Data Processing Agreement

Effective Date: 20 July 2026

This Data Processing Agreement ("DPA") forms part of the agreement between Atcloud Systems Private Limited ("Atcloud Systems", "Processor", "we", "us", or "our") and the customer or organization using the applicable Atcloud Systems Services ("Customer", "Controller", "you", or "your"). This DPA applies where Atcloud Systems processes Personal Data on behalf of the Customer in connection with the Services.

1. Definitions

"Personal Data" means information relating to an identified or identifiable individual as defined by applicable data-protection law.

"Processing" includes collecting, recording, storing, organizing, structuring, adapting, retrieving, using, disclosing, transmitting, restricting, deleting, or otherwise handling Personal Data.

"Data Subject" means the individual to whom Personal Data relates.

"Security Incident" means a confirmed unauthorized access, disclosure, alteration, loss, destruction, or compromise of Personal Data within the relevant systems controlled by Atcloud Systems.

2. Roles of the Parties

The Customer determines the purposes for which Customer Personal Data is processed. Atcloud Systems processes Customer Personal Data only as reasonably necessary to provide the Services, comply with lawful instructions, maintain security, provide support, prevent fraud, and comply with applicable law. The parties acknowledge that their legal roles may differ depending on the specific processing activity and applicable law.

3. Customer Responsibilities

The Customer is responsible for ensuring a lawful basis for processing; providing required notices; obtaining required consents; respecting Data Subject rights; ensuring data accuracy; determining appropriate retention periods; providing lawful instructions; and ensuring that Customer Data is not unlawfully submitted to the Services. The Customer must not submit sensitive or regulated information unless the Services and applicable agreement are suitable for such processing.

4. Processing Instructions

Atcloud Systems may process Personal Data as reasonably necessary to provide the Services; host and store Customer Data; provide technical support; maintain security; prevent fraud and abuse; troubleshoot technical issues; maintain backups; and comply with legal obligations. Atcloud Systems may process data according to the Customer's documented lawful instructions where applicable.

5. Confidentiality

Atcloud Systems will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.

6. Security Measures

Atcloud Systems will maintain reasonable technical and organizational safeguards appropriate to the nature and risks of the Services. Measures may include access controls; authentication controls; encryption in transit where appropriate; logging; backup procedures; security monitoring; incident-response procedures; personnel confidentiality obligations; and access limitation. No security measure guarantees absolute security.

7. Subprocessors

Atcloud Systems may use third-party service providers and subprocessors for hosting; cloud infrastructure; databases; authentication; payments; analytics; communications; support; security; and backups. Atcloud Systems may replace or add subprocessors where reasonably necessary. Where required by applicable law, Atcloud Systems will provide appropriate information regarding relevant subprocessors.

8. International Transfers

Customer Personal Data may be processed or accessed in countries outside the Customer's country where legally permitted. Atcloud Systems will implement measures required by applicable law for relevant international transfers.

9. Data Subject Requests

Where legally required and reasonably possible, Atcloud Systems will provide reasonable assistance to the Customer in responding to Data Subject requests. The Customer remains primarily responsible for responding to requests relating to its own processing purposes and instructions.

10. Security Incidents

If Atcloud Systems becomes aware of a confirmed Security Incident affecting Customer Personal Data, it will take reasonable steps to investigate, contain, and mitigate the incident. Where required by applicable law, Atcloud Systems will notify the Customer within a reasonable period after confirming the incident. Notifications may be made through the Customer's registered account contact. The Customer is responsible for determining whether and how to notify regulators or Data Subjects where the Customer is legally responsible for such notification.

11. Government Requests

Atcloud Systems may disclose Personal Data where required by law, court order, governmental authority, or valid legal process. Where legally permitted, Atcloud Systems may notify the Customer of such request.

12. Data Deletion and Return

Following termination, the Customer may export Customer Data where export functionality is available. Atcloud Systems may delete Customer Data according to its retention practices and applicable law. Atcloud Systems may retain information where necessary for legal, tax, accounting, security, fraud-prevention, dispute-resolution, or other lawful purposes.

13. Audits

The Customer may request reasonable information concerning Atcloud Systems' data-protection practices. Audits must be reasonably requested; respect confidentiality; not compromise security; not disrupt operations; and not expose information about other customers. Any audit costs may be payable by the Customer where reasonably incurred.

14. Liability

Liability relating to this DPA is subject to the liability provisions in the applicable Master SaaS Terms or written agreement unless otherwise expressly agreed in writing.

15. Order of Precedence

If this DPA conflicts with the Master SaaS Terms regarding data processing, this DPA controls only for the specific conflict.

16. Term

This DPA remains effective while Atcloud Systems processes Customer Personal Data on behalf of the Customer.

Contact

Data protection queries: privacy@atcloudsystem.com.