Zero-X Cloud (Infimatrix) Legal Policy Center

Effective since: November 15, 2025

Privacy Policy

Operating Corporate Entities: Infimatrix Inc. (Delaware, USA) & Infimatrix Technologies Private Limited (India) collectively called as Infimatrix

1. Scope and Controller-Processor Architecture

This Privacy Policy describes how personal data and cloud infrastructure telemetry are collected, processed, and secured when you visit www.zero-x.cloud (the “Website”) or subscribe to our cloud-native security platform applications and automated threat detection components (the “Services”).

For the purposes of applicable Data Protection Laws—including the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, and all amendments and guidelines issued thereunder (collectively, the “DPDPA”), the General Data Protection Regulation (GDPR) (EU) 2016/679, and UAE Federal Decree-Law No. 45 of 2021—Zero-X Cloud acts strictly as a Data Processor / Sub-fiduciary processing personal data solely on behalf of, and under the documented instructions of, the customer, who remains the Data Controller / Data Fiduciary.

2. Information Collection, Purpose, and Unbundled Consent

We reject bundled consent mechanics. We collect and process personal data under unbundled, purpose-linked grounds strictly to provide, secure, and maintain an enterprise security platform:

Account Activation Data: Upon voluntary portal registration, we collect your name, business email address, corporate telephone number, company name, and job title. This data is used exclusively to fulfill service requests, manage subscription accounts, and handle electronic billing.

Platform Security Logs: We automatically log Internet Protocol (IP) addresses, approximate geographic location, browser variants, operating systems, and functional session tokens over encrypted HTTPS channels to analyze traffic patterns, diagnose anomalies, and secure platform infrastructure.

3. Comprehensive Cookie Framework

We deploy cookies and similar tracking technologies to enhance user experiences and monitor platform metrics. Essential functional cookies are deployed automatically, while non-essential tracking cookies require your explicit consent:

Cookie Category

Served By

Operational Purpose

Regulatory Status

Strictly Necessary

Infimatrix, Inc.

Persists user secure authentication states over HTTPS and preserves cookie consent choices.

Mandatory — Cannot be disabled.

Performance & Analytics

Google Analytics

Captures anonymized traffic patterns and UI interaction flows to diagnose server bugs.

Optional — Requires user consent.

Targeted Advertising

Google Ads Manager

Utilizes cross-site telemetry to manage commercial product relevance and limit ad re-appearance.

Optional — Requires user consent.

Users may modify or completely withdraw their granular consent profiles at any time without retroactive penalty via our integrated Cookie Preference Manager located in the footer of the Website.

4. Strict AI Model Training Prohibition

We explicitly exclude your website interactions, connected source code, cloud configurations, or volunteered registration data from being sold to data brokers or third-party marketing networks.

In strict compliance with our corporate governance baselines, neither Customer Data, vulnerability profiles, nor platform scan results will be ingested, transferred, or utilized by Infimatrix, its subcontractors, or any third party to train, fine-tune, optimize, benchmark, or otherwise develop or improve any artificial intelligence models, large language models (LLMs), or automated remediation algorithms without the Customer’s express, standalone, prior written consent.

5. Data Retention Erasure Windows

We retain personal data strictly for the duration required to fulfill our active commercial service obligations and statutory compliance mandates:

Account and Contact Records: Form-fill data and business interaction profiles are retained for a period of three (3) years from the date of our last recorded interaction before secure erasure.

Platform Log Telemetry: Web interaction logs and infrastructure analytics telemetry are held for a maximum of twenty-six (26) months from collection before undergoing automated destruction or absolute anonymization.

6. Sub-Processor Framework and Transparency

Processing data collected through our platform involves integration with premier infrastructure providers. We engage third-party infrastructure hosting companies, database managers, and analytical service entities under strict Data Processor Agreements. All such sub-processors are contractually bound to confidentiality and security frameworks no less stringent than those imposed on Infimatrix. The primary dynamically updated authorized sub-processor index is maintained at www.infimatrix.com/legal#subprocessors.

7. Data Security Baseline

Infimatrix employs administrative, physical, and technical safeguards aligned with international ISO/IEC 27001:2022 benchmarks to shield personal data from unauthorized access, loss, or alteration. While we enforce robust encryption protocols—including TLS 1.3 in transit and AES-256 at rest—no method of transmission over the internet or system of electronic storage is completely secure. Infimatrix cannot guarantee the absolute security of website data transmissions, and any submission of information through this website is at your own risk.

