub-processorLocationPurposeSafeguards
GitHub (Microsoft)USASource code repository, CI/CD pipelinesGitHub DPA; SCCs (EU)
Atlassian (Jira, Confluence)USA, AustraliaProject management, issue trackingAtlassian DPA; SCCs (EU)
SlackUSATeam communication, which may contain Personal Data referencesSlack DPA; SCCs (EU)

C.3 Monitoring and observability

Monitoring and observability sub-processors
Sub-processorLocationPurposeSafeguards
DatadogUSA, EUApplication performance monitoring, loggingDatadog DPA; SCCs (EU)
SentryUSAError tracking and crash reportingSentry DPA; SCCs (EU)
PagerDutyUSAIncident alertingPagerDuty DPA

C.4 Communication

Communication sub-processors
Sub-processorLocationPurposeSafeguards
Google WorkspaceUSA, EUEmail and internal documents, which may contain Client Personal Data referencesGoogle Workspace DPA; SCCs (EU)
ZohoIndia, USACRM, business communicationsZoho DPA; DPDP Act compliant

AI tool sub-processors, such as OpenAI, Anthropic and Google DeepMind, are engaged on a project-specific basis. They are listed in the applicable SOW schedule for internal frameworks and AI tools, and notified under Section 9.3 of this DPA.

Schedule D: Cross-border transfer mechanisms

Transfer mechanism applied to each cross-border route
Transfer routeMechanismApplicable module or addendum
India to EEA or UK, for Personal Data of EU or UK Data SubjectsStandard Contractual Clauses (EU Commission SCCs 2021) plus UK IDTASCC Module 2 (controller to processor) where CipherCru acts as Processor
India to USA, for sub-processorsSCCs (Module 3, processor to sub-processor) or applicable adequacy or transfer mechanismConfirmed per sub-processor
Within IndiaNo cross-border transfer mechanism required, being domestic processingDPDP Act compliance
India to other destinations, where applicableAgreed in writing and documented per SOWAs negotiated

Strictly necessaryEssential for the site to function: page navigation, security, session management, and remembering the cookie choices you make here.
Always on
FunctionalRemembers choices you make, such as language, region or display preferences, so the site opens the way you left it.
Performance and analyticsPerformance and analytics cookies show us how the Website is used: which pages are visited, how long is spent on them, where visitors came from, and what errors occur. They are set by Google Analytics and by HubSpot, whose cookies also link the pages you viewed to any enquiry you later send us.
Marketing and targetingTracks browsing activity to measure advertising and show relevant ads. We set none of these today, and will not without your opt-in.