Click any yellow field to fill it in, then save your copy as a PDF.

Data Processing Agreement

Between [Client legal name] (the Controller) and Nactore Technologies LLP (the Processor). Version 1.0, [date of issue].

Controller[Client legal name], [registration number], of [registered address, country] (“Client”).
ProcessorNactore Technologies LLP, a limited liability partnership registered in India, with its registered office at 301, 3rd Floor, Ackruti Star, Chakala MIDC, Mumbai 400093, India. Contact: hello@nactore.com (“Nactore”).
Main agreementThe [Master Services Agreement / Statement of Work / proposal] dated [date] between the parties (the “Services Agreement”).
Effective date[date], or the date Nactore first processes Personal Data for the Client, if earlier.

1. Background and scope

1.1
Under the Services Agreement, Nactore builds or operates the Client’s software, or handles the Client’s CRM or customer data for marketing and growth work. In doing so Nactore processes Personal Data on behalf of the Client. For that Personal Data the Client is the controller and Nactore is the processor.
1.2
This DPA applies to all Personal Data that Nactore processes on the Client’s behalf under the Services Agreement. It is meant to satisfy Article 28(3) of the GDPR and the equivalent terms of the UK GDPR.
1.3
If this DPA conflicts with the Services Agreement on the handling of Personal Data, this DPA prevails. If it conflicts with the Standard Contractual Clauses or the UK Addendum, those prevail.

2. Definitions

2.1
“Applicable Data Protection Law” means the laws that apply to the Client’s Personal Data and to this processing, including Regulation (EU) 2016/679 (“GDPR”), the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (where relevant), US state privacy laws (where relevant), and India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”).
2.2
“Personal Data”, “process”, “controller”, “processor”, “data subject”, “supervisory authority” and “Personal Data Breach” have the meanings given in the GDPR.
2.3
“Subprocessor” means a third party engaged by Nactore that processes Personal Data on the Client’s behalf.
2.4
“SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914. “UK Addendum” means the International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0, in force from 21 March 2022.

3. Instructions

3.1
Nactore will process Personal Data only on the Client’s documented instructions, including on transfers to a third country, unless the law that applies to Nactore requires otherwise. In that case Nactore will tell the Client before processing, unless that law forbids it.
3.2
The Services Agreement, this DPA and the Client’s configuration and use of the services are the Client’s complete instructions at signing. Further instructions must be in writing (email to the Nactore contact is enough). If a further instruction needs extra work, the parties will agree any additional fees under the change control process in the Services Agreement.
3.3
The Client confirms that its instructions comply with Applicable Data Protection Law and that it has a lawful basis for the processing and has given all notices and obtained all consents needed. Nactore will tell the Client without delay if it believes an instruction infringes Applicable Data Protection Law, and may pause that part of the processing until the Client confirms or changes the instruction.
3.4
Annex I describes the subject matter, duration, nature and purpose of the processing, and the types of Personal Data and data subjects. Nactore will not process Personal Data for its own purposes or sell or share it.

4. Confidentiality

4.1
Nactore will keep Personal Data confidential and will allow access only to personnel who need it to deliver the services.
4.2
Everyone at Nactore who can access Personal Data (partners, employees, contractors) is bound by a written confidentiality agreement or a statutory duty of confidentiality, which continues after their engagement ends.

5. Security (Article 32)

5.1
Taking into account the state of the art, the cost, and the nature, scope, context and purpose of the processing, and the risk to individuals, Nactore will keep the technical and organisational measures in Annex II in place.
5.2
Nactore may update those measures if the update does not lower the overall level of protection. Nactore does not claim any third-party security certification (such as SOC 2 or ISO 27001) and this DPA does not imply one. Nactore’s infrastructure providers hold their own certifications, which are available from them.
5.3
The Client is responsible for the security of its own systems and accounts, for the access credentials it controls, and for the choice of what Personal Data it sends to Nactore. The Client will send only the Personal Data needed for the services.