8. Statutory Rights, Age Thresholds, and Grievance Mechanics

Children’s Privacy Protection: Zero-X Cloud is strictly an enterprise B2B infrastructure solution. In strict compliance with the DPDPA, we do not knowingly capture, store, or process the personal data of data principals under eighteen (18) years of age.

DPDPA Grievance Escalation: All data privacy complaints or summary review requests directed to our Grievance Officer will be formally acknowledged within forty-eight (48) hours of receipt. Infimatrix covenants to resolve such issues within thirty (30) days of receipt, or within the maximum statutory timeline prescribed under the DPDPA, whichever period is shorter. Unresolved issues may be escalated to the Data Protection Board of India (DPBI).

Grievance Operations Contact: Direct all statutory requests to our centralized privacy desk at privacy@zero-x.cloud

9. Policy Update Mechanism

Infimatrix reserves the right to modify this Privacy Policy at any time to reflect changing technical profiles or regulatory revisions. Changes take effect immediately upon their publication to this URL. For active subscription clients whose contact information is maintained, we will provide at least thirty (30) days’ direct written notification via email prior to the effective date of any material changes to our processing practices.

10. Choice of Law & Governing Jurisdiction

10.1 Contractual Dispute Resolution. Any commercial or contractual controversy arising strictly out of the interpretation of this Privacy Policy shall be submitted to exclusive binding arbitration in Wilmington, Delaware, USA, conducted by the American Arbitration Association (AAA) under its Commercial Arbitration Rules using a single arbitrator. All claims must be brought in your individual capacity, explicitly waiving any right to a jury trial or class action proceeding.

10.2 Statutory Regulatory Exception. The forum selection in Clause 10.1 applies strictly to commercial contract actions between the parties. It shall not apply to, limit, or abrogate the absolute statutory right of data principals to file regulatory complaints, summary reviews, or data breach notices directly with the Data Protection Board of India (DPBI) under the DPDPA, a competent EU Supervisory Authority under the GDPR, or the UAE Data Office under the UAE PDPL within their respective territorial jurisdictions.

TERMS OF SERVICE (TOS)

Operating Corporate Entity: Infimatrix Technologies Private Limited (India)

1. Acceptance, Corporate Capacity, and License Grant

This Terms of Service (“TOS”) constitutes a binding legal contract between the commercial business user (“Customer”, “You”, or “Your”) and Infimatrix Technologies Private Limited. By executing a digital Service Order, checking the online acceptance box, or connecting your cloud networks to the service, you represent that you possess the explicit legal capacity and corporate authority to bind your organization.

Subject to your strict compliance with these terms and the timely payment of fees, Infimatrix grants you a non-exclusive, limited, non-transferable, non-sublicensable, and revocable right during the subscription term to access and utilize the Zero-X Cloud dashboard interfaces for your internal business purposes on infrastructure environments owned or controlled by you. The platform is licensed, not sold.

Order of Precedence: This document forms a connected framework with our corporate terms. In the event of an irreconcilable conflict between this general click-through website TOS and a separately signed, custom enterprise Statement of Work (SOW) or Service Order executed offline, the terms of the custom enterprise Service Order or SOW shall control and take immediate precedence.

2. Commercial Tier Limits and Automated Billing

Plan Metric Boundaries: Zero-X Cloud enforces strict quantitative constraints ( technical and commercial ) across its tiers (Developer, Pro, Enterprise or others), limiting the number of allowed concurrent Users, connected Data Sources, total scanned Cloud Resources, and allowable Daily Scans & on demand basis any consumption be it for AI calls or for PenTests or additional workload times being invoked from Zero X Cloud Platform.

Automated Payments: Customer authorizes Infimatrix to automatically charge the credit card or electronic payment method specified at checkout on a recurring basis. Paid subscription fees are final and non-refundable. All amounts must be paid in full without deduction, setoff, or recoupment.

Resource Enforcement Throttling: If your infrastructure configuration metrics consistently exceed the limits established by your active tier, Infimatrix reserves the right, upon reasonable system notification, to throttle API interaction speeds or temporarily lock account processing until the account is upgraded to the appropriate billing tier.

Currency: Unless otherwise specified in an executed Service Order, all amounts are invoiced and settled in Indian Rupees (INR) for India-based engagements, and in United States Dollars (USD) for all other jurisdictions.

Payment Instruction Verification: Infimatrix will never issue account-modifying payment instructions by email alone. Customer should verify bank account details via a secondary channel before routing any payment to Infimatrix.

