Legal
Data Processing Addendum
Effective 12 July 2026
This Data Processing Addendum ("DPA") forms part of the RakshEx Terms of Service or an Order Form (the "Agreement") between the Customer and Rashi Technologies, operating RakshEx ("Processor"). It applies when Processor processes Personal Data on Customer's behalf.
1. Roles and Scope
Customer is the controller, business, or data fiduciary and Processor is the processor, service provider, or data processor, as applicable. Customer determines the purpose and means of processing Customer Personal Data. Processor will process Customer Personal Data only on documented instructions from Customer, including the Agreement, this DPA, product configuration, and authorised support requests, unless required by applicable law.
The processing details are in Annex 1. Customer is responsible for the lawfulness, accuracy, transparency, and rights basis for Customer Personal Data and for ensuring that its instructions do not violate law.
2. Processor Commitments
Processor will:
- process Customer Personal Data only to provide, secure, support, and improve the Service as authorised by Customer;
- ensure personnel are bound by confidentiality obligations;
- maintain appropriate technical and organisational measures described in Annex 2;
- assist Customer, taking account of the nature of processing, with data-subject requests, data-protection impact assessments, consultations, security obligations, and breach notifications;
- notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data, and provide available information needed for Customer's response;
- not sell Customer Personal Data or use it for advertising or general-model training;
- make available information reasonably necessary to demonstrate compliance and permit a reasonable audit process under Section 7; and
- at Customer's choice on termination, return or delete Customer Personal Data, unless retention is required by law.
Processor will promptly inform Customer if an instruction appears to violate applicable data-protection law, unless prohibited from doing so.
3. Confidentiality and Security
Processor limits access to personnel and subprocessors with a need to know. Processor maintains the security measures in Annex 2 and may update them if the overall level of protection is not materially reduced. Customer is responsible for its account roles, endpoint security, authorisations, backup choices, and provider credentials.
4. Subprocessors
Customer gives general written authorisation for Processor to use the subprocessors and categories in the Subprocessor Register. Processor will impose written data-protection obligations on subprocessors that are materially no less protective than this DPA and remains responsible for its obligations.
Processor will give at least 30 days' notice through the Subprocessor Register or Customer's designated administrative contact before adding or replacing a material subprocessor that processes Customer Personal Data. Customer may object on reasonable data-protection grounds during that period. The parties will work in good faith on a reasonable alternative; if none is available, Customer may terminate the affected Service and receive a pro-rata refund of unused prepaid fees for that affected Service.
5. International Transfers
Processor may process data in locations required to provide the Service. Where a transfer of Personal Data from the EEA, Switzerland, or United Kingdom requires a transfer mechanism, the parties will use the applicable Standard Contractual Clauses ("SCCs") or UK addendum, completed with this DPA's annexes. For EEA controller-to-processor transfers, the parties intend Module Two of Commission Implementing Decision (EU) 2021/914, with this DPA supplying the processing and security annexes. The parties will complete any required SCC options, parties, competent authority, and local addendum in an Order Form before relying on them.
6. Requests and Legal Demands
Processor will not respond to a request from a data subject except as authorised by Customer or required by law. If Processor receives a legally binding request for Customer Personal Data, it will notify Customer before disclosure where legally permitted and will disclose only what is required.
7. Audit and Information Rights
Once every 12 months, and additionally after a confirmed material incident, Customer may request current security documentation, a completed questionnaire, and relevant independent reports if available. If that is insufficient, Customer may conduct a remote audit or engage an independent auditor under confidentiality, with at least 30 days' notice, during normal business hours, without unreasonable interference, and at Customer expense. On-site access requires written agreement and is limited to systems processing Customer Personal Data.
8. Deletion and Return
During the subscription term, Customer may export available Customer Data through the Service. After termination, Processor will delete or de-identify Customer Personal Data according to the Privacy Policy and Customer's retention configuration, except for data retained for legal, security, billing, fraud-prevention, backup, or dispute purposes. Backup copies are deleted on a rolling schedule and remain protected until overwritten.
9. Conflict and Priority
This DPA prevails over conflicting privacy or data-processing terms in the Agreement. It does not reduce rights granted by mandatory law. If the SCCs apply and conflict with this DPA, the SCCs prevail for the relevant transfer.
Annex 1: Processing Details
Subject matter: delivery, security, administration, support, and improvement of the RakshEx AI governance and security Service.
Duration: the Agreement term plus deletion and legally required retention periods.
Nature and purpose: account administration, workspace configuration, credential and provider governance, scanning, telemetry and audit processing, policy evaluation, billing, support, incident response, and Customer-directed integrations.
Categories of data subjects: Customer personnel, authorised users, developers, contractors, end users represented in Customer Data, and individuals whose data appears in Customer-controlled source, logs, API specifications, or telemetry.
Categories of personal data: account identifiers, contact details, role and authentication data, IP and log data, workspace configuration, pseudonymous usage data, and Customer-controlled data that Customer submits or routes through the Service. Customer should not submit special-category, regulated health, payment-card, biometric, or highly sensitive data unless the Service configuration, DPA annexes, and applicable law support that use.
Sensitive data: not required for the standard Service. If Customer chooses to process it, Customer must document its lawful basis and configure appropriate controls, including private relay or self-hosted deployment where necessary.
Annex 2: Security Measures
- TLS for supported network connections and encrypted credential storage using a workspace-scoped vault design.
- Password hashing, access control, role-based workspace permissions, CSRF protections, rate limits, and audit logging for sensitive actions.
- Metadata-first secret discovery, credential fingerprints, masked list responses, and non-retention of raw prompts by default in hosted audit records.
- Environment separation, dependency review, code review, required CI checks, migration gates, health checks, and incident response procedures.
- Least-privilege access, production access logging, vulnerability handling, backups, restore planning, and vendor review.
- Private relay, self-hosted, customer-managed key, and data-residency options subject to an enterprise Order Form and implementation scope.
Security controls evolve with risk. Customer remains responsible for its own systems, authorised integrations, endpoints, users, and provider-account controls.
Annex 3: Contact Details
Processor privacy contact: privacy@rakshex.in
Processor security contact: security@rakshex.in
Customer contact: specified in the Order Form or workspace administration settings.
Signature Block
Customer legal name: ______________________________
Authorised signatory: ______________________________
Date: ______________________________
Rashi Technologies authorised signatory: ______________________________
Date: ______________________________