Legal

Data Processing Agreement (DPA)

Effective 4 September 2026Version 1.0Lalinx Private Limited

This Data Processing Agreement ("DPA") forms part of the agreement between Lalinx Private Limited ("Lalinx", the "Processor") and the customer identified in the applicable Order Form (the "Customer", the "Controller") for the Opsore ITSM service (the "Service") (together, the "Agreement").

It applies whenever Lalinx processes Personal Data contained in Customer Data on behalf of Customer, and is written to satisfy Article 28 GDPR / UK GDPR and the processor obligations of India's DPDP Act, 2023.

1. Definitions

"Personal Data", "Data Subject", "Processing", "Supervisory Authority", "Personal Data Breach" have the meanings given in the GDPR; "Data Principal" and "Data Fiduciary" have the meanings given in the DPDP Act. "Sub-processor" means a third party engaged by Lalinx to process Personal Data under this DPA.

2. Roles and scope

2.1 Customer is the Controller (or Data Fiduciary, or a processor acting for another controller) of Personal Data in Customer Data; Lalinx is the Processor (Data Processor).

2.2 Details of the Processing are set out in Annex 1.

2.3 Each party will comply with the data protection laws applicable to it ("Data Protection Laws").

3. Lalinx's obligations as Processor

Lalinx will:

a. process Personal Data only on Customer's documented instructions — the Agreement, this DPA, and use of the Service's features constitute those instructions — unless required otherwise by law, in which case Lalinx will inform Customer unless legally prohibited;

b. inform Customer if, in its opinion, an instruction infringes Data Protection Laws;

c. ensure persons authorized to process Personal Data are bound by confidentiality obligations;

d. implement the technical and organizational measures in Annex 3;

e. respect the sub-processing conditions in Section 5;

f. assist Customer, taking into account the nature of processing, in responding to Data Subject / Data Principal requests (Section 6) and in meeting Customer's obligations regarding security, breach notification, and data protection impact assessments;

g. delete or return Personal Data at end of service (Section 8);

h. make available information necessary to demonstrate compliance and allow audits (Section 9);

i. maintain a record of processing activities carried out on behalf of Customer.

4. Customer's obligations

Customer warrants that it has a lawful basis (including any required notices and consents to Data Principals under the DPDP Act) for the Personal Data it submits, that its instructions comply with Data Protection Laws, and that it will not submit special categories of data / sensitive data beyond what the Service is designed for (IT service management records).

5. Sub-processors

5.1 Customer gives general authorization for the Sub-processors listed in Annex 2.

5.2 Lalinx will give at least 15 days' prior notice (email to the account owner) before adding or replacing a Sub-processor. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected subscription and receive a pro-rata refund of prepaid unused fees.

5.3 Lalinx will impose data protection obligations on each Sub-processor no less protective than this DPA and remains liable for their performance.

6. Data subject / data principal requests

If Lalinx receives a request directly from an individual concerning Personal Data in Customer Data, it will (to the extent legally permitted) redirect the individual to Customer and not respond substantively. The Service provides search, export, correction, and deletion tools; where those are insufficient, Lalinx will provide reasonable assistance at Customer's request.

7. Personal Data Breach

7.1 Lalinx will notify Customer without undue delay, and in any case within 48 hours, after becoming aware of a Personal Data Breach affecting Customer's Personal Data, at the account owner's email.

7.2 The notice will describe, to the extent known: the nature of the breach, categories and approximate numbers of individuals and records affected, likely consequences, measures taken or proposed, and a contact point. Information may be provided in phases.

7.3 Lalinx will cooperate with Customer's own notification obligations (Supervisory Authority, Data Protection Board of India, Data Principals) and will make its own legally required reports (e.g. CERT-In). Lalinx will not notify Customer's regulators or data subjects on Customer's behalf unless required by law.

8. Return and deletion

For 30 days after termination or expiry, Customer may export Customer Data using the Service's export features or by written request. Lalinx will then delete all Personal Data within 60 days, except (a) backup copies, which are destroyed on the normal backup rotation cycle of 35 days, and (b) data Lalinx must retain by law, which remains protected under this DPA. On request, Lalinx will confirm deletion in writing.

