FAC Cloud - Data Processing Agreement
Effective Date: September 15, 2026, Version: 1.0
1. Background and structure
This Data Processing Agreement ("DPA") is entered into between Promantia Business Solutions Pvt. Ltd (CIN: U72900KA2017PTC108567), with its registered office at No 103, Maria Regency Manor, Madras Sappers Officers Colony, Banaswadi Mn Rd , Bangalore, Karnataka, India - 560033 ("Processor", "FAC Cloud", "we") and the Customer that has accepted the FAC Cloud Terms of Service ("Controller", "Customer", "you"). It forms part of, and is incorporated by reference into, those Terms (together, the "Agreement").
This DPA reflects the requirements of Article 28 of Regulation (EU) 2016/679 ("GDPR"), the equivalent provisions of the UK GDPR and Data Protection Act 2018, the Digital Personal Data Protection Act, 2023 of India ("DPDPA") and the DPDP Rules, 2025, as well as analogous data-protection laws elsewhere (including the CCPA / CPRA where applicable for California consumers, “Sensitive Personal Information” as defined under Cal. Civ. Code § 1798.121 is subject to the right to limit use and disclosure, and the parties shall cooperate to honour such request). Where Customer is not subject to any of these laws, this DPA still applies as a contractual baseline.
In case of conflict between this DPA and the rest of the Agreement on data-protection matters, this DPA prevails. The Standard Contractual Clauses incorporated by reference (Annex C, where applicable) prevail over any conflicting provisions of this DPA.
2. Definitions
Capitalised terms not defined here have the meaning given in the Terms or in applicable data-protection law.
- Applicable Data Protection Law — every law that applies to the processing of Personal Data under the Agreement, including GDPR, UK GDPR, DPDPA, CCPA / CPRA,the Personal Data Protection Act 2012 of Singapore (“PDPA”), the Lei Geral de Proteção de Dados Pessoais of Brazil (“LGPD”), the Act on the Protection of Personal Information of Japan (“APPI”), the Privacy Act 1988 of Australia, the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 of India (“SPDI Rules”) (to the extent they apply alongside the DPDPA), and any successor legislation.
- Controller, Processor, Sub-processor, Personal Data, Processing, Data Subject, Personal Data Breach — as defined in GDPR (or the analogous "Data Fiduciary", "Data Processor" and "Data Principal" under DPDPA).
- Customer Personal Data — Personal Data that is part of Customer Data and is processed by us on the Controller's behalf under the Agreement.
- Sub-processor — a third party engaged by us to process Customer Personal Data on the Controller's behalf.
- Standard Contractual Clauses or SCCs — the European Commission's standard contractual clauses for international transfers adopted by Implementing Decision (EU) 2021/914 of 4 June 2021, together with the UK International Data Transfer Addendum and the Swiss FDPIC adaptations where applicable.
3. Roles and scope
1. Roles
For Customer Personal Data, the Customer is the Controller (or Data Fiduciary) and FAC Cloud is the Processor (or Data Processor). For any Personal Data we process as Controller in our own right (such as billing contacts, registration metadata, audit logs we are required to maintain, and our service telemetry), our Privacy Policy applies and this DPA does not.
Where the Customer is itself a processor for another organisation, the Customer warrants that it has authority from its own controller(s) to engage us as a sub-processor on the terms of this DPA, and we will act in the capacity of sub-processor with the same obligations to the Customer as a processor under Article 28.
For processing of Personal Data of Indian Data Principals, FAC Cloud is engaged as a 'Data Processor' within the meaning of Sec 2(k) of the Digital Personal Data Protection Act, 2023. The written contract constituted by this DPA satisfies the written-contract requirement of Sec 8(2) of the DPDPA as between the Data Fiduciary (Customer) and the Data Processor (FAC Cloud). FAC Cloud acknowledges that it shall not process Personal Data of Indian Data Principals except as per the instructions of the Customer as Data Fiduciary, and shall implement such security safeguards as are prescribed under Sec 8(5) of the DPDPA and the DPDP Rules 2025.
2. Scope, duration and nature of processing
We process Customer Personal Data for the term of the Agreement and for the limited windows required to delete or return data after termination (see Clause 12). Processing covers all activities that are necessary to perform the Service as described in the Terms and as the Controller configures or directs through the Service interfaces and APIs, including:
- transmitting prompts, conversation history, retrieved memories and RAG snippets to LLM sub-processors and returning the responses;
- storing conversations, messages, attachments, memories, uploaded documents and embeddings;
- executing tools on the Customer's Frappe / ERPNext system via MCP, including HITL approvals;
- running scheduled or on-demand AI workflows;
- metering token usage, calculating credit consumption and generating invoices;
- maintaining security, audit and compliance records.