6. Subprocessors

6.1
General written authorisation. The Client gives Nactore general written authorisation to engage the Subprocessors listed in Annex III, and any later Subprocessor engaged under this clause 6.
6.2
Notice of changes. Nactore will give the Client at least 14 days’ notice by email (to [Client privacy contact email]) before adding or replacing a Subprocessor, with the name, location and function of the new Subprocessor.
6.3
Right to object. The Client may object on reasonable data protection grounds by writing to hello@nactore.com within that notice period. The parties will then work in good faith to find a solution, such as Nactore not using that Subprocessor for the Client’s data. If no solution is reached within 30 days, the Client may terminate the affected services on written notice and receive a pro-rata refund of prepaid fees for the terminated period. Fees for work already delivered remain payable.
6.4
Client-designated Subprocessors. If the Client requires Nactore to use a specific tool or vendor (for example the Client’s own CRM, repository or cloud account), that vendor is the Client’s own processor or is added to Annex III on the Client’s instruction. Nactore is not responsible for that vendor’s acts or omissions, except for Nactore’s own failure to follow the Client’s instructions when using it.
6.5
Flow-down. Nactore will bind each Subprocessor to data protection terms that give at least the level of protection in this DPA, and remains responsible to the Client for each Subprocessor’s performance of those obligations.

7. Assisting with data subject rights

7.1
Taking into account the nature of the processing, Nactore will help the Client, by appropriate technical and organisational measures, to answer requests from data subjects to exercise their rights (access, correction, erasure, restriction, portability, objection, and the right not to be subject to automated decisions).
7.2
If a data subject contacts Nactore directly about Client Personal Data, Nactore will pass the request to the Client within 5 business days and will not reply on the substance unless the Client instructs it to.

8. Personal Data Breach

8.1
Nactore will notify the Client without undue delay, and in any case within 48 hours, after becoming aware of a Personal Data Breach affecting the Client’s Personal Data. Notice goes to [Client security contact email and phone].
8.2
The notice will include, as far as known at the time: the nature of the breach, the categories and approximate number of data subjects and records affected, the likely consequences, and the measures taken or proposed. If all details are not yet available, Nactore will give them in phases without further undue delay.
8.3
Nactore will take reasonable steps to contain and fix the breach and will help the Client meet its duties to notify supervisory authorities and data subjects. Unless the law requires it, Nactore will not notify a supervisory authority or data subjects about the Client’s data without the Client’s prior written approval of the content. Notice under this clause is not an admission of fault or liability.

9. Assisting with DPIAs and consultations

9.1
Taking into account the nature of the processing and the information available to it, Nactore will help the Client with its duties under Articles 32 to 36 of the GDPR, including data protection impact assessments and prior consultation with a supervisory authority, by providing relevant information about the processing and the security measures.

10. Deletion or return of data

10.1
When the services end, or earlier on the Client’s written request, Nactore will, at the Client’s choice, return the Personal Data in a common format or delete it, and delete existing copies, within 30 days. The Client must tell Nactore its choice within 14 days of the end date; if it does not, Nactore will delete.
10.2
Copies held in routine encrypted backups at Nactore’s providers will be deleted on the providers’ normal cycle, not later than 90 days, and stay protected under this DPA until then.
10.3
Where the Client’s code and data sit in repositories or accounts owned by the Client, deletion from Nactore’s own devices and accounts is enough, and Nactore will remove its own access. Nactore may keep Personal Data only where the law requires and will tell the Client what it keeps and why. On request, Nactore will confirm deletion in writing.

11. Audits and information

11.1
Nactore will give the Client the information needed to show compliance with Article 28 of the GDPR and this DPA, and will allow and contribute to audits, including inspections, by the Client or an auditor the Client appoints.
11.2
To keep this proportionate, the parties will first use written questionnaires, documents and remote sessions. An on-site or deeper audit may happen once in any 12 months (more often after a Personal Data Breach, or if a supervisory authority requires it), on at least 30 days’ written notice, during business hours, under confidentiality terms, without access to other clients’ data, and without unreasonable disruption.
11.3
Each party bears its own costs. The Client bears the auditor’s costs, and reasonable charges for Nactore time beyond one working day per audit, unless the audit reveals a material breach by Nactore.

