Ninebloomninebloom
Ninebloom — Template

Data Processing Agreement (DPA)

Between Ninebloom (Processor) and {{Client Legal Name}} (Client / Fiduciary)
Effective date: {{DD/MM/YYYY}}  ·  DPA version: 1.0

This Data Processing Agreement (“DPA”) is entered into between Ninebloom, a sole proprietorship owned and operated by Veera Sankara Reddy Vare, Udyam-registered MSME (“Ninebloom”, “Processor”), having its contact email at privacy@ninebloom.co, and {{Client Legal Name}}, having its registered office at {{Client Address}} (“Client”, “Fiduciary”).

This DPA forms part of, and is subject to, the master services agreement or subscription agreement between the parties (“MSA”) and applies where Ninebloom processes Personal Data on behalf of the Client.

This DPA is a template. Fields marked with double braces ({{...}} ) or blank signature lines must be completed before signing. It should be reviewed by qualified legal counsel for each Client engagement to ensure alignment with the DPDP Act, GDPR, and any final DPDP Rules notified by the Government of India.

1. Definitions

TermMeaning
DPDP ActThe Digital Personal Data Protection Act, 2023 (India), and any rules issued under it.
GDPRThe General Data Protection Regulation (EU) 2016/679.
Personal DataAny information relating to an identified or identifiable natural person, as defined under the DPDP Act (“personal information”) and GDPR (“personal data”).
Client DataPersonal Data processed by Ninebloom on behalf of the Client through the Ninebloom platform.
Fiduciary / ControllerThe Client, who determines the purpose and means of processing Client Data.
ProcessorNinebloom, who processes Client Data on the Client's documented instructions.
Data Principal / Data SubjectThe individual to whom the Client Data relates.
Sub-processorA third party engaged by Ninebloom to assist in processing Client Data.
Personal Data BreachAny unauthorised or accidental access to, acquisition of, disclosure of, alteration of, loss of, or destruction of Client Data.
Tenant IsolationArchitectural separation under which each client's data is stored in a logically or physically segregated environment.

2. Scope, roles, and instructions

2.1 Roles

The Client is the Data Fiduciary under the DPDP Act and Controller under GDPR. Ninebloom is the Data Processor under the DPDP Act and Processor under GDPR. Ninebloom processes Client Data only on the Client's documented instructions, as set out in this DPA, the MSA, and the configuration the Client applies within the platform.

2.2 Subject matter and duration

The subject matter, duration, nature and purpose of processing, types of Personal Data, and categories of Data Principals are set out in Appendix 1. This DPA remains in effect for the duration of the MSA and thereafter until all Client Data has been deleted or returned in accordance with Section 10.

2.3 Documented instructions

Ninebloom will process Client Data only on the Client's documented instructions, including with regard to transfers of Client Data outside India or the EEA, unless required to process by a law to which Ninebloom is subject. Ninebloom will inform the Client if, in its opinion, an instruction infringes the DPDP Act, GDPR, or other applicable law — without being obliged to do so beyond this notification.

3. Processor obligations

Ninebloom shall:

  • Process Client Data only for the purposes described in this DPA and the MSA, and not for any purpose of its own, including marketing, product training, AI/ML model training, or analytics beyond what is strictly necessary to deliver and secure the service;
  • Ensure that personnel authorised to process Client Data are bound by confidentiality commitments and access Client Data only on a need-to-know basis;
  • Implement and maintain the security measures described in Section 5 and Appendix 3;
  • Assist the Client in responding to Data Principal / Data Subject requests, as described in Section 7;
  • Assist the Client in meeting obligations relating to security of processing, personal data breach notification, data protection impact assessments, and prior consultation with regulators, as described in Sections 6 and 8;
  • Notify the Client of any Personal Data Breach without undue delay, as described in Section 6;
  • Make available to the Client information necessary to demonstrate compliance with this DPA and allow for audits, as described in Section 8;
  • Delete or return all Client Data at the end of the services, as described in Section 10.

4. Sub-processors

4.1 General authorisation

The Client grants Ninebloom general authorisation to engage the sub-processors listed in Appendix 2 to assist in processing Client Data. Ninebloom remains fully liable for the performance of each sub-processor and for the compliance of their processing with this DPA.