3. Categories of Data Subjects
Customer Personal Data may relate to:
- Customer's employees, contractors, consultants and other End-Users authorised by the Customer to use the Service;
- Customer's customers, prospects, suppliers and other business contacts whose data is held in the Customer's Frappe / ERPNext system or referenced in prompts;
- any other natural person whose data the Customer chooses to process through the Service.
4. Categories of Personal Data
Categories of Customer Personal Data include identifiers (name, email, user ID, employee ID), contact details, professional / employment data, communications data (messages, attachments, prompts and responses), audit data (IP addresses, user agents, timestamps), and any other category present in the Customer's business data that the Customer chooses to expose to the Service through MCP tool calls, uploads, custom instructions, memories or workflow inputs. The Customer is responsible for not exposing special-category data unless it has a lawful basis to do so (see Clause 4.4).
4. Controller obligations
The Controller represents and warrants that:
- it has a lawful basis under Applicable Data Protection Law for all Processing it instructs us to perform, including transfer to our Sub-processors;
- it has provided all required notices to, and obtained all required consents from, Data Subjects (including any End-User notices for AI processing, memory extraction, RAG indexing of business documents and any automated decision-making the Controller configures);
its instructions to us comply with Applicable Data Protection Law;
it will implement reasonable technical and organizational measures to avoid using the Service to process Personal Data of Data Subjects under the age of 18 where such processing is not authorized, and will promptly notify FAC Cloud if it becomes aware that Personal Data of minors is being processed through the Service; provided that the parties acknowledge that FAC Cloud's primary obligation is to comply with Controller's instructions and that the Controller retains primary responsibility for user access controls. Without prejudice to the foregoing, where the Service is used to process Personal Data of children (defined as persons under 18 years of age under the DPDPA), the Controller, acting as Data Fiduciary, warrants that it shall: (i) not undertake processing of Personal Data of children in a manner that is likely to cause detrimental effect on their well-being, as prohibited under Sec 9(1) of the DPDPA; (ii) not engage in tracking or behavioural monitoring of children or targeted advertising directed at children, as prohibited under Sec 9(3) of the DPDPA; and (iii) obtain verifiable parental consent before processing Personal Data of children, as required under Sec 9(1) of the DPDPA and any rules notified thereunder. FAC Cloud shall not be liable for the Controller’s failure to comply with this obligation ;
- it will configure HITL approvals, tool-trust settings, document-visibility settings, retention windows and member access in line with its compliance obligations;
- it has the right to authorise our processing under Clause 3 and to make use of the Sub-processors listed in Annex B;
- it is responsible for the accuracy, quality, legality and integrity of Customer Personal Data it provides to us; and
- it will promptly notify us if it cannot comply with this DPA.
5. Processor obligations
We will:
- process Customer Personal Data only on the Controller's documented instructions (including those set out in the Agreement, those issued through the Service's interfaces and APIs and any other written instruction the Controller gives us). If we believe an instruction would violate Applicable Data Protection Law, we will inform the Controller without undue delay and may suspend the relevant processing until the issue is resolved; ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations;
- implement and maintain the technical and organisational measures described in Annex A and otherwise required by Article 32 GDPR;
engage Sub-processors only in accordance with Clause 7;
assist the Controller, taking into account the nature of the processing and the information available to us, in fulfilling its obligations to respond to Data Subject requests (Clause 8) and to maintain the security of the processing, to notify Personal Data Breaches and to carry out Data Protection Impact Assessments and prior consultations with supervisory authorities (Clause 9);
- on termination of the Agreement, delete or return Customer Personal Data as set out in Clause 12;
- make available to the Controller all information necessary to demonstrate compliance with Article 28 GDPR (and equivalents) and allow for and contribute to audits as set out in Clause 11;
- comply with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”) under the Information Technology Act, 2000 of India, to the extent that such rules continue to apply alongside the DPDPA during any transitional period. In particular, FAC Cloud shall maintain a comprehensive documented information security programme and information security policies in accordance with IS/ISO/IEC 27001, or such other standard as may be approved by the Central Government, when processing “sensitive personal data or information” (as defined under Rule 3 of the SPDI Rules) of Indian residents; and
- not sell or share Customer Personal Data in any sense recognised by Applicable Data Protection Law, and not use Customer Personal Data for our own commercial purposes other than aggregated and de-identified service telemetry as described in Clause 5.1.
