Data Processing Agreement
Effective Date: 20 July 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Atcloud Systems Private Limited ("Atcloud Systems", "Processor", "we", "us", or "our") and the customer or organization using the applicable Atcloud Systems Services ("Customer", "Controller", "you", or "your"). This DPA applies where Atcloud Systems processes Personal Data on behalf of the Customer in connection with the Services.
1. Definitions
"Personal Data" means information relating to an identified or identifiable individual as defined by applicable data-protection law.
"Processing" includes collecting, recording, storing, organizing, structuring, adapting, retrieving, using, disclosing, transmitting, restricting, deleting, or otherwise handling Personal Data.
"Data Subject" means the individual to whom Personal Data relates.
"Security Incident" means a confirmed unauthorized access, disclosure, alteration, loss, destruction, or compromise of Personal Data within the relevant systems controlled by Atcloud Systems.
2. Roles of the Parties
The Customer determines the purposes for which Customer Personal Data is processed. Atcloud Systems processes Customer Personal Data only as reasonably necessary to provide the Services, comply with lawful instructions, maintain security, provide support, prevent fraud, and comply with applicable law. The parties acknowledge that their legal roles may differ depending on the specific processing activity and applicable law.
3. Customer Responsibilities
The Customer is responsible for ensuring a lawful basis for processing; providing required notices; obtaining required consents; respecting Data Subject rights; ensuring data accuracy; determining appropriate retention periods; providing lawful instructions; and ensuring that Customer Data is not unlawfully submitted to the Services. The Customer must not submit sensitive or regulated information unless the Services and applicable agreement are suitable for such processing.
4. Processing Instructions
Atcloud Systems may process Personal Data as reasonably necessary to provide the Services; host and store Customer Data; provide technical support; maintain security; prevent fraud and abuse; troubleshoot technical issues; maintain backups; and comply with legal obligations. Atcloud Systems may process data according to the Customer's documented lawful instructions where applicable.
5. Confidentiality
Atcloud Systems will ensure that persons authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
6. Security Measures
Atcloud Systems will maintain reasonable technical and organizational safeguards appropriate to the nature and risks of the Services. Measures may include access controls; authentication controls; encryption in transit where appropriate; logging; backup procedures; security monitoring; incident-response procedures; personnel confidentiality obligations; and access limitation. No security measure guarantees absolute security.
7. Subprocessors
Atcloud Systems may use third-party service providers and subprocessors for hosting; cloud infrastructure; databases; authentication; payments; analytics; communications; support; security; and backups. Atcloud Systems may replace or add subprocessors where reasonably necessary. Where required by applicable law, Atcloud Systems will provide appropriate information regarding relevant subprocessors.
8. International Transfers
Customer Personal Data may be processed or accessed in countries outside the Customer's country where legally permitted. Atcloud Systems will implement measures required by applicable law for relevant international transfers.
9. Data Subject Requests
Where legally required and reasonably possible, Atcloud Systems will provide reasonable assistance to the Customer in responding to Data Subject requests. The Customer remains primarily responsible for responding to requests relating to its own processing purposes and instructions.
10. Security Incidents
If Atcloud Systems becomes aware of a confirmed Security Incident affecting Customer Personal Data, it will take reasonable steps to investigate, contain, and mitigate the incident. Where required by applicable law, Atcloud Systems will notify the Customer within a reasonable period after confirming the incident. Notifications may be made through the Customer's registered account contact. The Customer is responsible for determining whether and how to notify regulators or Data Subjects where the Customer is legally responsible for such notification.
11. Government Requests
Atcloud Systems may disclose Personal Data where required by law, court order, governmental authority, or valid legal process. Where legally permitted, Atcloud Systems may notify the Customer of such request.
12. Data Deletion and Return
Following termination, the Customer may export Customer Data where export functionality is available. Atcloud Systems may delete Customer Data according to its retention practices and applicable law. Atcloud Systems may retain information where necessary for legal, tax, accounting, security, fraud-prevention, dispute-resolution, or other lawful purposes.
13. Audits
The Customer may request reasonable information concerning Atcloud Systems' data-protection practices. Audits must be reasonably requested; respect confidentiality; not compromise security; not disrupt operations; and not expose information about other customers. Any audit costs may be payable by the Customer where reasonably incurred.
14. Liability
Liability relating to this DPA is subject to the liability provisions in the applicable Master SaaS Terms or written agreement unless otherwise expressly agreed in writing.
15. Order of Precedence
If this DPA conflicts with the Master SaaS Terms regarding data processing, this DPA controls only for the specific conflict.
16. Term
This DPA remains effective while Atcloud Systems processes Customer Personal Data on behalf of the Customer.
Contact
Data protection queries: privacy@atcloudsystem.com.