Data Processing Agreement
How The Cloud Market processes customer data for hosted services and business accounts.
DATA PROCESSING AGREEMENT (DPA)
TheCloud.market
www.thecloud.market
Effective Date: 22 February 2026 | Last Updated: 22 February 2026
This Data Processing Agreement ("DPA") is entered into between TheCloud.market ("Data Processor") and the customer ("Data Controller" or "Data Fiduciary") who has agreed to TheCloud.market's Terms of Service. This DPA governs the processing of personal data carried out by TheCloud.market on behalf of the Customer in connection with the provision of hosting services.
This DPA forms part of and is subject to TheCloud.market's Terms of Service and Privacy Policy. In case of conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data processing matters.
1. Definitions
"Personal Data" means any information relating to an identified or identifiable natural person ("Data Subject"), as defined under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and applicable Indian law
"Processing" means any operation performed on personal data, including collection, storage, use, disclosure, and deletion
"Data Controller" / "Data Fiduciary" means the Customer who determines the purposes and means of processing personal data of their end users
"Data Processor" means TheCloud.market, which processes personal data on behalf of the Customer per this DPA
"Sub-Processor" means any third party engaged by TheCloud.market to process personal data in connection with providing the Services
"Data Subject" / "Data Principal" means the natural person whose personal data is being processed
2. Scope and Purpose
TheCloud.market processes personal data on behalf of the Customer solely to the extent necessary to:
Provide and maintain the hosting Services contracted by the Customer
Ensure the security, availability, and integrity of the hosting infrastructure
Comply with legal obligations applicable to TheCloud.market as a service provider under Indian law
The Customer, as Data Fiduciary, is responsible for ensuring that any personal data processed using TheCloud.market's infrastructure is collected and used lawfully and with appropriate consent from Data Principals.
3. Customer Responsibilities as Data Fiduciary
The Customer acknowledges and agrees that:
They are the Data Fiduciary for all personal data of their end users stored or processed on TheCloud.market's infrastructure
They are responsible for obtaining all necessary consents and providing all required notices to their Data Principals prior to processing
They have a lawful basis for all personal data processing activities conducted through the Services
They will comply with all applicable data protection laws including the DPDP Act 2023 and SPDI Rules 2011
They will not instruct TheCloud.market to process personal data in a manner that would violate applicable law
They are responsible for the accuracy, quality, and legality of personal data uploaded to our servers
4. TheCloud.market Obligations as Data Processor
TheCloud.market agrees to:
4.1 Instruction-Based Processing
Process personal data only on documented instructions from the Customer, unless required to do so by applicable law. TheCloud.market will notify the Customer if it believes an instruction infringes applicable data protection law, unless prohibited from doing so by law.
4.2 Confidentiality
Ensure that all personnel authorised to process personal data are bound by confidentiality obligations and are trained in data protection requirements.
4.3 Security
Implement and maintain appropriate technical and organisational security measures to protect personal data, including:
Encryption of data in transit (TLS/SSL) and at rest (AES-256 where applicable)
Role-based access controls limiting data access to authorised personnel only
Regular security audits and vulnerability assessments
Incident response procedures for data breaches
4.4 Sub-Processing
Not engage any Sub-Processor to process the Customer's personal data without prior general or specific authorisation. TheCloud.market maintains a list of current Sub-Processors (see Section 7). Customers who wish to object to the engagement of a new Sub-Processor may do so within 14 days of notice.
4.5 Data Subject Rights
Assist the Customer in responding to Data Principal rights requests under the DPDP Act 2023, including rights to access, correction, erasure, and grievance redressal, to the extent technically feasible and within the scope of our Services.
4.6 Breach Notification
Notify the Customer without undue delay (and within 72 hours where feasible) upon becoming aware of a personal data breach affecting the Customer's data processed by TheCloud.market. Such notification will include, to the extent known:
Nature of the breach and categories of data affected
Approximate number of Data Subjects affected
Likely consequences and measures taken or proposed to address the breach
4.7 Data Protection Impact
Assist the Customer in carrying out data protection impact assessments (DPIAs) where required by applicable law, to the extent the assessment relates to our processing activities.
4.8 Audit Rights
Upon reasonable written notice, make available to the Customer all information necessary to demonstrate compliance with this DPA, and allow for audits conducted by the Customer or its authorised representative, subject to reasonable confidentiality protections and with costs borne by the Customer.
4.9 Deletion or Return
Upon termination of the Services or upon written request from the Customer, delete or return all personal data and copies thereof, unless retention is required by applicable Indian law. TheCloud.market will certify such deletion in writing upon request.
5. Data Retention and Deletion
TheCloud.market retains Customer data for the duration of the active service subscription. Upon service termination:
Account and hosted data: Deleted within 7 days of service termination
Backup snapshots: May persist for up to 30 days post-termination before being overwritten
Billing and transaction records: Retained for 7 years as required under Indian GST and financial regulations
Abuse and security logs: Retained for up to 180 days as required for compliance and law enforcement purposes
6. Cross-Border Data Transfers
TheCloud.market primarily stores Customer data in India (GCP Mumbai region). In limited circumstances, personal data may be processed by Sub-Processors operating outside India. All such transfers are subject to:
Contractual data processing terms with Sub-Processors incorporating equivalent protections
Compliance with any applicable data localisation requirements under Indian law
Disclosure to the Customer of any Sub-Processors located outside India (see Section 7)
7. Authorised Sub-Processors
TheCloud.market currently engages the following categories of Sub-Processors who may access Customer personal data in the course of providing the Services:
Cloud Infrastructure: Google Cloud Platform (India and Singapore regions) - compute, storage, and database
Payment Processing: RBI-authorised payment gateway partners (India) - for billing and subscription management
Email Delivery: Transactional email service provider - for service notifications and alerts
Customer Support: Helpdesk and ticketing platform - for support ticket management
Monitoring and Security: Infrastructure monitoring and security scanning tools
TheCloud.market will maintain and update this list as Sub-Processors change and will notify the Customer via email 14 days before engaging a new Sub-Processor that involves processing Customer personal data.
8. Liability
Each party is liable for their own obligations under this DPA and applicable data protection law. The total aggregate liability of TheCloud.market under this DPA shall be subject to the limitations set out in the Terms of Service. TheCloud.market is not liable for data breaches or processing issues caused by the Customer's own applications, misconfigurations, or failure to follow security best practices.
9. Term and Termination
This DPA remains in effect for the duration of the Customer's subscription to TheCloud.market Services. It terminates automatically upon full termination of the Services Agreement, subject to any data retention obligations that survive termination as set out in Section 5.
10. Governing Law
This DPA is governed by the laws of India, including the DPDP Act 2023 and the SPDI Rules 2011. Any disputes shall be resolved in accordance with the dispute resolution mechanism set out in the Terms of Service.
11. Contact - Data Protection
For data processing queries, breach notifications, or DPA-related requests:
TheCloud.market Data Protection Officer
Email:[email protected]
Grievance Officer: [email protected]
Website: www.thecloud.market
This Data Processing Agreement is governed by the DPDP Act 2023 and the laws of India. It forms an integral partof TheCloud.marketTerms of Service.