Data Processing Addendum (DPA)
Contractual data processing terms drafted pursuant to GDPR Article 28 and Section 8 of the Indian DPDP Act 2023.
1. Context & Purpose
This Data Processing Addendum ("DPA") supplements the Master Services Agreement ("MSA") or Statement of Work ("SoW") between BHISHMASEC CYBERSECURITY SOLUTIONS (OPC) PRIVATE LIMITED ("BhishmaSec" or "Processor") and the contracting corporate client ("Client" or "Controller"). This DPA governs the processing of Personal Data incidental to the performance of security architecture, DevSecOps pipeline reviews, cloud hardening, and offensive penetration testing services.
2. Processing Subject Matter & Instructions
Processor shall process Personal Data exclusively on documented instructions from Controller, including with respect to transfers of Personal Data, unless required to do so by applicable law. The duration of processing corresponds to the term of the applicable Statement of Work plus the standard 30-day re-test validation window.
3. Personnel Confidentiality
Processor ensures that all consultants, engineers, and personnel authorized to process Personal Data have executed strict non-disclosure commitments and are under an appropriate statutory obligation of confidentiality.
4. Technical & Organizational Security Measures (TOMs)
Pursuant to GDPR Article 32 and DPDP Act Section 8, Processor maintains institutional technical safeguards:
- Cryptographic Controls: Mandatory TLS 1.3 encryption for in-transit communication and AES-256 GCM encryption for stored engagement artifacts.
- Access Restriction: FIDO2/WebAuthn multi-factor authentication, IP-restricted bastions, and least-privilege role boundaries.
- Audit Logging: Immutable tamper-evident logging of all consultant interactions within client test environments.
- Post-Engagement Data Erasure: Automatic cryptographic purge of all raw vulnerability exploit scripts and temporary staging credentials within 30 days of re-test completion.
5. Authorized Sub-Processors
Controller provides general authorization for Processor to engage sub-processors listed in our Sub-Processor Directory. Processor remains fully liable to Controller for the performance of each sub-processor's obligations.
6. Incident Management & Breach Notification
In the event Processor becomes aware of a confirmed Security Incident or Personal Data Breach affecting Controller data, Processor shall:
- Notify Controller in writing without undue delay, and in any event within twenty-four (24) hours of confirmed discovery.
- Provide technical details regarding the nature of the breach, affected records, and immediate mitigation actions taken.
- Provide reasonable cooperation to enable Controller to fulfill mandatory regulatory reporting notifications (e.g. to the DPBI or EU Supervisory Authorities).
7. Deletion or Return of Personal Data
Upon conclusion of contracted services, Processor shall, at Controller's election, securely delete or return all Personal Data in its possession, certifying completion of deletion in writing.
8. Execution & Inquiries
To obtain an executed bilateral copy of this DPA for your compliance vendor file, contact: [email protected]