12. International transfers

12.1
Location. Nactore operates from India. Providing the services involves Personal Data being accessed from, and transferred to, India. India has no EU or UK adequacy decision, so the safeguards in this clause apply.
12.2
EU transfers (SCCs). For Personal Data subject to the GDPR, the SCCs Module Two (controller to processor) are incorporated into this DPA by reference, with the Client as “data exporter” and Nactore as “data importer”. They apply as completed below.
(a)
Clause 7 (docking clause): included.
(b)
Clause 9(a) (subprocessors): Option 2, general written authorisation, with the notice period in clause 6.2 of this DPA.
(c)
Clause 11(a) (redress): the optional independent dispute resolution wording is not included.
(d)
Clause 13 (supervisory authority): the authority responsible for the exporter under Annex I.C.
(e)
Clause 17 (governing law): Option 1, the law of [the EU Member State where the Client is established, provided it allows third-party beneficiary rights].
(f)
Clause 18(b) (forum): the courts of [the same Member State].
(g)
Annexes I, II and III of this DPA are Annexes I.A, I.B, I.C, II and III of the SCCs. Time limits for notice and the audit approach in this DPA are the agreed way of applying SCCs clauses 8.6, 8.9 and 9.
12.3
UK transfers (UK Addendum). For Personal Data subject to the UK GDPR, the UK Addendum is incorporated and the SCCs above apply as amended by it. The tables are completed as follows.
(a)
Table 1 (parties and details): as in Annex I.A. Start date: the Effective date.
(b)
Table 2 (selected SCCs): the Approved EU SCCs, Module Two, with the options in clause 12.2.
(c)
Table 3 (appendix information): Annexes I, II and III of this DPA.
(d)
Table 4 (ending the Addendum when the Approved Addendum changes): [Importer / Exporter / neither party].
(e)
The Mandatory Clauses of the Approved Addendum are incorporated in full. Governing law is the law of England and Wales and the courts of England and Wales have jurisdiction.
12.4
Switzerland (optional). [Delete if no Swiss Personal Data.] For Personal Data subject to the Swiss FADP, the SCCs apply with these changes: references to the GDPR mean the FADP; the Swiss Federal Data Protection and Information Commissioner is the competent authority; the law of the chosen Member State is Swiss law for Swiss data where required; and data subjects in Switzerland may sue in Switzerland.
12.5
Onward transfers. Some Subprocessors in Annex III process data outside India, including in the United States. Nactore will use them only with a valid transfer mechanism in place (for example the SCCs or the EU-US Data Privacy Framework certification of that provider).
12.6
Government access. Nactore will tell the Client promptly if it receives a legally binding request from a public authority for the Client’s Personal Data (unless the law forbids it), will challenge requests it reasonably believes are unlawful, and will disclose the minimum needed. As of the Effective date, Nactore has not received any such request relating to client data.
12.7
Order of precedence. If this DPA conflicts with the SCCs or the UK Addendum, the SCCs or UK Addendum prevail for the data they cover.

13. India: DPDP Act alignment

13.1
Nactore will handle any Personal Data that falls under the DPDP Act with the same standard of care as this DPA requires: only for the Client’s stated purposes, with reasonable security safeguards, erasure when the purpose ends, and breach reporting as in clause 8. Where the DPDP Act applies to Nactore as a data processor, the Client remains responsible for the notices and consents it must give as the data fiduciary. This clause does not reduce any protection owed under the GDPR or UK GDPR.

14. US state privacy laws

14.1
Where US state privacy laws (such as the California Consumer Privacy Act) apply, Nactore acts as the Client’s service provider or processor, will not sell or share Personal Data, will not retain, use or disclose it outside the direct business relationship or for any purpose other than the services, will not combine it with data from other sources except as the law allows, and will tell the Client if it can no longer meet its obligations under those laws.

15. Liability, term and general

15.1
Each party’s liability under this DPA is subject to the limitations and exclusions in the Services Agreement, except where the law, or the SCCs towards data subjects, do not allow them.
15.2
This DPA starts on the Effective date and lasts as long as Nactore processes Personal Data for the Client. Clauses that by their nature should survive (including 4, 10 and 15) survive termination.
15.3
If a law changes or a regulator issues new standard terms, the parties will agree in good faith to the changes needed to stay compliant. Changes to this DPA must be in writing and signed by both parties, except for updates to Annex III made under clause 6.
15.4
Except as clause 12 says for the SCCs and the UK Addendum, this DPA is governed by the law that governs the Services Agreement, and disputes are resolved under its dispute resolution clause. Notices go to the contacts in Annex I.
15.5
This DPA may be signed in counterparts and electronically.

Signatures

Signing this DPA also signs the SCCs and the UK Addendum as incorporated in clause 12, including their Annexes.