3. Usage Restrictions and Managed Services Safe Harbor

Customer shall not, and shall not permit any third party to: copy, modify, or create derivative works of the platform; reverse engineer, decompile, disassemble, or decode the underlying compiled source code; upload software viruses or Harmful Code; or utilize the platform infrastructure to launch unauthorized security attacks or perform competitive benchmarking.

MSP & Cloud Engineering Safe Harbor

The standard restrictions against utilizing the platform for commercial third-party distribution or service-bureau deployment shall not apply to authorized Infimatrix Personnel or its corporate Affiliates utilizing the platform to deliver manual managed services, DevOps infrastructure configuration, data engineering, or professional vulnerability consulting to designated third-party end clients.

4. Optional Marketing and Logo Consent

Subject to your explicit confirmation and opt-in via the dashboard preference console, Customer grants Infimatrix a limited, non-exclusive, revocable, royalty-free license to utilize the Customer’s corporate name and trademark logo design on our Website and marketing presentations solely to identify the Customer as an active user of Zero-X Cloud. Customer may revoke this consent at any time by issuing a written request to legal@infimatrix.com, upon which Infimatrix will remove all corporate branding references within fourteen (14) business days. Any associated goodwill shall inure exclusively to the benefit of the Customer.

5. Disclaimer of Warranties

THE SERVICES ARE PROVIDED TO YOU ENTIRELY “AS IS” AND WITH ALL FAULTS AND DEFECTS WITHOUT WARRANTY OF ANY KIND. TO THE MAXIMUM EXTENT PERMITTED UNDER APPLICABLE LAW, INFIMATRIX EXPRESSLY DISCLAIMS ALL WARRANTIES, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, WITH RESPECT TO THE SERVICES, INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. INFIMATRIX PROVIDES NO WARRANTY OR UNDERTAKING, AND MAKES NO REPRESENTATION OF ANY KIND THAT THE SERVICES WILL MEET YOUR REQUIREMENTS, ACHIEVE ANY INTENDED RESULTS, BE COMPATIBLE OR WORK WITH ANY OTHER THIRD-PARTY SOFTWARE, APPLICATIONS, OR SYSTEMS WITHOUT INTERRUPTION, MEET ANY PERFORMANCE STANDARDS, OR BE COMPLETELY ERROR-FREE.

6. User Indemnification Obligations

Customer agrees to defend, indemnify, and hold harmless Infimatrix, its corporate affiliates, and their respective officers, directors, employees, and agents from and against any and all losses, damages, judgments, liabilities, deficiencies, claims, actions, costs, or expenses (including reasonable attorneys’ fees and court costs) arising from third-party claims resulting from: (a) your access to or misuse of the Services; (b) Customer Data infringements; (c) your gross negligence, wilful misconduct, fraud, or misrepresentation; (d) your direct breach of the Acceptable Use Restrictions contained herein; or (e) any act or omission by Customer or its Authorised Users that results in liability being imposed on Infimatrix through no fault of Infimatrix.

7. Limitation of Liability

EXCLUSION OF CONSEQUENTIAL DAMAGES: EXCEPT AS OTHERWISE SPECIFICALLY PROVIDED IN SECTION III (THE PLATFORM SLA AND PRIVACY SUPER-CAP), IN NO EVENT SHALL EITHER PARTY BE LIABLE FOR ANY LOSS OF PRODUCTION, USE, REVENUE, OR PROFIT; LOSS OR CORRUPTION OF DATA; OR CONSEQUENTIAL, INCIDENTAL, INDIRECT, SPECIAL, ENHANCED, OR PUNITIVE DAMAGES, REGARDLESS OF FORESEEABILITY.

AGGREGATE LIABILITY CAP: THE AGGREGATE MONETARY LIABILITY OF INFIMATRIX ARISING OUT OF OR RELATED TO THIS PLATFORM AGREEMENT SHALL NOT EXCEED THE TOTAL FEES PAID BY CUSTOMER TO INFIMATRIX FOR THE PLATFORM SUITE IN THE TWELVE (12) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR ONE HUNDRED U.S. DOLLARS ($100), WHICHEVER IS GREATER.

8. Term and Termination Provisions

Subscription Term and Renewal: The initial term of platform access is one (1) year from the purchase timestamp, automatically renewing for successive one (1) year terms unless written notice of non-renewal is provided by either party at least thirty (30) days prior to the expiration of the then-current term.

