Skip to content

Data Processing Agreement

How Neverinstall processes personal data on behalf of its customers.

Last updated July 15, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service or other written or electronic agreement between Neverinstall (“Data Processor”) and you (“Data Controller”) for the use of Neverinstall's online services (the “Services”).

Neverinstall is committed to protecting the privacy and security of your personal data. This DPA sets out how Neverinstall processes personal data on your behalf, in line with applicable data protection laws including the GDPR, UK GDPR, and CCPA.

1. Definitions

  • Data Controller means the natural or legal person who determines the purposes and means of the processing of Personal Data.
  • Data Processor means Neverinstall, which processes Personal Data on behalf of the Controller.
  • Data Protection Officer (DPO) is the designated representative responsible for overseeing data protection strategy and implementation.

2. Data Processing Details

Neverinstall processes Personal Data only in accordance with your documented instructions and only to the extent necessary to provide the Services. We do not sell your Personal Data or use it for any other purpose, unless we are legally required to do so, in which case we will inform you first where the law allows. All Neverinstall personnel with access to Personal Data are bound by confidentiality obligations.

3. Data Subject Rights

If Neverinstall receives a request from a Data Subject seeking to exercise their rights (including access, rectification, erasure, restriction of processing, data portability, objection, or rights related to automated decision-making), we will promptly notify you and, taking into account the nature of the processing, provide reasonable assistance so you can respond. For more on these rights, see our Privacy Policy at https://neverinstall.com/privacy.

4. Authorized Sub-Processors

To deliver the Services, Neverinstall engages the Sub-processors listed below. Each is bound by written data protection terms no less protective than this DPA. We will give you at least 30 days' notice before adding or replacing a Sub-processor, and you may object on reasonable data-protection grounds.

Sub-ProcessorLocation / HostingPurpose of Processing
Microsoft Corporation (Microsoft Azure)India / GlobalCloud infrastructure and hosting of the Services, including managed PostgreSQL databases for accounts, workspaces, and usage data.
Oracle Corporation (Oracle Cloud Infrastructure)India / GlobalCloud infrastructure and hosting of the Services.
Stripe, Inc. and Razorpay Software Private LimitedUnited States / IndiaSecure payment processing and billing.
Hasura, Inc.United States / GlobalAPI and control-plane layer for accessing application data.
Intercom, Inc.United States / GlobalCustomer support, in-app messaging, and support communications.

5. Security Measures

Neverinstall maintains appropriate technical and organizational measures to protect Personal Data against unauthorized access, loss, or destruction, including:

  • Encryption: All data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
  • Access control: Role-based access control (RBAC), mandatory multi-factor authentication, and the principle of least privilege applied internally.
  • Breach notification: We will notify you of any Personal Data Breach affecting your data without undue delay, and in any event within 48 hours of becoming aware of it, with the information you need to meet your own notification obligations.

6. International Transfers (SCCs)

Where providing the Services involves transferring Personal Data from the EU/EEA, the UK, or Switzerland to countries without an adequacy decision, such transfers are governed by the EU Standard Contractual Clauses (Controller-to-Processor), which are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum where the UK GDPR applies.

7. Data Deletion and Return

Upon termination of our services and your contract, the Processor will, at the choice of the Controller, securely delete or return all Personal Data, unless domestic or international law explicitly requires continued storage.

8. Audit Rights

Neverinstall will make available the information reasonably necessary to demonstrate compliance with this DPA. Upon reasonable written request, we will provide evidence of our security and compliance measures, including relevant third-party audit reports or certifications such as SOC 2, or reasonably cooperate with audits, without compromising the security of other customers.

9. Data Protection Contact

Neverinstall has designated a data protection contact to oversee compliance and answer privacy inquiries:

Contact
Ram Pasala

Related documents

Get Skilled Services Private Limited
Bengaluru, Karnataka
[email protected]

Where to go next.