Data Processing Agreement (DPA)
{{Client Legal Name}} (Client / Fiduciary){{DD/MM/YYYY}} · DPA version: 1.0This Data Processing Agreement (“DPA”) is entered into between Ninebloom, a sole proprietorship owned and operated by Veera Sankara Reddy Vare, Udyam-registered MSME (“Ninebloom”, “Processor”), having its contact email at privacy@ninebloom.co, and {{Client Legal Name}}, having its registered office at {{Client Address}} (“Client”, “Fiduciary”).
This DPA forms part of, and is subject to, the master services agreement or subscription agreement between the parties (“MSA”) and applies where Ninebloom processes Personal Data on behalf of the Client.
1. Definitions
| Term | Meaning |
|---|---|
| DPDP Act | The Digital Personal Data Protection Act, 2023 (India), and any rules issued under it. |
| GDPR | The General Data Protection Regulation (EU) 2016/679. |
| Personal Data | Any information relating to an identified or identifiable natural person, as defined under the DPDP Act (“personal information”) and GDPR (“personal data”). |
| Client Data | Personal Data processed by Ninebloom on behalf of the Client through the Ninebloom platform. |
| Fiduciary / Controller | The Client, who determines the purpose and means of processing Client Data. |
| Processor | Ninebloom, who processes Client Data on the Client's documented instructions. |
| Data Principal / Data Subject | The individual to whom the Client Data relates. |
| Sub-processor | A third party engaged by Ninebloom to assist in processing Client Data. |
| Personal Data Breach | Any unauthorised or accidental access to, acquisition of, disclosure of, alteration of, loss of, or destruction of Client Data. |
| Tenant Isolation | Architectural separation under which each client's data is stored in a logically or physically segregated environment. |
2. Scope, roles, and instructions
2.1 Roles
The Client is the Data Fiduciary under the DPDP Act and Controller under GDPR. Ninebloom is the Data Processor under the DPDP Act and Processor under GDPR. Ninebloom processes Client Data only on the Client's documented instructions, as set out in this DPA, the MSA, and the configuration the Client applies within the platform.
2.2 Subject matter and duration
The subject matter, duration, nature and purpose of processing, types of Personal Data, and categories of Data Principals are set out in Appendix 1. This DPA remains in effect for the duration of the MSA and thereafter until all Client Data has been deleted or returned in accordance with Section 10.
2.3 Documented instructions
Ninebloom will process Client Data only on the Client's documented instructions, including with regard to transfers of Client Data outside India or the EEA, unless required to process by a law to which Ninebloom is subject. Ninebloom will inform the Client if, in its opinion, an instruction infringes the DPDP Act, GDPR, or other applicable law — without being obliged to do so beyond this notification.
3. Processor obligations
Ninebloom shall:
- Process Client Data only for the purposes described in this DPA and the MSA, and not for any purpose of its own, including marketing, product training, AI/ML model training, or analytics beyond what is strictly necessary to deliver and secure the service;
- Ensure that personnel authorised to process Client Data are bound by confidentiality commitments and access Client Data only on a need-to-know basis;
- Implement and maintain the security measures described in Section 5 and Appendix 3;
- Assist the Client in responding to Data Principal / Data Subject requests, as described in Section 7;
- Assist the Client in meeting obligations relating to security of processing, personal data breach notification, data protection impact assessments, and prior consultation with regulators, as described in Sections 6 and 8;
- Notify the Client of any Personal Data Breach without undue delay, as described in Section 6;
- Make available to the Client information necessary to demonstrate compliance with this DPA and allow for audits, as described in Section 8;
- Delete or return all Client Data at the end of the services, as described in Section 10.
4. Sub-processors
4.1 General authorisation
The Client grants Ninebloom general authorisation to engage the sub-processors listed in Appendix 2 to assist in processing Client Data. Ninebloom remains fully liable for the performance of each sub-processor and for the compliance of their processing with this DPA.
