Agreement
1. Purpose and Scope
This Data Processing Agreement ("DPA") governs the processing of Personal Data by AhuraSense Technologies Private Limited on behalf of Customer in connection with AhuraSense's cloud infrastructure, AI inference, AI training, compute, GPU pod, Kubernetes, database, object storage, security, domain, application deployment, support, and related services.
This DPA applies where AhuraSense processes Personal Data as a processor, service provider, or equivalent role on behalf of Customer.
This DPA does not apply where AhuraSense processes personal data as an independent data fiduciary/controller — such as for account registration, billing, fraud prevention, legal compliance, security monitoring, or business administration. Such processing is governed by the Privacy Policy.
2. Definitions
- "Agreement" means The Terms of Service, Order Form, Master Services Agreement, statement of work, or other written agreement between the parties.
- "Customer" means The entity or individual that has entered into the Agreement with AhuraSense.
- "Customer Personal Data" means Personal Data processed by AhuraSense on behalf of Customer through the services.
- "Data Protection Laws" means Applicable privacy, data protection, cybersecurity, and data security laws, including where applicable the Digital Personal Data Protection Act 2023, GDPR, UK GDPR, and other relevant laws.
- "Data Subject" means An identified or identifiable individual to whom Personal Data relates, including a Data Principal as defined under the Digital Personal Data Protection Act 2023.
- "Personal Data" means Information relating to an identified or identifiable individual, or equivalent definition under applicable Data Protection Laws.
- "Processing" means Any operation performed on Personal Data, including collection, storage, use, transmission, disclosure, deletion, organization, retrieval, or other handling.
- "Processor" means AhuraSense where it processes Customer Personal Data on behalf of Customer.
- "Controller" means Customer where it determines the purposes and means of processing Customer Personal Data.
- "Subprocessor" means A third party engaged by AhuraSense to process Customer Personal Data on behalf of Customer.
- "Security Incident" means A confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data processed by AhuraSense.
- "Standard Contractual Clauses" means The standard contractual clauses adopted by the European Commission for transfers of personal data to third countries, and, for UK transfers, the UK International Data Transfer Agreement or the UK Addendum to the EU clauses.
3. Roles of the Parties
Customer is the controller, data fiduciary, business, or equivalent entity responsible for determining the purposes and means of processing Customer Personal Data.
AhuraSense is the processor, data processor, service provider, or equivalent entity processing Customer Personal Data on behalf of Customer.
Customer is responsible for ensuring that:
- It has a lawful basis for processing Customer Personal Data.
- It has provided required notices and obtained required consents.
- Its instructions to AhuraSense are lawful.
- Customer Personal Data may be processed through the services.
- It has selected suitable services, regions, safeguards, and configurations.
- It complies with Data Protection Laws.
AhuraSense will process Customer Personal Data only as described in this DPA, the Agreement, Customer's documented instructions, or as required by law.
4. Customer Instructions
Customer instructs AhuraSense to process Customer Personal Data as necessary to provide the services — including hosting workloads, storing Customer Data, processing API requests, providing compute and GPU resources, running AI inference and training workloads, operating Kubernetes, databases, object storage, domains, and application deployment features, providing technical support, securing the services, and preventing abuse.
Customer may provide additional instructions through account settings, dashboard configurations, API calls, support requests, written instructions, and Order Forms.
AhuraSense may decline or suspend instructions that it reasonably believes violate law, the Agreement, supplier requirements, security requirements, or acceptable use rules. Where AhuraSense considers that an instruction infringes Data Protection Laws, it will inform Customer without undue delay.
5. Details of Processing
Subject Matter
The provision of cloud infrastructure and related technical services by AhuraSense to Customer.
Duration
Processing continues for the term of the Agreement and any period required for deletion, return, backup retention, legal compliance, billing, security, or dispute resolution.
