Data Processing Addendum

Last updated: July 27, 2026

If your organization needs a Data Processing Agreement to cover Burdenoff's processing of personal data on your behalf (for example, to satisfy GDPR Art. 28, the DPDP Act 2023, or an internal vendor-risk requirement), this page tells you how to get one downloaded, customized, and countersigned.

Download the DPA

The current standard DPA template — covering roles, processing activities, security measures, sub-processors, international transfers, data-subject-request assistance, deletion, audit rights, and a signature block — is available now:

Download DPA (text)

This document is also reproduced in full below for reference. The processing-activity annex reflects our default configuration; Enterprise customers with a materially different data flow receive a customized Annex 1 as part of execution.

How to Get It Signed

This is our current, documented execution process:

  1. Download the DPA above and review it, or request it via our contact form using the "Legal / DPA / Compliance" category — include your organization's legal name, the workspace or account this DPA covers, and a signatory contact.
  2. Our legal/compliance team reviews your request, confirms or customizes Annex 1 to match your actual configuration of the Service, and returns a countersignature-ready copy — typically within 5 business days.
  3. You and an authorized Burdenoff signatory execute the DPA (by wet signature, scanned copy, or a mutually agreed e-signature service). We do not require a specific e-signature platform; tell us if you have one you prefer to use.
  4. We countersign and return a fully executed copy to your signatory contact by email, and retain the executed copy as part of your account's legal record.
  5. Once executed, the DPA is legally binding immediately per its terms and applies for as long as your subscription to the Service continues, unless the parties agree otherwise in writing.

Enterprise customers: your DPA execution can be handled as part of your Order Form process by your account contact instead of the steps above — ask your Burdenoff contact to route it.

Full DPA Text

BURDENOFF DATA PROCESSING ADDENDUM (DPA)
Version 2026-08-01 (template)

This Data Processing Addendum ("DPA") forms part of the Terms of Service (or a
separately signed Master SaaS Agreement / Order Form) between the customer
identified in the applicable Order Form ("Customer," acting as data
controller or, where applicable, data processor on behalf of its own
customers) and Burdenoff Consultancy Services Pvt. Ltd. ("Burdenoff,"
acting as data processor / sub-processor), governing Burdenoff's processing
of personal data submitted to the Service on Customer's behalf.

1. DEFINITIONS
"Personal Data," "Processing," "Controller," "Processor," "Data Subject,"
and "Sub-processor" have the meanings given in the GDPR, or the closest
equivalent term under other applicable data protection law (including the
DPDP Act 2023 and the CCPA/CPRA), as context requires. "Customer Data" means
personal data that Customer or its authorized users submit to the Service.

2. ROLES
Customer is the controller (or processor, if Customer itself processes
personal data on behalf of a third party) of Customer Data. Burdenoff is a
processor / sub-processor that processes Customer Data solely to provide,
secure, and support the Service, on Customer's documented instructions as
set out in the Agreement and this DPA.

3. PROCESSING ACTIVITIES (ANNEX 1)
Identity & authentication (global-auth-svc): credentials, sessions, MFA state.
Tenant / organization management (global-tenant-svc): tenant metadata, member roles.
Billing (global-billing-svc): payment tokens, invoices, subscriptions.
Communications (global-notification-svc, global-channel-svc, global-newsletter-svc): contact info, message content.
Audit (global-activity-svc): activity logs, actor metadata.
Support (global-support-svc): tickets, messages, attachments.
Developer portal / marketplace (global-devportal-svc, global-store-svc): publisher/app metadata, order records.

4. SECURITY MEASURES (ANNEX 2)
Encryption in transit (TLS) for all Service traffic. Encryption at rest for
databases and object storage. Field-level AES-256 encryption for MFA
secrets, API/HMAC signing keys, OAuth tokens, and OIDC client secrets.
Tenant isolation via row-level scoping and opaque cross-service IDs.
Centrally enforced role-based access control (RBAC) at the API gateway; no
service re-implements its own authorization. Immutable activity/audit
logging with a mandatory 7-year retention floor and no admin-triggered
early deletion path. CI-gated CVE, IaC, and SBOM scanning before any
production deployment; commit-time secret scanning. Access to production
infrastructure restricted to authenticated operators via a managed Zero
Trust access broker; no public SSH.

5. SUB-PROCESSORS (ANNEX 3)
The current authoritative sub-processor list, including each party's
purpose and processing region, is published and kept up to date at
https://burdenoff.com/subprocessors. Burdenoff will provide at least 30
days' advance notice via that page before a new sub-processor with access
to Customer Data begins processing. Customer may object to a new
sub-processor on reasonable data-protection grounds by contacting
privacy@burdenoff.com within that notice period.

6. INTERNATIONAL TRANSFERS
Where Burdenoff transfers Customer Data out of the European Economic Area,
the United Kingdom, or Switzerland, the transfer is made under the European
Commission's Standard Contractual Clauses (Module 2 or Module 3, as
applicable), incorporated into this DPA by reference, or another legally
recognized transfer mechanism then available.

7. DATA SUBJECT REQUESTS
Burdenoff will provide reasonable assistance to Customer, to the extent
Customer cannot reasonably fulfil a data subject request itself using the
Service's available functionality, in responding to requests to exercise
data subject rights known to relate to Customer Data.

8. DATA DELETION
On termination of the Agreement, Burdenoff will delete or return Customer
Data within the period set out in the Agreement (absent a legal requirement
to retain it), consistent with Burdenoff's published data retention
practices at https://burdenoff.com/privacy.

9. SUB-PROCESSOR FLOW-DOWN
Burdenoff imposes data protection obligations on each sub-processor that
are substantially similar to those in this DPA and remains liable to
Customer for a sub-processor's performance of its data protection
obligations.

10. AUDIT
Burdenoff will make available information reasonably necessary to
demonstrate compliance with this DPA, and will allow for an audit,
including inspections, by Customer or an auditor mandated by Customer,
subject to reasonable advance notice, confidentiality, and no more than
once per 12-month period absent a security incident or regulator
requirement.

11. LIABILITY
Liability under this DPA is subject to the limitation of liability set out
in the Agreement.

12. EXECUTION
This DPA becomes legally binding on the Customer identified below once
counter-signed by an authorized Burdenoff representative and returned per
the execution process described above. Annex 1 may be supplemented with
customer-specific detail in the signed version where Customer's use of the
Service differs from the default description above.

Questions: privacy@burdenoff.com

Related Pages

Privacy Policy · Security · Subprocessors · Terms of Service

Last updated: July 27, 2026

Burdenoff LogoBurdenoff

Building tomorrow's products today through innovation, expertise, and dedication.

Contact

Stay Updated

Subscribe to our newsletter for the latest updates

Copyright © 2025 Burdenoff Consultancy Services Private Limited. All rights reserved.