4.2 Changes to sub-processors
Ninebloom will notify the Client at least 30 days before adding or replacing a sub-processor that processes Client Data, by email to the Client's designated contact. The Client may object to the change on reasonable data-protection grounds by notifying Ninebloom in writing within 30 days of receiving the notice. If the parties cannot resolve the objection within a further 30 days, the Client may terminate the affected portion of the services, and Ninebloom will refund any prepaid fees for the terminated portion.
4.3 Flow-down obligations
Each sub-processor is bound by a written agreement imposing data-protection obligations no less protective than those set out in this DPA. Where a sub-processor fails to meet its obligations, Ninebloom remains liable to the Client for that sub-processor's performance as if Ninebloom were performing the services itself.
5. Security measures
Ninebloom implements and maintains appropriate technical, organisational, and operational security measures to protect Client Data against unauthorised access, disclosure, alteration, loss, or destruction. The measures are designed to meet the requirements of Section 8 of the DPDP Act and Article 32 of the GDPR, taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing.
The current security measures are described in Appendix 3. Key measures include:
- Encryption of Client Data in transit (TLS 1.2+) and at rest (AES-256);
- Tenant isolation or dedicated per-client databases, with strict access boundaries that prevent cross-tenant access;
- Role-based access control with least-privilege principles and multi-factor authentication for all administrative access;
- Access logging and auditability of all access to Client Data environments;
- Regular security testing including vulnerability assessments and annual penetration testing;
- Secure software development lifecycle with code review and automated security scanning;
- Encrypted, access-controlled backups with tested recovery procedures.
Ninebloom may update the security measures from time to time, provided that any updates do not materially reduce the level of protection.
6. Personal data breach notification
6.1 Processor notification
Ninebloom will notify the Client without undue delay, and in any event within 24 hours of becoming aware of a Personal Data Breach affecting Client Data. The notification will include:
- the nature of the breach;
- the categories and approximate number of Data Principals and records concerned;
- the likely consequences; and
- the measures taken or proposed to address the breach and mitigate its effects.
Where it is not possible to provide all information at once, Ninebloom will provide it in phases as further details become available.
6.2 Client obligations
The Client is responsible for notifying the Data Protection Board of India (under the DPDP Act) and/or the relevant supervisory authority and affected Data Principals (under GDPR), as applicable. Ninebloom will cooperate with and assist the Client in meeting these notification obligations, including by providing all reasonably necessary information.
6.3 Documentation
Ninebloom will document all Personal Data Breaches, including the facts relating to the breach, its effects, and the remedial action taken, and will make this documentation available to the Client on request.
7. Data Principal / Data Subject requests assistance
7.1 Routing
If Ninebloom receives a request from a Data Principal whose data is processed through the Client's use of the platform (for example, a student of an educational institute or an employee of a company), Ninebloom will:
- Not respond to the request directly, except to acknowledge receipt and advise the Data Principal to contact the Client;
- Promptly notify the Client of the request; and
- Provide reasonable assistance to the Client in responding to the request within the timelines required by the DPDP Act or GDPR.
7.2 Assistance
Ninebloom will provide the Client with the tools and information reasonably necessary to respond to requests relating to access, correction, erasure, portability, restriction, objection, and withdrawal of consent. Where technically feasible, the platform includes self-service features that allow the Client to fulfil such requests directly.
7.3 Nominees and organization members
The Client may add one or more nominees or organization members to its Ninebloom account so that multiple authorised individuals are available to manage Client Data, consents, and compliance settings. The Client's administrator controls access levels and may revoke access at any time. For individual Data Principals, the platform supports the DPDP Act's nomination right (in the event of death or incapacity) where applicable to the Client's configuration.
8. Impact assessments and audits
8.1 Assistance with DPIAs
Ninebloom will provide reasonable assistance to the Client in conducting data protection impact assessments and prior consultations with regulators, taking into account the nature of the processing and the information available to Ninebloom.