1. Aggregated and de-identified data
We may generate aggregated and de-identified statistical data from the operation of the Service (such as request counts, latency, error rates, token volumes per model, feature-usage counters) and use that data for our internal business purposes, including operating, securing, improving and benchmarking the Service. Such data will not identify the Controller, any End-User or any Data Subject; we will not attempt re-identification; and we will not sell it.
2. No model training on Customer Data
We do not use Customer Personal Data, prompts or AI outputs to train our own foundation models. Our LLM Sub-processors are engaged on enterprise / API tiers that contractually exclude use of Controller inputs and outputs for training of their generally-available models. Annex B identifies the enterprise privacy commitments we rely on for each LLM Sub-processor.
3. Law Enforcement Requests
If FAC Cloud receives any demand, request or order from any law enforcement authority, intelligence agency, government body, or court for access to Customer Personal Data, FAC Cloud shall: (a) unless prohibited by law, notify the Controller promptly and before complying; (b) challenge any such demand that appears overbroad, disproportionate, or lacking a valid legal basis; (c) disclose only the minimum Personal Data required by the legally binding demand; and (d) maintain a log of such requests (to the extent permitted by law) and report annually to the Controller on the number and nature of requests received.'
6. Confidentiality
We treat Customer Personal Data as confidential. Personnel are subject to confidentiality obligations that survive termination of their engagement.
7. Sub-processors
1. General authorisation
The Controller provides general authorisation for the engagement of the Sub-processors listed in Annex B (as updated from time to time) for the processing activities described there.
2. Notification and right to object
We will provide at least 30 days' advance notice of any new Sub-processor or material change to existing Sub-processor arrangements (a shorter period may apply in emergencies, in which case we will provide notice as soon as reasonably practicable and document the reason).
Notice will be given by email, in-product banner, API response header, RSS feed or update to a public Sub-processor page, at our choice.
The Controller may object to a proposed new Sub-processor on reasonable, documented data-protection grounds within 30 days of notice. We will work in good faith to address the
objection, including by proposing an alternative configuration. If we cannot resolve the objection, the Controller may terminate the affected portion of the Service for convenience, on written notice, with a pro-rata refund of pre-paid fees attributable to the cancelled portion.
3. Flow-down
We will impose on each Sub-processor data-protection obligations substantially equivalent to those in this DPA, and we remain liable to the Controller for the acts and omissions of our Sub-processors as if they were our own.
We will, upon reasonable written request, make available to the Controller evidence that Sub-processor contracts meeting the requirements of this Clause 7.3 are in place, including, where permitted by confidentiality obligations, redacted copies of relevant contractual terms. We will exercise our audit and inspection rights against Sub-processors where reasonably requested by the Controller, and provide the Controller with a summary of findings.
8. Data Subject rights
Taking into account the nature of the Processing, we will assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to Data Subject requests (including access, rectification, erasure, restriction, portability, objection, withdrawal of consent and nomination under DPDPA).
The Service exposes the following tenant-level APIs that the Controller can call to fulfil such requests directly:
- export of an End-User's profile, conversations, messages, token usage, memories and documents (machine-readable JSON);
- erasure of an End-User's conversation history, messages, token usage, memories, documents and profile, with cascade into companion modules;
rectification of End-User profile fields;
restriction (the End-User is flagged as "processing restricted");
consent toggling (memory consent on / off);
conversation-level soft delete and purge. Where we receive a Data Subject request directly, we will (unless prohibited by law) promptly inform the Controller and will not respond to the request ourselves except on the Controller's instruction or as required by law. Reasonable assistance beyond the built-in APIs may be subject to a fee at our then-prevailing rates if the request is repetitive, manifestly unfounded or excessive.
8A. Consent Manager Support.
Where the Customer, acting as Data Fiduciary, uses or is required to use a Consent Manager (as defined in Sec 2(j) of the DPDPA) for obtaining, managing or withdrawing consent of Data Principals, FAC Cloud shall, upon reasonable written request and within a timeframe agreed by the parties (not to exceed 30 days), implement technical interfaces or provide data exports sufficient to enable the Customer to integrate the Service with such Consent Manager. FAC Cloud shall not obstruct or impede the exercise by Data Principals of their rights under Chapter IV of the DPDPA.