Nature and Purpose
Processing may include hosting, storage, transmission, retrieval, compute processing, AI inference, AI training, fine-tuning, embedding generation, database processing, Kubernetes orchestration, application deployment, security monitoring, backup and recovery, technical support, billing support, abuse prevention, and incident response.
Categories of Data Subjects
Customer Personal Data may relate to customer employees, contractors, administrators, developers, end users, business contacts, support users, and individuals included in datasets, files, logs, databases, prompts, outputs, or workloads uploaded by Customer.
Categories of Personal Data
Customer Personal Data may include names, email addresses, user IDs, IP addresses, device identifiers, account identifiers, application data, log data, support data, prompt and output data, dataset records, database records, files and documents, images, audio, or text submitted by Customer, and metadata.
Sensitive Data
Customer must not submit sensitive, regulated, children's, biometric, health, financial, payment card, government secret, or special-category data unless the applicable Agreement expressly permits such processing and Customer has implemented appropriate safeguards.
A consolidated summary of these details is set out in Schedule 1.
Data Protection
6. Confidentiality
AhuraSense will ensure that personnel authorized to process Customer Personal Data are subject to confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
AhuraSense will limit access to Customer Personal Data to personnel who need access to provide, secure, support, or maintain the services.
7. Security Measures
AhuraSense will implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data. These may include:
- Role-based access controls, authentication controls, and least-privilege practices.
- Encryption in transit and at rest where supported.
- Logging, monitoring, network security controls, and abuse detection.
- Vulnerability management, incident response procedures, and security testing.
- Segregation of customer environments, backup and recovery measures, and supplier security review.
The measures in place as at the effective date of this DPA are described in Schedule 2. AhuraSense may update those measures provided the overall level of protection is not materially reduced.
Customer remains responsible for securing accounts, API keys, SSH keys, passwords, secrets, containers, applications, databases, Kubernetes roles, firewalls, network policies, domain settings, AI models, training datasets, and end-user access.
8. Subprocessors
AhuraSense is generally authorised to engage Subprocessors as necessary to provide the Services. AhuraSense will maintain a public or Customer-accessible current Subprocessor List identifying Subprocessors that may process Customer Personal Data in connection with the Services. The Subprocessor List will identify, as applicable, the Subprocessor, purpose or service category and principal processing location.
Before allowing a Subprocessor to process Customer Personal Data, AhuraSense will impose written confidentiality, security, data-protection, deletion and assistance obligations appropriate to the processing.
Where required by Applicable Data Protection Law or a Customer's executed DPA, AhuraSense will provide advance notice before a new Subprocessor begins processing Customer Personal Data. Unless the executed DPA states another period, Customer may object within thirty days on reasonable data-protection grounds. The parties will attempt in good faith to resolve the objection through a reasonable alternative where commercially and technically feasible.
AhuraSense remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law and this DPA.
The current Subprocessor List is published at /subprocessors, and Customer may also request a copy by contacting [email protected].
9. US State Privacy Terms
To the extent Customer Personal Data is subject to a United States state privacy law that recognises a processor, service provider, contractor or equivalent restricted processing role, AhuraSense will act in that role to the extent required by the applicable law.
AhuraSense will not sell Customer Personal Data or share Customer Personal Data for cross-context behavioural advertising. AhuraSense will not retain, use or disclose Customer Personal Data outside the direct business relationship with Customer except as necessary to provide the Services, secure the Services, comply with Customer instructions, comply with law, prevent fraud or abuse, or as otherwise permitted for a processor or service provider under Applicable Data Protection Law.
AhuraSense will not combine Customer Personal Data received from or on behalf of one Customer with personal data received from another person or collected from AhuraSense's independent interaction with an individual except where necessary to provide the Services or otherwise permitted by Applicable Data Protection Law.
AhuraSense will provide the same level of privacy protection required of processors or service providers under Applicable Data Protection Law and will notify Customer if AhuraSense determines it can no longer meet a material applicable processing obligation. Customer may take reasonable and appropriate steps to help ensure that AhuraSense uses Customer Personal Data consistently with Customer's obligations and this DPA, subject to the audit limitations stated elsewhere in the DPA.