8.2 Audit rights
The Client has the right to audit Ninebloom's compliance with this DPA, subject to:
- providing at least 30 days written notice;
- conducting the audit during business hours and in a manner that does not disrupt Ninebloom's operations;
- ensuring that auditors are bound by confidentiality commitments and do not access data of other Ninebloom clients.
To minimise disruption, Ninebloom may, in lieu of an on-site audit, make available to the Client (no more than once per calendar year) a summary of its most recent security assessment, penetration test report, or independent audit report, where available.
9. Cross-border transfers
9.1 Default location
Client Data is hosted by default on Amazon Web Services (AWS) in the ap-south-1 region (Mumbai, India). Ninebloom will not transfer Client Data outside India or the EEA without the Client's prior written authorisation.
9.2 DPDP Act transfers
Where Client Data is transferred outside India, Ninebloom will comply with the DPDP Act's cross-border transfer framework, including any restrictions notified by the Central Government on transfers to specific countries.
9.3 GDPR transfers
Where the GDPR applies and Client Data is transferred outside the EEA, the parties will ensure an appropriate safeguard is in place, such as:
- an adequacy decision of the European Commission covering the destination country; or
- the Standard Contractual Clauses (SCCs) adopted by the European Commission (Module 2: Controller to Processor, or Module 3: Processor to Processor, as applicable), together with a transfer impact assessment where required; or
- another lawful transfer mechanism under Chapter V of the GDPR.
Where SCCs are required, Ninebloom will execute them with the Client or, where the sub-processor is the importer, ensure they are in place between Ninebloom and the sub-processor, with the Client as a third-party beneficiary.
10. Data exit and termination
10.1 Export window
When the MSA terminates — at expiry or early termination — the Client may export all of its Client Data, configuration, and compliance records in JSON or CSV format for 30 days after the termination date, through the platform's export function or with assistance from Ninebloom's support team.
10.2 Server shutdown
At the close of the export window, Ninebloom will:
- shut down the Client's tenant environment; and
- decommission any dedicated servers or databases provisioned exclusively for the Client.
10.3 Deletion
Ninebloom will delete all Client Data from its active systems within 30 days of the export window closing, and purge it from its backups within 90 days, subject to any legal hold. Ninebloom will issue a written deletion confirmation to the Client once deletion is complete. Deleted Client Data is never reused, mined, or retained in any form that could identify the Client's end-users.
10.4 Retention for law
Notwithstanding the above, Ninebloom may retain Client Data to the extent required by applicable law, provided that such data is kept confidential and used only for the purpose of complying with the legal requirement, and is deleted once the retention period expires.
11. Client obligations
The Client represents and warrants that it:
- has a lawful basis under the DPDP Act and GDPR for collecting and processing the Client Data, and for instructing Ninebloom to process it;
- has provided, and will maintain, appropriate privacy notices to its end-users whose data is processed through the platform;
- is responsible for the accuracy, quality, and legality of the Client Data and the means by which it acquired it;
- will ensure that its instructions to Ninebloom comply with applicable law;
- is responsible, where it qualifies as a Significant Data Fiduciary under the DPDP Act, for its own additional obligations (such as appointing a DPO, conducting DPIAs, and independent audits) that apply to it as Fiduciary;
- will configure the platform's retention, access control, and consent settings in a manner consistent with its own legal obligations;
- will secure its own account credentials and manage access for its organization members and nominees, and is responsible for the actions of its authorised users.
12. Liability and indemnity
Each party's liability under this DPA is subject to the limitations of liability set out in the MSA. Nothing in this DPA is intended to, or shall be deemed to, limit or exclude any liability that cannot be limited or excluded under applicable law.
13. Governing law and jurisdiction
This DPA is governed by the laws of India. The courts having jurisdiction over the proprietor's place of business shall have exclusive jurisdiction over any disputes arising out of or in connection with this DPA, without prejudice to any rights a Data Principal or Data Subject may have under the DPDP Act, GDPR, or other applicable law.