Termination for Cause: Either party may terminate this agreement upon thirty (30) days’ written notice of an uncured material breach by the other party. Infimatrix may suspend or immediately terminate access without notice if the Customer is involved in unpaid dues, fraudulent or unlawful activities, or if Customer’s usage breaches the platform restrictions or creates immediate legal or security exposures for Infimatrix.

Effect of Termination: Upon termination or expiry, all licenses and rights granted hereunder immediately cease. Customer must immediately remove and delete all downloadable agents or code components from its networks. Data return and erasure paths are executed in strict alignment with the timelines set forth in Section IV (Data Processing Addendum).

9. Severability & Entire Agreement

Severability: If any term or provision of this TOS is found to be invalid, illegal, or unenforceable in any jurisdiction, such invalidity or unenforceability shall not affect any other term or provision of this TOS, nor render such provision invalid or unenforceable in any other jurisdiction.

Entire Agreement: This TOS, alongside our Privacy Policy, Software License Agreement, and Data Processing Addendum (DPA), constitutes the sole and entire agreement between the parties with respect to Zero-X Cloud, superseding all prior oral or written understandings.

10. Governing Law and Dispute Resolution

10.1 This TOS and any controversies arising from it shall be governed by and construed in accordance with the laws of India, as applicable in the State of Maharashtra, without giving effect to conflicts of laws principles. Disputes shall be resolved in accordance with Clause 10.2 below.

10.2 All disputes, controversies, or claims arising out of or in connection with this TOS, including any question regarding its existence, validity, interpretation, breach, or termination, shall be referred to and finally resolved by binding arbitration. The parties shall attempt to resolve any dispute through good-faith negotiations for a period of thirty (30) days before commencing arbitration.

10.3 Unless Customer exercises its election right under Clause 10.4, all arbitrations shall be conducted under the rules of the Mumbai Centre for International Arbitration (MCIA) in force at the time of commencement, with the seat of arbitration in Mumbai, India. The arbitral tribunal shall consist of one (1) arbitrator unless either party requests a panel of three (3) within ten (10) days of commencement. The language of arbitration shall be English. The award shall be final and binding and may be enforced in any court of competent jurisdiction.

10.4 Customer may elect an alternative arbitral institution by written notice to Infimatrix at the time of commencing arbitration:

(a) Customers with a primary place of business in the United Arab Emirates: Dubai International Arbitration Centre (DIAC) rules, seat in Dubai.

(b) Customers with a primary place of business in the United States of America: American Arbitration Association (AAA) Commercial Arbitration Rules, seat in Wilmington, Delaware.

(c) Customers with a primary place of business in the European Union or United Kingdom: London Court of International Arbitration (LCIA) rules, seat in London, England.

10.5 Nothing in this Clause 10 shall prevent either party from seeking urgent injunctive or other interim relief from a court of competent jurisdiction to prevent or restrain a breach or threatened breach of confidentiality or usage restriction obligations, without waiving the right to arbitration.

10.6 For the avoidance of doubt, Customer’s election of an alternative arbitral institution and seat under Clause 10.4 affects only the procedural forum and rules of arbitration. The substantive governing law of this TOS remains that specified in Clause 10.1, unless otherwise expressly agreed in a signed Master Agreement, Statement of Work, or Order Form.

11. Infrastructure and Environment Responsibility

Save where Customer has purchased a Dedicated Cloud Infrastructure Hosting arrangement under a separately executed Service Order (in which case the dedicated hosting terms of that Service Order shall apply), the Zero-X Cloud Platform is hosted by Infimatrix on its own cloud infrastructure located in India. Customer is responsible for procuring and maintaining its own third-party software subscriptions, developer system credentials, and the underlying cloud or on-premises environments that Customer elects to connect to, or have scanned by, the Platform, including via the Zero-X Agent or API/SDK integrations.

12. Nature of Services

Infimatrix operates as a software product provider. Infimatrix does not furnish managed human compliance auditing services, does not accept any Data Fiduciary or Data Controller assignment on Customer’s behalf, and does not provide legal safety certifications. Customer remains solely responsible for its own operational, regulatory, and corporate safety disclosures. For the avoidance of doubt, the Data Processing Addendum (Section IV) governs Infimatrix’s role as Data Processor in relation to Personal Data specifically, and does not expand Infimatrix’s role beyond that of Processor.