9. Personal Data Breach notification
1. Notification to Controller
We will notify the Controller of any Personal Data Breach affecting Customer Personal Data without undue delay after becoming aware, and where feasible within 72 hours. Notice will be delivered to the Controller's billing and administrator contacts and through such other channels as we consider effective.
2. Contents
Notification will, to the extent then known, describe:
- the nature of the breach, including the categories and approximate number of Data Subjects and records affected;
- the likely consequences;
- the measures we have taken or propose to take to address the breach and mitigate adverse effects;
- the contact point for further information.
Where all information is not available at first notification, we will provide it in phases.
3. Assistance
We will provide reasonable assistance to enable the Controller to meet its own
breach-notification obligations to supervisory authorities and Data Subjects, including, for Customers and Data Principals in India, assistance with the Data Fiduciary's reporting obligations to the Data Protection Board of India and direct notification to affected Data Principals as required by Rule 7 of the DPDP Rules, 2025.
In the event that applicable law requires the Processor to directly notify a supervisory authority or Data Subjects of a breach (including under DPDP Rules 2025 Rule 7), FAC Cloud shall: (a) notify the Controller before making any such notification, unless prohibited by law; (b) coordinate the content of any such notification with the Controller; and (c) provide the Controller with a copy of any notification made.
4. No admission
A notification under this Clause 9 is not an acknowledgment of fault or liability.
10. Security
We implement the technical and organisational measures described in Annex A. We may update these measures from time to time, provided the overall level of security is not materially decreased.
11. Audit rights
We will make available to the Controller, on reasonable written request and no more than once per twelve-month period (provided that this limitation shall not apply: (a) where a supervisory authority requires more frequent audits; (b) following any Personal Data Breach (whether or not it materially affects the Controller); (c) where the Controller has reasonable grounds to suspect non-compliance with this DPA; or (d) as required by Applicable Data Protection Law):
our then-current SOC 2 or equivalent independent audit report when available;
a completed standard security questionnaire (CAIQ or our own);
our then-current information-security policy summary and the description of measures in Annex A; and
written responses to reasonable questions about our processing under this DPA.
Where Applicable Data Protection Law requires more, the Controller (or a mutually-acceptable independent auditor bound by confidentiality and not a direct competitor of the Processor in the AI-assistant or LLM-inference market) may carry out an on-site audit, on at least 30 days' written notice, during normal business hours, in a manner that does not unreasonably disrupt our operations, and at the Controller's expense. We may require the Controller to share the audit report with us. Both parties will protect any information learned through the audit as Confidential Information. For the avoidance of doubt, nothing in this Clause 11 limits or restricts the powers of the Data Protection Board of India to conduct inquiries and inspections under Sec 28 of the DPDPA or any other powers conferred on it by Applicable Data Protection Law; FAC Cloud shall cooperate fully with any such inquiry or inspection.
12. Return or deletion on termination
On termination of the Agreement, at the Controller's written choice received within 60 days of termination ( during which period FAC Cloud will continue to store Customer Personal Data and make it accessible to the Controller in its then-current format at no additional charge) , we will either:
- export Customer Personal Data in a structured, commonly-used, machine-readable format and provide it to the Controller, then delete; or
delete all Customer Personal Data from our active systems.
Either path is completed within 30 days of receipt of the Controller's instruction. Encrypted backups containing Customer Personal Data are deleted on their normal rotation cycle (currently 35 days from the date of backup); they are not accessed during that window except to recover from a disaster.
We may retain Customer Personal Data only to the extent required by Applicable Data Protection Law, including for tax and accounting record-keeping (invoices and related records are retained for 8 years under Indian tax law) and to defend legal claims. Any such retained data continues to be protected by this DPA.
13. International transfers
1. Transfers from the EEA, UK and Switzerland
Where Customer Personal Data is transferred from the EEA, UK or Switzerland to a country outside the European Economic Area / UK / Switzerland that is not subject to an adequacy decision, the parties incorporate the relevant Standard Contractual Clauses (Module 2: Controller-to-Processor; Module 3: Processor-to-Processor, as applicable), the UK International Data Transfer Addendum, and the Swiss FDPIC adaptations, by reference. Annex C sets out the docking of those clauses for our relationship; in case of conflict, the SCCs / Addendum / adaptations prevail.
