Operating Corporate Entity: Infimatrix Technologies Private Limited (India)
This Data Processing Addendum forms an integral part of the Zero-X Cloud product suite to govern the processing of personal data across global enterprise jurisdictions.
Customer acts as the Data Controller / Data Fiduciary, and Infimatrix acts as the Data Processor / Sub-fiduciary processing Personal Data solely on behalf of, and under the strict documented instructions of, the Customer as set out in this framework and applicable automated dashboard choices. If Infimatrix believes that an instruction infringes applicable Data Protection Laws, it shall promptly notify Customer and may suspend performance without liability.
Technical Safeguards: Infimatrix shall maintain technical and organizational measures aligned with ISO/IEC 27001:2022 standards, ensuring role-based access controls (RBAC), multi-factor authentication (MFA), TLS 1.3 transit encryption, and AES-256 rest encryption safeguards across multi-tenant environments.
48-Hour Breach Notification: In the event of an actual or reasonably suspected Security Incident involving Personal Data, Infimatrix shall notify Customer within forty-eight (48) hours of discovery, providing detailed metrics regarding affected data categories, approximate volumes, and proposed mitigation paths.
Taking into account the automated nature of the SaaS processing environment, Infimatrix shall implement functional measures to assist the Controller in fulfilling its obligations to respond to data principals exercising rights under applicable law. If Infimatrix receives a direct request from a data principal or data subject seeking to exercise their legal rights in relation to Personal Data processed on behalf of Customer, Infimatrix shall forward the request to Customer within five (5) business days of receipt. Infimatrix shall not respond to the data principal directly without Customer’s express prior written authorization.
4.1 Infimatrix shall maintain a current and accurate list of all Sub-processors engaged in the Processing of Personal Data under this DPA (the “Sub-processor List”), published at www.infimatrix.com/legal#subprocessors (the “Sub-processor URL”).
4.2 Infimatrix shall notify Customers of any intended addition or replacement of a Sub-processor by simultaneously: (a) updating the Sub-processor List at the Sub-processor URL; and (b) sending a single notification email to the primary account email address on file for each active Customer. Both actions shall be completed at least thirty (30) days before the new Sub-processor begins Processing Personal Data.
4.3 Customer may object to the engagement of a new Sub-processor on reasonable data protection grounds by notifying Infimatrix in writing within fourteen (14) days of receiving the notification under Clause 4.2. If Customer raises a timely objection, the parties shall negotiate in good faith to resolve it within a further fourteen (14) days. If unresolved, Customer may terminate the affected Services on written notice without liability for early termination fees. Failure to raise an objection within fourteen (14) days shall be deemed acceptance of the new Sub-processor.
Standard Erasure Window: Upon expiration or termination of the SaaS subscription, Infimatrix shall, at Customer’s written election, securely return all Personal Data in a commonly used machine-readable format or permanently delete all copies from its active multi-tenant production systems and backup paths within thirty (30) days. Written certification confirming structural deletion shall be delivered to the Customer within fourteen (14) days of completion.
Statutory Legal Holds Protocol: Infimatrix may retain Personal Data beyond standard deletion windows only to the extent and for the duration required by applicable statutory Law or regulatory audit mandates. In such instances, Infimatrix shall notify the Customer in writing when a hold is formally invoked (unless legally prohibited by regulatory enforcement orders). The data shall remain strictly isolated, heavily encrypted, and barred from any general commercial processing. Infimatrix covenants to execute destruction or return procedures within thirty (30) days once the underlying statutory hold is officially lifted.
Application: This module applies to the processing of Personal Data of data principals located in India under the DPDPA.
Compliance Standards: Infimatrix shall assist Customer in fulfilling all Section 13 data principal rights, including summary processing reviews, structural erasure, the right to nominate, and formal grievance redressal handled through our mandatory 48-hour acknowledgment window. Unresolved disputes may be escalated to the Data Protection Board of India.
Application: This module satisfies the mandatory processing requirements of Article 28 of the GDPR.
Explicit Article 28(3) Covenants: In accordance with Article 28(3) of the GDPR, Infimatrix complies with each of the following specific obligations:
(a) Documented Instructions: Process Personal Data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by Union or Member State law to which the processor is subject.
(b) Confidentiality: Ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
(c) Security of Processing: Take all measures required pursuant to Article 32 of the GDPR, as detailed in Section IV, Clause 2 of this Data Processing Addendum.
(d) Sub-Processors: Respect the conditions referred to in Articles 28(2) and 28(4) of the GDPR for engaging another processor, as set out in Section IV, Clause 4 of this Data Processing Addendum.
(e) Data Subject Rights: Taking into account the nature of the processing, assist the controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the controller’s obligation to respond to requests for exercising data subjects’ rights under Chapter III of the GDPR.
(f) Controller Assistance: Assist the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to the processor.
(g) Deletion or Return: At the choice of the controller, delete or return all personal data to the controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the personal data.
(h) Audits and Inspections: Make available to the controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
Where Customer Data containing Personal Data of EU/EEA data subjects is transferred from the EU/EEA to Infimatrix in India, such transfer is effected pursuant to the Standard Contractual Clauses adopted by the European Commission under Decision (EU) 2021/914 of 4 June 2021 (the “SCCs”), which are incorporated into this DPA by reference and form a binding part of it. The SCCs are accessible at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en
Module Two (Controller-to-Processor) of the SCCs applies where Customer is the Data Controller; Module Three (Processor-to-Processor) applies where Customer is itself a Data Processor acting on behalf of an upstream controller. The specific optional clause elections made by the parties are set out in the SCC Elections Schedule at the end of this DPA.
