Data Processing Addendum (Template)
This Data Processing Addendum (“DPA”) is entered into by DarkMatter Technologies (“Processor”) and [CUSTOMER LEGAL NAME] (“Controller”) under the applicable Statement of Work or services agreement (“Main Agreement”). DarkMatter Technologies Pvt. Ltd. is the preferred future legal name and is not represented as registered until government registration is complete. This DPA applies only to personal data processed by Processor on Controller's documented instructions in connection with the services.
1. Definitions and roles
“Personal Data”, “Process”, “Controller”, “Processor”, “Data Subject”, “Subprocessor”, and “Security Incident” have the meanings given by applicable data-protection law. The parties will identify a different role allocation if the law or the service requires it.
2. Instructions and purposes
Processor will process Personal Data only to provide, secure, support, and improve the contracted services as documented in the Main Agreement, SOW, or written instructions. Processor will not sell the Personal Data or use it for an unrelated purpose. Controller is responsible for the lawfulness of the data, notices, permissions, and instructions.
3. Confidentiality and access
Processor will ensure that people authorized to process Personal Data are bound by confidentiality duties and receive access only as needed for their role. Processor will notify Controller if it believes an instruction violates applicable data-protection law, unless law prohibits that notice.
4. Security measures
Processor will maintain administrative, technical, and organizational measures appropriate to the risk, including access control, confidentiality, security of systems, incident response, and secure deletion practices appropriate to the service. The applicable SOW may contain more specific controls.
5. Subprocessors
Controller authorizes Processor to use subprocessors needed to deliver the services. Processor will use written terms requiring appropriate confidentiality and security obligations, remain responsible for the subprocessors' contracted performance, and provide 30 days' notice of a material change where required by applicable law. Controller may object on reasonable data-protection grounds as specified in the Main Agreement.
6. Assistance
Taking into account the nature of processing, Processor will provide reasonable assistance with data-subject requests, security obligations, impact assessments, consultations, and incident response. Controller will reimburse reasonable costs for assistance beyond the normal service scope unless the Main Agreement says otherwise.
7. Security incidents
Processor will notify Controller without undue delay after confirming a Security Incident affecting Controller Personal Data, to the contact in the SOW. The notice will include available information about the nature of the incident, affected systems or data, likely impact, and response measures. Processor will cooperate with reasonable investigation and remediation requests.
8. International transfers
The parties will use the transfer mechanism required by applicable law for cross-border processing. The parties will cooperate on supplementary measures where required.
9. Return and deletion
At the end of the services, Processor will return or delete Controller Personal Data as instructed, unless retention is required by law or the data remains in secure backups scheduled for deletion. Processor will not retain production data longer than the agreed retention period.
10. Audit and information
Processor will make available information reasonably necessary to demonstrate compliance and will support a reasonable audit or questionnaire subject to confidentiality, security, scope, frequency, and cost limits. Audits must not compromise other customers' data or system security.
11. Order of precedence
If this DPA conflicts with the Main Agreement about data protection, this DPA controls for that conflict. If the law imposes a mandatory requirement that differs from this DPA, the mandatory requirement controls.
Execution Reference Allocation
[CUSTOMER LEGAL NAME]
Designated Data Controller under agreed SOW.
DarkMatter Technologies
(Preferred future legal name: DarkMatter Technologies Pvt. Ltd.)