Data Processing Agreement
Last updated 3 October 2026.
1. Introduction and Scope
This Data Processing Agreement (“DPA”) supplements the Terms of Service between SafeGrd (provided by Kush Kumar Sharma, of Bengaluru, India - 560048, “SafeGrd”, “Processor”, “we”, “us”) and the customer agreeing to these terms (“Customer”, “Controller”, “you”).
This DPA governs the processing of Personal Data in connection with the SafeGrd resilience platform pursuant to Article 28 of Regulation (EU) 2016/679 (the “GDPR”), the UK GDPR, and applicable data protection laws.
2. What SafeGrd Can and Cannot Access
What SafeGrd can read follows from choices Customer makes, each separately:
- Customer-Managed Key: Backups of your PostgreSQL databases, file directory trees, and IMAP mailboxes are compressed with zstandard and encrypted client-side with Age asymmetric cryptography (X25519) on your own host before transiting the network.
- Client-Side Encryption & Key Protection: By default, SafeGrd never receives database passwords, mailbox credentials or storage secret keys, and with a customer-managed key it never receives your Age private decryption key. Customer may choose, separately for each, to have SafeGrd hold a surface’s database or mailbox credential, a storage bucket’s secret key, or (under SafeGrd-managed key custody) the Age private key. SafeGrd stores anything so held encrypted under per-organization envelope protection, releases it only to enrolled host tokens during authorized operations (and the Age private key also to a drill Customer chose to run on SafeGrd, below), records every release in an audit log, and never returns it through the console or API.
- Where Backups Are Stored: Encrypted bytes stream directly from your host into your own storage bucket, or, if you choose SafeGrd-hosted storage, into compliance-locked object storage provided by SafeGrd. In the hosted case SafeGrd stores your backups only as ciphertext encrypted on your host, together with each object’s size and lock date. Backup contents never pass through SafeGrd’s control plane.
- Restore Drills Run on SafeGrd: Under SafeGrd-managed key custody, Customer may choose, for each surface, to have its restore drills run on SafeGrd instead of on Customer’s hosts. This is the only case in which SafeGrd decrypts a backup. For each such drill SafeGrd starts a virtual machine of its own with its compute Sub-processor. The machine downloads one snapshot from SafeGrd-hosted storage, decrypts it with the key SafeGrd releases to that drill alone, restores it into a temporary database or reads it in memory, checks it, and reports the result. The machine serves one drill of one organization. It is destroyed together with its storage when the drill ends or reaches its time limit. Every key release to a drill is recorded in Customer’s key access record. The decrypted contents never reach SafeGrd’s control plane, which keeps only the drill’s result.
- Backups Taken by SafeGrd: Under SafeGrd-managed key custody, Customer may give SafeGrd a database’s connection string to hold and have SafeGrd take that database’s backups. For each such backup SafeGrd starts a virtual machine of its own with its compute Sub-processor. The machine is released that connection string for that backup alone, connects to Customer’s database, dumps it, encrypts it to the organization’s key and writes it to SafeGrd-hosted storage. The machine is never released the key, serves one backup of one organization, and is destroyed when the backup ends or reaches its time limit. Every release of the connection string is recorded in Customer’s key access record. The dump never reaches SafeGrd’s control plane, which keeps only the backup’s record.
- What SafeGrd Processes: As Processor, SafeGrd processes technical metadata and telemetry: protected host and surface names, backup schedules, snapshot timestamps, item counts, byte sizes, table and folder names, SHA-256 integrity digests, and restore Fire Drill attestation records; for hosted storage, the ciphertext described above; and, for drills run on SafeGrd, the contents of the snapshot under drill, for the length of that drill.
3. Roles and Documented Instructions
Customer is the Data Controller (or a Processor acting on behalf of a third-party controller) and SafeGrd is the Data Processor. SafeGrd shall process Customer Personal Data only in accordance with documented instructions from Customer, including with respect to international data transfers, unless required to do so by applicable law.
The Customer’s configuration of the SafeGrd CLI, backup targets, schedules, retention policies, and restore verifications through the Web Console or API, including where each surface’s drills run, constitutes Customer’s complete instructions.
SafeGrd shall immediately inform Customer if, in its opinion, an instruction infringes the GDPR or other Union or Member State data protection provisions.
4. Confidentiality
SafeGrd ensures that persons authorized to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5. Security of Processing (Article 32)
SafeGrd implements appropriate technical and organizational measures (TOMs) to ensure a level of security appropriate to the risk, as detailed in Schedule 2 below. These measures include asymmetric encryption, strict enforcement of immutable WORM storage, TLS 1.3 in transit, salted password hashing, scoped personal access tokens, rate limiting, and an Ed25519 cryptographic attestation chain.
6. Sub-processors
Customer grants SafeGrd general written authorization to engage third-party Sub-processors to assist in delivering the Service. The current list of authorized Sub-processors is published at safegrd.dev/subprocessors.
SafeGrd shall inform Customer of any intended additions or replacements of Sub-processors at least thirty (30) days prior to authorizing the Sub-processor to process Personal Data, providing Customer the opportunity to object. SafeGrd imposes contractual data protection obligations on every Sub-processor that are no less protective than those set out in this DPA, and remains fully liable to Customer for the performance of each Sub-processor’s obligations.