13. Custom Development and Change Requests

For any strategic initiatives, if any custom feature builds, bespoke integrations, or pipeline-specific configuration changes requested by Customer beyond the standard SaaS scope ; a separate Statement of Work (SOW) or written change-request process is to be agreed between the parties separately.

14. Infrastructure and Environment Responsibility

Save where Customer has purchased a Dedicated Cloud Infrastructure Hosting arrangement under a separately executed Service Order (in which case the dedicated hosting terms of that Service Order shall apply), the Zero-X Cloud Platform is hosted by Infimatrix on its own cloud infrastructure located in India ( or overseas in future). Customer is responsible for procuring and maintaining its own third-party software subscriptions, developer system credentials, and the underlying cloud or on-premises environments that Customer elects to connect to, or have scanned by, the Platform, including via the Zero-X Agent or API/SDK or any other types of integrations.

15. Nature of Services

Infimatrix operates as a software product SAAS provider. Infimatrix does not furnish managed human compliance auditing services, does not accept any Data Fiduciary or Data Controller assignment on Customer’s behalf, and does not provide legal safety certifications. The customer remains solely responsible for its own operational, regulatory, and corporate safety disclosures. For the avoidance of doubt, the Data Processing Addendum (Section IV) governs Infimatrix’s role as Data Processor in relation to Personal Data specifically, and does not expand Infimatrix’s role beyond that of Processor.

SOFTWARE LICENSE & SERVICE LEVEL AGREEMENT (SLA)

Operating Corporate Entity: Infimatrix Technologies Private Limited (India)

1. Product Scope and Intellectual Property Governance

This Software License Agreement governs your deployment of the centralized Zero-X Cloud SaaS environment and any downloadable Zero-X Agent binary modules engineered to run locally within your hybrid cloud networks or local application clusters. All right, title, and interest in and to the Software, source code, Documentation, and security threat signature repositories remain exclusively vested in Infimatrix and its licensors. No ownership interest is transferred to you.

2. AutoFix Engine: Automated Remediation Risk Allocation

Zero-X Cloud features an integrated 1-Click AutoFix Engine designed to automatically generate code patches, Git repository Pull Requests (PRs) and live Terraform configurations to remediate detected cloud infrastructure vulnerabilities instantly.

Allocation of Operational Risk

Customer explicitly acknowledges and agrees that all automated remediation scripts, container policy patches, Git pull requests, and infrastructure code modifications generated by the platform — whether initiated manually via a single-click action or executed automatically via unattended, autonomous configuration rules established by the Customer (collectively, “Remediation Deployments”) — are strictly advisory in nature. Infimatrix does not warrant that any Remediation Deployment will be error-free, compatible with your production environment, or completely free from unintended logical disruption. Enforcing a headless automated remediation posture is performed entirely at the Customer’s risk, and Infimatrix assumes no liability for production downtime, pipeline corruption, cloud provider service outages, or system latency arising therefrom.

The Customer retains sole, exclusive operational control and assumes 100% legal and operational liability for reviewing, testing, verifying, and authorizing any automated code modifications before executing them in live or staging pipelines. Infimatrix disclaims any and all liability for production downtime, code corruption, cloud provider service outages, or system breaks resulting from self-initiated or automated AutoFix deployments.

3. Service Levels, Credits, and Aggregate Monthly Cap

Infimatrix will use commercially reasonable efforts to ensure the cloud-hosted Zero-X platform dashboards are Available at least ninety-nine percent (99%) of the time over a calendar year. This tracking explicitly excludes unavailability caused by customer failure, force majeure events, or scheduled routine maintenance managed between 10:00 PM and 6:00 AM Indian Standard Time (IST) upon 24 hours prior notice.

If a confirmed Service Level Failure occurs, Infimatrix will issue a credit to the Customer in the amount of ten percent (10%) of the pro-rated monthly fee for the affected service period. The maximum aggregate limit for all service credits issued within a single calendar month shall be capped at fifty percent (50%) of the total fees payable for that affected billing period, constituting the Customer’s sole and exclusive commercial remedy. Written claims must be submitted within thirty (30) days of the incident.

4. Consolidated Liability Matrix & Privacy Super-Cap

The financial risk parameters of this product deployment are strictly capped as follows:

 

Violation Category

Maximum Liability Cap

Legal Framework Reference

Standard Contract/Tort Claims

Trailing 12 months of paid fees or $100, whichever is greater.

Section II, Clause 7 / Section III, Clause 4

Direct Regulatory Fines

Three (3) Times the total fees paid by Customer during the preceding 12-month window.