10. International Transfers
Customer acknowledges that AhuraSense and its Subprocessors may process Customer Personal Data in India, the United Kingdom, and other jurisdictions where services, infrastructure, support, or suppliers operate.
Where Customer Personal Data is subject to transfer restrictions, the parties will use appropriate safeguards including Standard Contractual Clauses, transfer impact assessments, data processing terms, customer-approved regions, contractual safeguards, and other lawful transfer mechanisms.
For transfers of EU/EEA personal data to a third country without an adequacy decision, the parties incorporate the European Commission's Standard Contractual Clauses, Module Two (controller to processor) or Module Three (processor to processor) as applicable, with Customer as data exporter and AhuraSense as data importer. For UK personal data, the UK International Data Transfer Agreement or the UK Addendum to the EU clauses applies. Schedules 1 and 2 serve as the corresponding annexes describing the transfer and the technical and organisational measures.
Transfers of digital personal data outside India are made in accordance with the Digital Personal Data Protection Act 2023 and any territorial restrictions notified by the Central Government.
Assistance & Incidents
11. Data Subject Requests
Taking into account the nature of processing and information available to AhuraSense, AhuraSense will provide reasonable assistance to Customer in responding to Data Subject requests, including requests to access, correct, delete, export, restrict, or object to processing, or to withdraw consent.
Customer is responsible for responding to Data Subject requests. If AhuraSense receives a request directly relating to Customer Personal Data, AhuraSense may direct the requester to Customer unless legally required to respond.
12. Compliance Assistance
AhuraSense will provide reasonable assistance to Customer for security obligations, data protection impact assessments, prior consultations with regulators where applicable, breach response, data deletion or export, audit requests, transfer safeguards, and compliance documentation.
AhuraSense may charge reasonable fees for assistance that is outside standard support or requires significant engineering, legal, compliance, or operational effort.
13. Security Incident Notification
AhuraSense will notify Customer without undue delay after becoming aware of a confirmed Security Incident affecting Customer Personal Data. The notice may include, where available:
- Nature of the incident and affected services.
- Categories of affected data and approximate number of affected records, where known.
- Likely consequences and measures taken or proposed.
- Recommended customer actions and contact point for follow-up.
Customer acknowledges that initial notices may be based on incomplete information and may be updated as investigation progresses. Customer is responsible for determining whether it must notify regulators, Data Subjects, customers, or other parties, including under GDPR Articles 33 and 34, the UK GDPR, and the breach notification requirements of the Digital Personal Data Protection Act 2023.
14. Government and Legal Requests
If AhuraSense receives a legal request for Customer Personal Data, AhuraSense will, where legally permitted and practical: notify Customer, direct the requester to Customer, challenge or narrow unlawful or excessive requests where appropriate, and disclose only the information legally required.
AhuraSense may disclose Customer Personal Data where required by law, court order, regulator, law enforcement, registry requirement, sanctions authority, or other valid legal process.
Customer Responsibilities
15. Customer Security Responsibilities
Customer must secure account credentials, use strong passwords and MFA where available, rotate keys and secrets, restrict administrative access, configure IAM and RBAC properly, avoid public exposure of private data, encrypt sensitive data where appropriate, maintain backups, test disaster recovery, monitor workloads, patch customer-managed software, review logs, remove inactive users, and report suspected incidents promptly. Schedule 4 sets out these configuration responsibilities by service area.
AhuraSense is not responsible for Security Incidents caused by Customer misconfiguration, exposed credentials, insecure code, vulnerable containers, public buckets, excessive permissions, unsupported software, or Customer failure to use available safeguards.
16. AI-Specific Processing Terms
Where Customer uses AhuraSense services for AI workloads, prompts, inputs, outputs, training and evaluation datasets, embeddings, checkpoints, adapters, and model weights submitted to or generated on the services are Customer Personal Data or Customer Data as applicable, and are processed by AhuraSense solely as a processor on Customer's documented instructions.
