Skip to content
LEGAL

Data Processing Addendum

Last updated — 26 July 2026 · v2.1

This Data Processing Addendum ("DPA") forms part of the agreement between Triophase Global Services Pvt. Ltd., a company incorporated in India with registered office at ASO-411, 4th Floor, South Block, Astra Tower, Newtown, Kolkata – 700135, West Bengal, India ("Triophase", "Processor") and the customer identified in the applicable order documentation ("Customer", "Controller") (the "Agreement").

Where the Agreement is entered into by accepting the Terms of Service, this DPA is incorporated automatically and no separate signature is required. A countersigned copy is available on request.

Where this DPA conflicts with the Agreement, this DPA prevails on matters of data protection. Where this DPA conflicts with the Standard Contractual Clauses, the Standard Contractual Clauses prevail.


1. Definitions

"Applicable Data Protection Law" means all laws relating to the protection of personal data applicable to the processing under this DPA, including the EU General Data Protection Regulation 2016/679 ("GDPR"), the UK GDPR and the Data Protection Act 2018, the Swiss Federal Act on Data Protection, and India's Digital Personal Data Protection Act, 2023 ("DPDP Act").

"Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR. Where the DPDP Act applies, "Data Fiduciary" corresponds to Controller, "Data Processor" to Processor, and "Data Principal" to Data Subject.

"Customer Personal Data" means Personal Data contained within Customer Data that Triophase processes on Customer's behalf under the Agreement.

"Sub-processor" means any third party engaged by Triophase to process Customer Personal Data.

"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914.

"UK Addendum" means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.


2. Roles and scope

2.1 The parties acknowledge that in respect of Customer Personal Data, Customer is the Controller and Triophase is the Processor. Where Customer is itself a Processor acting for a third-party Controller, Customer warrants that it has authority to instruct Triophase as a Sub-processor, and references to Controller are construed accordingly.

2.2 Triophase acts as a Controller in respect of personal data it collects for its own purposes, including account administration, billing, service security and its own marketing. That processing is governed by the Privacy Policy and not by this DPA.

2.3 This DPA applies for as long as Triophase processes Customer Personal Data.


3. Customer obligations and warranties

3.1 Customer warrants that it has a valid legal basis for the processing it instructs, has provided all notices and obtained all consents required, and that its instructions comply with Applicable Data Protection Law.

3.2 Customer is solely responsible for the accuracy, quality and legality of Customer Personal Data and for the means by which it acquired it.

3.3 Customer will not provide Triophase with production Personal Data for development, testing or demonstration purposes unless it has determined that doing so is lawful and necessary. Triophase strongly recommends synthetic or anonymised datasets for non-production environments, and Customer accepts responsibility for the consequences of choosing otherwise.

3.4 Customer will not instruct Triophase to process special category data, data relating to criminal convictions, government identifiers, or payment card data unless the parties have agreed additional safeguards in writing.

3.5 Customer is responsible for configuring the application, access permissions and retention settings within any environment Triophase delivers, once control of that environment has passed to Customer.


4. Triophase obligations

Triophase will:

4.1 Process only on documented instructions. Process Customer Personal Data only on Customer's documented instructions, including as set out in the Agreement, the order documentation, the specification and this DPA, and for no other purpose. If Triophase is required by law to process otherwise, it will inform Customer before processing unless the law prohibits that notification on important grounds of public interest.

4.2 Notify unlawful instructions. Immediately inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law. Triophase may suspend performance of that instruction pending resolution, without liability for the resulting delay.

4.3 Confidentiality. Ensure that persons authorised to process Customer Personal Data are bound by written confidentiality obligations that survive termination of their engagement, and are trained on their data protection responsibilities.

4.4 Security. Implement and maintain the technical and organisational measures set out in Annex II, taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of processing.

4.5 No training on Customer Personal Data. Not use Customer Personal Data, Customer Data or Customer's source code to train, fine-tune, evaluate or otherwise improve any machine learning model, and contractually require the same of every Sub-processor providing model inference.

4.6 Assist with data subject rights. Taking into account the nature of the processing, assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer's obligation to respond to requests to exercise Data Subject rights. Triophase will not respond to a Data Subject directly except to confirm receipt and to direct the Data Subject to Customer, unless legally compelled or instructed by Customer.

4.7 Assist with compliance. Provide reasonable assistance with data protection impact assessments and prior consultations with a Supervisory Authority, taking into account the nature of processing and the information available to Triophase.

4.8 Deletion and return. On termination or expiry, and at Customer's election made within 30 days, delete or return Customer Personal Data and delete existing copies, unless retention is required by law. In the absence of an election, Triophase will delete Customer Personal Data within 90 days of termination. Encrypted backups are deleted on the ordinary backup cycle described in Annex II.

4.9 Records. Maintain records of processing carried out on Customer's behalf, as required by Article 30(2) GDPR.

4.10 Assistance is subject to cost recovery. Assistance under 4.6 and 4.7 is provided free of charge where the effort involved is trivial. Where a request requires material engineering or professional time, Triophase may charge at its then-current professional rates, having notified Customer of the estimated cost in advance and obtained approval.