4.2 Changes to sub-processors

Ninebloom will notify the Client at least 30 days before adding or replacing a sub-processor that processes Client Data, by email to the Client's designated contact. The Client may object to the change on reasonable data-protection grounds by notifying Ninebloom in writing within 30 days of receiving the notice. If the parties cannot resolve the objection within a further 30 days, the Client may terminate the affected portion of the services, and Ninebloom will refund any prepaid fees for the terminated portion.

4.3 Flow-down obligations

Each sub-processor is bound by a written agreement imposing data-protection obligations no less protective than those set out in this DPA. Where a sub-processor fails to meet its obligations, Ninebloom remains liable to the Client for that sub-processor's performance as if Ninebloom were performing the services itself.

5. Security measures

Ninebloom implements and maintains appropriate technical, organisational, and operational security measures to protect Client Data against unauthorised access, disclosure, alteration, loss, or destruction. The measures are designed to meet the requirements of Section 8 of the DPDP Act and Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.

The current security measures are described in Appendix 3. Key measures include:

  • Encryption of Client Data in transit (TLS 1.2+) and at rest (AES-256);
  • Tenant isolation or dedicated per-client databases, with strict access boundaries that prevent cross-tenant access;
  • Role-based access control with least-privilege principles and multi-factor authentication for all administrative access;
  • Access logging and auditability of all access to Client Data environments;
  • Regular security testing including vulnerability assessments and annual penetration testing;
  • Secure software development lifecycle with code review and automated security scanning;
  • Encrypted, access-controlled backups with tested recovery procedures.

Ninebloom may update the security measures from time to time, provided that any updates do not materially reduce the level of protection.

6. Personal data breach notification

6.1 Processor notification

Ninebloom will notify the Client without undue delay, and in any event within 24 hours of becoming aware of a Personal Data Breach affecting Client Data. The notification will include:

  • the nature of the breach;
  • the categories and approximate number of Data Principals and records concerned;
  • the likely consequences; and
  • the measures taken or proposed to address the breach and mitigate its effects.

Where it is not possible to provide all information at once, Ninebloom will provide it in phases as further details become available.

6.2 Client obligations

The Client is responsible for notifying the Data Protection Board of India (under the DPDP Act) and/or the relevant supervisory authority and affected Data Principals (under GDPR), as applicable. Ninebloom will cooperate with and assist the Client in meeting these notification obligations, including by providing all reasonably necessary information.

6.3 Documentation

Ninebloom will document all Personal Data Breaches, including the facts relating to the breach, its effects, and the remedial action taken, and will make this documentation available to the Client on request.

7. Data Principal / Data Subject requests assistance

7.1 Routing

If Ninebloom receives a request from a Data Principal whose data is processed through the Client's use of the platform (for example, a student of an educational institute or an employee of a company), Ninebloom will:

  • Not respond to the request directly, except to acknowledge receipt and advise the Data Principal to contact the Client;
  • Promptly notify the Client of the request; and
  • Provide reasonable assistance to the Client in responding to the request within the timelines required by the DPDP Act or GDPR.

7.2 Assistance

Ninebloom will provide the Client with the tools and information reasonably necessary to respond to requests relating to access, correction, erasure, portability, restriction, objection, and withdrawal of consent. Where technically feasible, the platform includes self-service features that allow the Client to fulfil such requests directly.

7.3 Nominees and organization members

The Client may add one or more nominees or organization members to its Ninebloom account so that multiple authorised individuals are available to manage Client Data, consents, and compliance settings. The Client's administrator controls access levels and may revoke access at any time. For individual Data Principals, the platform supports the DPDP Act's nomination right (in the event of death or incapacity) where applicable to the Client's configuration.

8. Impact assessments and audits

8.1 Assistance with DPIAs

Ninebloom will provide reasonable assistance to the Client in conducting data protection impact assessments and prior consultations with regulators, taking into account the nature of the processing and the information available to Ninebloom.

