Data Processing Agreement

Last Updated: August 01, 2026 | Version 1.0

This Data Processing Agreement ("DPA") forms part of the Agreement between HarkX Technologies Global Private Limited ("HarkX", "Provider", "Processor" or “Service Provider”, as applicable) and the customer identified in the applicable Order Form or Agreement ("Customer", "Controller", "Business", or “Data Fiduciary”, as applicable).

This DPA applies only where and to the extent HarkX Processes Personal Data on behalf of Customer in connection with the Services.

If there is any conflict between this DPA and the Agreement with respect to the Processing of Personal Data, this DPA will prevail solely with respect to such Processing.

1. Definitions

Unless otherwise defined in the Agreement, the following terms have the meanings below.

Applicable Data Protection Laws means all laws applicable to the Processing of Personal Data under the Agreement, including, where applicable, the GDPR, UK GDPR, DPDP Act, CCPA/CPRA and any other applicable privacy or data protection laws.

Personal Data means any information relating to an identified or identifiable natural person that is included within Customer Data and regulated by Applicable Data Protection Laws.

Customer Data has the meaning assigned in the Agreement.

Processing means any operation performed on Personal Data including collecting, recording, storing, using, transmitting, analysing, disclosing, deleting or otherwise handling Personal Data.

Security Incident means any confirmed accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to Personal Data Processed by HarkX.

Subprocessor means any third party engaged by HarkX to Process Personal Data on HarkX's behalf in connection with the Services.

2. Scope

This DPA applies only to Personal Data that HarkX Processes on behalf of Customer while providing the Services.

This DPA does not apply to:

  • information processed by HarkX as an independent controller;
  • publicly available information;
  • anonymised information that no longer identifies an individual; or
  • information that does not constitute Personal Data under Applicable Data Protection Laws.

3. Roles of the Parties

Except where otherwise agreed in writing:

  1. Customer acts as the Controller or Business or Data Fiduciary (or a Processor acting on behalf of a Controller); and
  2. HarkX acts solely as a Processor or Service Provider with respect to Personal Data Processed under the Agreement.

Nothing in this DPA transfers ownership of Customer Data or Personal Data to HarkX.

4. Processing of Personal Data

HarkX will Process Personal Data only:

  1. on Customer's documented instructions;
  2. as necessary to provide, maintain, secure, support and improve the Services;
  3. to comply with applicable law; or
  4. as otherwise permitted under the Agreement.

By entering into the Agreement and this DPA, Customer authorises and instructs HarkX to Process Personal Data for the purposes described in the Agreement, this DPA, and Schedule 1.

If HarkX reasonably believes that a Customer instruction violates Applicable Data Protection Laws, HarkX will notify Customer unless prohibited by law.

5. Confidentiality

HarkX will ensure that all personnel authorised to Process Personal Data:

  1. are subject to appropriate confidentiality obligations;
  2. receive appropriate security and privacy training; and
  3. access Personal Data only where necessary to perform their responsibilities.

These obligations survive termination of employment or engagement.

6. Security Measures

HarkX will implement and maintain appropriate technical and organisational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to Personal Data, taking into account the nature, scope, context, and purposes of the Processing, as well as the risks to the rights and freedoms of natural persons.

Such measures will be appropriate to the Services and the risks associated with the Processing and may include, as appropriate, measures relating to access controls, encryption, system security, vulnerability management, logging and monitoring, incident response, backup and recovery, personnel security, and secure software development. HarkX may review and update its technical and organisational measures from time to time, provided that such updates do not materially diminish the overall level of protection afforded to Personal Data.

7. Security Incidents

HarkX will notify Customer without undue delay after becoming aware of a Security Incident affecting Personal Data Processed under this DPA. HarkX will take reasonable steps to investigate, mitigate and remediate the Security Incident.

To the extent reasonably available, the notification will include:

  1. the nature of the Security Incident;
  2. the categories of affected Personal Data;
  3. the likely consequences;
  4. measures taken or proposed to mitigate the incident; and
  5. contact information for further communications.

Notification of a Security Incident does not constitute an admission of fault or liability.

8. Assistance to Customer

Taking into account the nature of the Processing and the information available to HarkX, HarkX will provide reasonable assistance to Customer to enable Customer to comply with its obligations under Applicable Data Protection Laws, including with respect to:

  1. responding to Data Subject requests;
  2. data protection impact assessments;
  3. prior consultation with supervisory authorities where required; and
  4. investigations relating to Personal Data Processed under this DPA.

Where the requested assistance falls outside the Services or requires significant additional effort, HarkX may charge reasonable fees after informing Customer in advance.

9. Subprocessors

Customer authorises HarkX to engage Subprocessors to support delivery of the Services.

HarkX will:

  1. enter into written agreements requiring Subprocessors to protect Personal Data to a standard substantially equivalent to this DPA;
  2. remain responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Laws;
  3. maintain an up-to-date list of Subprocessors available on HarkX website or otherwise made available to Customer.

