Data Processing Addendum
This Data Processing Addendum (DPA) governs the processing of personal data by Networkz on behalf of clients subject to the EU General Data Protection Regulation (GDPR) or UK GDPR. It supplements the Master Services Agreement.
Template Document
This DPA is a template. It must be executed as a signed agreement between Networkz and the Client, together with the relevant Statement of Work, before it has legal effect. For enterprise or high-volume engagements, specific processing activities should be described in the applicable SOW or a schedule to this DPA.
1. Definitions
In this Data Processing Addendum ("DPA"), the following terms have the meanings set out below. Capitalised terms not defined here have the meanings given in the Master Services Agreement ("MSA").
| Term | Meaning |
|---|---|
| Controller | The party that determines the purposes and means of processing Personal Data. |
| Processor | The party that processes Personal Data on behalf of the Controller. |
| Personal Data | Any information relating to an identified or identifiable natural person, as defined in the GDPR. |
| Processing | Any operation or set of operations performed on Personal Data, including collection, recording, storage, retrieval, use, disclosure, erasure, or destruction. |
| GDPR | Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016. |
| UK GDPR | The GDPR as retained in UK law by the European Union (Withdrawal) Act 2018. |
| Data Subject | An identified or identifiable natural person to whom the Personal Data relates. |
| Supervisory Authority | The data protection regulatory authority with jurisdiction over the Controller. |
| SCCs | Standard Contractual Clauses as approved by the European Commission for international transfers of Personal Data. |
| Security Incident | Any unauthorised access, disclosure, alteration, loss, or destruction of Personal Data processed under this DPA. |
| Sub-Processor | A third party engaged by Networkz (as Processor) to carry out processing activities on Personal Data on behalf of the Client (as Controller). |
2. Roles of the Parties
For the purposes of this DPA and in relation to the processing of Client Personal Data:
- The Client is the Controller and determines the purposes and means of processing Personal Data of its own customers, users, or other data subjects.
- Networkz is the Processor and processes Personal Data on behalf of the Client solely as required to deliver the services described in the MSA and the applicable SOW.
Each party acknowledges that it is also an independent Controller of its own internal personal data (e.g., employee data, business contact data) and that this DPA does not govern such independent processing.
3. Subject Matter and Duration
This DPA governs Networkz's processing of Client Personal Data in connection with the services provided under the MSA and the applicable SOW. Processing commences on the effective date of the relevant SOW and continues until termination of the SOW or the MSA, or until all Client Personal Data has been returned or deleted pursuant to Section 13, whichever is later.
4. Nature and Purpose of Processing
Networkz will process Client Personal Data only for the following purposes:
- Designing, developing, and delivering the software systems described in the SOW;
- Testing, debugging, and quality assurance of such systems;
- Deploying, configuring, and maintaining such systems as agreed in the MSA;
- Providing technical support and maintenance services under any applicable retainer;
- Complying with applicable law.
Networkz will not process Client Personal Data for any other purpose, including for its own commercial benefit, advertising, or profiling.
5. Categories of Personal Data and Data Subjects
The categories of personal data processed and the types of data subjects will be as specified in the relevant SOW or in a schedule attached to this DPA. In the absence of a specific schedule, the default categories are:
| Item | Details (default) |
|---|---|
| Data subjects | End-users and customers of the Client's product or service |
| Categories of data | Identifiers (name, email, user ID), usage data, transactional data — as required to deliver the system described in the SOW |
| Special categories | None, unless explicitly agreed in writing in the SOW |
6. Processing Instructions
Networkz will process Client Personal Data only on the documented instructions of the Client. The MSA and the relevant SOW constitute the initial documented instructions. Any change to the processing instructions must be made in writing (including via email).
If Networkz believes that an instruction would violate applicable data protection law, it will promptly notify the Client in writing. In that case, Networkz is entitled to suspend processing under the relevant instruction until the Client provides a revised instruction that Networkz reasonably believes is lawful.
7. Confidentiality of Processing Personnel
Networkz will ensure that all personnel who process Client Personal Data are bound by a duty of confidentiality at least as protective as the confidentiality obligations in the MSA, and will limit access to Client Personal Data to personnel who need access to perform the services.
8. Technical and Organisational Security Measures
Networkz will implement and maintain appropriate technical and organisational measures to protect Client Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include:
- Encryption of data in transit using TLS 1.2 or higher;
- Encryption of data at rest using the facilities of the hosting provider;
- Access controls and authentication (role-based access, strong passwords, JWT tokens);
- Network-level controls including Cloudflare-managed DDoS protection and WAF;
- Rate limiting and input validation on all data endpoints;
- Secrets management via environment variables (no credentials in source code);
- Regular dependency security audits;
- Security-aware development practices informed by OWASP Top 10.