7. Assistance with Data Subject Requests
Taking into account the nature of the processing, SafeGrd assists Customer insofar as possible by appropriate technical and organizational measures for the fulfillment of Customer’s obligation to respond to requests for exercising Data Subject rights under Chapter III of the GDPR (including access, rectification, erasure, and data portability).
With a customer-managed key, Customer holds the only decryption key, so SafeGrd cannot read, search or alter the contents of backups, and Customer maintains direct control over restoring data and applying erasure or rectification requests. For data held on immutable WORM snapshots, Customer is responsible for maintaining an erasure suppression register and re-applying deletion requests post-restore.
SafeGrd shall also assist Customer, taking into account the nature of processing and the information available to SafeGrd, in ensuring compliance with Articles 32 to 36 of the GDPR, including data protection impact assessments and prior consultation with a supervisory authority.
8. Personal Data Breach Notification
SafeGrd shall notify Customer without undue delay, and in any event within 72 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data under SafeGrd’s custody. The notification shall describe the nature of the incident, the categories and approximate number of data subjects affected, and the remedial measures taken or planned.
9. Deletion and Return of Data
Upon termination of the Service, SafeGrd shall, at Customer’s choice, delete or return all Customer Personal Data stored in the control plane within thirty (30) days, unless applicable European Union or Member State law requires continued storage.
Customer may delete an organization from the console at any time, which ends its processing in the Service. SafeGrd then retains that organization’s control-plane records only to restore it at Customer’s request, and deletes them twelve (12) months after the deletion, or within thirty (30) days of Customer’s written request to support@safegrd.dev or of termination, whichever comes first.
Backups in SafeGrd-hosted storage are written under a compliance-mode object lock whose date Customer’s plan and settings fixed at the time of writing. Nobody, including SafeGrd, can delete a locked object before that date. Customer instructs SafeGrd to keep each hosted backup until its lock ends, and SafeGrd deletes it within one day after. Customer may download hosted backups before closing the account; they remain encrypted with Customer’s key throughout.
10. Audits and Attestation
SafeGrd shall make available to Customer all information necessary to demonstrate compliance with Article 28 of the GDPR, and shall allow for and contribute to audits, including inspections, conducted by Customer or an auditor mandated by Customer. Audits are requested in writing with at least thirty (30) days’ notice, are limited to once a year unless a supervisory authority requires otherwise or a Personal Data Breach has occurred, are carried out during business hours under confidentiality, and are at Customer’s cost. SafeGrd will first offer its written security documentation and its signed Ed25519 Fire Drill attestation records, which demonstrate that backups are intact and restorable, and which may answer the audit without an inspection.
11. International Transfers
Where personal data originating in the EEA, Switzerland, or the UK is transferred to countries outside those territories that have not received an adequacy decision, the parties agree that the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914, Module 2 Controller-to-Processor) are incorporated into this DPA by reference. For transfers from the United Kingdom, the International Data Transfer Addendum issued by the Information Commissioner applies to those clauses; for transfers from Switzerland, the clauses apply with the amendments required by the Swiss Federal Act on Data Protection.
Schedule 1: Details of Processing
| Subject Matter | Automated backup orchestration, verification attestation, and disaster recovery metadata management. |
| Duration | The duration of Customer’s subscription under the Terms of Service, plus up to 30 days for data deletion upon account closure. |
| Nature & Purpose | Scheduling backups, monitoring host health, detecting mass-deletion anomalies (Threat Shield), asserting restore integrity via automated Fire Drills, and, where Customer chooses it, running those drills on SafeGrd’s drill machines. |
| Data Types | Account data (names, emails, password hashes), technical metadata (snapshot sizes, table and folder names, file counts, digests), and, for hosted storage only, backup contents as client-side encrypted ciphertext. Backups may contain any category of personal data, including special categories, as determined by Customer. SafeGrd processes them in readable form only during a drill Customer chose to run on SafeGrd, as described in section 2. |
| Data Subjects | Customer administrative users and engineers, and end-users whose information is contained within Customer’s backed-up systems. |
Schedule 2: Technical and Organizational Measures (TOMs)
- Asymmetric Client-Side Encryption: Data is encrypted using Age (X25519 / ChaCha20-Poly1305) before transmission; SafeGrd holds no private keys under customer custody mode.
- Immutable Storage (WORM): S3 Object Lock in compliance mode prevents modification or deletion before retention expiry, including on SafeGrd-hosted storage. Backups written to a local directory are made read-only, which deters but does not prevent deletion by an administrator of that host.
- Transport Security: All API and console communications are enforced over TLS 1.3 / TLS 1.2 with HSTS.
- Authentication & Access Controls: Scoped Personal Access Tokens (PATs), bcrypt password hashing, HttpOnly session cookies with CSRF protection, and strict CSP preventing inline script execution.
- Drill Isolation: Each drill run on SafeGrd has a Firecracker virtual machine of its own that serves no other drill or organization. A restored database runs as an unprivileged user that cannot read the drill’s credential. The machine and its storage are destroyed when the drill ends or reaches its time limit.
- Cryptographic Attestation: Restore verification proofs are sealed with Ed25519 signatures over append-only SHA-256 hash chains.