Unless separately agreed in writing, AhuraSense will not use Customer Personal Data or Customer Data to train, fine-tune, or evaluate foundation models for AhuraSense or third parties, and will not disclose it to other customers.
For hosted inference and training services, AhuraSense records operational metadata — including timestamps, model and endpoint identifiers, request and token counts, latency, error codes, and account identifiers — for billing, capacity management, abuse prevention, and troubleshooting. Prompt and output content is not retained in AhuraSense operational logs by default. Where Customer enables a logging, tracing, evaluation, or debugging feature that persists request content, that content is stored within Customer-controlled resources under the retention settings Customer selects, and Customer is responsible for those settings.
Customer is responsible for lawful collection and use of training data, dataset rights, consent and notice, personal data minimization, sensitive data safeguards, bias and safety testing, output validation, model license compliance, human review where required, end-user disclosures, and regulatory compliance, including any obligations arising under applicable AI-specific legislation.
AhuraSense may process operational telemetry, logs, usage metrics, and de-identified or aggregated data to provide, secure, improve, and measure the services, provided such processing does not identify Customer or disclose Customer Data.
Data Lifecycle
17. Deletion and Return
Upon termination or expiry of the Agreement, AhuraSense will delete or return Customer Personal Data in accordance with the Agreement, service functionality, and Customer instructions. Unless otherwise agreed:
- Customer should export Customer Data before termination.
- AhuraSense may delete or disable access to Customer Data after the applicable post-termination period.
- Backups may be retained until overwritten or expired according to backup cycles.
- Logs, billing records, security records, and legal records may be retained as required for compliance, security, fraud prevention, dispute resolution, and legitimate business purposes.
18. Audits and Information Rights
AhuraSense will make available information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and commercial sensitivity restrictions. Customer may request audit information no more than once annually unless a Security Incident or legal requirement justifies additional review.
Audit requests must be reasonable in scope, subject to confidentiality, non-disruptive to AhuraSense operations, and limited to controls relevant to Customer Personal Data. AhuraSense may satisfy audit obligations through security documentation, certifications, summaries, questionnaires, third-party audit reports, or written responses.
Legal
19. Liability
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement, unless prohibited by applicable law. Nothing in this DPA limits liability that cannot legally be limited.
20. Conflict
If there is a conflict between this DPA and the Agreement, this DPA controls only with respect to processing of Customer Personal Data. If there is a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses control. If there is a conflict between this DPA and mandatory Data Protection Laws, the mandatory Data Protection Laws control.
21. Term
This DPA remains in effect for as long as AhuraSense processes Customer Personal Data on behalf of Customer. Sections that by their nature should survive termination will continue to apply, including confidentiality, deletion, audit, liability, and legal compliance provisions.
Schedules
22. Schedule 1 — Processing Details
| Item | Details |
|---|---|
| Processor | AhuraSense Technologies Private Limited |
| Controller | Customer |
| Services | AI inference, AI training, compute, GPU pods, Kubernetes, databases, object storage, security, domains, application deployment, support, APIs, dashboards |
| Subject Matter | Provision of cloud infrastructure and related technical services by AhuraSense to Customer under the Agreement |
| Nature of Processing | Hosting, storage, transmission, retrieval, compute processing, inference, training, fine-tuning, embedding generation, database processing, orchestration, backup and recovery, support, monitoring, security |
| Purpose | Provision, operation, security, billing, support, and improvement of services on Customer's documented instructions |
| Duration | Term of Agreement plus deletion, backup, legal, security, and compliance retention periods |
| Frequency | Continuous for the duration of the Agreement, determined by Customer's use of the services |
| Data Subjects | Customer users, admins, developers, employees, contractors, end users, dataset subjects, application users, business and support contacts |
| Personal Data | Account data, application data, logs, prompts, outputs, datasets, files, database content, images, audio, text, identifiers, metadata, support data |
| Sensitive Data | Not permitted unless expressly allowed by the Agreement and protected by appropriate safeguards |
| Transfer Mechanism | Standard Contractual Clauses, UK IDTA or Addendum, or other lawful mechanism where transfer restrictions apply |
23. Schedule 2 — Technical & Organisational Measures
The following measures are in place as at the effective date of this DPA. AhuraSense's security programme is designed to align with recognised industry frameworks for information security management, including ISO/IEC 27001 and the CIS Critical Security Controls. AhuraSense may update these measures provided the overall level of protection is not materially reduced.
