Data Processing Addendum
Data processing terms governing IOBend's processing of Customer Personal Data where IOBend acts as a processor or service provider on behalf of Customer.
1.Scope & Applicability
This Data Processing Addendum ("DPA") supplements the IOBend Terms of Service, Master Subscription Agreement, Enterprise Agreement, Order Form, or other written agreement (the "Agreement") entered into by and between IOBend Technologies Private Limited, an Indian private limited company ("IOBend"), and the customer identified in the Agreement ("Customer").
This DPA applies where and to the extent that IOBend processes Customer Personal Data on behalf of Customer in connection with Customer's access to and use of the IOBend Unified Developer Experience Platform, IOBend CLI, developer environments, APIs, and associated developer services (the "Services"), and where applicable data protection law requires the parties to execute data processing terms.
2.Definitions & Interpretation
"Applicable Data Protection Law" means all data privacy and personal data protection laws, rules, and regulations applicable to the processing of Customer Personal Data under the Agreement, including India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000, and, where applicable to European data subjects, the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the UK GDPR.
"Customer Personal Data" means any Personal Data submitted, configured, or transmitted by Customer or its authorized users to the Services, or processed by IOBend on Customer's behalf in the performance of the contracted Services.
"Personal Data" means any information that relates to an identified or identifiable natural person (or "Data Principal" under Indian law), as defined under Applicable Data Protection Law.
"Processing", "Controller", "Processor", and "Data Subject" have the meanings given to them under the GDPR or equivalent definitions under other data protection laws.
"Data Fiduciary" and "Data Processor" have the meanings given to them under India's DPDP Act.
"Security Incident" means a confirmed breach of IOBend's security measures leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or unauthorized access to Customer Personal Data in IOBend's custody.
"Subprocessor" means any third-party entity engaged by IOBend to process Customer Personal Data in connection with the provision of the Services.
3.Processing Roles & Legal Status
The parties acknowledge and agree that the legal characterization of each party depends on the nature of the processing activity:
- For Customer Personal Data Processed to Provide the Services: Customer determines the business purposes and means of processing developer and team data. Customer acts as a Controller (or Data Fiduciary under the DPDP Act), and IOBend acts as a Processor (or Data Processor under the DPDP Act) processing such data strictly on Customer's behalf and in accordance with Customer's documented instructions.
- For IOBend's Own Business Operations: For account billing records, direct commercial customer relationship management, and regulatory compliance data, IOBend acts independently as a Controller (or Data Fiduciary), and processes such data in accordance with our Privacy Policy.
4.Customer Instructions & Processing Scope
IOBend shall process Customer Personal Data solely:
- To provide, operate, maintain, and support the Services in accordance with the Agreement;
- In accordance with Customer's documented, lawful instructions as configured through the IOBend web console, API, or CLI;
- To maintain platform security, prevent abuse, and troubleshoot service interruptions; and
- As otherwise required to comply with Applicable Data Protection Law or statutory legal mandates.
IOBend shall not sell Customer Personal Data or process Customer Personal Data for any commercial purpose other than providing the contracted Services. If IOBend is required by applicable statutory law to process data outside Customer's instructions, IOBend will inform Customer prior to processing, unless prohibited by law on public interest grounds.
5.Details of Processing
The provision of the IOBend Unified Developer Experience Platform, CLI utilities, developer environments, devcontainers, artifact repositories, and developer control planes.
The term of the Agreement plus any post-termination retention periods required by statutory law or standard backup lifecycles.
Hosting, storage, transmission, authentication, organization/workspace management, RBAC enforcement, automated configuration scaffolding, diagnostic checks, API metering, and technical support.
User names, work email addresses, usernames, user IDs, role and permission mappings, authentication tokens, IP addresses, operational audit logs, technical support requests, and repository metadata. (Source code, repository assets, and secrets are governed by the Agreement and product documentation).
Customer's employees, software engineers, devops personnel, contractors, consultants, and authorized administrators.
