Data Processing Agreement
This Data Processing Agreement outlines our commitment to privacy and data protection when processing your data.
1. Introduction
This Data Processing Addendum (“DPA”) forms part of the agreement between the customer identified in the applicable order form, subscription, services agreement, or other agreement (“Customer”) and NitroBerry AI Private Limited (“NitroBerry”) governing the Customer’s use of NitroBerry’s services (“Agreement”).
This DPA applies to the extent NitroBerry processes Personal Data on behalf of the Customer in connection with the NitroBerry platform and related services.
This DPA is intended to address applicable data protection requirements, including, where applicable, the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”), the General Data Protection Regulation (EU) 2016/679 (“GDPR”), and other applicable data protection laws.
2. Definitions
For purposes of this DPA:
“Applicable Data Protection Law” means data protection or privacy laws applicable to the processing of Personal Data under the Agreement.
“Customer Personal Data” means Personal Data processed by NitroBerry on behalf of Customer in connection with the Services.
“Data Fiduciary” has the meaning assigned under the DPDP Act.
“Data Principal” has the meaning assigned under the DPDP Act.
“Data Processor” has the meaning assigned under the DPDP Act.
“Controller”, “Processor”, “Data Subject”, “Personal Data”, and “Personal Data Breach” have the meanings provided by Applicable Data Protection Law.
“Services” means the NitroBerry platform and related products or services supplied to Customer under the Agreement.
“Subprocessor” means a third party engaged by NitroBerry to process Customer Personal Data in connection with providing the Services.
Where terminology differs between applicable laws, references in this DPA will be interpreted using the corresponding terminology under the relevant law.
3. Roles of the Parties
3.1 DPDP Act
Where the DPDP Act applies and Customer determines the purpose for which Customer Personal Data is processed:
- Customer acts as the Data Fiduciary; and
- NitroBerry acts as the Data Processor processing Customer Personal Data on behalf of Customer.
Customer remains responsible for determining the purposes for which Customer Personal Data is processed and for complying with obligations applicable to it as a Data Fiduciary.
NitroBerry will process Customer Personal Data on behalf of Customer in accordance with the Agreement, this DPA, and Customer’s documented lawful instructions.
3.2 GDPR and Similar Laws
Where the GDPR or another law using Controller and Processor terminology applies:
- Customer acts as the Controller where it determines the purposes and means of processing;
- NitroBerry acts as the Processor processing Personal Data on Customer’s behalf.
Where Customer itself processes Personal Data on behalf of another Controller:
- Customer may act as a Processor; and
- NitroBerry may act as a Subprocessor.
3.3 NitroBerry as an Independent Data Fiduciary or Controller
NitroBerry may independently act as a Data Fiduciary, Controller, or equivalent entity for Personal Data that NitroBerry processes for its own purposes.
This may include Personal Data relating to:
- Customer account administration
- Billing
- Contract management
- NitroBerry’s legal obligations
- Security and fraud prevention
- Customer relationship management
- Customer support administration
- NitroBerry’s own business communications
Such processing is governed by NitroBerry’s Privacy Policy and does not constitute processing on behalf of Customer under this DPA.
4. Customer Instructions
NitroBerry will process Customer Personal Data only:
- To provide the Services;
- As specified by the Agreement and this DPA;
- In accordance with Customer’s documented instructions; or
- As otherwise required by applicable law.
The Agreement, this DPA, Customer’s configuration and use of the Services, and documented instructions submitted through agreed support channels constitute Customer’s documented instructions to NitroBerry.
If NitroBerry reasonably believes that an instruction violates Applicable Data Protection Law, NitroBerry may notify Customer and, where appropriate, suspend the affected processing until the issue is resolved.
5. Customer Responsibilities
Customer is responsible for ensuring that:
- Customer Personal Data is collected and processed lawfully;
- Customer has provided notices required by applicable law;
- Valid consent has been obtained where consent is required;
- Customer has another lawful authority for processing where consent is not required;
- Customer’s instructions to NitroBerry comply with Applicable Data Protection Law;
- Customer does not provide Personal Data that it is prohibited from processing through the Services;
- Customer responds appropriately to Data Principal or Data Subject requests for which Customer is responsible.
Where the DPDP Act applies, Customer is responsible for complying with applicable obligations imposed upon it as Data Fiduciary, including obligations relating to notices, consent or applicable legitimate uses, Data Principal rights, security safeguards, grievance redressal, and erasure.
6. Nature and Purpose of Processing
NitroBerry processes Customer Personal Data as reasonably necessary to provide, secure, maintain, support, and improve the contracted functionality of the Services.
Processing activities may include:
- Collection
- Recording
- Organisation
- Storage
- Retrieval
- Consultation
- Transmission
- Use
- Structuring
- Hosting
- Backup
- Troubleshooting
- Deletion
The purposes of processing are limited to providing and supporting the Services and carrying out Customer’s documented lawful instructions.