Encryption
- Encryption in transit using TLS 1.2 or higher for public endpoints, dashboards, and APIs, with weak ciphers and protocol versions disabled.
- Encryption at rest using AES-256 for managed storage, managed databases, block volumes, and backups where the service supports it.
- Key management with restricted access to key material, periodic rotation, and customer-managed encryption options where available.
Access Control and Least Privilege
- Role-based access control for production systems, provisioned on a documented need-to-know basis.
- Least-privilege defaults, with administrative and privileged access restricted to a limited set of named personnel.
- Periodic access reviews and prompt revocation of access on role change or termination.
- Unique named accounts; shared credentials are not used for production access.
Authentication
- Multi-factor authentication required for AhuraSense personnel accessing production and administrative systems.
- MFA available to Customer for account and dashboard access.
- Secrets and API credentials stored in a managed secret store rather than in source code or configuration files.
Network Security and Segmentation
- Segmentation between production, staging, corporate, and management networks.
- Firewall and security-group controls with default-deny ingress on production boundaries.
- Tenant isolation and logical separation between customer environments.
- DDoS and abuse mitigation at the network edge where available.
Logging and Monitoring
- Centralised collection of platform, access, and security event logs with restricted, tamper-resistant storage.
- Monitoring and alerting for anomalous authentication, privilege escalation, and abuse patterns.
- Audit logging of administrative actions on production infrastructure.
Vulnerability and Patch Management
- Regular vulnerability scanning of infrastructure and container images.
- Risk-based remediation timelines, with expedited handling of critical vulnerabilities.
- Patching of AhuraSense-managed operating systems, hypervisors, and platform components.
- Change management and code review for production changes.
Backup and Resilience
- Backup of platform and control-plane systems, with encryption applied to backup data.
- Backup and snapshot features for customer workloads where purchased or included in the service.
- Documented recovery procedures, periodically tested for AhuraSense-managed components.
Personnel Security and Training
- Written confidentiality obligations for all personnel with access to Customer Personal Data.
- Security and data protection awareness training at onboarding and periodically thereafter.
- Background screening for personnel in sensitive roles where lawful and applicable.
- Documented joiner, mover, and leaver processes.
Secure Disposal
- Logical deletion of Customer Data following the retention periods in the Agreement.
- Cryptographic erasure or secure wiping of storage media before reuse.
- Secure destruction or certified disposal of decommissioned media containing Customer Personal Data.
Incident Response
- Documented incident response plan covering detection, triage, containment, eradication, and recovery.
- Defined severity levels and escalation paths, with a designated security contact.
- Customer notification process for confirmed Security Incidents, as described in this DPA.
- Post-incident review and remediation tracking.
Supplier and Subprocessor Management
- Security and data protection review before engaging a Subprocessor that will process Customer Personal Data.
- Written data protection obligations imposed on Subprocessors.
- Restriction and monitoring of Subprocessor access to production systems.
24. Schedule 3 — Subprocessor Terms
AhuraSense may use Subprocessors to provide infrastructure, support, security, billing, analytics, communications, and operational services. Customer grants a general authorisation for such engagement, subject to the terms of this Schedule.
Before allowing a Subprocessor to process Customer Personal Data, AhuraSense will:
- Carry out a proportionate assessment of the Subprocessor's security and data protection practices.