Section IV (Data Processing Addendum)

Uncapped Violations

Unlimited (Gross negligence, willful misconduct, or corporate fraud).

Common Law / Statutory Mandate

The Privacy Super-Cap Application: Where a Data Processing Addendum (DPA) has been executed between the parties, and a validated security or data processing failure by Infimatrix directly results in definitive statutory enforcement actions or direct regulatory penalties imposed on the Customer by an authorized supervisory authority (such as the Data Protection Board of India or an EU Data Protection Authority), Infimatrix’s maximum aggregate financial liability under the DPA shall be strictly capped at three (3) times the trailing 12 months of subscription fees.

5. Corporate Administration and Notice Hub

All legal notices, regulatory alerts, and formal contract inquiries must be dispatched to our centralized corporate compliance channel via a trackable delivery method:

Corporate Registered Address: Infimatrix Technologies Private Limited, Attn: Legal Department, Level 10 AWFIS, Aston Building, Andheri West, Mumbai 400 053, India.

General Legal Escalations: legal@infimatrix.com

Data Protection Officer / Grievance Officer: privacy@infimatrix.com

DATA PROCESSING ADDENDUM (DPA)

Operating Corporate Entity: Infimatrix Technologies Private Limited (India)

This Data Processing Addendum forms an integral part of the Zero-X Cloud product suite to govern the processing of personal data across global enterprise jurisdictions.

1. Roles and Documented Processing Instructions

Customer acts as the Data Controller / Data Fiduciary, and Infimatrix acts as the Data Processor / Sub-fiduciary processing Personal Data solely on behalf of, and under the strict documented instructions of, the Customer as set out in this framework and applicable automated dashboard choices. If Infimatrix believes that an instruction infringes applicable Data Protection Laws, it shall promptly notify Customer and may suspend performance without liability.

2. Security Framework & Data Breach Notification

Technical Safeguards: Infimatrix shall maintain technical and organizational measures aligned with ISO/IEC 27001:2022 standards, ensuring role-based access controls (RBAC), multi-factor authentication (MFA), TLS 1.3 transit encryption, and AES-256 rest encryption safeguards across multi-tenant environments.

48-Hour Breach Notification: In the event of an actual or reasonably suspected Security Incident involving Personal Data, Infimatrix shall notify Customer within forty-eight (48) hours of discovery, providing detailed metrics regarding affected data categories, approximate volumes, and proposed mitigation paths.

3. Data Subject Rights & Request Forwarding Procedure

Taking into account the automated nature of the SaaS processing environment, Infimatrix shall implement functional measures to assist the Controller in fulfilling its obligations to respond to data principals exercising rights under applicable law. If Infimatrix receives a direct request from a data principal or data subject seeking to exercise their legal rights in relation to Personal Data processed on behalf of Customer, Infimatrix shall forward the request to Customer within five (5) business days of receipt. Infimatrix shall not respond to the data principal directly without Customer’s express prior written authorization.

4. New Sub-Processor Notice & Customer Objection Window

4.1 Infimatrix shall maintain a current and accurate list of all Sub-processors engaged in the Processing of Personal Data under this DPA (the “Sub-processor List”), published at www.infimatrix.com/legal#subprocessors (the “Sub-processor URL”).

4.2 Infimatrix shall notify Customers of any intended addition or replacement of a Sub-processor by simultaneously: (a) updating the Sub-processor List at the Sub-processor URL; and (b) sending a single notification email to the primary account email address on file for each active Customer. Both actions shall be completed at least thirty (30) days before the new Sub-processor begins Processing Personal Data.

4.3 Customer may object to the engagement of a new Sub-processor on reasonable data protection grounds by notifying Infimatrix in writing within fourteen (14) days of receiving the notification under Clause 4.2. If Customer raises a timely objection, the parties shall negotiate in good faith to resolve it within a further fourteen (14) days. If unresolved, Customer may terminate the affected Services on written notice without liability for early termination fees. Failure to raise an objection within fourteen (14) days shall be deemed acceptance of the new Sub-processor.

5. Return and Deletion Windows & Legal Holds Note

Standard Erasure Window: Upon expiration or termination of the SaaS subscription, Infimatrix shall, at Customer’s written election, securely return all Personal Data in a commonly used machine-readable format or permanently delete all copies from its active multi-tenant production systems and backup paths within thirty (30) days. Written certification confirming structural deletion shall be delivered to the Customer within fourteen (14) days of completion.