7. Categories of Personal Data
Depending on Customer’s use of the Services, Customer Personal Data may include:
- Names
- Business email addresses
- Telephone numbers
- Employee identifiers
- User account information
- Job titles
- Organisational information
- Authentication information
- Workflow records
- Task records
- Operational records
- Documents and files uploaded by Customer
- Communications submitted through the Services
- Technical and usage information
- Other Personal Data Customer chooses to process using the Services
Customer controls the Personal Data it submits to the Services and should avoid submitting Personal Data that is unnecessary for its purposes.
8. Categories of Data Principals / Data Subjects
Customer Personal Data may relate to:
- Customer employees
- Contractors
- Platform users
- Suppliers
- Customer business contacts
- Authorised representatives
- Other individuals whose Personal Data Customer lawfully processes through the Services
9. Confidentiality
NitroBerry will ensure that personnel authorised to process Customer Personal Data are subject to appropriate confidentiality obligations.
Access to Customer Personal Data will be limited to personnel who reasonably require access for purposes connected with providing or supporting the Services.
10. Security Measures
NitroBerry will implement reasonable technical and organisational security safeguards appropriate to the nature and risks of the processing.
Such safeguards may include, as appropriate:
- Encryption of data in transit
- Encryption of stored information where appropriate
- Identity and access management
- Role-based access controls
- Authentication controls
- Infrastructure and network security
- Audit logging
- Monitoring
- Backup procedures
- Recovery procedures
- Vulnerability management
- Security incident procedures
- Measures designed to detect unauthorised access
NitroBerry may update its safeguards as technologies, risks, and industry practices evolve, provided the overall protection of Customer Personal Data is not materially reduced.
11. Subprocessors
Customer authorises NitroBerry to engage Subprocessors where reasonably necessary to provide the Services.
NitroBerry will require Subprocessors that process Customer Personal Data on NitroBerry’s behalf to be subject to contractual data protection obligations appropriate to the nature of the processing.
Such obligations will include, where appropriate:
- Confidentiality
- Appropriate security safeguards
- Processing limitations
- Personal Data Breach obligations
- Deletion or return requirements
NitroBerry remains responsible for managing its Subprocessors in accordance with its obligations under this DPA.
Where required by Applicable Data Protection Law or Customer’s applicable agreement, NitroBerry will make relevant information concerning material Subprocessors available to Customer.
12. Data Principal and Data Subject Rights
Where Customer receives a request from a Data Principal or Data Subject concerning Customer Personal Data processed through NitroBerry, NitroBerry will provide reasonable assistance to Customer, taking into account the nature of the processing and functionality available within the Services.
Under the DPDP Act, such requests may concern applicable rights including:
- Access to information regarding Personal Data processing
- Correction
- Completion
- Updating
- Erasure
- Grievance redressal
- Nomination
Where other Applicable Data Protection Laws apply, assistance may also relate to other legally applicable rights.
If NitroBerry directly receives a request concerning Customer Personal Data for which Customer acts as Data Fiduciary or Controller, NitroBerry may direct the individual to Customer unless NitroBerry is legally required to respond directly.
NitroBerry will not independently make decisions concerning Customer’s obligations to Data Principals or Data Subjects unless required by law.
13. Withdrawal of Consent and Erasure
Where Customer informs NitroBerry that Customer Personal Data must be erased because:
- Consent has validly been withdrawn;
- The specified processing purpose is no longer being served;
- A valid erasure request has been accepted by Customer;
- The Agreement has terminated; or
- Applicable law otherwise requires deletion,
NitroBerry will erase or make available mechanisms for Customer to erase the relevant Customer Personal Data in accordance with the Agreement, this DPA, applicable retention requirements, and technical limitations.
Where Customer Personal Data has been provided to applicable Subprocessors, NitroBerry will require those Subprocessors to erase the relevant Personal Data where required by Applicable Data Protection Law and applicable contractual obligations.
Deletion from backup systems may occur through normal backup rotation cycles, provided Personal Data remaining solely in protected backups is not restored for active processing except where necessary for disaster recovery, security, or legal compliance.
14. Personal Data Breaches and Security Incidents
NitroBerry will notify Customer without undue delay after becoming aware of a confirmed Personal Data Breach affecting Customer Personal Data where notification to Customer is required under Applicable Data Protection Law or the Agreement.
The notification will include information reasonably available to NitroBerry that may assist Customer in fulfilling applicable breach notification obligations.
Such information may include:
- The nature of the breach
- Categories of Personal Data affected
- Known or reasonably estimated scope
- Likely consequences, where known
- Mitigation or remediation measures taken or proposed
- Relevant contact information
NitroBerry may provide information in phases as additional facts become available.