Where required by Applicable Data Protection Laws, HarkX will provide prior notice of the appointment or replacement of a Subprocessor.

If Customer reasonably objects to a new Subprocessor on data protection grounds, the parties will work together in good faith to resolve the concern.

10. Data Subject Rights

Where HarkX receives a request from a Data Subject relating to Personal Data Processed on behalf of Customer, HarkX will promptly notify Customer unless prohibited by law.

HarkX will not respond directly to such request except:

  1. where authorised by Customer;
  2. where required by law; or
  3. where necessary to protect the security of the Services.

11. Government Requests

Unless legally prohibited, HarkX will promptly notify Customer of any legally binding request from a governmental authority seeking access to Personal Data.

Where appropriate, HarkX will use reasonable efforts to limit disclosure and challenge requests that are unlawful or overbroad.

12. International Transfers

Where Personal Data is transferred outside the jurisdiction from which it originated, HarkX will ensure that an appropriate transfer mechanism recognised under Applicable Data Protection Laws is implemented.

Where required, such mechanism may include:

  1. the European Commission Standard Contractual Clauses;
  2. the UK International Data Transfer Addendum;
  3. an adequacy decision; or
  4. any other legally recognised transfer mechanism.

13. Return and Deletion

Upon termination of the Services or upon Customer's written request, HarkX will, within a commercially reasonable period:

  1. return Customer Personal Data; or
  2. securely delete Customer Personal Data,

unless retention is required by applicable law or necessary for legitimate backup, disaster recovery or legal hold purposes. Where retained, such Personal Data will remain subject to this DPA until deleted.

14. Audit and Compliance

Upon reasonable written request, and no more than once in any twelve months, HarkX will make available information reasonably necessary to demonstrate compliance with this DPA.

Where such information is insufficient to satisfy Customer's legal obligations, the parties may agree upon a reasonable audit conducted:

  1. during normal business hours;
  2. with reasonable advance notice;
  3. subject to confidentiality obligations; and
  4. in a manner that does not unreasonably interfere with HarkX's business.

HarkX may satisfy audit requests by providing independent audit reports, certifications, or other documentation reasonably demonstrating its compliance with this DPA. Each party will bear its own costs unless otherwise agreed.

15. Changes in Applicable Data Protection Laws

If changes in Applicable Data Protection Laws materially affect the Services or this DPA, the parties will cooperate in good faith to implement appropriate amendments necessary to maintain compliance.

16. Liability

The liability of each party arising from this DPA is subject to the exclusions, limitations and liability caps set out in the Agreement.

Nothing in this DPA limits liability that cannot be excluded under Applicable Data Protection Laws.

17. General

This DPA forms part of the Agreement.

Except as expressly modified by this DPA, the Agreement remains unchanged.

This DPA terminates automatically when HarkX no longer Processes Personal Data on behalf of Customer.

Schedule 1 – Description of Processing

This Annex forms part of the Data Processing Agreement (DPA).

1. Subject Matter of Processing

HarkX processes Personal Data on behalf of Customer solely for the purpose of providing, operating, securing, maintaining, supporting, and improving the Services in accordance with the Agreement and Customer's documented instructions.

2. Nature and Purpose of Processing

Processing activities may include the collection, recording, organisation, storage, hosting, retrieval, use, transmission, analysis, disclosure where authorised, deletion, and other processing necessary to provide the Services.

HarkX may also process Personal Data to:

  1. detect, investigate, and respond to cybersecurity threats and incidents;
  2. authenticate users and manage access to the Services;
  3. provide technical support and customer service;
  4. maintain the security, integrity, availability, and performance of the Services; and
  5. comply with applicable legal or regulatory obligations.

3. Categories of Data Subjects

Depending on Customer's use of the Services, Personal Data may relate to:

  1. Customer personnel, including employees, contractors, consultants, and authorised users;
  2. Customer's customers, vendors, suppliers, or business partners;
  3. individuals whose Personal Data is contained in Customer's systems, logs, alerts, investigations, or other Customer Data submitted to the Services.

4. Categories of Personal Data

Customer determines the categories of Personal Data submitted to the Services. Such Personal Data may include:

  1. names;
  2. business contact details;
  3. email addresses;
  4. usernames and user identifiers;
  5. IP addresses;
  6. device identifiers;
  7. authentication and identity information;
  8. security logs and audit records;
  9. network, endpoint, application, and email security metadata;
  10. incident investigation records;
  11. support communications; and
  12. any other Personal Data included in Customer Data.

Customer should not submit Special Categories of Personal Data or sensitive Personal Data unless expressly agreed by the parties, and Customer has obtained all notices, consents, permissions or other lawful authorisations required under Applicable Data Protection Laws.

5. Duration of Processing

HarkX will Process Personal Data for the duration of the Agreement and thereafter only for so long as necessary to comply with applicable law, legal obligations, legitimate backup and disaster recovery requirements, or Customer's documented instructions.