5. Personal Data Breach

5.1 Triophase will notify Customer without undue delay and in any event within 48 hours of becoming aware of a Personal Data Breach affecting Customer Personal Data.

5.2 The notification will include, to the extent then known: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, the measures taken or proposed, and a contact point for further information. Where the information is not available at once, it will be provided in phases without further undue delay.

5.3 Triophase will take reasonable steps to contain, investigate and remediate the breach, and will cooperate with Customer's own notification obligations.

5.4 Triophase's notification is not, and will not be construed as, an acknowledgement of fault or liability.

5.5 Customer is responsible for notifying Supervisory Authorities and Data Subjects where required. Triophase will not make any public statement identifying Customer in relation to a breach without Customer's prior written consent, except where legally compelled.

5.6 Where Triophase is itself subject to a reporting obligation, including to CERT-In under Indian law, it will comply with that obligation and will inform Customer that it has done so.


6. Sub-processors

6.1 Customer grants Triophase general written authorisation to engage Sub-processors, subject to this section.

6.2 The current list of Sub-processors is published at /sub-processor. Customer may subscribe to change notifications at that page.

6.3 Triophase will give Customer at least 30 days' notice before a new Sub-processor begins processing Customer Personal Data.

6.4 Customer may object to a new Sub-processor on reasonable data protection grounds within 15 days of notice. The parties will discuss the objection in good faith. If no resolution is reached, Customer may terminate the affected portion of the Agreement on written notice, and Triophase will refund prepaid fees for services not delivered as at the termination date. Termination on this ground does not entitle Customer to any other refund, damages or penalty.

6.5 Triophase will impose on each Sub-processor data protection obligations no less protective than those in this DPA, and remains fully liable to Customer for the performance of its Sub-processors' obligations.

6.6 Where a Sub-processor must be engaged at short notice to avert a material risk to service availability or security, Triophase may do so and will notify Customer as soon as practicable, and section 6.4 then applies from the date of notice.


7. International transfers

7.1 Customer authorises Triophase to transfer Customer Personal Data to India and to the countries in which its Sub-processors operate, as identified at /sub-processor.

7.2 Where Customer Personal Data protected by the GDPR is transferred to a country without an adequacy decision, the SCCs are incorporated into this DPA by reference and apply as follows:

  • Module Two (Controller to Processor) applies where Customer is a Controller.
  • Module Three (Processor to Processor) applies where Customer is a Processor acting for a third-party Controller.
  • Clause 7 (docking clause) applies.
  • Clause 9: Option 2, general written authorisation, with a notice period of 30 days as set out in section 6.3.
  • Clause 11: the optional independent dispute resolution body language does not apply.
  • Clause 17: Option 1, governed by the law of Ireland.
  • Clause 18(b): disputes resolved before the courts of Ireland.
  • Annex I, II and III of the SCCs are populated by Annex I, Annex II and the published Sub-processor list to this DPA respectively.

7.3 Where Customer Personal Data protected by the UK GDPR is transferred, the UK Addendum is incorporated, with Table 1 populated by the parties' details in this DPA, Tables 2 and 3 populated by section 7.2 and the Annexes, and Table 4 specifying that neither party may terminate under Section 19 of the Addendum.

7.4 Where the Swiss FADP applies, references in the SCCs to the GDPR are read as references to the FADP, the competent authority is the Swiss Federal Data Protection and Information Commissioner, and the term "member state" does not prevent Data Subjects in Switzerland from suing in their place of habitual residence.

7.5 Transfers of personal data out of India are made in accordance with section 16 of the DPDP Act and any restriction notified by the Central Government.


8. Audit

8.1 Triophase will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA.

8.2 Triophase will satisfy audit requests in the first instance by providing its then-current security documentation, including the Security statement, its policies in summary form, penetration test summaries where available, and written responses to a reasonable security questionnaire.

8.3 Where that documentation is genuinely insufficient to address a specific and identified concern, Customer may conduct an audit, subject to all of the following:

  • No more than once in any twelve-month period, except following a Personal Data Breach affecting Customer Personal Data or where required by a Supervisory Authority
  • At least 30 days' prior written notice
  • During normal business hours, in a manner that does not disrupt Triophase's operations
  • Limited in scope to systems and records relating to Customer Personal Data, and expressly excluding other customers' data, Triophase's commercially sensitive information, and any environment where access would breach a third-party obligation
  • Conducted by Customer or an independent auditor who is not a competitor of Triophase and who executes a confidentiality agreement acceptable to Triophase
  • At Customer's cost, including Triophase's reasonable time at its then-current professional rates

8.4 Findings are Triophase's Confidential Information and may be disclosed only to Customer's advisers and to a Supervisory Authority on request.


9. Liability

9.1 Each party's liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service or the Agreement, and any reference in those provisions to liability of a party means the aggregate liability of that party under the Agreement and this DPA together.

9.2 Nothing in this DPA limits liability that cannot be limited under Applicable Data Protection Law, or a Data Subject's rights under the SCCs.