- Impose written obligations that are no less protective in substance than those in this DPA, including confidentiality, security, assistance, and deletion obligations.
- Put in place an appropriate transfer mechanism where the engagement involves a restricted international transfer.
- Limit the Subprocessor's access to what is necessary to perform its function.
AhuraSense remains fully liable to Customer for the performance of a Subprocessor's data protection obligations where the Subprocessor fails to fulfil them.
Unless the executed DPA or applicable Order Form states another period, AhuraSense will give Customer at least thirty (30) days' notice before a new Subprocessor begins processing Customer Personal Data, by email to the account's notification address or through the AhuraSense website. Customer may object in writing within that notice period on reasonable data protection grounds, stating the grounds relied upon. The parties will work in good faith to resolve the objection — for example by offering an alternative region, configuration, or service. If no resolution is reached, Customer may stop using the affected service or terminate the affected Order as permitted by the Agreement, without penalty for the terminated portion. This does not limit any remedy that Applicable Data Protection Law requires to be available to Customer.
Customer may request a list of current Subprocessors by contacting [email protected].
25. Schedule 4 — Customer Configuration Responsibilities
AhuraSense secures the underlying platform. Customer is responsible for configuring and securing what it builds on top of it, including the areas below. Failure to apply these controls is a common cause of data exposure and is outside AhuraSense's responsibility.
| Area | Customer Responsibility |
|---|---|
| Identity and Access | IAM users, roles and groups, least-privilege policies, MFA enforcement, password policies, removal of inactive users, periodic access reviews |
| API Access | API keys, tokens, scope restriction, rotation schedules, revocation of leaked credentials |
| Compute | Guest OS patching and hardening, workload configuration, container image provenance and updates, host-level firewall settings |
| Network | Firewall and security group rules, ingress and egress restrictions, private networking, VPN or peering configuration, avoiding unnecessary public exposure |
| GPU Pods | Drivers and runtime versions, container security, data movement into and out of pods, job isolation and cleanup |
| Kubernetes | RBAC bindings, secrets management, namespace isolation, ingress configuration, network policies, admission controls |
| Databases | Credentials, schema and grants, encryption options, backup and point-in-time recovery settings, restricting public access |
| Object Storage | Bucket and object permissions, blocking public access, lifecycle rules, versioning, retention and object lock settings |
| Encryption Options | Enabling available encryption features, selecting customer-managed keys where offered, key rotation and custody |
| Backup and Recovery | Backup scope and frequency, retention periods, off-region copies, restore testing |
| Data Classification | Classifying data before upload, applying handling rules by class, keeping restricted and regulated data out of services not approved for it, data minimisation |
| Domains | Registrant data accuracy, DNS settings, DNSSEC where available, renewal, lawful use |
| AI Workloads | Dataset rights and lawful basis, privacy compliance, prompt and output logging settings, output review, model licence compliance |
| Applications | Application code security, dependency management, secret handling, end-user consent and disclosures, logging hygiene |
| Monitoring | Reviewing available logs and alerts, retaining audit records as required, reporting suspected incidents promptly |
26. Schedule 5 — Contact Details
AhuraSense Technologies Private Limited
CIN: [To be updated]
Registered Address: [To be updated]
Privacy Contact: [email protected]
Security Contact: [email protected]
Legal Contact: [email protected]
Grievance Officer (India, DPDP Act 2023): [To be updated]
Phone: [To be updated]
Notices under this DPA, including Subprocessor objections and Data Subject request assistance, should be sent to the privacy contact above. Security Incident reports and vulnerability disclosures should be sent to the security contact. Contractual notices, including requests for Standard Contractual Clauses, should be sent to the legal contact.
Data Principals in India may raise grievances with the Grievance Officer identified above, as required by the Digital Personal Data Protection Act 2023. Where AhuraSense acts as a processor, such grievances will ordinarily be routed to the relevant Customer as data fiduciary.