LEGAL · DPA
Data Processing Agreement
Agreement between Cyphertree Technologies (Processor) and Client (Controller) for the processing of personal data under GDPR Article 28.
Draft, pending legal review. This document is published for transparency and is being finalised with counsel. For a binding agreement, contact support@cyphertree.com.
1. Parties & Definitions
| Term | Definition |
|---|---|
| "Controller" / "Client" | The European company engaging Cyphertree's EOR services, who determines the purposes and means of processing employee personal data. |
| "Processor" / "Cyphertree" | Cyphertree Technologies, Pune, Maharashtra, India — acting as the data processor under GDPR and data processor under DPDP Act. |
| "Data Subject" / "Data Principal" | The employee(s) hired in India through the EOR arrangement, and any applicants processed through the ATS. |
| "Personal Data" | Any information relating to an identified or identifiable natural person as defined in GDPR Art. 4(1) and DPDP Sec. 2(t). |
| "Sub-Processor" | A third party engaged by Cyphertree to process personal data on behalf of the Controller. |
| "Supervisory Authority" | The competent data protection authority, including the Autoriteit Persoonsgegevens (Netherlands) and the Data Protection Board of India. |
2. Scope of Processing
Cyphertree processes personal data on behalf of the Controller solely for the purpose of delivering EOR services as described below:
| Processing activity | Categories of data | Data subjects | Duration |
|---|---|---|---|
| Payroll processing | Name, salary, bank details, PAN, TDS computations | Employees | Duration of employment + 8 years |
| Tax compliance (TDS, PF, ESI) | PAN, salary components, tax declarations | Employees | Duration + 8 years (Indian IT Act) |
| Employee onboarding | Identity, contact, address, emergency contacts, qualifications | Employees | Duration of employment |
| Employee offboarding | Termination details, final settlement, experience letters | Former employees | 3 years post-termination |
| Performance management | Reviews, goals, feedback, ratings | Employees | Duration + 3 years |
| Electronic signatures | Name, email, signature data, RFC-3161 timestamps | Employees, Clients | 7–10 years |
| Recruitment / ATS | Resumes, assessments, AI ranking scores, interview notes | Applicants | 24 months from application |
| Leave & attendance | Leave records, attendance logs, IP addresses | Employees | Duration + 3 years |
Cyphertree shall not process personal data for any purpose other than those specified above or as instructed by the Controller in writing.
3. Processor Obligations
Cyphertree shall:
- Process personal data only on documented instructions from the Controller, unless required by Indian or EU law
- Ensure that all persons authorised to process personal data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures as described in Section 4
- Not engage sub-processors without prior specific or general written authorisation of the Controller (see Section 5)
- Assist the Controller in responding to data subject requests (access, rectification, erasure, portability)
- Assist the Controller in ensuring compliance with breach notification, DPIA, and prior consultation obligations
- Delete or return all personal data upon termination of services, at the Controller's choice (see Section 10)
- Make available all information necessary to demonstrate compliance and allow for audits (see Section 9)
- Immediately inform the Controller if an instruction infringes GDPR, DPDP, or other applicable data protection law
4. Technical & Organisational Security Measures
Cyphertree implements the following measures to ensure a level of security appropriate to the risk:
| Category | Measure | Details |
|---|---|---|
| Encryption | In transit | TLS 1.3 on all connections |
| Encryption | At rest | AES-256 for PAN, Aadhaar, bank details, salary data |
| Access control | Authentication | Google OAuth 2.0 + session-based authentication |
| Access control | Authorisation | Multi-tenant RBAC with PostgreSQL Row-Level Security |
| Access control | Principle of least privilege | Role-based access; admin/client/employee segregation |
| Data isolation | Tenant separation | PostgreSQL RLS policies ensure complete tenant isolation |
| Monitoring | Audit logging | All PII operations logged (who, what, when, data categories) |
| Infrastructure | Database | Neon PostgreSQL, EU Frankfurt region |
| Infrastructure | CDN / WAF | Cloudflare — DDoS protection, bot management |
| Infrastructure | Resend — transactional email with TLS | |