6.Customer Obligations & Lawful Basis
Customer represents and warrants that:
- It has established and will maintain all necessary lawful bases, notices, and consents required under Applicable Data Protection Law to collect and transfer Customer Personal Data to IOBend;
- Its processing instructions to IOBend comply with all applicable legal requirements;
- It is solely responsible for its configuration of role-based permissions, access controls, workspace invites, and developer environment privileges; and
- It will avoid submitting unnecessary sensitive personal data (such as financial account numbers, government identifiers, or special category data) into unencrypted source code or arbitrary metadata fields.
7.IOBend Obligations
IOBend shall:
- Process Customer Personal Data in accordance with Customer's documented instructions and the Agreement;
- Implement and maintain reasonable technical and organizational security measures as described in Section 8;
- Ensure all personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations;
- Engage Subprocessors only in accordance with Section 10;
- Promptly notify Customer of confirmed Security Incidents in accordance with Section 11; and
- Provide reasonable assistance to Customer in fulfilling Data Principal and Data Subject rights requests as set forth in Section 12.
8.Technical & Organizational Measures (TOMs)
IOBend implements and maintains commercially reasonable technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access:
Data in transit is encrypted using TLS 1.3/1.2. Primary databases utilize AES-256 encryption at rest. Customer secrets utilize envelope encryption where configured.
Principle of least privilege, multi-factor authentication (MFA) for administrative access, role-based authorization, and automated session invalidation.
Centralized security event logging, rate limiting, intrusion monitoring, and regular vulnerability dependency scanning.
Automated encrypted backup snapshots, redundant database clustering, and disaster recovery replication across tier-1 cloud infrastructure.
9.Personnel Confidentiality
IOBend ensures that all employees, contractors, and technical personnel who have access to Customer Personal Data are informed of the confidential nature of the data, have received appropriate data protection training, and are bound by written confidentiality obligations that survive the termination of their employment or engagement.
10.Subprocessors & Vendor Governance
Customer provides general authorization for IOBend to engage third-party subprocessors to deliver hosting, database, security, and infrastructure services.
Our core subprocessors include Amazon Web Services (AWS), Cloudflare, MongoDB Atlas, Upstash Redis, Razorpay/Stripe, and Google Cloud (for enterprise AI processing where enabled). A current list of authorized infrastructure providers is maintained on our Trust Center.
IOBend executes written agreements with each Subprocessor containing data protection obligations substantially similar to those in this DPA. IOBend remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law and the Agreement.
11.Security Incidents & Incident Response
Upon confirming a Security Incident affecting Customer Personal Data, IOBend shall:
- Notify Customer without undue delay via email to Customer's registered primary administrator or security contact;
- Take prompt, reasonable steps to contain, mitigate, and remediate the effects of the Security Incident; and
- Provide Customer with information reasonably necessary to enable Customer to assess the incident and fulfill its statutory reporting obligations under Applicable Data Protection Law.
Notification of a Security Incident shall not be construed as an acknowledgment of fault or liability by IOBend.
12.Data Principal & Data Subject Rights
To the extent Customer cannot directly fulfill a Data Subject or Data Principal request through the self-service capabilities of the IOBend platform (e.g., workspace user deletion or role revocation), IOBend shall, taking into account the nature of the processing, provide reasonable assistance to Customer in responding to verified requests for access, correction, erasure, or nomination under Applicable Data Protection Law.
If IOBend receives a request directly from a Data Subject concerning Customer Personal Data, IOBend will advise the individual to submit their request directly to Customer.
13.Government Inquiries & Legal Disclosures
If IOBend receives a legally binding order, subpoena, or inquiry from a government authority or court of competent jurisdiction seeking access to Customer Personal Data, IOBend will, unless legally prohibited, notify Customer promptly to allow Customer to seek a protective order or appropriate legal remedy.
14.Data Deletion, Return & Backup Lifecycles
Upon termination or expiration of the Agreement, IOBend will, at Customer's election and subject to the terms of the Agreement, delete or return all Customer Personal Data in its possession or control, except where retention is required by applicable law, tax or corporate accounting regulations, or ongoing dispute resolution.