Statutory Legal Holds Protocol: Infimatrix may retain Personal Data beyond standard deletion windows only to the extent and for the duration required by applicable statutory Law or regulatory audit mandates. In such instances, Infimatrix shall notify the Customer in writing when a hold is formally invoked (unless legally prohibited by regulatory enforcement orders). The data shall remain strictly isolated, heavily encrypted, and barred from any general commercial processing. Infimatrix covenants to execute destruction or return procedures within thirty (30) days once the underlying statutory hold is officially lifted.

6. Dynamic Jurisdiction Modules

MODULE 1: Digital Personal Data Protection Act, 2023 (India)

Application: This module applies to the processing of Personal Data of data principals located in India under the DPDPA.

Compliance Standards: Infimatrix shall assist Customer in fulfilling all Section 13 data principal rights, including summary processing reviews, structural erasure, the right to nominate, and formal grievance redressal handled through our mandatory 48-hour acknowledgment window. Unresolved disputes may be escalated to the Data Protection Board of India.

MODULE 2: General Data Protection Regulation (EU/EEA GDPR)

Application: This module satisfies the mandatory processing requirements of Article 28 of the GDPR.

Explicit Article 28(3) Covenants: In accordance with Article 28(3) of the GDPR, Infimatrix complies with each of the following specific obligations:

(a) Documented Instructions: Process Personal Data only on documented instructions from the controller, including with regard to transfers of personal data to a third country or an international organization, unless required to do so by Union or Member State law to which the processor is subject.

(b) Confidentiality: Ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

(c) Security of Processing: Take all measures required pursuant to Article 32 of the GDPR, as detailed in Section IV, Clause 2 of this Data Processing Addendum.

(d) Sub-Processors: Respect the conditions referred to in Articles 28(2) and 28(4) of the GDPR for engaging another processor, as set out in Section IV, Clause 4 of this Data Processing Addendum.

(e) Data Subject Rights: Taking into account the nature of the processing, assist the controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the controller’s obligation to respond to requests for exercising data subjects’ rights under Chapter III of the GDPR.

(f) Controller Assistance: Assist the controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR, taking into account the nature of processing and the information available to the processor.

(g) Deletion or Return: At the choice of the controller, delete or return all personal data to the controller after the end of the provision of services relating to processing, and delete existing copies unless Union or Member State law requires storage of the personal data.

(h) Audits and Inspections: Make available to the controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR, and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.

Transfer Mechanisms (EU/EEA to India)

Where Customer Data containing Personal Data of EU/EEA data subjects is transferred from the EU/EEA to Infimatrix in India, such transfer is effected pursuant to the Standard Contractual Clauses adopted by the European Commission under Decision (EU) 2021/914 of 4 June 2021 (the “SCCs”), which are incorporated into this DPA by reference and form a binding part of it. The SCCs are accessible at: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en

Module Two (Controller-to-Processor) of the SCCs applies where Customer is the Data Controller; Module Three (Processor-to-Processor) applies where Customer is itself a Data Processor acting on behalf of an upstream controller. The specific optional clause elections made by the parties are set out in the SCC Elections Schedule at the end of this DPA.

MODULE 3: UAE Federal Decree-Law No. 45 of 2021 (UAE)

Application: This Module applies to the Processing of Personal Data of data subjects located in the United Arab Emirates under the UAE PDPL.

Processing Standards: Customer is the Controller; Infimatrix is the Processor. Processing shall be executed strictly on Customer’s documented instructions, and technical safeguards must align with UAE Data Office regulations. Security incidents must be reported to the Controller within forty-eight (48) hours of discovery. Cross-border transfers require strict alignment with UAE adequacy frameworks or appropriate contractual safeguards approved under the UAE PDPL. Disputes relating solely to this module may be referred to the competent courts of the United Arab Emirates.

MODULE 4: United States State Privacy Laws (United States)

Application: This Module applies to the Processing of Personal Information of consumers located in the United States under applicable comprehensive state privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the “CCPA”), the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and other substantially similar comprehensive state privacy laws in force from time to time (collectively, “US State Privacy Laws”).

Processing Standards: Customer is the Business or Controller, and Infimatrix acts as the Service Provider, Contractor, or Processor (as applicable under the relevant US State Privacy Law), Processing Personal Information solely for the specific business purposes disclosed in this DPA or the applicable Service Order. Infimatrix shall not: (a) sell or share Personal Information, as those terms are defined under the CCPA; (b) retain, use, or disclose Personal Information for any purpose outside the direct business relationship between the parties, including for cross-context behavioral advertising; or (c) combine Personal Information received from Customer with personal information received from or on behalf of any other source, except as permitted under applicable US State Privacy Laws.

