DPA (Data Processing Agreement)

Last Updated On: 20th December 2024

In this Agreement, ‘You’ or ‘Your’ refers to the Customer/Client, and ‘We’, ‘Us’, or ‘Ours’ refers to Almashines Technologies Private Limited.

This Data Protection Addendum (“Addendum”) is entered into between Almashines Technologies Private Limited (“Almashines”) and the Customer (as defined in the Agreement), and is governed by the Terms of Service set forth at www.almashines.com.

This Data Protection Addendum (“DPA”) is incorporated into and made part of the Terms of Service (“Terms”) and governs the processing of personal data by Almashines as a Processor on behalf of Customer. This DPA shall be effective on or later of (i) the effective date of the Terms; or (ii) the date both parties execute this DPA in accordance with Section 1 below (‘Effective Date’). Unless otherwise defined in this DPA, capitalized terms shall have the same meaning as given to them in the Terms.

  1. Instructions and Effectiveness

  1. By accepting the Terms of Service or by accessing or using the Almashines Services, the Customer agrees to be bound by this Data Processing Agreement (“DPA”), which is incorporated into and forms a part of the Agreement. This DPA becomes effective on the date the Customer accepts the Terms. No separate signature or submission is required.

  2. This DPA shall terminate automatically upon termination of the Terms, unless earlier terminated pursuant to the terms of this DPA.

  1. Definitions

  1. “Data Protection Officer” means a data protection officer appointed pursuant to Data Protection Law.

  2. “Affiliate” means an entity that owns or controls, is owned or controlled by or is or under common control or ownership with either Customer or Almashines (as the context allows), where control is defined as the possession, directly or indirectly, of the power to direct or cause the direction of the management and policies of an entity, whether through ownership of voting securities, by contract or otherwise;

  3. Customer: An individual or business that uses Almashines services

  4. “Term” refers to the duration or period during which an agreement remains in effect. It defines when the agreement starts, how long it lasts, and the conditions for its expiration, renewal, or termination.

  5. “Customer Personal Data” means any Personal Data provided by or made available by Customer to Almashines or collected by Almashines on behalf of Customer which is Processed by Almashines to perform the Services (As mentioned in agreement);

  6. “Controller to Processor SCCs” means the standard contractual clauses for cross-border transfers published by the European Commission on June 4, 2021 governing the transfer of European Area Personal Data to Third Countries as adopted by the European Commission, (i) the international data transfer addendum (“UK Transfer Addendum”) adopted by the UK Information Commissioner’s Office (“UK ICO”) for data transfers from the UK to Third Countries; or (ii) any similar such clauses adopted by a data protection regulator relating to Personal Data transfers to Third Countries, including without limitation any successor clauses thereto;

  7. “Data Protection Laws” means any local, state, or national law regarding the processing of Personal Data applicable to Almashines in the jurisdictions in which the Services are provided to Customer, including, without limitation, privacy, security, and data protection law;

  8. “EU Area” means the European Union, European Economic Area, United Kingdom, and Switzerland;

  9. “EU Area Law” means (i) Directive 95/46/EC and, from May 25, 2018, Regulation (EU) 2016/679 (“EU GDPR”) together with applicable legislation implementing or supplementing the same or otherwise relating to the processing of Personal Data of natural persons; (ii) the Data Protection Act 1998 of the United Kingdom and the EU GDPR as saved into United Kingdom Law by virtue of section 3 of the United Kingdom’s European Union (Withdrawal) Act 2018 (the “UK GDPR”); (iii) any other law relating to the data protection, security, or privacy of individuals that applies in the EU Area; or (iv) any successor or amendments thereto (including, without limitation, implementation of the EU GDPR by Member States into their national law);

  10. “Services” means the services to be supplied by Almashines to Customer or Customer’s Affiliates pursuant to the Agreement; and

  11. “Third Country” means countries that, where required by applicable Data Protection Laws, have not received an adequacy decision from an applicable authority relating to cross-border data transfers of Personal Data, including regulators such as the European Commission, UK ICO.

  12. The terms “Business”, “Business Purpose”, “commercial purpose”, “Contractor”, “Controller”, “Data Subject”, “Personal Data”, “Personal Data Breach”, “Process”, “Processor”, “Sell”, “Service Provider”, “Share”, “Sub processor”, “Supervisory Authority”, and “Third Party” have the same meanings as described in applicable Data Protection Laws and cognate terms shall be construed accordingly.

