Legal / Data Processing Agreement

Data Processing Agreement

Last updated 3 October 2026.

1. Introduction and Scope

This Data Processing Agreement (“DPA”) supplements the Terms of Service between SafeGrd (provided by Kush Kumar Sharma, of Bengaluru, India - 560048, “SafeGrd”, “Processor”, “we”, “us”) and the customer agreeing to these terms (“Customer”, “Controller”, “you”).

This DPA governs the processing of Personal Data in connection with the SafeGrd resilience platform pursuant to Article 28 of Regulation (EU) 2016/679 (the “GDPR”), the UK GDPR, and applicable data protection laws.

2. What SafeGrd Can and Cannot Access

What SafeGrd can read follows from choices Customer makes, each separately:

3. Roles and Documented Instructions

Customer is the Data Controller (or a Processor acting on behalf of a third-party controller) and SafeGrd is the Data Processor. SafeGrd shall process Customer Personal Data only in accordance with documented instructions from Customer, including with respect to international data transfers, unless required to do so by applicable law.

The Customer’s configuration of the SafeGrd CLI, backup targets, schedules, retention policies, and restore verifications through the Web Console or API, including where each surface’s drills run, constitutes Customer’s complete instructions.

SafeGrd shall immediately inform Customer if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.

4. Confidentiality

SafeGrd ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

5. Security of Processing (Article 32)

SafeGrd implements appropriate technical and organizational measures (TOMs) to ensure a level of security appropriate to the risk, as detailed in Schedule 2 below. These measures include asymmetric encryption, strict enforcement of immutable WORM storage, TLS 1.3 in transit, salted password hashing, scoped personal access tokens, rate limiting, and an Ed25519 cryptographic attestation chain.

6. Sub-processors

Customer grants SafeGrd general written authorization to engage third-party Sub-processors to assist in delivering the Service. The current list of authorized Sub-processors is published at safegrd.dev/subprocessors.

SafeGrd shall inform Customer of any intended additions or replacements of Sub-processors at least thirty (30) days prior to authorizing the Sub-processor to process Personal Data, providing Customer the opportunity to object. SafeGrd imposes contractual data protection obligations on every Sub-processor that are no less protective than those set out in this DPA, and remains fully liable to Customer for the performance of each Sub-processor’s obligations.

7. Assistance with Data Subject Requests

Taking into account the nature of the processing, SafeGrd assists Customer insofar as possible by appropriate technical and organizational measures for the fulfillment of Customer’s obligation to respond to requests for exercising Data Subject rights under Chapter III of the GDPR (including access, rectification, erasure, and data portability).

With a customer-managed key, Customer holds the only decryption key, so SafeGrd cannot read, search or alter the contents of backups, and Customer maintains direct control over restoring data and applying erasure or rectification requests. For data held on immutable WORM snapshots, Customer is responsible for maintaining an erasure suppression register and re-applying deletion requests post-restore.

SafeGrd shall also assist Customer, taking into account the nature of processing and the information available to SafeGrd, in ensuring compliance with Articles 32 to 36 of the GDPR, including data protection impact assessments and prior consultation with a supervisory authority.

8. Personal Data Breach Notification

SafeGrd shall notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data under SafeGrd’s custody. The notification shall describe the nature of the incident, the categories and approximate number of data subjects affected, and the remedial measures taken or planned.

9. Deletion and Return of Data

Upon termination of the Service, SafeGrd shall, at Customer’s choice, delete or return all Customer Personal Data stored in the control plane within thirty (30) days, unless applicable European Union or Member State law requires continued storage.

Customer may delete an organization from the console at any time, which ends its processing in the Service. SafeGrd then retains that organization’s control-plane records only to restore it at Customer’s request, and deletes them twelve (12) months after the deletion, or within thirty (30) days of Customer’s written request to support@safegrd.dev or of termination, whichever comes first.

Backups in SafeGrd-hosted storage are written under a compliance-mode object lock whose date Customer’s plan and settings fixed at the time of writing. Nobody, including SafeGrd, can delete a locked object before that date. Customer instructs SafeGrd to keep each hosted backup until its lock ends, and SafeGrd deletes it within one day after. Customer may download hosted backups before closing the account; they remain encrypted with Customer’s key throughout.

10. Audits and Attestation

SafeGrd shall make available to Customer all information necessary to demonstrate compliance with Article 28 of the GDPR, and shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. Audits are requested in writing with at least thirty (30) days’ notice, are limited to once a year unless a supervisory authority requires otherwise or a Personal Data Breach has occurred, are carried out during business hours under confidentiality, and are at Customer’s cost. SafeGrd will first offer its written security documentation and its signed Ed25519 Fire Drill attestation records, which demonstrate that backups are intact and restorable, and which may answer the audit without an inspection.

11. International Transfers

Where personal data originating in the EEA, Switzerland, or the UK is transferred to countries outside those territories that have not received an adequacy decision, the parties agree that the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2 Controller-to-Processor) are incorporated into this DPA by reference. For transfers from the United Kingdom, the International Data Transfer Addendum issued by the Information Commissioner applies to those clauses; for transfers from Switzerland, the clauses apply with the amendments required by the Swiss Federal Act on Data Protection.

Schedule 1: Details of Processing

Subject Matter Automated backup orchestration, verification attestation, and disaster recovery metadata management.
Duration The duration of Customer’s subscription under the Terms of Service, plus up to 30 days for data deletion upon account closure.
Nature & Purpose Scheduling backups, monitoring host health, detecting mass-deletion anomalies (Threat Shield), asserting restore integrity via automated Fire Drills, and, where Customer chooses it, running those drills on SafeGrd’s drill machines.
Data Types Account data (names, emails, password hashes), technical metadata (snapshot sizes, table and folder names, file counts, digests), and, for hosted storage only, backup contents as client-side encrypted ciphertext. Backups may contain any category of personal data, including special categories, as determined by Customer. SafeGrd processes them in readable form only during a drill Customer chose to run on SafeGrd, as described in section 2.
Data Subjects Customer administrative users and engineers, and end-users whose information is contained within Customer’s backed-up systems.

Schedule 2: Technical and Organizational Measures (TOMs)