Application: This Module applies to the Processing of Personal Data of data subjects located in the United Arab Emirates under the UAE PDPL.
Processing Standards: Customer is the Controller; Infimatrix is the Processor. Processing shall be executed strictly on Customer’s documented instructions, and technical safeguards must align with UAE Data Office regulations. Security incidents must be reported to the Controller within forty-eight (48) hours of discovery. Cross-border transfers require strict alignment with UAE adequacy frameworks or appropriate contractual safeguards approved under the UAE PDPL. Disputes relating solely to this module may be referred to the competent courts of the United Arab Emirates.
Application: This Module applies to the Processing of Personal Information of consumers located in the United States under applicable comprehensive state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and other substantially similar comprehensive state privacy laws in force from time to time (collectively, “US State Privacy Laws”).
Processing Standards: Customer is the Business or Controller, and Infimatrix acts as the Service Provider, Contractor, or Processor (as applicable under the relevant US State Privacy Law), Processing Personal Information solely for the specific business purposes disclosed in this DPA or the applicable Service Order. Infimatrix shall not: (a) sell or share Personal Information, as those terms are defined under the CCPA; (b) retain, use, or disclose Personal Information for any purpose outside the direct business relationship between the parties, including for cross-context behavioral advertising; or (c) combine Personal Information received from Customer with personal information received from or on behalf of any other source, except as permitted under applicable US State Privacy Laws.
Certification: Infimatrix certifies that it understands the restrictions set out in this Module and shall comply with them.
Consumer Rights Assistance: Infimatrix shall provide reasonable assistance to Customer in responding to verified consumer requests to exercise rights of access, deletion, correction, portability, and opt-out under applicable US State Privacy Laws, consistent with the request-forwarding procedure set out in Section IV, Clause 3.
Security Incidents: Security Incidents involving Personal Information of US consumers shall be notified in accordance with the forty-eight (48) hour notification standard set out in Section IV, Clause 2, which meets or exceeds the “without unreasonable delay” standard applicable under US State Privacy Laws and applicable state data breach notification statutes.
California Private Right of Action: Customer acknowledges that California uniquely affords consumers a private right of action for certain data breaches resulting from a business’s failure to implement reasonable security procedures. Nothing in this DPA limits Infimatrix’s security obligations under Section IV, Clause 2 or the Data Security Baseline set out in Section I, Clause 7.
Mandatory Non-Compliance Notification: Infimatrix shall notify Customer promptly, and in no event later than five (5) business days, if Infimatrix determines that it can no longer meet its obligations under applicable US State Privacy Laws (Cal. Civ. Code § 1798.100(d)(4)).
Customer Monitoring and Remediation Rights: Customer maintains the right, upon reasonable written notice, to take reasonable and appropriate steps to stop and remediate any unauthorized Processing of Personal Information by Infimatrix, including under the notice referred to above (Cal. Civ. Code § 1798.100(d)(5)).
Where a Customer, in its capacity as a Data Controller or Data Fiduciary, determines that it is required by applicable Data Protection Laws to conduct a data protection impact assessment or privacy impact assessment in connection with a processing activity carried out by Infimatrix on its behalf, Infimatrix shall provide the Customer with such reasonable cooperation and information as the Customer may request to facilitate the completion of that assessment, to the extent the assessment relates to Infimatrix’s processing operations under this DPA.
For the avoidance of doubt: (a) the obligation to determine whether a DPIA is required and to conduct it rests solely with the Customer as Controller or Fiduciary; Infimatrix’s role is limited to providing operational assistance upon request; (b) this Clause does not create any right on the part of any data principal or data subject to request, receive, or review any DPIA; and (c) where prior consultation with a supervisory authority or the Data Protection Board of India is required following completion of a DPIA, Infimatrix shall cooperate with the Customer in such consultation to the extent it relates to Infimatrix’s processing activities under this DPA.
This Schedule sets out the elections made by the parties in respect of the Standard Contractual Clauses (SCCs) incorporated into this DPA under Module 2 (GDPR). The SCCs are a European Commission template containing certain optional provisions that the contracting parties must select at the time of incorporation. References to “Clause [X]” below are to the numbered provisions within the SCCs document accessible at the link provided in Module 2 above. The elections below are binding on both parties.
Module Selection: Module Two (Controller-to-Processor) applies where Customer is the Data Controller. Module Three (Processor-to-Processor) applies where Customer is a Data Processor acting on behalf of an upstream controller.
Clause 7 — Docking Clause: Omitted. Additional controllers or processors may not accede to this DPA without the prior written consent of both parties.
Clause 9(a) — Sub-Processor Authorisation: Option 2 applies. Infimatrix shall give Customer thirty (30) days’ prior written notice of any new Sub-processor, consistent with Clause 4.2 of this DPA.
Clause 11 — Redress: The optional language permitting data subjects to lodge complaints with an independent dispute resolution body is omitted.
Clause 17 — Governing Law: Option 1 applies. The SCCs are governed by the laws of Ireland as a Member State of the European Union.
Clause 18(b) — Choice of Forum: Disputes arising under or in connection with the SCCs shall be resolved before the courts of Ireland.
Annex I and Annex II: The identity of the Data Exporter (Customer) and Data Importer (Infimatrix Technologies Private Limited), together with the description of the processing activities and security measures set out in this DPA, constitute the information required by Annex I and Annex II of the SCCs respectively.