We have carried out a transfer impact assessment in light of Schrems II and apply supplementary measures including encryption in transit and at rest, access controls, transparency reporting, and challenging government access requests where lawful.
2. Transfers from India
Where Customer Personal Data of Indian Data Principals is transferred outside India, we comply with the DPDPA and any restrictions notified by the Government of India under Sec 16 of the DPDPA. FAC Cloud shall: (a) maintain an up-to-date mapping of the countries to which Personal Data of Indian Data Principals is transferred; (b) promptly notify the Controller (and in any event within 5 Business Days) upon becoming aware that any such transfer may be restricted or prohibited; and (c) suspend or re-route any affected transfer within 10 Business Days of such notification or of the effective date of any governmental restriction, whichever is earlier. The Controller may, by written notice, specify that no Personal Data of Indian Data Principals shall be transferred to specified countries. We will provide notice and update Annex B if and when such restrictions affect a Sub-processor.
3. Onward transfers
Sub-processors that further transfer Customer Personal Data are bound, by their contracts with us, to maintain the same standard of protection.
14. Liability
Each party's liability under this DPA for breach of obligations that do not arise under, and cannot be excluded by, Applicable Data Protection Law is subject to the limitations of liability set out in the Agreement. For the avoidance of doubt, neither party excludes or limits: (a) any liability to Data Subjects under GDPR Art. 82 or equivalent provisions; (b) any administrative fine or penalty imposed by a supervisory authority; (c) liability for death or personal injury caused by negligence; or (d) any other liability that cannot lawfully be excluded. Nothing in this Clause limits any rights of Data Subjects under Applicable Data Protection Law or any liability that cannot be excluded or limited by such law.
15. Term, governing law and miscellaneous
This DPA takes effect on the effective date of the Agreement and remains in force for as long as we process Customer Personal Data on the Controller's behalf. The governing-law,
dispute-resolution and miscellaneous provisions of the Terms apply to this DPA, save that, where the SCCs are incorporated, the SCCs' choice-of-law and forum provisions apply to processing within their scope.
If any provision of this DPA is held invalid, the remaining provisions will continue in full force. To the extent of any conflict between this DPA and the Privacy Policy, this DPA prevails.
16. Contact
Data Protection Officer: [email protected]
Privacy enquiries: [email protected]
Grievance Officer (India, DPDPA): Sunitha Ravindran, Manager - HR & Administration, Promantia . Email [email protected]
Security incidents: [email protected]
Postal: Promantia Business Solutions Pvt. Ltd. (CIN: U72900KA2017PTC108567), No 103, Maria Regency Manor, Madras Sappers Officers Colony, Banaswadi Mn Rd, Bangalore, Karnataka, India – 560033
FAC Cloud undertakes that the Grievance Officer will acknowledge grievances within 48 hours and resolve them within 30 days of receipt, or within such other period as may be prescribed under the DPDP Rules 2025 or notified by the Central Government. FAC Cloud shall also comply with the cybersecurity incident reporting obligations under the directions issued by the Indian Computer Emergency Response Team (CERT-In) under Sec 70B of the Information Technology Act, 2000, including reporting qualifying incidents to CERT-In within 6 hours of detection.
Annex A - Technical and Organisational Measures
The following measures describe the security baseline we maintain. Specific implementations evolve; the overall level of security will not be materially decreased without notice.
1. Pseudonymisation and encryption
- TLS 1.2 or higher for all data in transit.
- AES-256 encryption at rest for sensitive fields, including: Tenant Secret (HMAC shared secret), OAuth access and refresh tokens for the Customer's Frappe instance, LLM provider API keys, payment-gateway secrets (Stripe secret key, Razorpay key secret, both webhook signing secrets) and user MCP-server OAuth tokens. Encryption uses the Frappe framework's password fieldtype layer.
- Encryption-key persistence and rotation guarded by application startup checks.
2. Confidentiality, integrity, availability and resilience
- Multi-tenant logical isolation: every record carries a tenant identifier; conversations, memories, documents, workflows and Redis vector keys are scoped per tenant.
- HMAC-SHA256 request signing with timestamp checks, replay protection and origin-binding (bound host, rebind tokens).
- Role-based access control to production systems; production access logged.
- Backups; documented disaster-recovery procedures.
3. Restoration
- Ability to restore the availability of and access to Customer Personal Data in a timely manner after a physical or technical incident, through backups and infrastructure redundancy.