| Incident response | Breach procedure | 72-hour notification per GDPR Art. 33; documented escalation |
| Personnel | Confidentiality | All personnel bound by NDAs and confidentiality agreements |
| Backup | Recovery | Automated daily backups with point-in-time recovery |
5. Sub-Processors
The Controller provides general written authorisation for Cyphertree to engage sub-processors. The current list of approved sub-processors is:
| Sub-Processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Neon (Neon Inc.) | Database hosting (PostgreSQL) | EU — Frankfurt | DPA + EU hosting |
| Cloudflare (Cloudflare Inc.) | CDN, DNS, DDoS protection, WAF | Global (EU processing) | DPA + SCCs |
| Resend (Resend Inc.) | Transactional & marketing email delivery | US | DPA + SCCs |
| Google (Google LLC) | OAuth authentication, Calendar API | Global | DPA + SCCs |
| AI Model Provider | Resume screening & candidate ranking (ATS) | API only — no data retention | DPA + data minimisation |
Change notification: Cyphertree shall inform the Controller of any intended addition or replacement of sub-processors at least 14 days in advance, giving the Controller the opportunity to object. If the Controller objects on reasonable data protection grounds, the parties shall discuss in good faith. If no resolution is reached, the Controller may terminate this DPA and the affected services.
The current sub-processor list is published at cyphertree.com/sub-processors and updated upon any change.
6. International Data Transfers
Personal data transferred from the EEA to India is protected by:
- Standard Contractual Clauses (SCCs) — European Commission Implementing Decision (EU) 2021/914, Module Two (Controller to Processor)
- Transfer Impact Assessment (TIA) — Cyphertree maintains a documented TIA evaluating Indian data protection laws and supplementary measures
- Supplementary measures — Encryption at rest and in transit, access controls, audit logging, and contractual commitments
SCCs incorporation: The Standard Contractual Clauses (Module Two: Controller to Processor) as set out in the Annex to Commission Implementing Decision (EU) 2021/914 are hereby incorporated by reference into this DPA. In the event of conflict between this DPA and the SCCs, the SCCs shall prevail.
Under the DPDP Act, transfers to countries not on the Indian government's restricted list are permitted. Cyphertree monitors the restricted list and will notify the Controller of any changes affecting data flows.
7. Data Subject Rights Assistance
Cyphertree shall assist the Controller in fulfilling its obligations to respond to data subject requests under GDPR Articles 15–22 and DPDP Sections 11–14:
| Right | Cyphertree's obligation | Response time |
|---|---|---|
| Access (Art. 15 / Sec. 11) | Provide all personal data held about the data subject upon Controller request | 10 business days |
| Rectification (Art. 16 / Sec. 12) | Correct inaccurate data upon Controller instruction | 5 business days |
| Erasure (Art. 17 / Sec. 13) | Delete data unless legal retention applies; confirm deletion | 15 business days |
| Portability (Art. 20) | Export data in structured, machine-readable format (JSON/CSV) | 10 business days |
| Restriction (Art. 18) | Flag and pause processing of specified data | 5 business days |
| Grievance (DPDP Sec. 13) | Forward to Grievance Officer; assist in resolution | 15 business days |
If Cyphertree receives a data subject request directly, it shall promptly notify the Controller and shall not respond without the Controller's instruction, unless legally required.
8. Data Breach Notification
In the event of a personal data breach, Cyphertree shall:
- Notify the Controller without undue delay and no later than 24 hours after becoming aware of the breach
- Provide the following information (to the extent available):
- Nature of the breach (categories and approximate number of data subjects affected)
- Categories of personal data affected
- Likely consequences of the breach
- Measures taken or proposed to address the breach
- Contact point for further information
- Cooperate fully with the Controller's investigation and any supervisory authority inquiry
- Document the breach, its effects, and remedial actions taken
- Assist the Controller in notifying the supervisory authority (within 72 hours per GDPR Art. 33) and affected data subjects (per GDPR Art. 34) where required
DPDP obligation: Under Section 8(6) of the DPDP Act, Cyphertree shall also notify the Data Protection Board of India without delay of any breach affecting Data Principals in India.