8.2 Audit rights

The Client has the right to audit Ninebloom's compliance with this DPA, subject to:

  • providing at least 30 days written notice;
  • conducting the audit during business hours and in a manner that does not disrupt Ninebloom's operations;
  • ensuring that auditors are bound by confidentiality commitments and do not access data of other Ninebloom clients.

To minimise disruption, Ninebloom may, in lieu of an on-site audit, make available to the Client (no more than once per calendar year) a summary of its most recent security assessment, penetration test report, or independent audit report, where available.

9. Cross-border transfers

9.1 Default location

Client Data is hosted by default on Amazon Web Services (AWS) in the ap-south-1 region (Mumbai, India). Ninebloom will not transfer Client Data outside India or the EEA without the Client's prior written authorisation.

9.2 DPDP Act transfers

Where Client Data is transferred outside India, Ninebloom will comply with the DPDP Act's cross-border transfer framework, including any restrictions notified by the Central Government on transfers to specific countries.

9.3 GDPR transfers

Where the GDPR applies and Client Data is transferred outside the EEA, the parties will ensure an appropriate safeguard is in place, such as:

  • an adequacy decision of the European Commission covering the destination country; or
  • the Standard Contractual Clauses (SCCs) adopted by the European Commission (Module 2: Controller to Processor, or Module 3: Processor to Processor, as applicable), together with a transfer impact assessment where required; or
  • another lawful transfer mechanism under Chapter V of the GDPR.

Where SCCs are required, Ninebloom will execute them with the Client or, where the sub-processor is the importer, ensure they are in place between Ninebloom and the sub-processor, with the Client as a third-party beneficiary.

10. Data exit and termination

10.1 Export window

When the MSA terminates — at expiry or early termination — the Client may export all of its Client Data, configuration, and compliance records in JSON or CSV format for 30 days after the termination date, through the platform's export function or with assistance from Ninebloom's support team.

10.2 Server shutdown

At the close of the export window, Ninebloom will:

  • shut down the Client's tenant environment; and
  • decommission any dedicated servers or databases provisioned exclusively for the Client.

10.3 Deletion

Ninebloom will delete all Client Data from its active systems within 30 days of the export window closing, and purge it from its backups within 90 days, subject to any legal hold. Ninebloom will issue a written deletion confirmation to the Client once deletion is complete. Deleted Client Data is never reused, mined, or retained in any form that could identify the Client's end-users.

10.4 Retention for law

Notwithstanding the above, Ninebloom may retain Client Data to the extent required by applicable law, provided that such data is kept confidential and used only for the purpose of complying with the legal requirement, and is deleted once the retention period expires.

11. Client obligations

The Client represents and warrants that it:

  • has a lawful basis under the DPDP Act and GDPR for collecting and processing the Client Data, and for instructing Ninebloom to process it;
  • has provided, and will maintain, appropriate privacy notices to its end-users whose data is processed through the platform;
  • is responsible for the accuracy, quality, and legality of the Client Data and the means by which it acquired it;
  • will ensure that its instructions to Ninebloom comply with applicable law;
  • is responsible, where it qualifies as a Significant Data Fiduciary under the DPDP Act, for its own additional obligations (such as appointing a DPO, conducting DPIAs, and independent audits) that apply to it as Fiduciary;
  • will configure the platform's retention, access control, and consent settings in a manner consistent with its own legal obligations;
  • will secure its own account credentials and manage access for its organization members and nominees, and is responsible for the actions of its authorised users.

12. Liability and indemnity

Each party's liability under this DPA is subject to the limitations of liability set out in the MSA. Nothing in this DPA is intended to, or shall be deemed to, limit or exclude any liability that cannot be limited or excluded under applicable law.

13. Governing law and jurisdiction

This DPA is governed by the laws of India. The courts having jurisdiction over the proprietor's place of business shall have exclusive jurisdiction over any disputes arising out of or in connection with this DPA, without prejudice to any rights a Data Principal or Data Subject may have under the DPDP Act, GDPR, or other applicable law.

14. Order of precedence

In the event of a conflict between this DPA and the MSA, this DPA shall prevail with respect to the processing of Client Data and the subject matter of this DPA.