For the Client
[Client legal name]
Signature

Name: [name]
Title: [title]
Date: [date]

For Nactore Technologies LLP
 
Signature

Name: [name]
Title: Managing Partner
Date: [date]

Annex I: Parties and description of processing

A. List of parties

Data exporter (controller): the Client
Name and address[Client legal name, address, country]
Contact person[name, role, email]
EU/UK representative or DPO (if any)[name and contact, or “none”]
Activities relevant to the transferUses Nactore’s services described below.
RoleController
Data importer (processor): Nactore
Name and addressNactore Technologies LLP, 301, 3rd Floor, Ackruti Star, Chakala MIDC, Mumbai 400093, India
Contact personManaging Partner, hello@nactore.com
Activities relevant to the transferProviding the services described below.
RoleProcessor

B. Description of the processing and transfer

Categories of data subjects[Select and edit: Client’s customers; prospects and leads; website and app users; Client employees and contractors; other: ____]
Categories of Personal Data[Select and edit: name; business and personal email; phone; job title and company; account and login identifiers; IP address and device data; usage and analytics data; CRM records and communications; billing contact data; other: ____]
Sensitive data (Article 9 or 10)[None expected / list categories and any extra safeguards]. The Client will not send special category data to Nactore without telling Nactore first and agreeing safeguards in writing.
Frequency of transfer[Continuous for the term / one-off / on request]
Nature of the processing[Select: software development, hosting and maintenance; CRM administration and data hygiene; email and campaign operations; analytics and reporting; support and debugging; other: ____]. Operations include access, storage, organisation, adjustment, transmission and deletion.
Purpose of the processingTo provide the services in the Services Agreement: [describe, for example “build and operate the Client’s web application” or “manage the Client’s CRM for outbound marketing”].
RetentionFor the term of the services, then deleted or returned under clause 10.
Subprocessor transfersAs in Annex III: the subject matter is hosting, email and document services and source code hosting, for the term of the services.

C. Competent supervisory authority

EU[Supervisory authority of the Member State where the Client is established, or of its EU representative, or where the data subjects are located]
UKInformation Commissioner’s Office (ICO), if UK GDPR applies.

D. Contacts for notices

Client security and breach contact[email, phone]
Client privacy contact (Subprocessor notices)[email]
Nactore contacthello@nactore.com

Annex II: Technical and organisational measures

These are the measures Nactore keeps in place as of the date of this DPA. Nactore is a small team and describes its practices plainly. It holds no SOC 2, ISO 27001 or similar certification.

AreaMeasure
AuthenticationMulti-factor authentication is switched on for Nactore’s Google Workspace, GitHub, Cloudflare and Razorpay accounts.
Access controlLeast-privilege access: people and tools get only the access needed for the client work they do. Access is removed when a person leaves a project or Nactore.
Encryption in transitHTTPS only for Nactore-operated websites and services. Data moved between Nactore systems and providers uses encrypted connections.
Encryption at restNactore’s infrastructure and productivity providers (Cloudflare, Google, GitHub) encrypt stored data at rest.
Client code and data locationWhere the Client requires it, the Client’s code is kept in repositories the Client owns, and Nactore works through access the Client grants and can withdraw.
Personnel confidentialityEveryone who touches client data is bound by a non-disclosure agreement.
Client separationEach client’s work and data are kept in separate repositories, workspaces or accounts, and are not mixed with other clients’ data.
Data minimisationNactore asks only for the data needed for the service, and does not use client Personal Data for its own products, testing, or marketing.
Incident responseSecurity events are escalated to the Managing Partner. Confirmed Personal Data Breaches are notified to the Client under clause 8 (within 48 hours of awareness).
DeletionClient data is deleted or returned at the end of the engagement under clause 10.
Subprocessor managementSubprocessors are limited to those in Annex III, bound by data protection terms, and changed only under clause 6.
Assistance to the ClientNactore will help the Client with data subject requests, DPIAs and audits under clauses 7, 9 and 11, and applies the same measures to Subprocessors as its contracts with them allow.

Annex III: Subprocessors

The Client authorises the following Subprocessors under clause 6.

SubprocessorService and processingLocation
Cloudflare, Inc.Hosting, content delivery and security of websites and apps; email routing.Global network; company based in the United States. [Confirm region used]
Google LLC (Google Workspace)Business email and documents, including files shared with or by the Client.United States and other Google data centre locations
GitHub, Inc.Source code hosting and collaboration, where the Client’s code is not held in the Client’s own repository.United States
[Client-designated or approved Subprocessor][Service][Location]

Other Subprocessors are used only when the Client designates or approves them in writing, or after notice under clause 6.2.

Nactore Technologies LLP, 301, 3rd Floor, Ackruti Star, Chakala MIDC, Mumbai 400093, India. hello@nactore.com.

Template. Review with your counsel before signing. This template is provided as a starting point and is not legal advice. Have a licensed advocate review before signing.