Data Processing Agreement
Last updated: July 1, 2026. For GDPR and DPDPA compliance.
1. Definitions
The following terms have the meanings set out below throughout this Data Processing Agreement ("DPA"):
- Controller — The customer who determines the purposes and means of processing Personal Data.
- Processor — Semaphore Cloud Technologies Pvt. Ltd., which processes Personal Data on behalf of the Controller.
- Personal Data — Any information relating to an identified or identifiable natural person (data subject).
- Processing — Any operation performed on Personal Data, including collection, storage, use, transfer, or deletion.
- Data Subject — A natural person whose Personal Data is processed under this DPA.
- GDPR — The EU General Data Protection Regulation (EU) 2016/679.
- DPDPA 2023 — The Digital Personal Data Protection Act 2023 of India.
2. Scope & Purpose
This DPA governs Semaphore Cloud's processing of Personal Data on behalf of customers (Controllers) in connection with the cloud hosting services described in the Terms of Service. This DPA forms part of, and is incorporated into, the Terms of Service.
Semaphore Cloud acts solely as a Processor and processes Personal Data only upon and in accordance with the documented instructions of the Controller. Semaphore Cloud will not process Personal Data for any purpose other than providing the contracted services, unless required to do so by applicable law.
3. Customer Obligations
As the Controller, the customer is responsible for: ensuring that the collection and use of Personal Data is lawful and complies with applicable regulations including GDPR and DPDPA 2023; ensuring that Data Subjects have been provided with appropriate privacy notices; not instructing Semaphore Cloud to perform any processing that would violate applicable data protection law; and ensuring appropriate access controls within the customer's own systems and account.
4. Semaphore's Obligations
As the Processor, Semaphore Cloud commits to: process Personal Data only on documented instructions from the Controller; ensure that all personnel authorised to process Personal Data are bound by appropriate confidentiality obligations; implement and maintain appropriate technical and organisational security measures; assist the Controller in fulfilling Data Subject rights requests (see Section 8); and notify the Controller of any personal data breach within 72 hours of becoming aware of it (see Section 9).
5. Sub-Processors
Semaphore Cloud engages the following sub-processors in connection with providing our services. All sub-processors are bound by data processing agreements with obligations no less protective than this DPA.
| Sub-Processor | Purpose | Location |
|---|---|---|
| Razorpay | Payment processing | India |
| Stripe | Payment processing | United States |
| AWS (SES) | Transactional email delivery | India / EU |
| Cloudflare | DDoS protection & network security | Global |
We will notify Controllers at least 30 days before engaging any new sub-processor, providing an opportunity to object. If you object and we cannot accommodate the objection, you may terminate the relevant services without penalty.
6. International Data Transfers
Data stored on Semaphore Cloud infrastructure is primarily located in India. Transfers of Personal Data outside India are performed only where appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission for transfers to EU-regulated data, and adequacy decisions where applicable.
For EU customers, transfers to sub-processors in third countries (such as Stripe in the US) are governed by Module 3 SCCs (Processor-to-Processor), incorporated by reference into this DPA.
7. Security Measures
Semaphore Cloud maintains technical and organisational measures including: AES-256 encryption for all Personal Data at rest; TLS 1.3 for all data in transit; strict role-based access controls with least-privilege principles; comprehensive audit logging of access to systems holding Personal Data; regular third-party penetration testing (at least annually); and a documented incident response procedure tested twice yearly.
8. Data Subject Rights
Semaphore Cloud will assist the Controller in responding to Data Subject requests for access, erasure, data portability, and rectification. Upon receiving a validated request from the Controller, Semaphore Cloud will provide the requested assistance within 30 days. Semaphore Cloud will forward any Data Subject requests received directly to the Controller without responding directly, unless legally required to do so.
9. Breach Notification
In the event of a confirmed personal data breach affecting the Controller's data, Semaphore Cloud will notify the Controller within 72 hours of becoming aware of the breach. The notification will include, to the extent known: the nature of the breach, categories and approximate number of Data Subjects and records affected, the likely consequences, and measures taken or proposed to address the breach.
10. Audit Rights
The Controller may audit Semaphore Cloud's compliance with this DPA once per calendar year, with at least 30 days' written notice. Audits are conducted during normal business hours and must not unreasonably disrupt operations. The Controller may alternatively commission an independent third-party auditor, provided the auditor is bound by confidentiality obligations acceptable to Semaphore Cloud.
Semaphore Cloud may satisfy audit requests by providing current third-party certification reports (such as SOC 2 Type II reports) in lieu of an on-site audit, where the Controller agrees this is sufficient.
11. Termination
Upon termination of the services agreement, Semaphore Cloud will, at the Controller's election, either return all Personal Data in a commonly used machine-readable format or securely delete all Personal Data within 30 days. Semaphore Cloud will provide written certification of deletion upon request. Sub-processors will be instructed to delete or return data in the same timeframe.
12. Contact
For all DPA-related enquiries, requests to execute a countersigned DPA, or questions about data processing practices, please contact:
Email: support@semaphorecloud.com
Post: Data Protection Officer, Semaphore Technosoft LLP, Surat, Gujarat, India
Enterprise customers can request a countersigned copy for their compliance records.
Request Signed DPA