Signatures

For Ninebloom (Processor):
Name: Veera Sankara Reddy Vare
Designation: Proprietor
Signature: _________________________
Date: ______________________________
For {{Client Legal Name}} — Client / Fiduciary:
Name: ______________________________
Designation: ________________________
Signature: _________________________
Date: ______________________________

Appendix 1 — Details of Processing

ItemDetails
Subject matterProcessing of Client Data through the Ninebloom compliance platform
Duration of processingFor the term of the MSA, plus the data-exit period in Section 10
Nature and purpose of processingHosting, storing, securing, and processing Client Data to deliver compliance, consent management, data subject request handling, audit, and breach-response features
Types of Personal DataAs determined and configured by the Client; typically identity details, contact details, consent records, audit logs, data subject request records, and other personal data the Client chooses to process through the platform
Categories of Data PrincipalsAs determined by the Client; typically the Client's employees, students, customers, or website visitors
Processing locationAWS ap-south-1 (Mumbai, India) by default; other locations only with the Client's written authorisation
Normal operating hours24/7 platform availability; support during business hours unless otherwise agreed

Appendix 2 — Approved Sub-processors

Sub-processorPurposeHosting location
Amazon Web Services (AWS)Cloud hosting, compute, storage, databasesap-south-1 (Mumbai, India)
Zoho MailBusiness emailIndia
Zoho DeskSupport ticketingIndia
Zoho BillingSubscription billing and invoicingIndia
Zoho PaymentsPayment processingIndia

An up-to-date list is maintained at https://www.ninebloom.co/subprocessors.

Appendix 3 — Security Measures Summary

  • Encryption: all Client Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256. Encryption keys are managed through AWS Key Management Service (KMS) with rotation policies.
  • Tenant isolation and dedicated databases: each client's data resides in a logically isolated tenant environment with strict access boundaries that prevent cross-tenant access. Clients may also opt for a dedicated, single-tenant database. Client data is never commingled across tenants.
  • Access control: role-based access control (RBAC) with least-privilege principles. All access to Client Data environments requires multi-factor authentication (MFA), is logged and auditable, and is reviewed quarterly. Access is revoked promptly when no longer required.
  • Security testing: regular vulnerability assessments and annual penetration tests conducted by independent third-party security firms. Secure software development lifecycle (SSDLC) with code reviews, automated security scanning, and dependency monitoring.
  • Incident response: documented security incident response plan with defined roles, escalation paths, and notification timelines aligned with Section 6 of this DPA.
  • Personnel security: all personnel and contractors sign confidentiality and acceptable-use agreements and undergo privacy and security training at onboarding and annually thereafter.
  • Business continuity: encrypted, access-controlled backups with tested recovery procedures, stored in a different availability zone with separate key material.

Appendix 4 — International Transfer Mechanisms (GDPR)

Where the GDPR applies and Client Data is transferred outside the EEA, the parties agree to incorporate by reference the Standard Contractual Clauses set out in the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

  • Module 2 (Controller to Processor) applies where the Client is a Controller;
  • Module 3 (Processor to Processor) applies where the Client is itself a Processor acting on behalf of a Controller.

Where the SCCs apply:

  • Clause 9 (use of sub-processors) — the option of general written authorisation applies; the Client's authorisation is granted under Section 4 of this DPA;
  • Clause 11 (redress) — the optional language permitting Data Subjects to lodge complaints with an independent dispute resolution body does not apply;
  • Clause 17 (governing law) — the law of the EU member state agreed by the parties; in the absence of agreement, the law of Ireland;
  • Clause 18 (choice of forum and jurisdiction) — the courts of the EU member state agreed by the parties; in the absence of agreement, the courts of Ireland.

For transfers to sub-processors outside the EEA, Ninebloom ensures that SCCs (or an equivalent mechanism) are in place between Ninebloom and the sub-processor, with the Client as a third-party beneficiary where applicable.

This DPA is a template. Fields marked with double braces ({{...}} ) or blank signature lines must be completed before signing. It should be reviewed by qualified legal counsel for each Client engagement to ensure alignment with the DPDP Act, GDPR, and any final DPDP Rules notified by the Government of India.