NitroBerry’s notification of an incident does not constitute an admission of fault or liability.
Where Customer acts as Data Fiduciary under the DPDP Act, Customer remains responsible for determining and fulfilling notification obligations applicable to the Data Fiduciary.
NitroBerry will provide reasonable assistance to Customer for such obligations where the breach concerns Customer Personal Data processed by NitroBerry.
15. International Data Processing
Customer acknowledges that NitroBerry and its Subprocessors may process Customer Personal Data in countries other than the country in which Customer or the relevant Data Principal is located.
Where the DPDP Act applies, NitroBerry will process Customer Personal Data outside India subject to applicable restrictions imposed by the Government of India and Customer’s lawful instructions.
Where the GDPR applies, international transfers will be made using legally recognised safeguards where required, which may include Standard Contractual Clauses or another lawful transfer mechanism.
16. Data Retention and Return
NitroBerry will retain Customer Personal Data for the period necessary to provide the Services or as otherwise permitted by the Agreement, Customer’s lawful instructions, or applicable law.
Upon termination or expiry of the Agreement, and subject to the functionality of the Services, Customer should export any Customer Personal Data it wishes to retain.
Following termination, NitroBerry will delete or anonymise Customer Personal Data in accordance with its applicable retention and deletion procedures unless:
- Customer requests lawful return of the data;
- Applicable law requires retention;
- A contractual retention period applies; or
- Limited retention is reasonably necessary for legal claims or security purposes.
Any Personal Data retained pursuant to a legal requirement will remain protected under this DPA for as long as NitroBerry retains it.
17. Audits and Compliance Information
Upon reasonable written request, NitroBerry will provide Customer with information reasonably necessary to demonstrate NitroBerry’s compliance with its applicable obligations under this DPA.
Where required by Applicable Data Protection Law, NitroBerry will reasonably cooperate with lawful audits relating to Customer Personal Data.
Audit requests must:
- Be reasonable in scope;
- Protect NitroBerry’s confidential information;
- Avoid unreasonable disruption to NitroBerry’s business;
- Not compromise the security or confidentiality of other customers;
- Comply with reasonable security requirements.
Where appropriate, NitroBerry may satisfy audit requests by providing relevant certifications, audit reports, security documentation, or questionnaire responses instead of allowing direct inspection.
18. Government and Legal Requests
If NitroBerry receives a legally binding request from a governmental, regulatory, judicial, or law-enforcement authority requiring disclosure of Customer Personal Data, NitroBerry may disclose the information required by law.
Where legally permitted and reasonably practicable, NitroBerry will notify Customer before making such disclosure.
19. Children’s Personal Data
Customer will not knowingly instruct NitroBerry to process Personal Data of children in violation of Applicable Data Protection Law.
Where processing of children’s Personal Data is permitted, Customer is responsible for satisfying requirements applicable to it as Data Fiduciary or Controller, including obtaining verifiable parental or guardian consent where required.
NitroBerry will provide reasonable assistance relating to such processing where required by Applicable Data Protection Law and relevant to NitroBerry’s role as Data Processor.
20. Significant Data Fiduciary Requirements
If Customer is designated as a Significant Data Fiduciary under the DPDP Act and additional obligations applicable to Customer affect NitroBerry’s processing of Customer Personal Data, NitroBerry will reasonably cooperate with Customer in relation to those obligations to the extent relevant to NitroBerry’s role as Data Processor and subject to the Agreement.
Nothing in this DPA represents that NitroBerry or Customer has been designated as a Significant Data Fiduciary unless such designation has actually been made under applicable law.
21. Liability
Liability arising from or related to this DPA is subject to the exclusions and limitations of liability contained in the Agreement, except to the extent such limitations are prohibited by Applicable Data Protection Law.
22. Conflict
If there is a conflict between this DPA and the Agreement regarding processing of Customer Personal Data, this DPA will control to the extent of that conflict.
If Applicable Data Protection Law imposes a mandatory requirement that conflicts with this DPA, the mandatory legal requirement will prevail.
23. Changes to this DPA
NitroBerry may update this DPA where reasonably necessary to:
- Reflect changes in Applicable Data Protection Law;
- Reflect regulatory requirements;
- Update security or operational practices; or
- Address changes to the Services.
Material changes affecting Customer’s data protection rights or obligations will be handled in accordance with the Agreement and Applicable Data Protection Law.
24. Contact
Questions concerning this DPA or NitroBerry’s processing of Customer Personal Data may be sent to:
NitroBerry AI Private Limited
Privacy & Data Protection:
privacy@nitroberry.com
General Support:
support@nitroberry.com
Where a matter concerns Customer Personal Data, Customer should identify the applicable Customer account and provide sufficient information for NitroBerry to locate and address the relevant processing activity.