DATA PROCESSING ADDENDUM (DPA)
(RainDrive – DPDP Act, 2023 Aligned)
Document Version: v1.0
Effective Date: 05 February 2026
This Data Processing Addendum (“DPA”) forms an integral part of the RainDrive Managed Backup &
Disaster Recovery Service Agreement and shall not exist independently.
This Data Processing Addendum (“DPA”) forms part of the RainDrive Managed Backup & Disaster
Recovery Service Agreement (“Agreement”) entered between:
Indsys Tech Services India Pvt Ltd, operating RainDrive (“Service Provider”)
and
[Customer Legal Name] (“Customer”).
This DPA is effective from [Effective Date].
1. Purpose of This DPA
This DPA sets out the terms under which the Service Provider processes Personal Data on behalf
of the Customer in accordance with the Digital Personal Data Protection Act, 2023 (India) (“DPDP
Act”).
2. Roles Under DPDP Act
The Customer acts as the Data Fiduciary
The Service Provider (Indsys / RainDrive) acts as the Data Processor
The Service Provider shall process Personal Data only on documented instructions of the Customer
and strictly for the purpose of delivering RainDrive services.
3. Nature & Purpose of Processing
3.1 Nature of Processing
Processing includes:
- Secure storage of backup data
- Transfer of encrypted backup data
- Restore operations upon customer request
- Monitoring required for service delivery
3.2 Purpose
Processing is limited to:
- Providing managed backup and recovery services
- Ensuring service reliability and security
- Meeting contractual obligations
4. Categories of Data
4.1 Data Subjects
May include:
- Customer employees
- Contractors
- Authorized users
- Business contacts
4.2 Types of Personal Data
May include:
- Business contact information
- Files and system data included in backups
- RainDrive does not intentionally collect or analyze sensitive personal data unless
explicitly disclosed and required by the Customer.
5. Data Ownership
All Personal Data and Backup Data remain the sole property of the Customer.
Nothing in this DPA transfers ownership rights to the Service Provider.
6. Security Measures
The Service Provider shall implement reasonable technical and organizational measures, including:
- Encryption in transit and at rest
- Access controls and authentication
- Restricted administrative access
- Logging and monitoring
The Customer acknowledges that no system can guarantee absolute security.
7. Access & Confidentiality
Access to Personal Data is limited to authorized personnel only
Personnel are bound by confidentiality obligations
Backup data content is not inspected, analyzed, or used for any purpose other than service
delivery
8. Sub-Processing
The Service Provider may use sub-processors (including infrastructure and technology providers)
solely for delivering RainDrive services.
The Service Provider remains responsible for compliance with this DPA.
9. Data Location & Transfer
Backup data may be stored:
- In India
- On customer-approved infrastructure
- In cloud environments as agreed
- Cross-border transfers, if any, shall comply with applicable Indian laws.
10. Data Retention & Deletion
Data is retained as per the agreed backup retention policy
Upon service termination, the Customer shall be given a defined grace period to retrieve data
Data is securely deleted thereafter unless legally required to retain
11. Data Breach Notification
In the event of a personal data breach:
- The Service Provider shall notify the Customer without undue delay
- The Customer remains responsible for statutory notifications under the DPDP Act unless
otherwise agreed
12. Assistance to Customer
The Service Provider shall reasonably assist the Customer in:
- Responding to data principal requests
- Meeting DPDP compliance obligations
- Providing information required for audits (limited to scope)
13. Limitation of Liability
Liability under this DPA shall be subject to the limitations set out in the Service Agreement
and SLA.
14. Term & Termination
This DPA remains effective for the duration of the Agreement and terminates automatically upon
termination of the Agreement.
15. Governing Law
This DPA shall be governed by the laws of India.
Acceptance
This DPA is deemed accepted upon execution of the RainDrive Service Agreement.
Audit & Compliance Assistance
Any assistance provided by the Service Provider in connection with audits or compliance requests
shall be reasonable, limited to the scope of services, and subject to confidentiality and
security obligations. The Service Provider is not obligated to permit onsite audits unless
explicitly agreed in writing.