This Data Processing Agreement ("DPA") forms part of the agreement under which Cruzetec Solutions, a partnership firm, Mohali (SAS Nagar), Punjab, India ("Provider"), provides Servertorch to the customer that accepted the Terms of Service ("Customer"). It applies to personal data the Provider processes on the Customer's behalf, and is written to satisfy section 8(2) of India's Digital Personal Data Protection Act, 2023 and Article 28 of the GDPR.
For visitor and security data collected from the Customer's monitored sites, the Customer is the Data Fiduciary / controller and the Provider is the Data Processor. For account, billing and sign-in data, the Provider is an independent Data Fiduciary under its privacy notice.
The Provider processes Customer personal data only on the Customer's documented instructions — the Terms, this DPA, and the configuration the Customer sets in the console (sites, agent collection settings, retention, IP masking, alert channels) — unless the law requires otherwise, in which case it tells the Customer first where the law allows. The Provider will say if it believes an instruction infringes data-protection law.
Everyone authorised to process Customer personal data is bound by confidentiality and accesses it only as needed to provide or support the service.
The Provider maintains the technical and organisational measures in Annex 2 and keeps them appropriate to the risk.
The Customer authorises the subprocessors in Annex 3. The Provider gives at least 30 days' notice (email to company owners) of an addition or replacement; the Customer may object on reasonable data-protection grounds, and if no solution is found may terminate the affected service with a pro-rata refund. Each subprocessor is bound by obligations no less protective than these, and the Provider remains responsible for them.
During the service the Customer can export its data from the console. On termination, or when the Customer deletes its company, all Customer personal data is erased after a 14-day grace period (and backups roll off on their own cycle), except where the law requires the Provider to keep something — such as tax invoices.
The Provider makes available the information needed to show compliance with this DPA — this page, the security page, and written answers to reasonable questionnaires — and allows an audit by the Customer or an auditor it appoints, at the Customer's cost, on 30 days' notice, no more than once a year unless a breach makes it necessary, under confidentiality and without access to other customers' data.
Customer personal data is hosted by the Provider's hosting provider and transferred abroad only to the subprocessors in Annex 3 that are abroad. Transfers comply with DPDP s.16 (no transfer to a country the Government of India restricts) and, for data subject to the GDPR, rely on the EU Standard Contractual Clauses (Module 3, processor to processor) incorporated by reference.
Liability is as limited in the Terms. If this DPA and the Terms conflict on data protection, this DPA prevails. It is governed by the laws of India; the the courts at SAS Nagar (Mohali), Punjab have jurisdiction.
Accepting the Terms of Service accepts this DPA. Customers who need a countersigned copy can sign the download and email it to privacy@dxcslabs.com.
Customer: ______________________ Name / title: ______________________ Date: __________
Provider (Cruzetec Solutions): ______________________ Name / title: ______________________ signatory to be confirmed Date: __________