  1. Relationship of the parties

    Where applicable Data Protection Law provides for the roles of “controller,” “processor,” and “sub processor”:

  1. Where you are a controller of the personal data covered by this DPA, we shall be a processor processing personal data on your behalf and this DPA shall apply accordingly;

  2. Where you are a processor of the personal data covered by this DPA, we shall be a Sub processor of the personal data and this DPA shall apply accordingly; and

  3. Where and to the extent we process personal data as a controller (e.g., for billing, product improvement, or legal compliance), we will process such personal data in compliance with applicable Data Protection Laws.

  1. Data Processing 

  1. Almashines shall 

(i) Process Customer Personal Data for the legitimate business purpose and/or to provide Almashines Services.

(ii) Process Customer Personal Data only in accordance with the specific instructions of the Customer or Permitted Users unless Processing is required by applicable laws. Such instructions can be in writing or by electronic means.

(iii) Comply with all applicable Data Protection Laws in the Processing of Customer Personal Data.

  1. Each Customer or Permitted User hereby instructs and authorizes Almashines (and authorizes Almashines to instruct each Subprocessor) to Process Customer Personal Data for the above purposes including authorizing Almashines to transfer such data to any country or territory as reasonably necessary for the provision of Almashines Services and consistent with the Terms.

  2. You will be responsible for providing or making Customer Personal Data available to us in compliance with the Data Protection Law, including providing any necessary notices to, and obtaining any necessary consents from, Data Subjects whose Personal Data is provided by you to us for Processing pursuant to this DPA.

  3. You acknowledge and agree that as part of providing Almashines’ Services, we have the right to use data relating to or obtained in connection with the operation, support or use of the Almashines’ Service for our legitimate internal business purposes, such as to support billing processes, to administer Almashines’ Service, to improve, benchmark, and develop our products and services, to comply with applicable laws (including law enforcement requests), to ensure the security of Almashines Service and to prevent fraud or mitigate risk. To the extent any such data is personal data, we warrant and agree that

    1. we will process such personal data in compliance with applicable Data Protection Law and only for the purposes that are compatible with those described in this Section 3; and

    2. we will not use such personal data for any other purpose or disclose it externally unless we have first aggregated and anonymized the data, so it does not identify you or any other person or entity.

  1. Personnel Security 

    We shall take reasonable steps to ensure the reliability of all our employees who have access to Customer Personal Data and Account-Related Information and to ensure that such employees have committed themselves to a binding duty of confidentiality in respect of such Personal Data and Account-Related Information.

  2. Parties’ Obligations

  1. We Shall

    (i) Make copies of the Account-Related Information and Customer Personal Data only to the extent reasonably necessary for the provision of Almashines Services (which, for clarity, may include generating logs, back-up, mirroring and other similar techniques for security, disaster recovery, testing of Almashines Services).

    (ii) Retain all Account-Related Information and Customer Personal Data during the validity of the Subscription Term and as per the Subscription Plan purchased by you. In case of Termination for any reason, unless otherwise agreed, we may, at our sole discretion, delete all or part of the Account-Related Information and Customer Personal Data within such time as we may deem appropriate.

    (iii) Provide copy of all Account-Related Information and Customer Personal Data held by us to you or Permitted Users in a commonly used format and medium.

    (iv) Obtain your prior written approval before using or making available any Account-Related Information or Customer Personal Data other than as provided for in the Terms.

    (v) Attempt to redirect the law enforcement agency to you if a law enforcement agency sends us a demand for Customer Personal Data (e.g., a subpoena or court order). As part of this effort, we may provide your contact information to the law enforcement agency. If compelled to disclose Customer Personal Data to a law enforcement agency, then we will give you reasonable notice of the demand to allow you to seek a protective order or other appropriate remedy to the extent we are legally permitted to do so.

  2. You acknowledge that we are under no duty to investigate or ensure the completeness, accuracy or sufficiency of (i) any instructions received from you or (ii) any Account-Related Information or Customer Personal Data.

  3. You will

    (i) Ensure that you are entitled to transfer Account-Related Information and Customer Personal Data to us so that we may lawfully process and transfer the said information in accordance with the Terms and this DPA;

    (ii) Ensure that the Account-Related Information or Customer Personal Data sent to us for Processing pursuant to the Terms and this DPA is accurate, updated, adequate, relevant and limited to what is necessary in relation to the purposes for which it is processed;

    (iii) Ensure that relevant Data Subjects have been informed of, and have given their consent to, such use, processing and transfer as required under Data Protection Law;

    (iv) Notify us in writing about delay or any situation or development that shall in any way influence, change or limit our ability to process Account-Related Information or Customer Personal Data as set out in the Terms and this DPA;

  1. Security & Audit

  1. We shall, in accordance with requirements under the Data Protection Law, implement appropriate technical and organizational measures to safeguard the Account-Related Information and Customer Personal Data from unauthorized or unlawful Processing, or accidental loss, alteration, disclosure, destruction or damage, and that, having regard to the state of technological development and the cost of implementing any measures. Such measures are described in Annex-A  to this DPA. Such measures shall be proportionate and reasonable to ensure a level of security appropriate to the harm that might result from the unauthorized or unlawful Processing or accidental loss, alteration, disclosure, destruction or damage and to the nature of the Customer Personal Data to be protected.