4. Testing and assessment
- Regular vulnerability scanning, dependency monitoring and patching.
- Periodic security assessments and penetration tests.
- Code review of changes to authentication, authorisation, encryption and tenant-isolation paths.
- Identification of risks and incident response
- Documented incident-response procedure with defined roles and severity levels.
- Centralised security and access logging; alerting on suspicious activity.
- Personnel security awareness training.
5. Sub-processor due diligence
- Documented due-diligence and onboarding process for Sub-processors, covering their security posture, transfer mechanisms and processing terms; written DPAs flowing down the obligations of this DPA.
Annex B — Authorised Sub-processors
- The following Sub-processors are authorised as of the Effective Date. We will update this list and notify the Controller as set out in Clause 7.2.
| Sub-processor | Role | Categories of data | Processing location | Enterprise privacy commitment / link |
|---|---|---|---|---|
| Anthropic, PBC | LLM inference (Claude models) | Prompts, conversation context, system instructions, RAG snippets, memories, AI outputs | United States | Anthropic API / Claude for Work — no training on customer inputs/outputs |
| OpenAI, Inc. | LLM inference (GPT and o-series models) | Prompts, conversation context, system instructions, RAG snippets, memories, AI outputs | United States | OpenAI Enterprise Privacy — no training on business data |
| Amazon Web Services, Inc. (Amazon Bedrock) | LLM inference (models served via Amazon Bedrock) | Prompts, conversation context, system instructions, RAG snippets, memories, AI outputs | United States, and other AWS regions as configured | AWS Service Terms for Amazon Bedrock — inputs and outputs are not used to train AWS or third-party models |
| Google LLC (Vertex AI) | LLM inference (Gemini models) | Prompts, conversation context, system instructions, RAG snippets, memories, AI outputs | United States, and other Google Cloud regions as configured | Google Cloud / Vertex AI data governance — customer data is not used to train Google's foundation models |
| Stripe, Inc. / Stripe India | Global payment processing | Billing email, country, tokenised payment-method data, webhook events | Global (Stripe regions) | PCI DSS Level 1 |
| Razorpay Software Pvt. Ltd. | India and select non-India payment processing | Billing email, phone (eMandate), country, tokenised payment-method data, webhook events | India | RBI compliant, PCI DSS |
| Cloud infrastructure provider(s) | Hosting of Service infrastructure | All Customer Personal Data processed by the Service | India and other regions, as configured | Major-provider security certifications (ISO 27001, SOC 2) |
| Email delivery provider(s) | Transactional email (verification, invoices, alerts) | Billing email, administrator email, content of the transactional message | As provider operates | SPF/DKIM/DMARC, TLS in transit |
- Embedding-model providers, if used, are added to this list before going into production for any Customer; if we operate self-hosted embedding models, no third-party embedding sub-processor is involved
Annex C — Standard Contractual Clauses (incorporation summary)
Where the SCCs apply (see Clause 13.1):
Module: Module 2 (Controller-to-Processor) where the Controller is the controller of Customer Personal Data; Module 3 (Processor-to-Processor) where the Controller is itself a processor for another organisation.
Clause 7 (Docking clause): included; further Controllers may accede on the terms of the SCCs and this DPA.
- Clause 9 (Sub-processors): Option 2 (general written authorisation) with the 30-day notice period set out in Clause 7.2 of this DPA.
Clause 11 (Redress): the optional independent dispute-resolution body is not selected.
Clause 17 (Governing law): the law of the India.
Clause 18 (Choice of forum and jurisdiction): the courts of the Republic of Ireland.
Annex I.A (Parties): Controller is the Customer; Processor is FAC Cloud, with the contact details set out above.
- Annex I.B (Description of transfer): as described in Clause 3.2–3.4 of this DPA and in the Privacy Policy.
- Annex I.C (Competent supervisory authority): the supervisory authority of the Member State in which the Controller's lead establishment or EU representative is located.
Technical and organisational measures: Annex A of this DPA
Sub-processors: Annex B of this DPA.
For transfers subject to the UK GDPR, the parties additionally incorporate the UK International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (issued by the ICO) with the SCCs above. For transfers subject to the Swiss FADP, the parties incorporate the FDPIC-recognised adaptations.
The SCCs (and the UK Addendum / Swiss adaptations) take precedence over any conflicting term of this DPA in respect of transfers within their scope.