Networkz will review and update these measures as appropriate in light of technological developments and the nature of the processing. The measures described are minimum standards; additional or more specific measures may be agreed in the SOW.
9. Sub-Processors
9.1 Current approved sub-processors
The Client provides general authorisation for Networkz to engage the following sub-processors in connection with the services:
| Sub-Processor | Role | Location |
|---|---|---|
| Vercel Inc. | Hosting and server-side processing | USA |
| Cloudflare Inc. | CDN, edge security, DDoS protection | USA / Global |
| Upstash Inc. | Redis-based rate limiting | EU / USA |
| Resend Inc. | Transactional email | USA |
9.2 Change notification
Networkz will notify the Client at least 30 days before engaging any new sub-processor or making any material changes to an existing sub-processor that would affect processing of Client Personal Data. The Client may object to the change within this notice period. If the Client objects and the parties cannot reach agreement, the Client may terminate the affected SOW on written notice without penalty.
9.3 Sub-processor obligations
Networkz will impose data protection obligations on sub-processors that are no less protective than those in this DPA. Networkz remains responsible to the Client for the performance of sub-processors to the extent that they process Client Personal Data.
10. Data Subject Rights
Networkz will promptly notify the Client if it receives a request from a Data Subject exercising rights under applicable data protection law (e.g., access, rectification, erasure, restriction, portability, objection). Networkz will not respond to such requests directly without Client instruction, except as required by law.
Networkz will provide the Client with reasonable assistance, including by implementing appropriate technical measures, to enable the Client to fulfil its obligations to respond to Data Subject requests within the time periods prescribed by applicable law.
11. Security Incidents
Networkz will notify the Client without undue delay, and in any event within 72 hours of becoming aware of a Security Incident affecting Client Personal Data. The notification will include (to the extent then known):
- A description of the nature of the Security Incident;
- The categories and approximate number of Data Subjects and Personal Data records concerned;
- The likely consequences of the Security Incident;
- The measures taken or proposed to address the incident and mitigate its effects.
Networkz will cooperate with the Client in investigating, remediating, and (where required) reporting the Security Incident to the relevant Supervisory Authority and/or affected Data Subjects. Networkz's notification under this Section does not constitute an admission of fault.
12. Data Protection Impact Assessments and Prior Consultation
Networkz will provide the Client with reasonable assistance in carrying out data protection impact assessments (DPIAs) and in any prior consultation with a Supervisory Authority where required by applicable law, taking into account the nature of the processing and the information available to Networkz.
13. Deletion or Return of Personal Data on Termination
On termination or expiry of the relevant SOW or the MSA, and at the Client's written election, Networkz will:
- Return a copy of all Client Personal Data in a structured, commonly used machine-readable format; and/or
- Delete all Client Personal Data from Networkz's systems and, to the extent technically practicable, from sub-processor systems.
Networkz will confirm in writing within 30 days of completing deletion that all Client Personal Data has been deleted. Networkz may retain Personal Data to the extent required by applicable law, in which case it will inform the Client of the nature and duration of such retention.
14. Audit Rights
Networkz will make available to the Client all information reasonably necessary to demonstrate compliance with its obligations under this DPA. On the Client's reasonable written request (no more than once per calendar year, except where an audit is required following a Security Incident), Networkz will allow for and cooperate with audits by the Client or a mutually agreed third-party auditor, subject to:
- Reasonable prior notice of at least 30 days;
- Execution of a confidentiality agreement by the auditor;
- The audit being conducted during normal business hours and in a manner that minimises disruption.
The Client bears the cost of any audit unless the audit reveals a material breach of this DPA by Networkz, in which case Networkz will bear reasonable audit costs.
15. International Transfers
Where Networkz transfers Client Personal Data to a country outside the EEA or UK that is not subject to an adequacy decision, Networkz will ensure that such transfer is made subject to appropriate safeguards as required by applicable law, including the use of Standard Contractual Clauses (SCCs) approved by the European Commission (or UK equivalent approved by the ICO), or such other mechanism as the parties may agree in writing.
The parties acknowledge that sub-processors listed in Section 9.1 are located in the USA and that transfers to them are currently made under SCCs or equivalent mechanisms maintained by those providers.
16. Order of Precedence
This DPA supplements and forms part of the MSA. In the event of a conflict between this DPA and the MSA with respect to data protection matters, this DPA prevails. For all other matters, the MSA prevails.
17. Governing Law
This DPA is governed by the law of India and the courts of competent jurisdiction in Mumbai, Maharashtra, India shall have exclusive jurisdiction, unless a different governing law is agreed in writing between the parties (for example, where the Client is established in an EEA member state and requires the DPA to be governed by the law of that state for GDPR compliance purposes).