Back to Terms and Conditions
Legal

CtrlOps Data Processing Agreement (DPA)

Last Updated: August 26, 2026

This Data Processing Agreement ("DPA") explains how TST Tech Matrix Pvt Ltd ("CtrlOps", "we", "us") handles personal data when we provide CtrlOps to a business customer ("Customer", "you"). It is designed to meet the requirements of the EU GDPR, the UK GDPR, and other data protection laws that apply to our customers.

How this DPA applies: this DPA is part of our Terms and Conditions and applies automatically to every customer, with no separate signing needed. If your organization needs a signed copy for its records, email us at support@ctrlops.io and we will provide one.

If anything here conflicts with the rest of our Terms on the handling of personal data, this DPA wins.

01. Some quick definitions

  • Personal data, processing, controller, processor, and data subject have the meaning given in the GDPR.
  • Data protection laws means all privacy and data protection laws that apply to the processing under this DPA, including the EU GDPR and the UK GDPR.
  • Customer personal data means personal data that we process on your behalf to provide CtrlOps, as described in Annex 1.
  • Sub-processor means another company we use to help process customer personal data.
  • SCCs means the European Commission's Standard Contractual Clauses. UK IDTA means the UK International Data Transfer Agreement (or Addendum).

02. Who is who

  • For the customer personal data we process to provide CtrlOps, you are the controller and we are the processor, acting on your instructions.
  • We are also an independent controller for a limited set of data we decide the purposes of ourselves, such as billing, account security, fraud prevention, and improving CtrlOps. How we handle that is set out in our Privacy Policy.
  • Because CtrlOps is local-first, your server credentials, keys, commands, logs, files, and server contents never reach us, so they are not part of this DPA.

03. What we process, and your instructions

We will process customer personal data only to provide and support CtrlOps, and only following your documented instructions, which include this DPA, our Terms, and your normal use of the product.

The subject matter, purpose, types of personal data, and categories of data subjects are described in Annex 1. If the law ever requires us to process data in another way, we will tell you first, unless the law prevents us from doing so.

04. Our commitments as processor

We will:

  • Process only on your instructions, as described above.
  • Make sure the people who handle customer personal data are under a duty of confidentiality.
  • Keep appropriate security measures in place (Section 05 and Annex 2).
  • Help you respond to data subject requests and to meet your own obligations, such as security, breach notices, and data protection assessments, taking into account the information available to us.
  • Delete or return customer personal data at the end, as described in Section 10.
  • Make available the information you reasonably need to show that we are meeting these obligations.

05. Security

We keep appropriate technical and organizational measures to protect customer personal data, described in Annex 2 and in the security section of our Privacy Policy. This includes encryption in transit and at rest for our backend, access controls, monitoring, and a documented incident response process.

06. Sub-processors

You give us general authorization to use sub-processors to help provide CtrlOps. Our current sub-processors, what they do, and where they are based, are listed on our Sub-Processors page at /sub-processors.

  • We will put a written agreement in place with each sub-processor that requires it to protect data to a standard no lower than this DPA.
  • We will notify you before adding or replacing a sub-processor (by updating that page and, where required, contacting you), so you have a chance to object on reasonable data protection grounds.
  • We remain responsible to you for the work our sub-processors do.

07. International data transfers

We are based in India, and some of our sub-processors operate in other countries, so customer personal data may be transferred across borders.

Where we transfer personal data from the EU or UK to a country without an adequacy decision, that transfer is protected by the EU SCCs and the UK IDTA, which are incorporated into this DPA by reference and completed with the details in the Annexes. We also apply additional safeguards where appropriate.

By agreeing to this DPA, both sides are treated as having signed the relevant SCCs and UK IDTA for those transfers.

08. Helping with data subject rights

If a data subject contacts us directly about customer personal data, we will direct them to you where appropriate. Taking into account the nature of the processing, we will help you respond to requests to access, correct, delete, or object, including by providing the information we hold.

09. Personal data breaches

If we become aware of a breach affecting customer personal data, we will notify you without undue delay, and no later than 72 hours after we become aware. Our notice will describe, as far as we know it, what happened, the data and people likely affected, the likely impact, and the steps we are taking.

10. Deletion or return at the end

When our services to you end, we will, at your choice, delete or return the customer personal data we hold, within 90 days, and delete existing copies, unless the law requires us to keep some of it. Where we must keep data to meet a legal duty, we will keep only what is needed and continue to protect it.

11. Audits

We will make available the information reasonably needed to demonstrate our compliance with this DPA. Where you reasonably need an audit, we can satisfy it by providing relevant reports, certifications, or a summary of our controls. Any on-site audit will be on reasonable prior notice, no more than once a year unless the law or a regulator requires otherwise, during business hours, and subject to confidentiality, so it does not disrupt our operations or other customers.

12. Liability

Each side's liability under this DPA is subject to the limitation of liability in our Terms and Conditions.

13. How long this DPA lasts

This DPA applies for as long as we process customer personal data for you, and any parts that by their nature should continue (such as confidentiality and the transfer safeguards) continue afterward.

14. Governing law

This DPA is governed by the laws of India, with the courts of Ahmedabad, Gujarat having jurisdiction, except where data protection law requires otherwise for the SCCs or UK IDTA.

Annex 1: Details of the processing

  • Subject matter: providing the CtrlOps service to the Customer.
  • Duration: for as long as the Customer uses CtrlOps, and for as long as we need the data to meet our legal, tax, and accounting duties, as described in our Privacy Policy.
  • Nature and purpose: hosting accounts, authenticating users, issuing and validating licenses, providing support, and understanding product usage to improve the service.
  • Types of personal data: account email address and name, license and subscription data, product usage events, support communications, and payment and billing details.
  • Categories of data subjects: the Customer's account holders, their team members or authorized users, and website visitors.
  • Special category data: none is intended or required.

Annex 2: Security measures

  • Local-by-design architecture, so server credentials, keys, commands, logs, and files stay on the user's device and never reach us.
  • Encryption in transit and at rest (TLS/HTTPS) for backend account and license data.
  • Access controls on a need-to-know, least-privilege basis for our staff.
  • Logging and monitoring of backend systems.
  • Regular patching, dependency updates, and security review.
  • Vendor due diligence on every sub-processor.
  • A documented incident response process.

Annex 3: Sub-processors

The current list of sub-processors, including what each does and where it is based, is maintained on our Sub-Processors page at /sub-processors, which forms part of this DPA.

Need a signed copy?

For any question about this DPA, or to request a signed copy, email us.

support@ctrlops.io
TST Tech Matrix Pvt LtdMondeal Heights, B-1702, Sarkhej - Gandhinagar Hwy, Satellite, Ahmedabad, Gujarat 380015, IndiaGSTIN: 24AAKCT6577G1ZX

CtrlOps by TST Tech Matrix Pvt Ltd.