14. Order of precedence
In the event of a conflict between this DPA and the MSA, this DPA shall prevail with respect to the processing of Client Data and the subject matter of this DPA.
Signatures
{{Client Legal Name}} — Client / Fiduciary:Appendix 1 — Details of Processing
| Item | Details |
|---|---|
| Subject matter | Processing of Client Data through the Ninebloom compliance platform |
| Duration of processing | For the term of the MSA, plus the data-exit period in Section 10 |
| Nature and purpose of processing | Hosting, storing, securing, and processing Client Data to deliver compliance, consent management, data subject request handling, audit, and breach-response features |
| Types of Personal Data | As determined and configured by the Client; typically identity details, contact details, consent records, audit logs, data subject request records, and other personal data the Client chooses to process through the platform |
| Categories of Data Principals | As determined by the Client; typically the Client's employees, students, customers, or website visitors |
| Processing location | AWS ap-south-1 (Mumbai, India) by default; other locations only with the Client's written authorisation |
| Normal operating hours | 24/7 platform availability; support during business hours unless otherwise agreed |
Appendix 2 — Approved Sub-processors
| Sub-processor | Purpose | Hosting location |
|---|---|---|
| Amazon Web Services (AWS) | Cloud hosting, compute, storage, databases | ap-south-1 (Mumbai, India) |
| Zoho Mail | Business email | India |
| Zoho Desk | Support ticketing | India |
| Zoho Billing | Subscription billing and invoicing | India |
| Zoho Payments | Payment processing | India |
An up-to-date list is maintained at https://www.ninebloom.co/subprocessors.
Appendix 3 — Security Measures Summary
- Encryption: all Client Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256. Encryption keys are managed through AWS Key Management Service (KMS) with rotation policies.
- Tenant isolation and dedicated databases: each client's data resides in a logically isolated tenant environment with strict access boundaries that prevent cross-tenant access. Clients may also opt for a dedicated, single-tenant database. Client data is never commingled across tenants.
- Access control: role-based access control (RBAC) with least-privilege principles. All access to Client Data environments requires multi-factor authentication (MFA), is logged and auditable, and is reviewed quarterly. Access is revoked promptly when no longer required.
- Security testing: regular vulnerability assessments and annual penetration tests conducted by independent third-party security firms. Secure software development lifecycle (SSDLC) with code reviews, automated security scanning, and dependency monitoring.
- Incident response: documented security incident response plan with defined roles, escalation paths, and notification timelines aligned with Section 6 of this DPA.
- Personnel security: all personnel and contractors sign confidentiality and acceptable-use agreements and undergo privacy and security training at onboarding and annually thereafter.
- Business continuity: encrypted, access-controlled backups with tested recovery procedures, stored in a different availability zone with separate key material.
Appendix 4 — International Transfer Mechanisms (GDPR)
Where the GDPR applies and Client Data is transferred outside the EEA, the parties agree to incorporate by reference the Standard Contractual Clauses set out in the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.
- Module 2 (Controller to Processor) applies where the Client is a Controller;
- Module 3 (Processor to Processor) applies where the Client is itself a Processor acting on behalf of a Controller.
Where the SCCs apply:
- Clause 9 (use of sub-processors) — the option of general written authorisation applies; the Client's authorisation is granted under Section 4 of this DPA;
- Clause 11 (redress) — the optional language permitting Data Subjects to lodge complaints with an independent dispute resolution body does not apply;
- Clause 17 (governing law) — the law of the EU member state agreed by the parties; in the absence of agreement, the law of Ireland;
- Clause 18 (choice of forum and jurisdiction) — the courts of the EU member state agreed by the parties; in the absence of agreement, the courts of Ireland.
For transfers to sub-processors outside the EEA, Ninebloom ensures that SCCs (or an equivalent mechanism) are in place between Ninebloom and the sub-processor, with the Client as a third-party beneficiary where applicable.