Certification: Infimatrix certifies that it understands the restrictions set out in this Module and shall comply with them.

Consumer Rights Assistance: Infimatrix shall provide reasonable assistance to Customer in responding to verified consumer requests to exercise rights of access, deletion, correction, portability, and opt-out under applicable US State Privacy Laws, consistent with the request-forwarding procedure set out in Section IV, Clause 3.

Security Incidents: Security Incidents involving Personal Information of US consumers shall be notified in accordance with the forty-eight (48) hour notification standard set out in Section IV, Clause 2, which meets or exceeds the “without unreasonable delay” standard applicable under US State Privacy Laws and applicable state data breach notification statutes.

California Private Right of Action: Customer acknowledges that California uniquely affords consumers a private right of action for certain data breaches resulting from a business’s failure to implement reasonable security procedures. Nothing in this DPA limits Infimatrix’s security obligations under Section IV, Clause 2 or the Data Security Baseline set out in Section I, Clause 7.

Mandatory Non-Compliance Notification: Infimatrix shall notify Customer promptly, and in no event later than five (5) business days, if Infimatrix determines that it can no longer meet its obligations under applicable US State Privacy Laws (Cal. Civ. Code § 1798.100(d)(4)).

Customer Monitoring and Remediation Rights: Customer maintains the right, upon reasonable written notice, to take reasonable and appropriate steps to stop and remediate any unauthorized Processing of Personal Information by Infimatrix, including under the notice referred to above (Cal. Civ. Code § 1798.100(d)(5)).

7. Data Protection Impact Assessment Assistance

Where a Customer, in its capacity as a Data Controller or Data Fiduciary, determines that it is required by applicable Data Protection Laws to conduct a data protection impact assessment or privacy impact assessment in connection with a processing activity carried out by Infimatrix on its behalf, Infimatrix shall provide the Customer with such reasonable cooperation and information as the Customer may request to facilitate the completion of that assessment, to the extent the assessment relates to Infimatrix’s processing operations under this DPA.

For the avoidance of doubt: (a) the obligation to determine whether a DPIA is required and to conduct it rests solely with the Customer as Controller or Fiduciary; Infimatrix’s role is limited to providing operational assistance upon request; (b) this Clause does not create any right on the part of any data principal or data subject to request, receive, or review any DPIA; and (c) where prior consultation with a supervisory authority or the Data Protection Board of India is required following completion of a DPIA, Infimatrix shall cooperate with the Customer in such consultation to the extent it relates to Infimatrix’s processing activities under this DPA.

SCHEDULE: SCC ELECTIONS AND SPECIFICATIONS

This Schedule sets out the elections made by the parties in respect of the Standard Contractual Clauses (SCCs) incorporated into this DPA under Module 2 (GDPR). The SCCs are a European Commission template containing certain optional provisions that the contracting parties must select at the time of incorporation. References to “Clause [X]” below are to the numbered provisions within the SCCs document accessible at the link provided in Module 2 above. The elections below are binding on both parties.

Module Selection: Module Two (Controller-to-Processor) applies where Customer is the Data Controller. Module Three (Processor-to-Processor) applies where Customer is a Data Processor acting on behalf of an upstream controller.

Clause 7 — Docking Clause: Omitted. Additional controllers or processors may not accede to this DPA without the prior written consent of both parties.

Clause 9(a) — Sub-Processor Authorisation: Option 2 applies. Infimatrix shall give Customer thirty (30) days’ prior written notice of any new Sub-processor, consistent with Clause 4.2 of this DPA.

Clause 11 — Redress: The optional language permitting data subjects to lodge complaints with an independent dispute resolution body is omitted.

Clause 17 — Governing Law: Option 1 applies. The SCCs are governed by the laws of Ireland as a Member State of the European Union.

Clause 18(b) — Choice of Forum: Disputes arising under or in connection with the SCCs shall be resolved before the courts of Ireland.

Annex I and Annex II: The identity of the Data Exporter (Customer) and Data Importer (Infimatrix Technologies Private Limited), together with the description of the processing activities and security measures set out in this DPA, constitute the information required by Annex I and Annex II of the SCCs respectively.

Scroll to Top