Backup Snapshots Lifecycle
Customer Personal Data may remain temporarily in encrypted backup or disaster-recovery systems until those systems are overwritten or rotated in accordance with IOBend's routine backup lifecycle. Such backup data is isolated and rendered inaccessible to active operations.
15.International Transfers & Data Hosting
Customer acknowledges that IOBend utilizes cloud hosting and subprocessor infrastructure that may process Customer Personal Data in data centers located in India, the United States, and the European Union.
Where cross-border data transfers occur, IOBend implements reasonable administrative, organizational, and technical safeguards in accordance with Applicable Data Protection Law and contractual transfer requirements.
16.Jurisdiction Provisions (India DPDP & GDPR)
A. India — DPDP Act Framework
Where the processing of Customer Personal Data is governed by the Digital Personal Data Protection Act, 2023, Customer acts as the Data Fiduciary and IOBend acts as the Data Processor. IOBend processes personal data solely for the purpose of fulfilling the contracted Services and maintains technical safeguards in compliance with the DPDP framework.
B. European Union / UK — GDPR Framework
Where GDPR or UK GDPR applies, this DPA incorporates the obligations of Article 28. Where qualifying international transfers from the EEA or UK to third countries require Standard Contractual Clauses (SCCs), the applicable SCC module and annexes may be executed as part of an enterprise agreement schedule.
17.Compliance Verification & Audit Information
Upon Customer's reasonable written request, IOBend shall provide information reasonably necessary to demonstrate compliance with its obligations under this DPA, through available security summaries, architecture overviews, and compliance documentation published in our Trust Center.
For enterprise accounts with negotiated audit rights, any customer audit must be reasonable, conducted during normal business hours upon at least thirty (30) days advance notice, subject to strict confidentiality, and designed so as not to compromise multi-tenant isolation, intellectual property, or other customers' confidential data.
18.Impact Assessments & Regulatory Assistance
Taking into account the nature of processing and information available to IOBend, IOBend shall provide reasonable assistance to Customer, at Customer's expense where substantial effort is involved, in connection with any required Data Protection Impact Assessments (DPIAs) or prior consultations with supervisory authorities required by Applicable Data Protection Law.
19.AI Processing & Model Safeguards
Where Customer utilizes opt-in IOBend AI assistance features (such as iobend ai generate or web console diagnostics):
- Prompt text and project structural metadata are transmitted to provide configuration scaffolding and troubleshooting;
- IOBend does not use Customer Personal Data or prompt contents to train general-purpose foundation AI models; and
- Automated sanitization routines filter recognized credential and token patterns prior to model processing.
20.Secrets & Cryptographic Controls
IOBend provides security mechanisms designed to reduce exposure of credentials and secrets (including in-memory handling and KMS envelope encryption where configured).
Where a Service is architected such that IOBend does not hold the cryptographic key material, IOBend is technically unable to decrypt those secrets. Customer remains responsible for managing its encryption keys, access policies, and secret rotation schedules.
21.Order of Precedence
In the event of any conflict or inconsistency between this DPA and any other agreement between the parties concerning data protection or the processing of Customer Personal Data, the provisions of this DPA shall control to the extent of the conflict.
Where Customer has executed a separate custom Enterprise Agreement with IOBend, the agreed contractual hierarchy in that executed agreement shall govern.
22.Term, Termination & Survival
This DPA shall remain in effect for as long as IOBend processes Customer Personal Data on Customer's behalf under the Agreement. Provisions relating to confidentiality, security incidents, data deletion, and limitation of liability shall survive termination.
23.Limitation of Liability
Each party's liability arising out of or related to this DPA (whether in contract, tort, negligence, or otherwise) shall be subject to the aggregate limitations of liability and liability exclusions set forth in the Agreement.
24.DPA Requests & Enterprise Execution
Request an Executed Enterprise DPA
Organizations requiring a formal, countersigned Data Processing Addendum customized with corporate entity details, SCC annexes, or custom security schedules can submit an execution request directly to our legal team.
25.Contact & Legal Notices
For questions, legal notices, or DPA execution inquiries:
Governing Entity: IOBend Technologies Private Limited, India.