9.3 Where Triophase pays compensation or a fine attributable to Customer's breach of this DPA, its unlawful instructions, or the inaccuracy or illegality of Customer Personal Data, Customer will indemnify Triophase for that amount and for reasonable associated costs.


10. General

10.1 This DPA takes effect on the effective date of the Agreement and continues until Triophase ceases to process Customer Personal Data.

10.2 Triophase may amend this DPA where necessary to comply with Applicable Data Protection Law, on 30 days' notice. Where an amendment materially reduces Customer's protections, Customer may object and terminate the affected services under the process in section 6.4.

10.3 Except as modified by the SCCs, this DPA is governed by the law stated in the Terms of Service, and the courts identified there have exclusive jurisdiction.

10.4 If any provision is held invalid, the remainder continues in force.


Annex I — Details of processing

A. List of parties

Data exporter: Customer, as identified in the order documentation. Role: Controller (or Processor, where section 2.1 applies). Contact: as stated in the order documentation. Activities: receipt of software development, specification and related services from Triophase.

Data importer: Triophase Global Services Pvt. Ltd., ASO-411, 4th Floor, South Block, Astra Tower, Newtown, Kolkata – 700135, West Bengal, India. Role: Processor. Contact: privacy@triophase.com. Activities: specification, design, development, testing, deployment, hosting of non-production environments, and, where the order documentation provides for it, hosting and operation of production environments, and support of software on Customer's instructions.

B. Description of transfer

Item Detail
Categories of Data Subjects Customer's personnel and contractors; Customer's own customers and end users; Customer's suppliers and business contacts; any other Data Subject whose data Customer places in an environment to which Triophase has access
Categories of Personal Data Identity and contact data; account and authentication data; role and permission data; usage, transaction and content data held within the application; technical identifiers including IP address and device data; any other category Customer chooses to place in scope
Sensitive data None, unless separately agreed in writing under section 3.4. Where agreed, restrictions and safeguards will be recorded in the order documentation
Frequency Continuous for the duration of the engagement
Nature of processing Collection, storage, organisation, structuring, retrieval, consultation, use, testing, migration, transmission, restriction, erasure and destruction, as necessary to deliver the services
Purpose Specification, design, development, testing, deployment, migration, support and maintenance of software for Customer, and where agreed, ongoing hosting and operation of the delivered application
Retention For the duration of the engagement, then as set out in section 4.8
Sub-processor processing As set out at /sub-processor, for the duration of the engagement

C. Competent Supervisory Authority

Determined in accordance with Clause 13 of the SCCs. Where Customer is established in the EEA, the authority of Customer's place of establishment. Where Customer is not established in the EEA but has appointed an Article 27 representative, the authority of the member state of that representative. Otherwise, the authority of the member state in which the Data Subjects are located.


Annex II — Technical and organisational measures

The measures below are summarised. The full statement is published at /security and is incorporated into this Annex by reference.

Access control. Role-based access on a least-privilege basis. Multi-factor authentication required on all administrative and production-adjacent systems. Access reviewed at least quarterly and revoked within one business day of role change or departure. No shared accounts.

Environment isolation. Each project is built in a dedicated, ephemeral build environment and previewed on a per-project staging server. Environments are not shared between customers. Environments are destroyed on project completion in accordance with the retention schedule.

Encryption. TLS 1.2 or above in transit. AES-256 or equivalent at rest. Object storage encrypted at rest with additional application-layer encryption. Credentials and secrets held in an encrypted secrets store, never in source control, never in plain text in configuration.

Secure development. Test-driven development with defined coverage expectations. Peer and senior engineer review of all AI-generated output before acceptance. Automated dependency vulnerability scanning. Static analysis in the pipeline. Pipeline completion is the authoritative signal that a milestone is complete.

Logging and monitoring. Authentication events, administrative actions and infrastructure changes logged. Logs retained for 12 months and protected against unauthorised alteration.

Resilience. Encrypted backups on a rolling cycle of up to 90 days. Restore procedures tested periodically. Documented business continuity and disaster recovery arrangements.

Personnel. Background verification carried out on all employees and contractors before engagement, to the extent permitted by applicable law. Written confidentiality obligations for all personnel and contractors. Data protection and security awareness training on onboarding and at least annually. Documented offboarding checklist covering credential revocation and device handling.

Vendor management. Sub-processors assessed before engagement and bound by written data protection terms. Sub-processor list maintained publicly.

Incident response. Documented incident response plan with defined severities, escalation paths and notification timelines, tested periodically.

Pseudonymisation and minimisation. Synthetic or anonymised datasets used in non-production environments by default. Personal data collected and retained on a minimisation basis.

Self-operated systems. Source control and CI run on a self-managed GitLab instance, and error tracking and application monitoring are self-hosted. Customer source code and runtime data are not held by third-party code hosting or monitoring services.

Cookies

We use essential cookies to run this site, and — with your agreement — analytics cookies to understand how it is used. You can change your mind by clearing your cookies. Cookie Policy