9. Audit

Lalinx will make available, on written request no more than once per 12 months: its current security documentation, completed security questionnaires (e.g. CAIQ), and summaries of any third-party assessments it holds. If these are insufficient to demonstrate compliance, Customer may conduct (directly or via an independent auditor under NDA) an audit of relevant records and facilities, on at least 30 days' notice, during business hours, at Customer's cost, no more than once per year, and without access to other customers' data.

10. International transfers

Personal Data is stored at rest in India on DigitalOcean infrastructure (Bangalore region). Traffic in transit is routed via Cloudflare's edge network. Lalinx will not transfer stored Personal Data outside India except via Sub-processors in Annex 2. For transfers of EEA/UK Personal Data to countries without an adequacy decision, the parties incorporate the EU Standard Contractual Clauses (Module 2: controller→processor) and the UK Addendum by reference, with Customer as data exporter and Lalinx as data importer; details completed per Annexes 1–3.

11. Liability and order of precedence

Liability under this DPA is subject to the limitations and exclusions in the Agreement's Limitation of Liability section. In case of conflict between this DPA and the Agreement, this DPA prevails for data protection matters.

Annex 1 — Details of Processing

ItemDescription
Subject matterProvision of the Opsore ITSM SaaS platform
DurationTerm of the Agreement plus the deletion period in Section 8
Nature & purposeHosting, storage, display, transmission, backup, and support of Customer Data to deliver IT service management functionality (ticketing, asset management, workflows, knowledge base, reporting)
Categories of Data SubjectsCustomer's employees, contractors, and end users who submit or are referenced in tickets; Customer's administrators
Categories of Personal DataName, business email, phone, employee ID, department/role, IP address, device/asset identifiers, ticket contents (free text may contain any data the requester includes), authentication logs
Special categoriesNone intended; Customer is instructed not to submit them
FrequencyContinuous during the term

Annex 2 — Approved Sub-processors

Sub-processorPurposeLocation / RegionSafeguard
DigitalOcean LLCCloud infrastructure: VPS, managed database, object storage & backupsIndia — Bangalore (BLR1)DO DPA; SOC 2 / ISO 27001 certified
Cloudflare, Inc.DNS, CDN, TLS, DDoS/WAF protection (data in transit only — nothing stored)Global edge networkCloudflare DPA + SCCs; ISO 27001
Zoho Corporation (Zoho Mail API)Transactional email notifications from the ServiceIndiaZoho DPA
Razorpay Software Pvt LtdBilling & payments (account/billing contacts only — no Customer Data)IndiaRazorpay terms/DPA

Current list also published at: opsore.com/subprocessors [TO CREATE].

Annex 3 — Technical and Organizational Measures

Lalinx may update these measures from time to time, provided updates do not materially reduce the overall level of protection during a subscription term.

  • Encryption: TLS 1.2+ for all data in transit (edge TLS via Cloudflare with Full-strict encryption to origin); managed database encrypted at rest; block-storage volumes encrypted at rest; backups stored on encrypted object storage.
  • Access control: role-based access; production access restricted to named engineers; MFA mandatory for all administrative and infrastructure access; access reviewed quarterly and revoked on personnel exit.
  • Tenant isolation: logical separation of customer workspaces at the application and database layer.
  • Backups: automated daily backups; retained 35 days on a rolling cycle; restore procedure tested at least quarterly.
  • Vulnerability management: dependency and OS patching on a monthly cycle; critical security patches applied as soon as practicable.
  • Logging & monitoring: authentication and administrative actions logged; monitoring and log aggregation via self-hosted Grafana on Lalinx-controlled infrastructure (no third-party monitoring service); logs retained 180 days (rolling) within India per the CERT-In Directions, 2022.
  • Secure development: code review before production deployment; secrets kept out of source control; separate production and development environments.
  • Personnel: confidentiality agreements for all staff; security awareness as part of onboarding; offboarding checklist including access revocation.
  • Incident response: documented incident response plan with defined roles and the customer-notification commitment in Section 7.
  • Physical security: inherited from the cloud infrastructure provider's certified data centers.

⚠️ for internal review. Before first signature: fill Annex 2, confirm the 48-hour breach window is achievable, and have counsel verify SCC incorporation language if you target EEA/UK customers.

Questions about this document?

Write to legal@opsore.com, or for privacy matters privacy@opsore.com.

Contact us