This Data Processing Addendum ("DPA") forms part of the agreement between DevOpsX Technologies Pvt. Ltd., headquartered in India ("DevOpsX"), and the customer entity ("Customer").
This DPA sets out the terms under which DevOpsX processes Personal Data on behalf of the Customer in providing its Services.
1. Definitions
"Controller" means the entity determining the purposes and means of Personal Data Processing.
"Processor" means the entity processing Personal Data on behalf of the Controller.
"Data Protection Laws" means all applicable privacy and data protection laws, including but not limited to: the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, India's Digital Personal Data Protection Act (DPDPA) 2023, the California Consumer Privacy Act (CCPA/CPRA), and any similar laws.
"Personal Data" means any information relating to an identified or identifiable natural person.
"Sub-processor" means any third party engaged by DevOpsX to process Personal Data.
"Services" means DevOpsX's AI-powered DevOps automation and optimization platform, including integrations, support, and related offerings.
2. Roles of the Parties
2.1. Customer acts as the Controller, and DevOpsX acts as the Processor.
2.2. DevOpsX processes Personal Data solely to provide the Services in accordance with Customer's documented instructions, unless otherwise required by law.
2.3. DevOpsX does not sell or share Personal Data, nor use it for advertising or unrelated purposes.
3. Confidentiality
DevOpsX ensures that all personnel authorized to process Personal Data are bound by confidentiality obligations.
4. Security
DevOpsX implements technical and organizational measures designed to protect Personal Data, including:
- Encryption at rest (AES-256) and in transit (TLS 1.2+).
- Role-based access controls and MFA.
- Logging, monitoring, and alerting of security events.
- Regular vulnerability testing and system hardening.
- Employee training on data protection and security.
While DevOpsX does not yet hold certifications such as ISO 27001 or SOC 2, our security practices align with industry standards, and we are actively working toward independent audits and certifications.
5. Sub-processing
5.1. Customer provides a general authorization for DevOpsX to engage Sub-processors.
5.2. DevOpsX shall:
- Engage Sub-processors under written agreements requiring equivalent data protection obligations.
- Remain responsible for Sub-processor actions.
- Provide notice of any new Sub-processors.
6. Data Subject Rights
DevOpsX shall assist Customer, to the extent reasonably possible, in fulfilling requests from Data Subjects regarding:
- Access, correction, deletion, or restriction of Personal Data.
- Data portability requests.
7. Personal Data Breaches
If DevOpsX becomes aware of a Personal Data Breach, it will:
- Notify Customer without undue delay.
- Provide information about the nature of the breach, affected data, and steps taken.
- Cooperate with Customer to investigate and mitigate the breach.
8. International Data Transfers
As DevOpsX is headquartered in India, Personal Data may be processed in India and other jurisdictions where Sub-processors operate. Where required, transfers will be safeguarded using mechanisms such as Standard Contractual Clauses (SCCs), the UK Addendum, or equivalent legal tools.
9. Retention and Deletion
Upon termination of Services, DevOpsX will either delete or return all Personal Data, unless retention is required by applicable law.
10. Audit Rights
DevOpsX will make available information necessary to demonstrate compliance with this DPA. Customer may conduct audits, subject to reasonable notice, frequency limits, and confidentiality obligations.
11. Liability
Each Party's liability under this DPA is subject to the limitations of liability set forth in the main Agreement.
12. Term
This DPA remains in effect for as long as DevOpsX processes Personal Data on behalf of Customer.
Schedule 1: Details of Processing
Data Subjects:
- Customer employees and contractors
- End users of Customer's integrated systems
- Other individuals whose data Customer submits
Data Categories:
- Contact details (name, email, job title, phone)
- Login credentials (hashed, never plain text)
- Usage logs, metadata, and service configuration data
- Limited billing/payment data (processed via third-party providers)
Special Categories:
DevOpsX does not intentionally process sensitive data (health, biometric, religious, etc.).
Purpose of Processing:
- Delivering AI-powered DevOps automation services
- Cost optimization, orchestration, and compliance insights
- Support, troubleshooting, and analytics
Retention:
For the duration of Services, unless longer retention is required by law.
Schedule 2: Security Measures
- Data encryption at rest and in transit
- Role-based access control with MFA
- Logging and monitoring of access
- Regular vulnerability scans and security testing
- Employee background checks and training
- Backup, disaster recovery, and business continuity measures
13. Contact
Questions about this DPA can be directed to:
India
DEVOPSX PRIVATE LIMITED
House No. 1106, Khasra No.573/1, Khimlasa, Sagar, Sagar- 470118, Madhya Pradesh, India
USA
DevopsX LLC
16192 Coastal Highway, Lewes, Delaware 19958, County of Sussex, Delaware, USA
contact@devopsx.ai