9. Audit Rights
Cyphertree shall make available to the Controller all information necessary to demonstrate compliance with this DPA and GDPR Article 28 obligations.
Audit process:
- The Controller may conduct audits up to once per year, with 30 days' written notice
- Audits may be conducted by the Controller directly or by an independent third-party auditor bound by confidentiality
- Cyphertree shall provide reasonable cooperation, including access to relevant systems, records, and personnel
- Audits shall be conducted during normal business hours and shall not unreasonably disrupt Cyphertree's operations
- The Controller bears the cost of audits, unless the audit reveals material non-compliance by Cyphertree
Cyphertree may satisfy audit requests by providing relevant SOC 2 reports, ISO 27001 certifications, or equivalent third-party audit reports where available.
10. Data Retention & Deletion
Upon termination of this DPA or the underlying service agreement:
- Cyphertree shall, at the Controller's choice, return or delete all personal data within 30 days
- Deletion includes all copies, backups, and data held by sub-processors
- Cyphertree shall provide written confirmation of deletion upon request
Exceptions: Cyphertree may retain personal data to the extent required by Indian law (including tax and labour law retention obligations). In such cases:
| Data type | Mandatory retention | Legal basis |
|---|---|---|
| Payroll & TDS records | 8 years post-employment | Indian Income Tax Act |
| PF/ESI records | 5 years post-employment | EPF & ESI Acts |
| Employee contracts | 3 years post-termination | Indian Limitation Act |
| Electronic signatures | 7–10 years | Indian IT Act, 2000 / eIDAS |
| Audit logs | 5 years | Regulatory compliance |
Retained data shall continue to be protected under this DPA until deletion.
11. Liability
Each party's liability under this DPA is subject to the limitations and exclusions set out in the underlying service agreement between the parties.
Cyphertree shall be liable to the Controller for damages caused by processing that violates this DPA, GDPR, or the DPDP Act, to the extent that Cyphertree has not complied with obligations specifically directed to processors or has acted outside or contrary to the Controller's lawful instructions.
Where both parties are responsible for damage caused to a data subject, each party shall be liable for the entire damage to ensure effective compensation (GDPR Art. 82(4)). The party that has paid full compensation may claim back the portion attributable to the other party.
12. Term & Termination
This DPA shall:
- Come into effect on the date both parties sign the underlying service agreement
- Remain in force for the duration of the service agreement
- Survive termination with respect to obligations regarding data retention, deletion, and ongoing confidentiality
Either party may terminate this DPA if the other party materially breaches its obligations and fails to remedy the breach within 30 days of written notice.
13. Annexes
Annex I — Details of Processing
| Field | Details |
|---|---|
| Controller | [Client Company Name], [Address], [EU Country] |
| Processor | Cyphertree Technologies, Pune, Maharashtra, India |
| Subject matter | Employer of Record services for Indian employees of EU companies |
| Duration | Duration of the service agreement |
| Nature and purpose | Payroll, tax compliance, employee lifecycle, recruitment, performance management, electronic signatures |
| Categories of data subjects | Employees, applicants, client personnel |
| Categories of personal data | Identity, contact, financial (salary, bank, PAN), employment, recruitment, performance, signatures |
| Sensitive data | PAN, Aadhaar (encrypted at rest), health data only if provided by employee for ESI |
| Processing operations | Collection, storage, computation, transmission, deletion |
| Supervisory authority | Autoriteit Persoonsgegevens (Netherlands) / Controller's local DPA |
Annex II — Technical & Organisational Measures
See Section 4 of this DPA for the complete list of security measures implemented by Cyphertree.
Annex III — Sub-Processors
See Section 5 of this DPA. The current sub-processor list is maintained at cyphertree.com/sub-processors.