  2. We shall, in accordance with Data Protection Laws, make available to you such information in our possession or control as you may reasonably request with a view to demonstrating our compliance with the obligations of data processors under Data Protection Laws in relation to its processing of Customer Personal Data.

  3. You may exercise your right of audit under Data Protection Laws in relation to Personal Information. Upon request, and on the condition that you have entered into an applicable non-disclosure agreement with us, we shall:

    (i) supply (on a confidential basis) a summary copy of our audit report(s) (“Report”) to you, so you can verify our compliance with the audit standards against which we have been assessed; and

    (ii) provide written responses (on a confidential basis) to all reasonable requests for information made by you related to our Processing of Customer Personal Data, including responses to information security and audit questionnaires, that are necessary to confirm our compliance with this DPA, provided that you shall not exercise this right more than once per year.

  1. Data Subjects Rights and Requests

  1. Taking into account the nature of the Processing, Almashines Service provides functionality to assist you by appropriate technical and organizational measures (where possible), to access, correct, amend, restrict, or delete Customer Personal Data contained in Almashines Services to address requests by a Data Subject under the GDPR. To the extent you, in your use of Almashines’ Services, are not familiar with Almashines’ Services functionality that may be used for these purposes, we will provide you with additional Documentation or customer support assistance to educate you on how to take such actions.

  2. We shall not disclose the Customer Personal Data to any Data Subject or to a third party other than at your request, as provided for in this DPA, or as required by law in which case we shall to the extent permitted by law inform you of that legal requirement before we disclose the Customer Personal Data to any Data Subject or third party.

  3. We shall not respond to any request from a Data Subject except on the documented instructions of yours or a Permitted User or as required by law, in which case we shall to the extent permitted by law inform you of legal requirement before we respond to the request.

  1. Incident Reporting

  1. We shall notify you of any confirmed Security Incident within 24 hours of becoming aware of it, unless prohibited by law, and shall provide you with sufficient information to enable you to meet any obligations to report or inform: (a) affected Data Subjects; and (b) any other persons or entities required to be notified of the Security Incident.

  2. We shall use reasonable efforts to cooperate with you and take such commercially reasonable steps as are directed by you to assist in the investigation, mitigation, and remediation of each such Security Incident. Our notification of or response to a Security Incident in accordance with this DPA will not be construed as an acknowledgement by us of any fault or liability of us in respect of such Security Incident.

  1. Return or Disposal of Personal Data

    Prior to or upon termination or expiration of the Terms for any reason, we may retrieve Customer Personal Data processed by Almashines’ Services in accordance with the Terms at your request provided in writing to us. We shall, as soon as possible, return or delete Customer Personal Data from Almashines Services, unless applicable law requires storage of the Customer Personal Data.

  2. Restricted Transfers

    In connection with the performance of the Terms and this DPA, you authorize us to transfer Personal Information internationally, and in particular to locations outside of the United Kingdom and EEA , such as the United States, India, and Singapore, where Customer Personal Data will be primarily stored in AWS servers, as listed in our Subprocessor list.. When such transfers qualify as Restricted Transfers under applicable Data Protection Law, they shall be subject to the appropriate Standard Contractual Clauses (SCCs), which shall be deemed incorporated into and form a part of this DPA.

  3. Subprocessors

  1. You agree that we may engage Subprocessors to process Customer Personal Data on your behalf. The Subprocessors currently engaged by us and authorized by you are listed at https://www.almashines.io/subprocessors. With respect to each Subprocessor, we shall

  1. before the Subprocessor first Processes Customer Personal Data, carry out adequate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Customer Personal Data required by the Terms and this DPA;

  2. ensure that the arrangement between Almashines, or its Affiliate or the relevant intermediate Subprocessor, and the Subprocessor, is governed by a written contract including terms which offer at least the same level of protection for Customer Personal Data as those set out in this DPA; and

  3. remain fully responsible to you for the performance of such Subprocessor’s data protection obligations under such terms.

