Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the agreement under which Cruzetec Solutions, a partnership firm, Mohali (SAS Nagar), Punjab, India ("Provider"), provides ServerPulse to the customer that accepted the Terms of Service ("Customer"). It applies to personal data the Provider processes on the Customer's behalf, and is written to satisfy section 8(2) of India's Digital Personal Data Protection Act, 2023 and Article 28 of the GDPR.
1. Roles
For visitor and security data collected from the Customer's monitored sites, the Customer is the Data Fiduciary / controller and the Provider is the Data Processor. For account, billing and sign-in data, the Provider is an independent Data Fiduciary under its privacy notice.
2. Instructions
The Provider processes Customer personal data only on the Customer's documented instructions — the Terms, this DPA, and the configuration the Customer sets in the console (sites, agent collection settings, retention, IP masking, alert channels) — unless the law requires otherwise, in which case it tells the Customer first where the law allows. The Provider will say if it believes an instruction infringes data-protection law.
3. Confidentiality
Everyone authorised to process Customer personal data is bound by confidentiality and accesses it only as needed to provide or support the service.
4. Security
The Provider maintains the technical and organisational measures in Annex 2 and keeps them appropriate to the risk.
5. Subprocessors
The Customer authorises the subprocessors in Annex 3. The Provider gives at least 30 days' notice (email to company owners) of an addition or replacement; the Customer may object on reasonable data-protection grounds, and if no solution is found may terminate the affected service with a pro-rata refund. Each subprocessor is bound by obligations no less protective than these, and the Provider remains responsible for them.
6. Assisting the Customer
- Rights requests: the console lets the Customer find, export and delete visitor records and shorten retention; requests the Provider receives directly are forwarded to the Customer without delay.
- Breaches: the Provider notifies the Customer without undue delay and in any event within 24 hours of becoming aware of a personal-data breach affecting Customer data, with what is known and updates as they come, so the Customer can meet its own duty to inform the Data Protection Board and affected people (DPDP Rules r.7: without delay, detailed report within 72 hours).
- Assessments: reasonable help with data-protection impact assessments and consultations with authorities.
7. Deletion at the end
During the service the Customer can export its data from the console. On termination, or when the Customer deletes its company, all Customer personal data is erased after a 14-day grace period (and backups roll off on their own cycle), except where the law requires the Provider to keep something — such as tax invoices.
8. Demonstrating compliance
The Provider makes available the information needed to show compliance with this DPA — this page, the security page, and written answers to reasonable questionnaires — and allows an audit by the Customer or an auditor it appoints, at the Customer's cost, on 30 days' notice, no more than once a year unless a breach makes it necessary, under confidentiality and without access to other customers' data.
9. Transfers
Customer personal data is hosted by the Provider's hosting provider and transferred abroad only to the subprocessors in Annex 3 that are abroad. Transfers comply with DPDP s.16 (no transfer to a country the Government of India restricts) and, for data subject to the GDPR, rely on the EU Standard Contractual Clauses (Module 3, processor to processor) incorporated by reference.
10. General
Liability is as limited in the Terms. If this DPA and the Terms conflict on data protection, this DPA prevails. It is governed by the laws of India; the the courts at SAS Nagar (Mohali), Punjab have jurisdiction.
Annex 1 — Processing
- Subject matter and duration: monitoring the Customer's websites and servers for as long as the service is provided.
- Nature and purpose: collection (by the agent the Customer installs), storage, analysis, display and alerting.
- Data subjects: visitors to the Customer's monitored sites; people who attempt to attack them; the Customer's site users where a username appears in a security event.
- Personal data: IP address (optionally masked in display), country and network, request time, method, path and query string, status, response size and time, referrer, user agent, a daily-rotating salted session key, usernames tried in failed logins, short excerpts of malicious input.
- Special categories: none intended. The Customer must not configure the service to collect them.
- Retention: traffic 14 days, security events 90 days, or shorter as the Customer sets.
Annex 2 — Security measures
- TLS 1.2+ for all traffic with HSTS; agent requests HMAC-signed with replay protection; signed agent updates.
- Encryption at rest for secrets (agent secrets, 2FA seeds, repository tokens, webhook addresses); passwords bcrypt-hashed; API tokens stored as hashes.
- Tenant isolation enforced per request and by authorisation policies; four-role access model; two-factor authentication and passkeys; password confirmation for sensitive actions.
- Rate limiting and account lockout; security-event logging with alerting; audit log of administrative actions kept one year.
- Strict browser security headers (CSP with nonces, frame-ancestors none, HSTS); outbound requests to customer-supplied addresses resolved, vetted and pinned against SSRF.
- Automated retention enforcement; documented breach-response procedure with a breach register.
- Dependency auditing in the release process; least-privilege service accounts; production secrets outside the code repository.
Annex 3 — Subprocessors
- Hostinger International Ltd. (VPS data-centre region as provisioned) — Hosting of the platform (virtual private server, database, backups) and, for now, outgoing email.
- Anthropic, PBC (United States) — AI analysis of suspicious files and findings, the console assistant, and code-fix explanations.
- Razorpay Software Private Limited (India) — Payment collection for invoices.
- Team Cymru Inc.; regional Internet registries via rdap.org (United States / registries worldwide) — Looking up which network an IP address belongs to (attack attribution, CDN/origin detection).
Signatures
Accepting the Terms of Service accepts this DPA. Customers who need a countersigned copy can sign the download and email it to privacy@dxcslabs.com.
Customer: ______________________ Name / title: ______________________ Date: __________
Provider (Cruzetec Solutions): ______________________ Name / title: ______________________ signatory to be confirmed Date: __________