0. How to use this template
This is a template, not legal advice. The operative agreement is the version both parties execute. It is drafted to align with Article 28 of the EU/UK GDPR and to be compatible with India’s DPDPA 2023 and the UAE PDPL. Where your organisation has its own DPA, we are happy to review it.
1. Definitions and roles
“Controller”, “Processor”, “Data Subject”, “Personal Data”, “Processing”, and “Personal Data Breach” have the meanings given in applicable data-protection law. For the Platform, the customer is the Controller and EEVSEC is the Processor. Under DPDPA 2023, the customer is the Data Fiduciary and EEVSEC is a Data Processor.
2. Subject matter and details of processing
- Subject matter: provision of the EEVSEC CyberRange training platform.
- Duration: the term of the customer’s subscription, plus any wind-down period in Section 9.
- Nature and purpose: hosting and operating training accounts, matches, and analytics.
- Categories of data subjects: the customer’s authorised users (e.g. employees, students).
- Categories of personal data: account identifiers (name, email, role), authentication data, and match/usage telemetry. The Platform is not intended for special-category data.
3. Processor obligations (Article 28)
EEVSEC will: (a) process personal data only on the Controller’s documented instructions, including for international transfers, unless required by law; (b) ensure persons authorised to process the data are bound by confidentiality; (c) implement the technical and organisational measures in Section 5; (d) respect the conditions for engaging sub-processors in Section 4; (e) assist the Controller, by appropriate measures, in responding to data-subject requests; (f) assist the Controller with security, breach notification, and data-protection impact assessments; (g) at the Controller’s choice, delete or return the data at the end of the services per Section 9; and (h) make available information necessary to demonstrate compliance and allow for audits per Section 7.
4. Sub-processors
The Controller provides general authorisation for EEVSEC to engage the sub-processors needed to deliver the Platform. As of the template date these include: hosting/CDN (GitHub Pages and, where deployed, Cloudflare), waitlist and transactional email (Loops.so), and contact-form delivery (Web3Forms); enterprise deployments may add cloud-infrastructure and identity providers named in the order form. EEVSEC will impose data-protection terms on each sub-processor no less protective than this DPA, remains liable for their performance, and will give the Controller prior notice of any intended addition or replacement so the Controller can object on reasonable data-protection grounds.
5. International transfers and security
Where personal data is transferred across borders (for example, processing in India), the transfer is protected by an appropriate safeguard — the EU/UK Standard Contractual Clauses (or the UK IDTA/Addendum) and equivalent mechanisms — which the parties incorporate by reference and complete in the order form. EEVSEC protects personal data with encryption in transit and at rest, role-based access controls, isolated single-use simulation environments, logging, and ongoing security monitoring, as further described in our Security policy.
6. Personal data breach notification
EEVSEC will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller’s data, and in any event within the timeframe set in the order form (target: 72 hours), providing the information the Controller needs to meet its own notification duties. Our incident process is summarised at Incident Response & Breach Notification.
7. Audit and assistance
EEVSEC will make available the information reasonably necessary to demonstrate compliance with Article 28 and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, and frequency limits. Where available, EEVSEC may satisfy an audit request by providing current third-party reports or security documentation.
8. Data-subject requests
If EEVSEC receives a request from a data subject under any data-protection law, it will, to the extent legally permitted, promptly forward it to the Controller and will not respond directly except on the Controller’s documented instructions. EEVSEC will provide reasonable assistance to enable the Controller to respond within statutory timeframes.
9. Return and deletion
On termination or expiry of the services, EEVSEC will, at the Controller’s choice, delete or return all personal data and delete existing copies, unless retention is required by law. Deletion will be carried out within a commercially reasonable period and confirmed on request.
10. Contact and execution
DPA execution / enterprise: hi@eevsec.com · contact form
EEVSEC PRIVATE LIMITED, CIN U62013GJ2026PTC177190
401, Garud Apartment, Opp: Mahabaleshwar Flat, Jodhpur Char Rasta, Ahmedabad, Gujarat 380015, India