  1. We will inform you of any intended changes concerning the addition or replacement of Subprocessors by updating our designated Subprocessor webpage and, where applicable, by providing direct notice to Customers. You acknowledge that it is your responsibility to check this webpage regularly for updates. If the location (URL) of the Subprocessor list changes, we will notify you by email or through in-product notification. You may object to such changes on reasonable data protection grounds within ten (10) business days of being notified of the engagement of the new Subprocessor. If you object to a new Subprocessor as permitted above, we will use reasonable efforts to make available a change in the Almashines Services or recommend a commercially reasonable configuration change to avoid Processing of Customer Personal Data by the objected-to Subprocessor. If we are unable to implement such changes within a reasonable period of time (not to exceed thirty (30) days), either party may terminate the affected component of the Almashines Services by providing written notice. Upon termination, we will refund any prepaid fees covering the remainder of your subscription term for the terminated component, without imposing any termination penalty.         

  1. General 

  1. The parties agree that this DPA shall replace any existing DPA the parties may have previously entered into in connection with Almashines’ Services.            

  2. Except for the changes made by this DPA, the Terms remains unchanged and in full force and effect. If there is any conflict between this DPA and the Terms, this DPA shall prevail to the extent of that conflict in connection with the processing of Customer Personal Data. If there is any conflict between the Standard Contractual Clauses and the Terms (including this DPA), the Standard Contractual Clauses shall prevail to the extent of that conflict in connection with the processing of Customer Personal Data.

  3. Notwithstanding anything to the contrary in the Terms or this DPA, Almashines’ aggregate liability under this DPA shall not exceed one hundred percent (100%) of the fees paid by the Customer in the twelve (12) months preceding the event giving rise to the claim, except in cases of willful misconduct or gross negligence.

  4. This DPA will be governed by and construed in accordance with governing law and jurisdiction provisions in the Terms, unless required otherwise by applicable Data Protection Laws.

  5. This DPA and the Standard Contractual Clauses will terminate simultaneously and automatically with the termination or expiry of the Terms.

 

Annexure A:

Technical and Organizational Security Measures

Almashines will maintain administrative, physical, and technical safeguards for protection of the security, confidentiality and integrity of Personal Information uploaded to Almashines Portal, as described in this Exhibit. All capitalized terms not otherwise defined herein shall have the meanings as set forth in the DPA.

  1. Security Governance 

    We maintain an information security program (including the adoption and enforcement of internal policies and procedures) designed to:

    (a) help our customers secure their data processed using our online products and services against accidental or unlawful loss, access, or disclosure,

    (b) identify reasonably foreseeable and internal risks to security and unauthorized access to our online products and services, and

    (c) minimize security risks, including through risk assessment and regular testing.

    Our CISO conducts information security program which includes

  • Application security (secure development, security feature design, and secure development training)

  • Infrastructure security (data centers, cloud security, and strong authentication)

  • Monitoring and incident response

  • Vulnerability management

  • Compliance and technical privacy

  • Security awareness (onboarding training and awareness campaigns)

  1. Access Control

  1. Preventing unauthorized access

    Third party data hosting and processing: Almashines Service are hosted with third party cloud infrastructure providers. We maintain contractual relationships with these vendors in accordance with this DPA. We rely on contractual agreements, privacy policies, and vendor compliance programs in order to protect data processed or stored by these vendors.

    Physical and environmental security: Almashines Service infrastructure is hosted with multi-tenant, outsourced infrastructure providers. Their physical and environmental security controls are audited for ISO 27001 & GDPR compliance.

    Authentication: Customers who interact with Almashines Services via the user interface are required to authenticate before they are able to access their non-public data.

    Authorization: Customer Content and Customer Personal Data is stored in multi-tenant storage systems which are only accessible to our customers via application user interfaces and application programming interfaces. Customers are not allowed direct access to the underlying application infrastructure. The authorization model is designed to ensure that only the appropriately assigned individuals can access relevant data, features, views, and customization options. Authorization to data sets is performed through validating the user’s permissions against the attributes associated with each data set.

  2. Preventing Unauthorized Use

    We implement industry standard access controls and detection capabilities for the internal networks that support our platform.

    Access Controls -Network access control mechanisms are designed to prevent network traffic using unauthorized protocols from

    reaching the product infrastructure.

    Static code analysis: Security reviews of code stored in our source code repositories, performed through static code analysis, checking for coding best practices and identifiable software vulnerabilities.

    Penetration testing: We maintain relationships with industry recognized penetration testing service providers for annual penetration tests. The intent of the penetration tests is to identify and resolve foreseeable attack vectors and potential abuse scenarios.

  1. Encryption

    All customer data in Almashines Services is encrypted at rest and in transit over all networks to protect it from unauthorized disclosure or modification. Our implementation of TLS enforces the use of strong ciphers and key-lengths wherever supported by the browser.