RainDrive | Disaster Recovery as a Service
Data Processing Addendum – RainDrive

DATA PROCESSING ADDENDUM (DPA)

(RainDrive – DPDP Act, 2023 Aligned)

Document Version: v1.0

Effective Date: 05 February 2026

This Data Processing Addendum (“DPA”) forms an integral part of the RainDrive Managed Backup & Disaster Recovery Service Agreement and shall not exist independently.

This Data Processing Addendum (“DPA”) forms part of the RainDrive Managed Backup & Disaster Recovery Service Agreement (“Agreement”) entered between:

Indsys Tech Services India Pvt Ltd, operating RainDrive (“Service Provider”) and [Customer Legal Name] (“Customer”).

This DPA is effective from [Effective Date].

1. Purpose of This DPA

This DPA sets out the terms under which the Service Provider processes Personal Data on behalf of the Customer in accordance with the Digital Personal Data Protection Act, 2023 (India) (“DPDP Act”).

2. Roles Under DPDP Act

The Customer acts as the Data Fiduciary

The Service Provider (Indsys / RainDrive) acts as the Data Processor

The Service Provider shall process Personal Data only on documented instructions of the Customer and strictly for the purpose of delivering RainDrive services.

3. Nature & Purpose of Processing

3.1 Nature of Processing

Processing includes:

  • Secure storage of backup data
  • Transfer of encrypted backup data
  • Restore operations upon customer request
  • Monitoring required for service delivery

3.2 Purpose

Processing is limited to:

  • Providing managed backup and recovery services
  • Ensuring service reliability and security
  • Meeting contractual obligations

4. Categories of Data

4.1 Data Subjects

May include:

  • Customer employees
  • Contractors
  • Authorized users
  • Business contacts

4.2 Types of Personal Data

May include:

  • Business contact information
  • Files and system data included in backups
  • RainDrive does not intentionally collect or analyze sensitive personal data unless explicitly disclosed and required by the Customer.

5. Data Ownership

All Personal Data and Backup Data remain the sole property of the Customer.

Nothing in this DPA transfers ownership rights to the Service Provider.

6. Security Measures

The Service Provider shall implement reasonable technical and organizational measures, including:

  • Encryption in transit and at rest
  • Access controls and authentication
  • Restricted administrative access
  • Logging and monitoring

The Customer acknowledges that no system can guarantee absolute security.

7. Access & Confidentiality

Access to Personal Data is limited to authorized personnel only

Personnel are bound by confidentiality obligations

Backup data content is not inspected, analyzed, or used for any purpose other than service delivery

8. Sub-Processing

The Service Provider may use sub-processors (including infrastructure and technology providers) solely for delivering RainDrive services.

The Service Provider remains responsible for compliance with this DPA.

9. Data Location & Transfer

Backup data may be stored:

  • In India
  • On customer-approved infrastructure
  • In cloud environments as agreed
  • Cross-border transfers, if any, shall comply with applicable Indian laws.

10. Data Retention & Deletion

Data is retained as per the agreed backup retention policy

Upon service termination, the Customer shall be given a defined grace period to retrieve data

Data is securely deleted thereafter unless legally required to retain

11. Data Breach Notification

In the event of a personal data breach:

  • The Service Provider shall notify the Customer without undue delay
  • The Customer remains responsible for statutory notifications under the DPDP Act unless otherwise agreed

12. Assistance to Customer

The Service Provider shall reasonably assist the Customer in:

  • Responding to data principal requests
  • Meeting DPDP compliance obligations
  • Providing information required for audits (limited to scope)

13. Limitation of Liability

Liability under this DPA shall be subject to the limitations set out in the Service Agreement and SLA.

14. Term & Termination

This DPA remains effective for the duration of the Agreement and terminates automatically upon termination of the Agreement.

15. Governing Law

This DPA shall be governed by the laws of India.

Acceptance

This DPA is deemed accepted upon execution of the RainDrive Service Agreement.

Audit & Compliance Assistance

Any assistance provided by the Service Provider in connection with audits or compliance requests shall be reasonable, limited to the scope of services, and subject to confidentiality and security obligations. The Service Provider is not obligated to permit onsite audits unless explicitly agreed in writing.