Data Processing Agreement
How Neverinstall processes personal data on behalf of its customers.
This Data Processing Agreement (“DPA”) forms part of the Terms of Service or other written or electronic agreement between Neverinstall (“Data Processor”) and you (“Data Controller”) for the use of Neverinstall's online services (the “Services”).
Neverinstall is committed to protecting the privacy and security of your personal data. This DPA sets out how Neverinstall processes personal data on your behalf, in line with applicable data protection laws including the GDPR, UK GDPR, and CCPA.
1. Definitions
- Data Controller means the natural or legal person who determines the purposes and means of the processing of Personal Data.
- Data Processor means Neverinstall, which processes Personal Data on behalf of the Controller.
- Data Protection Officer (DPO) is the designated representative responsible for overseeing data protection strategy and implementation.
2. Data Processing Details
Neverinstall processes Personal Data only in accordance with your documented instructions and only to the extent necessary to provide the Services. We do not sell your Personal Data or use it for any other purpose, unless we are legally required to do so, in which case we will inform you first where the law allows. All Neverinstall personnel with access to Personal Data are bound by confidentiality obligations.
3. Data Subject Rights
If Neverinstall receives a request from a Data Subject seeking to exercise their rights (including access, rectification, erasure, restriction of processing, data portability, objection, or rights related to automated decision-making), we will promptly notify you and, taking into account the nature of the processing, provide reasonable assistance so you can respond. For more on these rights, see our Privacy Policy at https://neverinstall.com/privacy.
4. Authorized Sub-Processors
To deliver the Services, Neverinstall engages the Sub-processors listed below. Each is bound by written data protection terms no less protective than this DPA. We will give you at least 30 days' notice before adding or replacing a Sub-processor, and you may object on reasonable data-protection grounds.
| Sub-Processor | Location / Hosting | Purpose of Processing |
|---|---|---|
| Microsoft Corporation (Microsoft Azure) | India / Global | Cloud infrastructure and hosting of the Services, including managed PostgreSQL databases for accounts, workspaces, and usage data. |
| Oracle Corporation (Oracle Cloud Infrastructure) | India / Global | Cloud infrastructure and hosting of the Services. |
| Stripe, Inc. and Razorpay Software Private Limited | United States / India | Secure payment processing and billing. |
| Hasura, Inc. | United States / Global | API and control-plane layer for accessing application data. |
| Intercom, Inc. | United States / Global | Customer support, in-app messaging, and support communications. |
5. Security Measures
Neverinstall maintains appropriate technical and organizational measures to protect Personal Data against unauthorized access, loss, or destruction, including:
- Encryption: All data is encrypted at rest (AES-256) and in transit (TLS 1.2+).
- Access control: Role-based access control (RBAC), mandatory multi-factor authentication, and the principle of least privilege applied internally.
- Breach notification: We will notify you of any Personal Data Breach affecting your data without undue delay, and in any event within 48 hours of becoming aware of it, with the information you need to meet your own notification obligations.
6. International Transfers (SCCs)
Where providing the Services involves transferring Personal Data from the EU/EEA, the UK, or Switzerland to countries without an adequacy decision, such transfers are governed by the EU Standard Contractual Clauses (Controller-to-Processor), which are incorporated into this DPA by reference, together with the UK International Data Transfer Addendum where the UK GDPR applies.
7. Data Deletion and Return
Upon termination of our services and your contract, the Processor will, at the choice of the Controller, securely delete or return all Personal Data, unless domestic or international law explicitly requires continued storage.
8. Audit Rights
Neverinstall will make available the information reasonably necessary to demonstrate compliance with this DPA. Upon reasonable written request, we will provide evidence of our security and compliance measures, including relevant third-party audit reports or certifications such as SOC 2, or reasonably cooperate with audits, without compromising the security of other customers.
9. Data Protection Contact
Neverinstall has designated a data protection contact to oversee compliance and answer privacy inquiries:
- Contact
- Ram Pasala
- [email protected]
Related documents
Get Skilled Services Private Limited
Bengaluru, Karnataka
[email protected]