DATA PROCESSING AGREEMENT

This Data Processing Agreement ("DPA") establishes a legally binding framework between Quentech Soft ("Data Processor") and the entity accepting these terms ("Data Controller"), effective as of (Effective Date).

Role of the Data Controller

The Data Controller is responsible for defining the objectives and legal basis for processing personal data and ensuring compliance with relevant data protection laws.

Role of the Data Processor

The Data Processor is engaged by the Data Controller to process personal data strictly in accordance with the Controller’s instructions and applicable regulations.

Definition of Personal Data

As per data protection regulations, "personal data" refers to any information that can be used to identify an individual, either directly or indirectly.

Scope of Processing Activities

Processing includes activities such as data collection, organization, storage, modification, retrieval, transmission, and deletion, as directed by the Data Controller.

Data Security Responsibilities

The Data Processor must implement technical and organizational security measures to protect personal data against unauthorized access, loss, or disclosure.

Confidentiality Obligations

All personal data must be treated as confidential. The Data Processor and its personnel are prohibited from disclosing data to unauthorized third parties.

Rights of Data Subjects

The Data Processor shall assist the Data Controller in responding to data subjects’ requests regarding access, correction, restriction, or deletion of their personal data.

Data Breach Protocol

In the event of a data breach, the Data Processor must notify the Data Controller without undue delay and take necessary steps to mitigate risks.

Subprocessors

The Data Processor may not engage third-party subprocessors without the Data Controller’s prior written consent. Any subprocessors must adhere to the same data protection obligations.

Legal Compliance

Both parties agree to comply with all applicable data protection laws and regulations.

Right to Audit

The Data Controller has the right to conduct audits or request documentation to verify the Data Processor’s adherence to this DPA, subject to reasonable notice.

Data Retention and Deletion

Upon termination of this agreement, the Data Processor must either return or securely delete all processed personal data as per the Data Controller’s instructions.

Data Retention Period

Personal data shall only be retained for as long as necessary, in accordance with the terms specified in the agreement or applicable legal requirements.

Notification Requirements

The Data Processor must promptly inform the Data Controller of any regulatory changes that may impact personal data processing.

Liability Clause

Each party’s liability under this agreement will be determined in accordance with the terms of the primary service agreement.

Indemnification

The Data Processor agrees to indemnify and hold the Data Controller harmless against any claims or penalties resulting from non-compliance with data protection obligations.

Governing Law

All disputes arising from this agreement shall be subject to Indian legal statutes.

Amendments and Modifications

Any amendments to this DPA must be documented in writing and signed by both parties to be legally valid.

The parties acknowledge and agree to the terms of this Data Processing Agreement as of the effective date.

(Signature lines for both parties)